Proszę o pomoc w usunięciu trojanów nie znam się na tym za bardzo załapałem chyba przez skypa;/
Z góry dziekóweczka
Oto log z Combofix...
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.3327.2419 [GMT 2:00]
Uruchomiony z: f:\downland\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning enabled* (Updated)
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Dane aplikacji\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Rataj\Dane aplikacji\psvr32.exe
D:\resycled
d:\resycled\boot.com
E:\resycled
e:\resycled\boot.com
F:\resycled
f:\resycled\boot.com
G:\resycled
g:\resycled\boot.com
I:\resycled
----- BITS: Możliwe zainfekowane strony -----
hxxp://www.dirtysexgames.net
.
((((((((((((((((((((((((( Pliki utworzone od 2009-02-28 do 2009-03-29 )))))))))))))))))))))))))))))))
.
2009-03-29 17:11 . 2009-03-29 17:11 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Grisoft
2009-03-29 15:24 . 2009-03-29 15:24 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\McAfee
2009-03-29 15:08 . 2009-03-29 15:08 <DIR> d-------- c:\documents and settings\Rataj\Dane aplikacji\Thinstall
2009-03-29 04:24 . 2009-03-29 04:24 108,336 --a------ c:\windows\system32\mswinsck.ocx
2009-03-29 03:52 . 2009-03-29 03:52 <DIR> d-------- c:\program files\3wPlayer
2009-03-29 03:51 . 2009-03-29 03:51 465,874 --a------ c:\documents and settings\Rataj\Dane aplikacji\psvrr.exe
2009-03-29 03:50 . 2009-03-29 03:51 <DIR> d-------- c:\documents and settings\Rataj\Dane aplikacji\_78afb80c5a18f9320445e0af0d30615a
2009-03-29 03:50 . 2009-03-29 03:50 714,543 --a------ c:\documents and settings\Rataj\Dane aplikacji\svchost.exe
2009-03-09 23:19 . 2009-03-09 23:19 <DIR> d-------- c:\documents and settings\Rataj\Dane aplikacji\dvdcss
2009-03-07 23:44 . 2009-03-07 23:44 <DIR> d-------- c:\program files\Jasc Software Inc
2009-03-07 23:44 . 2009-03-07 23:44 <DIR> d-------- c:\documents and settings\Rataj\Dane aplikacji\Jasc Software Inc
2009-03-04 22:55 . 2009-03-04 22:55 <DIR> d-------- c:\program files\Streamripper
2009-03-04 22:55 . 2009-03-04 22:55 <DIR> d-------- c:\documents and settings\Rataj\Dane aplikacji\streamripper
2009-03-01 14:22 . 2009-03-01 14:22 <DIR> d-------- C:\scrypty travian
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 18:17 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\skypePM
2009-03-29 18:17 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\Skype
2009-03-29 18:13 53,904 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-29 18:13 5,956,640 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-29 18:13 5,932 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-29 18:13 499,744 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-29 18:13 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\uTorrent
2009-03-29 12:32 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab
2009-03-15 17:53 --------- d-----w c:\program files\Common Files\Adobe
2009-02-22 14:01 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-14 16:53 --------- d-----w c:\program files\OpenAL
2009-02-14 16:53 --------- d-----w c:\program files\Eidos
2009-02-14 01:14 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\Media Player Classic
2009-02-14 01:13 --------- d-----w c:\program files\K-Lite Codec Pack
2009-02-10 14:54 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-02-09 18:15 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\PC Suite
2009-02-09 18:15 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\Nokia
2009-02-09 18:15 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\PC Suite
2009-02-09 18:12 --------- d-----w c:\program files\PC Connectivity Solution
2009-02-09 18:12 --------- d-----w c:\program files\Nokia
2009-02-09 18:12 --------- d-----w c:\program files\DIFX
2009-02-09 18:12 --------- d-----w c:\program files\Common Files\PCSuite
2009-02-09 18:12 --------- d-----w c:\program files\Common Files\Nokia
2009-02-09 18:11 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Installations
2009-02-08 00:11 --------- d-----w c:\program files\Pcsx2_0.9.4
2009-02-05 22:50 --------- d-----w c:\program files\BearShare
2009-02-05 19:08 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\Sony Corporation
2009-02-05 18:57 --------- d-----w c:\program files\Common Files\Sony Shared
2009-02-05 18:57 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\InstallShield
2009-02-05 18:56 --------- d-----w c:\program files\Sony
2009-02-05 18:55 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Sony Corporation
2009-02-05 18:54 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-03 18:22 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-02-03 18:22 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-01 22:59 --------- d-----w c:\program files\Lock My PC 4
2009-02-01 21:23 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Codemasters
2009-02-01 19:43 --------- d-----w c:\program files\Gadu-Gadu
2009-02-01 15:59 22,328 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-02-01 15:59 22,328 ----a-w c:\documents and settings\Rataj\Dane aplikacji\PnkBstrK.sys
2009-02-01 14:55 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-02-01 14:55 --------- d-----w c:\program files\AGEIA Technologies
2009-01-31 14:00 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\vlc
2009-01-31 13:58 --------- d-----w c:\program files\VideoLAN
2009-01-31 12:55 --------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2009-01-31 00:42 --------- d-----w c:\program files\SystemRequirementsLab
2009-01-30 23:51 --------- d-----w c:\program files\Skype
2009-01-30 23:51 --------- d-----w c:\program files\Common Files\Skype
2009-01-30 23:51 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Skype
2009-01-30 21:55 --------- d-----w c:\program files\Rockstar Games
2009-01-30 21:52 --------- d-----w c:\program files\Usb to Serial Driver 1.12.28
2009-01-30 21:33 --------- d-----w c:\program files\Vimicro
2009-01-30 20:48 --------- d-----w c:\program files\Kaspersky Lab
2009-01-30 20:44 --------- d--h--r c:\documents and settings\Rataj\Dane aplikacji\SecuROM
2009-01-30 20:26 --------- d-----w c:\program files\Winamp
2009-01-30 20:08 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2009-01-30 19:46 --------- d-----w c:\program files\MSBuild
2009-01-30 19:44 --------- d-----w c:\program files\Reference Assemblies
2009-01-30 19:30 --------- d-----w c:\program files\uTorrent
2009-01-30 19:24 --------- d-----w c:\program files\Java
2009-01-30 19:21 --------- d-----w c:\program files\Switch Off
2009-01-30 19:19 --------- d-----w c:\program files\Common Files\Ahead
2009-01-30 19:19 --------- d-----w c:\program files\Ahead
2009-01-30 19:18 --------- d-----w c:\program files\DAEMON Tools
2009-01-30 19:12 639,224 ----a-w c:\windows\system32\drivers\sptd.sys
2009-01-30 19:10 --------- d-----w c:\program files\ACDSee32
2009-01-30 18:58 --------- d-----w c:\program files\totalcmd
2009-01-30 18:56 --------- d-----w c:\documents and settings\Rataj\Dane aplikacji\Creative
2009-01-30 18:56 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Creative
2009-01-30 18:54 --------- d-----w c:\program files\Creative
2009-01-30 18:53 --------- d--h--w c:\program files\Creative Installation Information
2009-01-30 18:53 --------- d-----w c:\program files\Common Files\Creative
2009-01-30 18:25 --------- d-----w c:\program files\ASUS
2009-01-30 18:19 --------- d-----w c:\program files\Intel
2009-01-30 18:10 --------- d-----w c:\program files\microsoft frontpage
2009-01-30 18:09 --------- d-----w c:\program files\Usługi online
2006-06-24 22:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\StrongGG.exe" [2007-12-08 21504]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"lmpc4"="c:\program files\Lock My PC 4\lockpc.exe" [2006-10-06 818176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Six Engine"="c:\program files\ASUS\EPU-6 Engine\SixEngine.exe" [2008-07-04 5968384]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-11-19 1970176]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-30 136600]
"BigDog303"="c:\windows\VM303_STI.EXE" [2005-06-23 61440]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"WMAAD"="c:\program files\Sony\WALKMAN Launcher\WMAAD.exe" [2007-02-16 110592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"*ctfmon32"="c:\documents and settings\Rataj\Dane aplikacji\svchost.exe" [2009-03-29 714543]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-10 201992]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
"P17Helper"="P17.dll" [2005-05-03 c:\windows\system32\P17.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]
2006-11-02 14:44 39936 c:\windows\system32\fsp_lmwl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2007-03-23 14:20 227328 c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"c:\\Documents and Settings\\All Users\\Dane aplikacji\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Polish\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"d:\\games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\games\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\BearShare\\Bearshare.exe"=
"d:\\games\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-03-25 24592]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2009-01-30 36864]
R3 LMPC4;LMPC4;c:\windows\system32\drivers\lmpc4.sys [2009-01-31 6656]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c6fb307c-eefe-11dd-aec2-806d6172696f}]
\Shell\AutoRun\command - j:\bin\ASSETUP.exe
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKCU-Run-Windows Update Utility - c:\program files\Mozilla Firefox\svchast.exe
HKCU-Run-WinProx32_1 - c:\documents and settings\Rataj\Ustawienia lokalne\Temp\part.exe
HKLM-Run-WinProx32_1 - c:\documents and settings\Rataj\Ustawienia lokalne\Temp\part.exe
.
------- Skan uzupełniający -------
.
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Rataj\Dane aplikacji\Mozilla\Firefox\Profiles\dtxtjjt6.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-29 20:17:12
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)????????????????0?????????@??????????????
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_USERS\S-1-5-21-854245398-515967899-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:b3,90,02,ad,35,d9,60,ab,0a,ad,a1,b3,32,6a,5d,5c,63,3a,b7,86,85,
a5,f8,db,6c,11,91,4c,f8,4b,20,17,66,3c,67,28,45,1a,4c,fa,ab,20,5c,40,e4,d4,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'winlogon.exe'(1124)
c:\windows\system32\fsp_lmwl.dll
c:\windows\system32\klogon.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Gadu-Gadu\gg.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Czas ukończenia: 2009-03-29 20:18:38 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-03-29 18:18:35
Przed: 4 440 207 360 bajtów wolnych
Po: 4,506,959,872 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
243 --- E O F --- 2009-03-13 19:27:38