Skocz do zawartości


Zdjęcie

Logi - Szalejący kursor myszy


  • Zamknięty Temat jest zamknięty
3 odpowiedzi w tym temacie

#1 aras16

aras16

    Początkujący

  • 66 postów

Napisano 01 08 2008 - 00:05

Witam
Od pewnego czasu, gdy zostawię mysz na chwile, kursor zaczyna się sam poruszać. Mysz jest dobra ponieważ sprawdziłem ją na innym komputerze,a poza tym mam inną uszkodzoną mysz i w niej kursor przesuwa sie minimalnie a w tym przypadku kursor "lata" po całym ekranie. ComboFix wykrył pliki i klucze rejestru i usunął ale wolę poradzić się bardziej doświadczonych userów. Komputer skanowałem Avastem, AdAvare, SpywareDoctor i nic nie wykryło.
Oto logi:
HJT
Logfile of Trend Micro HijackThis v2.0.2Scan saved at 23:54:45, on 2008-07-31Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Alwil Software\Avast4\aswUpdSv.exeC:\Program Files\Alwil Software\Avast4\ashServ.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\DAEMON Tools Lite\daemon.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\tlntsvr.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\explorer.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url="http://google.pl/"]http://google.pl/[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url="http://go.microsoft.com/fwlink/?LinkId=69157"]http://go.microsoft.com/fwlink/?LinkId=69157[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url="http://go.microsoft.com/fwlink/?LinkId=54896"]http://go.microsoft.com/fwlink/?LinkId=54896[/url]R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ŁączaO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exeO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /trayO4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorunO4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exeO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dllO23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exeO23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe--End of file - 3688 bytes
ComboFix
ComboFix 08-07-31.01 - xxx 2008-07-31 23:51:20.1 - NTFSx86Microsoft Windows XP Professional  5.1.2600.2.1250.1.1045.18.1668 [GMT 2:00]Running from: C:\Documents and Settings\xxx\Pulpit\ComboFix.exe * Created a new restore point<strong class='bbc'>WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED Dołączona grafika</strong>.(((((((((((((((((((((((((((((((((((((((   Other Deletions   ))))))))))))))))))))))))))))))))))))))))))))))))).C:\WINDOWS\clofghls.dll.(((((((((((((((((((((((((   Files Created from 2008-06-28 to 2008-07-31  ))))))))))))))))))))))))))))))).2008-07-31 11:15 . 2008-07-31 11:15	<DIR>	d--------	C:\Program Files\Ortalion Entertainment2008-07-28 20:59 . 2008-07-28 20:59	<DIR>	d--------	C:\Program Files\Lavalys2008-07-24 12:00 . 2008-07-31 10:48	<DIR>	d--------	C:\Program Files\Spyware Doctor2008-07-24 12:00 . 2008-07-24 12:00	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\PC Tools2008-07-24 12:00 . 2008-07-31 23:50	<DIR>	d-a------	C:\Documents and Settings\All Users\Dane aplikacji\TEMP2008-07-24 12:00 . 2008-06-10 21:22	81,288	--a------	C:\WINDOWS\system32\drivers\iksyssec.sys2008-07-24 12:00 . 2008-06-02 15:19	66,952	--a------	C:\WINDOWS\system32\drivers\iksysflt.sys2008-07-24 12:00 . 2008-06-02 15:19	42,376	--a------	C:\WINDOWS\system32\drivers\ikfilesec.sys2008-07-24 12:00 . 2008-06-02 15:19	29,576	--a------	C:\WINDOWS\system32\drivers\kcom.sys2008-07-24 11:33 . 2008-07-24 11:47	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\SecTaskMan2008-07-24 11:14 . 2008-07-24 11:21	287	--a------	C:\WINDOWS\EReg072.dat2008-07-24 11:12 . 2008-07-24 11:12	<DIR>	d--------	C:\Documents and Settings\xxx\WINDOWS2008-07-24 11:12 . 1998-05-01 13:39	299,008	--a------	C:\WINDOWS\uninst.exe2008-07-24 10:29 . 2008-07-24 13:26	987	--a------	C:\emu8086.io2008-07-24 01:49 . 2008-07-24 13:26	<DIR>	d--------	C:\emu80862008-07-24 01:49 . 2004-01-21 18:49	389,120	--a------	C:\WINDOWS\system32\cmax20.ocx2008-07-24 01:02 . 2008-07-24 01:02	<DIR>	d--------	C:\Program Files\IDA Free2008-07-24 01:02 . 2008-07-24 01:02	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\Datarescue2008-07-23 15:48 . 2008-07-24 01:06	<DIR>	d--------	C:\Program Files\Cheat Engine2008-07-23 15:48 . 2007-12-26 17:30	1,970,176	--a------	C:\WINDOWS\system32\d3dx9.dll2008-07-23 15:48 . 2007-12-26 17:30	679,936	--a------	C:\WINDOWS\system32\D3DX81ab.dll2008-07-18 12:02 . 2008-07-18 12:04	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\Equestrian Challenge2008-07-17 10:57 . 2008-07-17 10:57	<DIR>	d--h-----	C:\WINDOWS\system32\GroupPolicy2008-07-16 22:27 . 2008-07-16 22:27	<DIR>	d--------	C:\Program Files\CGN2008-07-16 22:26 . 2008-07-17 00:05	<DIR>	d--------	C:\Program Files\DOSBox-0.722008-07-15 00:56 . 2008-07-15 00:56	<DIR>	d--------	C:\Program Files\Trend Micro2008-07-12 14:53 . 2008-07-12 14:53	<DIR>	dr-h-----	C:\Documents and Settings\xxx\Dane aplikacji\SecuROM2008-07-10 22:29 . 2008-07-10 22:29	61	---hs----	C:\WINDOWS\cnerolf.dat2008-07-10 22:27 . 2008-07-10 22:27	<DIR>	d--------	C:\Program Files\SquawkBox32008-07-10 16:49 . 2001-08-17 22:02	9,600	--a------	C:\WINDOWS\system32\drivers\hidusb.sys2008-07-10 16:49 . 2001-08-17 22:02	9,600	--a--c---	C:\WINDOWS\system32\dllcache\hidusb.sys2008-07-10 11:44 . 2008-07-10 11:44	<DIR>	d--------	C:\Program Files\English Translator 22008-07-10 09:46 . 2008-07-10 09:46	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\Atari2008-07-10 09:42 . 2008-07-10 09:42	<DIR>	d--------	C:\Program Files\Common Files\PocketSoft2008-07-10 09:42 . 2008-07-10 09:42	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\Leadertech2008-07-10 09:42 . 2002-02-27 18:50	197,120	--a------	C:\WINDOWS\patchw32.dll2008-07-09 13:08 . 2008-07-28 13:19	<DIR>	d--------	C:\Program Files\Odkurzacz2008-07-09 12:00 . 2008-07-17 10:22	<DIR>	d--------	C:\siec2008-07-09 10:23 . 2008-07-09 10:25	<DIR>	d--------	C:\Program Files\EA GAMES2008-07-09 09:52 . 2008-07-09 09:52	<DIR>	d--h-----	C:\WINDOWS\PIF2008-07-08 13:08 . 2008-07-08 13:08	<DIR>	d--------	C:\Program Files\WorldUnlock Codes Calculator2008-07-07 15:35 . 2004-08-18 10:34	442,368	-ra------	C:\WINDOWS\system32\vp6vfw.dll2008-07-07 14:52 . 2008-07-07 14:54	<DIR>	d--------	C:\Program Files\YafRay2008-07-07 14:35 . 2008-07-07 15:11	<DIR>	d--------	C:\tmp2008-07-07 14:35 . 2008-07-07 14:35	103,394	--a------	C:\bez tytułu.JPG2008-07-07 00:36 . 2008-07-07 00:36	<DIR>	d--------	C:\Program Files\Blender Foundation2008-07-07 00:36 . 2008-07-07 00:36	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\Blender Foundation2008-07-05 19:06 . 2008-07-05 19:06	<DIR>	d--------	C:\Program Files\ToniArts2008-07-05 14:14 . 2008-07-05 14:14	<DIR>	d--hs----	C:\found.0002008-06-27 13:37 . 2008-06-27 13:37	<DIR>	d--------	C:\Bwgen2008-06-27 13:31 . 2008-06-27 14:04	<DIR>	d--------	C:\Program Files\BrainWave Generator2008-06-27 13:31 . 1998-10-02 19:00	327,168	--a------	C:\WINDOWS\IsUninst.exe2008-06-26 20:12 . 2008-06-26 20:12	<DIR>	d---s----	C:\Documents and Settings\xxx\UserData2008-06-25 20:19 . 2008-06-25 20:19	<DIR>	d--------	C:\Temp2008-06-25 11:42 . 2008-06-25 11:42	1,962,773	--a------	C:\WINDOWS\system32\4.scr2008-06-25 11:40 . 2008-06-25 11:40	968,021	--a------	C:\WINDOWS\system32\1.scr2008-06-24 14:21 . 2008-06-24 14:21	<DIR>	d--------	C:\Program Files\OSWINSCK2008-06-24 14:21 . 2008-06-24 14:21	249,856	---------	C:\WINDOWS\Setup1.exe2008-06-24 14:20 . 2008-06-24 14:20	73,216	--a------	C:\WINDOWS\ST6UNST.EXE2008-06-24 13:30 . 2008-06-24 13:30	<DIR>	d--------	C:\WINDOWS\Downloaded Installations2008-06-24 13:30 . 2008-06-24 13:30	<DIR>	d--------	C:\Program Files\GabbaSoft2008-06-18 16:52 . 2008-06-18 16:52	<DIR>	d--------	C:\WINDOWS\system32\LogFiles2008-06-18 16:52 . 2008-06-18 16:52	<DIR>	d--------	C:\WINDOWS\system32\drivers\UMDF2008-06-18 16:51 . 2008-06-18 20:59	<DIR>	d--------	C:\Program Files\GameShadow2008-06-18 16:44 . 2008-06-18 16:44	<DIR>	d--------	C:\Program Files\OpenAL2008-06-18 16:44 . 2008-06-18 16:44	418,480	--a------	C:\WINDOWS\system32\wrap_oal.dll2008-06-18 16:44 . 2008-06-18 16:44	115,432	--a------	C:\WINDOWS\system32\OpenAL32.dll2008-06-17 19:34 . 2004-08-03 23:08	31,616	--a------	C:\WINDOWS\system32\drivers\usbccgp.sys2008-06-17 19:34 . 2004-08-03 23:08	31,616	--a--c---	C:\WINDOWS\system32\dllcache\usbccgp.sys2008-06-17 16:53 . 2008-06-17 16:53	<DIR>	d--------	C:\Program Files\MGrenda2008-06-16 15:18 . 2008-06-16 15:18	578	--a------	C:\WINDOWS\eReg.dat2008-06-16 11:10 . 2008-06-16 11:10	<DIR>	d--------	C:\Program Files\MarBit2008-06-14 10:38 . 2008-06-14 10:38	<DIR>	d--------	C:\Documents and Settings\xxx\Dane aplikacji\fltk.org2008-06-12 15:29 . 2008-07-31 10:49	116	--a------	C:\WINDOWS\NeroDigital.ini2008-06-12 13:45 . 2008-06-12 13:45	171,520	--a------	C:\WINDOWS\system32\cncs32.dll2008-06-12 13:45 . 2008-06-12 13:45	18	--a------	C:\WINDOWS\gfact.ini2008-06-12 11:49 . 2008-06-12 11:49	<DIR>	d--------	C:\Program Files\Foxit Software2008-06-10 22:13 . 2008-07-01 17:12	<DIR>	d--------	C:\Program Files\Mario Forever2008-06-10 19:10 . 2008-06-14 20:01	273,024	---------	C:\WINDOWS\system32\drivers\bthport.sys2008-06-09 15:57 . 2008-07-12 12:54	<DIR>	d--------	C:\Program Files\EA Sports2008-06-03 20:12 . 2008-07-18 16:07	23,972	--a------	C:\WINDOWS\scct1ses.dat2008-06-03 20:12 . 2008-07-18 16:07	576	--a------	C:\WINDOWS\scct1.dat2008-06-03 18:56 . 2008-07-18 16:07	4	--a------	C:\WINDOWS\scct.cfg2008-06-01 16:06 . 2008-06-01 16:06	<DIR>	d--------	C:\Program Files\WinPcap2008-06-01 16:06 . 2008-06-01 22:18	<DIR>	d--------	C:\Program Files\Cain.((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))).2008-07-29 09:17	---------	d-----w	C:\Documents and Settings\xxx\Dane aplikacji\uTorrent2008-07-10 07:40	---------	d--h--w	C:\Program Files\InstallShield Installation Information2008-07-01 15:10	---------	d-----w	C:\Program Files\ElastoManiaRegistered2008-06-20 17:42	246,784	----a-w	C:\WINDOWS\system32\mswsock.dll2008-06-20 10:45	360,320	----a-w	C:\WINDOWS\system32\drivers\tcpip.sys2008-06-20 10:44	138,368	----a-w	C:\WINDOWS\system32\drivers\afd.sys2008-06-20 09:52	225,920	----a-w	C:\WINDOWS\system32\drivers\tcpip6.sys2008-06-18 14:52	107,888	----a-w	C:\WINDOWS\system32\CmdLineExt.dll2008-06-16 13:16	---------	d-----w	C:\Program Files\Common Files\InstallShield2008-06-01 18:53	---------	d-----w	C:\Documents and Settings\xxx\Dane aplikacji\Winamp2008-06-01 11:10	---------	d-----w	C:\Program Files\Sun2008-06-01 11:08	---------	d-----w	C:\Documents and Settings\xxx\Dane aplikacji\Hamachi2008-05-31 18:21	---------	d-----w	C:\Program Files\Gadu-Gadu2008-05-31 17:16	---------	d-----w	C:\Documents and Settings\xxx\Dane aplikacji\InternetCalls2008-05-31 17:15	---------	d-----w	C:\Program Files\InternetCalls.com2008-05-30 14:05	---------	d-----w	C:\Documents and Settings\xxx\Dane aplikacji\mIRC2008-05-30 12:55	---------	d-----w	C:\Program Files\mIRC2008-05-28 16:09	---------	d-----w	C:\Program Files\WebServ2008-05-28 13:32	---------	d-----w	C:\Program Files\BearShare2008-05-26 17:38	28,006	----a-w	C:\Program Files\wsock32.dll2008-05-23 11:43	14,656	----a-w	C:\WINDOWS\gdrv.sys2008-05-23 11:41	315,392	----a-w	C:\WINDOWS\HideWin.exe2008-05-07 05:16	1,291,264	----a-w	C:\WINDOWS\system32\quartz.dll2008-04-30 15:27	442,368	----a-w	C:\WINDOWS\system32\NVUNINST.EXE2008-04-21 07:03	662,016	----a-w	C:\WINDOWS\system32\wininet.dll2004-08-03 22:44	24,064	----a-w	C:\Program Files\wsock32_org.dll.(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 12:04 2127296]"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 14:44 266240][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360][HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]--a------ 2006-08-01 17:04 3313664 C:\Program Files\BearShare\BearShare.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InternetCalls]--a------ 2007-04-18 15:49 7116352 C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]--a------ 2008-03-25 04:28 144784 C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]-r------- 2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="H:\\Program Files\\EA Sports\\UEFA EURO 2008\\EURO08.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe"="D:\\Program Files\\Counter-Strike\\hl.exe"="C:\\Program Files\\Gadu-Gadu\\gg.exe"="C:\\Program Files\\BearShare\\BearShare.exe"="C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\WebServ\\apache2\\bin\\WebServ(apache).exe"="C:\\Program Files\\WebServ\\mysql\\bin\\WebServ(mysqld).exe"="C:\\Program Files\\InternetCalls.com\\InternetCalls\\InternetCalls.exe"="C:\\WINDOWS\\system32\\mshta.exe"="D:\\Program Files\\Microsoft Games\\Flight Simulator 9\\fs9.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\Program Files\\SquawkBox3\\squawkbox.exe"="H:\\Program Files\\Electronic Arts\\Need For Speed III\\nfs3.exe"=R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]S3 cpuz129;cpuz129;C:\DOCUME~1\KWASIG~1\USTAWI~1\Temp\cpuz_x32.sys []S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 22:22]*Newly Created Service* - CATCHME*Newly Created Service* - PROCEXP90.- - - - ORPHANS REMOVED - - - -Notify-WgaLogon - (no file).------- Supplementary Scan -------.FireFox -: Profile - C:\Documents and Settings\xxx\Dane aplikacji\Mozilla\Firefox\Profiles\uc3tu15m.default\FireFox -: prefs.js - STARTUP.HOMEPAGE - google.pl**************************************************************************catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]Rootkit scan 2008-07-31 23:52:16Windows 5.1.2600 Dodatek Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.Completion time: 2008-07-31 23:53:23ComboFix-quarantined-files.txt  2008-07-31 21:52:50Pre-Run: 102,998,016 bajtów wolnychPost-Run: 836,595,712 bajtów wolnych196	--- E O F ---	2008-07-09 11:41:32


Z góry dziękuje za pomoc.
Pozdrawiam :P

  • 0

#2 ordynat

ordynat

    Zaawansowany użytkownik

  • 804 postów

Napisano 01 08 2008 - 20:09

C:\WINDOWS\scct1ses.dat
C:\WINDOWS\scct1.dat
C:\WINDOWS\scct.cfg

Sprawdź je na --> http://virusscan.jotti.org/
albo na http://www.virustotal.com/en/indexf.html.

C:\Program Files\wsock32.dll
C:\Program Files\wsock32_org.dll

Znasz te programy?

FireFox -: Profile - C:\Documents and Settings\xxx\Dane aplikacji\Mozilla\Firefox\Profiles\uc3tu15m.default\

Twoje?

Nic tu więcej podejrzanego nie widzę.

Jeśli to nie myszka "nawaliła", to oddaj komputer do jakiegoś serwisu naprawczego, niech przejrzą wszystkie części i połączenia.

ordynat

  • 0

#3 aras16

aras16

    Początkujący

  • 66 postów

Napisano 01 08 2008 - 20:56

C:\WINDOWS\scct1ses.dat
C:\WINDOWS\scct1.dat
C:\WINDOWS\scct.cfg

Pliki, w których są zapisane statystyki od timera.

C:\Program Files\wsock32.dll
C:\Program Files\wsock32_org.dll

Znam

FireFox -: Profile - C:\Documents and Settings\xxx\Dane aplikacji\Mozilla\Firefox\Profiles\uc3tu15m.default\

Mój profil.


Co zrobić z plikiem i kluczami rejestru dodanymi do kwarantanny?
  • 0

#4 ordynat

ordynat

    Zaawansowany użytkownik

  • 804 postów

Napisano 01 08 2008 - 21:36

Usuń ręcznie folder C:\Qoobox.

ordynat

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych