Skocz do zawartości


Zdjęcie

Logi - Usunięcie "trojan.W32.looksky"


  • Zamknięty Temat jest zamknięty
6 odpowiedzi w tym temacie

#1 Stratos

Stratos

    Nowy

  • 1 postów

Napisano 31 08 2007 - 11:51

Od niedzawna mam taki problem z tym trojanem z 10 razy juz przeskanowalem komputer pelnym skanem i nic nie wykryto a wciaz mi sie pokazuje alert ze istnieje ten virus i zeby go usunac musze sciagnac Ultimate Defender'a. I nie mam pojecia zielonego co mam zrobic, a jeszcze zmienil mi sie puplit na czerwony z ostrzezeniem ze moja prywatnosc jest naruszaszna. Prosze o pomoc i dziekuje z gory .A co do tego puplitu to nie moge go usunac zmieniajac na inny to jakby reklama sama w sobie gdy nacisne na pulpit wyrzuca mnie do jakiejs stronki z kolejnym programem prosze o pomoc.

  • 0

#2 mgx8

mgx8

    Początkujący

  • 148 postów

Napisano 31 08 2007 - 11:51

Może trochę głupia ta odpowiedź, będzie, ale tego wirusa jest ciężko wywalić z systemu, więc zalecam zrobić formata

  • 0

#3 Maciej13

Maciej13

    SecurityMaster

  • 261 postów

Napisano 01 09 2007 - 23:03

Może trochę głupia ta odpowiedź, będzie, ale tego wirusa jest ciężko wywalić z systemu, więc zalecam zrobić formata


Następna taka porada, a post wyleci.

Pokaż logi z Hijack This + Silent Runners.
  • 0

#4 pakapi

pakapi

    Nowy

  • 2 postów

Napisano 05 09 2007 - 18:22

Witam!
Mam ten sam problem a nie chce formatować dysku!!
Tu są moje logi z hijack'a i silent runnera

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:24:44, on 2007-09-05
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Programy\Avast\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
D:\Programy\Avast\ashServ.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
D:\Programy\Deamon Tools\daemon.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programy\Avast\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
D:\Programy\Bluesoleil\BlueSoleil.exe
D:\Programy\HP F380\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programy\Bluesoleil\BTNtService.exe
D:\Programy\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
D:\Programy\HP F380\Digital Imaging\bin\hpqSTE08.exe
D:\Programy\Avast\ashWebSv.exe
D:\Programy\Avast\ashMaiSv.exe
D:\Programy\Opera\Opera.exe
C:\Program Files\Neostrada TP\NeostradaTP.exe
C:\Program Files\Neostrada TP\ComComp.exe
C:\Program Files\Neostrada TP\Watch.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://szukaj.wp.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programy\Adobe Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Programy\BitComet\tools\BitCometBHO_1.1.3.28.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSVPS System - {F4CF814F-970F-405D-A42C-0CE06EB97373} - C:\WINDOWS\mxduo.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Programy\Deamon Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programy\Avast\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HP Software Update] D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "D:\Programy\Finereader\AbbyyNewsReader.exe"
O4 - HKLM\..\Run: [TrojanScanner] D:\Programy\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Programy\Gadu-Gadu\gg.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Programy\HP F380\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programy\Adobe Reader\Reader\reader_sl.exe
O8 - Extra context menu item: Download all links using BitComet - res://D:\Programy\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://D:\Programy\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://D:\Programy\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{724B933A-BC25-4B62-969D-BEC19221D217}: NameServer = 194.204.159.1 217.98.63.164
O21 - SSODL: wmphost - {CBC10224-33DD-4D96-80B9-6C699DB418A3} - C:\WINDOWS\wmphost.dll
O21 - SSODL: wmpdev - {AC9BCCD4-5425-49F5-AE5D-A826571D1CFB} - C:\WINDOWS\wmpdev.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Programy\Avast\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programy\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programy\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programy\Avast\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Programy\Bluesoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Programy\Alcohol 120\StarWind\StarWindServiceAE.exe
O24 - Desktop Component 1: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 6414 bytes


SILENT RUNNER

"Silent Runners.vbs", revision 52, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"Gadu-Gadu" = ""D:\Programy\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"WOOWATCH" = "C:\PROGRA~1\NEOSTR~1\Watch.exe" ["France Télécom R&D"]
"SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
"DAEMON Tools-1033" = ""D:\Programy\Deamon Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
"avast!" = "D:\Programy\Avast\ashDisp.exe" ["ALWIL Software"]
"BluetoothAuthenticationAgent" = "rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" [MS]
"HP Software Update" = "D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Development Company, L.P."]
"WOOTASKBARICON" = "C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" ["France Télécom R&D"]
"WooCnxMon" = "C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [empty string]
"FineReader7NewsReaderPro" = ""D:\Programy\Finereader\AbbyyNewsReader.exe"" ["ABBYY (BIT Software)"]
"TrojanScanner" = "D:\Programy\Trojan Remover\Trjscan.exe" ["Simply Super Software"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "D:\Programy\Adobe Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
\InProcServer32\(Default) = "D:\Programy\BitComet\tools\BitCometBHO_1.1.3.28.dll" ["BitComet"]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Notifier BHO"
\InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll" ["Google Inc."]
{F4CF814F-970F-405D-A42C-0CE06EB97373}\(Default) = (no title provided)
-> {HKLM...CLSID} = "MSVPS System"
\InProcServer32\(Default) = "C:\WINDOWS\mxduo.dll" [empty string]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "D:\Programy\WinRar\rarext.dll" [null data]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "D:\Programy\Avast\ashShell.dll" ["ALWIL Software"]
"{52B87208-9CCF-42C9-B88E-069281105805}" = "Trojan Remover Shell Extension"
-> {HKLM...CLSID} = "Trojan Remover Shell Extension"
\InProcServer32\(Default) = "D:\Programy\TROJAN~1\Trshlex.dll" ["Simply Super Software"]

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"wmphost" = "{CBC10224-33DD-4D96-80B9-6C699DB418A3}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\wmphost.dll" [null data]
"wmpdev" = "{AC9BCCD4-5425-49F5-AE5D-A826571D1CFB}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\wmpdev.dll" [null data]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\Software\Classes\PROTOCOLS\Filter\
<<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "D:\Programy\Adobe Reader\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "D:\Programy\Avast\ashShell.dll" ["ALWIL Software"]
ContMenu\(Default) = "{EBDF1F20-C829-11D1-8233-0020AF3E97A9}"
-> {HKLM...CLSID} = " "
\InProcServer32\(Default) = "D:\Programy\AnyReader\contmenu.dll" [null data]
Trojan Remover\(Default) = "{52B87208-9CCF-42C9-B88E-069281105805}"
-> {HKLM...CLSID} = "Trojan Remover Shell Extension"
\InProcServer32\(Default) = "D:\Programy\TROJAN~1\Trshlex.dll" ["Simply Super Software"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "D:\Programy\WinRar\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ContMenu\(Default) = "{EBDF1F20-C829-11D1-8233-0020AF3E97A9}"
-> {HKLM...CLSID} = " "
\InProcServer32\(Default) = "D:\Programy\AnyReader\contmenu.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "D:\Programy\WinRar\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
-> {HKLM...CLSID} = "avast"
\InProcServer32\(Default) = "D:\Programy\Avast\ashShell.dll" ["ALWIL Software"]
FineReader\(Default) = "{AC0DD14A-8F29-4F88-BE1D-0F0ED1B06C9F}"
-> {HKLM...CLSID} = "FineReaderExplorerContextMenuHandler"
\InProcServer32\(Default) = "d:\programy\finereader\fecmenu.dll" ["ABBYY (BIT Software)"]
Trojan Remover\(Default) = "{52B87208-9CCF-42C9-B88E-069281105805}"
-> {HKLM...CLSID} = "Trojan Remover Shell Extension"
\InProcServer32\(Default) = "D:\Programy\TROJAN~1\Trshlex.dll" ["Simply Super Software"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "D:\Programy\WinRar\rarext.dll" [null data]


Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------

Note: detected settings may not have any effect.

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\pakapipl\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"

Active Desktop web content (hidden if disabled):

HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\1\
"FriendlyName" = "Privacy Protection"
"Source" = "file:///C:\WINDOWS\privacy_danger\index.htm"
"SubscribedURL" = ""


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


Startup items in "pakapipl" & "All Users" startup folders:
----------------------------------------------------------

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
"BlueSoleil" -> shortcut to: "D:\Programy\Bluesoleil\BlueSoleil.exe" ["IVT Corporation"]
"HP Digital Imaging Monitor" -> shortcut to: "D:\Programy\HP F380\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Development Company, L.P."]
"Adobe Reader Speed Launch" -> shortcut to: "D:\Programy\Adobe Reader\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000004\LibraryPath = "%SystemRoot%\system32\wshbth.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 18
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
-> {HKLM...CLSID} = "&Google"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

Explorer Bars

HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\(Default) = "Volet Wanadoo"
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]

HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\(Default) = "ToolBand Class"
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]

HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\(Default) = "Volet Wanadoo"
Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\audience\audience.dll" [empty string]

HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Badanie"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
"ButtonText" = "Badanie"


Miscellaneous IE Hijack Points
------------------------------

HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
<<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
-> {HKLM...CLSID} = "Search Class"
\InProcServer32\(Default) = "C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL" [empty string]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
avast! Antivirus, avast! Antivirus, ""D:\Programy\Avast\ashServ.exe"" ["ALWIL Software"]
avast! iAVS4 Control Service, aswUpdSv, ""D:\Programy\Avast\aswUpdSv.exe"" ["ALWIL Software"]
avast! Mail Scanner, avast! Mail Scanner, ""D:\Programy\Avast\ashMaiSv.exe" /service" ["ALWIL Software"]
avast! Web Scanner, avast! Web Scanner, ""D:\Programy\Avast\ashWebSv.exe" /service" ["ALWIL Software"]
BlueSoleil Hid Service, BlueSoleil Hid Service, "D:\Programy\Bluesoleil\BTNtService.exe" [null data]
Bluetooth Support Service, BthServ, "C:\WINDOWS\system32\svchost.exe -k bthsvcs" {"C:\WINDOWS\System32\bthserv.dll" [MS]}
StarWind AE Service, StarWindServiceAE, "D:\Programy\Alcohol 120\StarWind\StarWindServiceAE.exe" ["Rocket Division Software"]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
HP Standard TCP/IP Port\Driver = "HpTcpMon.dll" ["Hewlett Packard"]
LIDIL hpzll054\Driver = "hpzll054.dll" ["Hewlett-Packard Company"]
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]


---------- (launch time: 2007-09-05 18:27:05)
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 64 seconds, including 9 seconds for message boxes)


  • 0

#5 Grupens

Grupens

    Początkujący

  • 23 postów

Napisano 05 09 2007 - 19:27

Odwiedż stronę, gdzie znajdują sie antywirusy on-line np. panda lub inne. Powinno pomóc.
  • 0

#6 Maciej13

Maciej13

    SecurityMaster

  • 261 postów

Napisano 06 09 2007 - 15:09

Użyj SmitFraudFix z opcji 2 w Trybie Awaryjnym.

Po pracy pokaż logi z: Hijack + Silent + ComboFix.
  • 0

#7 pakapi

pakapi

    Nowy

  • 2 postów

Napisano 06 09 2007 - 19:40

Z ekranu zniknęła reklama i zrobił się niebieski (tzn tapetą jest niebieski kolor).
Ponadto narazie już nie wyskakuja te głupie okienka.
A tu logi po użyciu Smitfraudfix'a

Hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:40:33, on 2007-09-06
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
D:\Programy\Avast\aswUpdSv.exe
D:\Programy\Avast\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
D:\Programy\Deamon Tools\daemon.exe
C:\WINDOWS\system32\RunDll32.exe
D:\Programy\Avast\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
D:\Programy\Gadu-Gadu\gg.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programy\Bluesoleil\BlueSoleil.exe
D:\Programy\HP F380\Digital Imaging\bin\hpqtra08.exe
D:\Programy\Adobe Reader\Reader\reader_sl.exe
D:\Programy\Bluesoleil\BTNtService.exe
C:\WINDOWS\system32\HPZipm12.exe
D:\Programy\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
D:\Programy\Avast\ashMaiSv.exe
D:\Programy\Avast\ashWebSv.exe
D:\Programy\HP F380\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Neostrada TP\NeostradaTP.exe
C:\Program Files\Neostrada TP\ComComp.exe
C:\Program Files\Neostrada TP\Watch.exe
D:\Programy\Opera\Opera.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada TP
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programy\Adobe Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - D:\Programy\BitComet\tools\BitCometBHO_1.1.3.28.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Programy\Deamon Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [avast!] D:\Programy\Avast\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HP Software Update] D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "D:\Programy\Finereader\AbbyyNewsReader.exe"
O4 - HKLM\..\Run: [TrojanScanner] D:\Programy\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Programy\Gadu-Gadu\gg.exe" /tray
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Programy\HP F380\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Programy\Adobe Reader\Reader\reader_sl.exe
O8 - Extra context menu item: Download all links using BitComet - res://D:\Programy\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://D:\Programy\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://D:\Programy\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{724B933A-BC25-4B62-969D-BEC19221D217}: NameServer = 194.204.159.1 217.98.63.164
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Programy\Avast\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Programy\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Programy\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Programy\Avast\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Programy\Bluesoleil\BTNtService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Programy\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 5985 bytes


Silent

"Silent Runners.vbs", revision 52, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"Gadu-Gadu" = ""D:\Programy\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"WOOWATCH" = "C:\PROGRA~1\NEOSTR~1\Watch.exe" ["France Télécom R&D"]
"SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
"DAEMON Tools-1033" = ""D:\Programy\Deamon Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
"Cmaudio" = "RunDll32 cmicnfg.cpl,CMICtrlWnd" [MS]
"avast!" = "D:\Programy\Avast\ashDisp.exe" ["ALWIL Software"]
"BluetoothAuthenticationAgent" = "rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" [MS]
"HP Software Update" = "D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Development Company, L.P."]
"WOOTASKBARICON" = "C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" ["France Télécom R&D"]
"WooCnxMon" = "C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [empty string]
"FineReader7NewsReaderPro" = ""D:\Programy\Finereader\AbbyyNewsReader.exe"" ["ABBYY (BIT Software)"]
"TrojanScanner" = "D:\Programy\Trojan Remover\Trjscan.exe" ["Simply Super Software"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
\InProcServer32\(Default) = "D:\Programy\Adobe Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\(Default) = "BitComet ClickCapture"
-> {HKLM...CLSID} = "BitComet Helper"
\InProcServer32\(Default) = "D:\Programy\BitComet\tools\BitCometBHO_1.1.3.28.dll" ["BitComet"]
{AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Helper"
\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Google Toolbar Notifier BHO"
\InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll" ["Google Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"
-> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]


Combofix

ComboFix 07-08-30.3 - "pakapipl" 2007-09-06 19:44:20.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.210 [GMT 2:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 19:43 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-09-06 19:31 2,728 --a------ C:\WINDOWS\system32\tmp.reg
2007-09-04 18:49 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2007-09-04 18:49 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2007-09-04 18:49 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2007-09-04 18:49 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2007-09-04 18:49 <DIR> d-------- C:\DOCUME~1\pakapipl\DANEAP~1\Simply Super Software
2007-09-04 18:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\TEMP
2007-09-04 18:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Simply Super Software
2007-09-04 18:42 <DIR> d-------- C:\Program Files\Trend Micro
2007-09-02 19:59 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\ABBYY
2007-08-29 14:04 <DIR> d-------- C:\DOCUME~1\pakapipl\DANEAP~1\Winamp
2007-08-28 18:02 966,144 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2007-08-28 18:02 877,568 --a------ C:\WINDOWS\system32\NCTAudioFile2.dll
2007-08-28 18:02 634,880 --a------ C:\WINDOWS\system32\NCTAudioEditor2.dll
2007-08-28 18:02 522,752 --a------ C:\WINDOWS\system32\NCTAudioTransform2.dll
2007-08-28 18:02 467,968 --a------ C:\WINDOWS\system32\NCTAudioRecord2.dll
2007-08-28 18:02 467,456 --a------ C:\WINDOWS\system32\NCTAudioPlayer2.dll
2007-08-28 18:02 307,200 --a------ C:\WINDOWS\system32\msvcr70.dll
2007-08-28 18:02 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2007-08-28 18:02 <DIR> d-------- C:\DOCUME~1\pakapipl\DANEAP~1\concept design
2007-08-28 17:20 <DIR> d-------- C:\Program Files\Yahoo!
2007-08-24 23:03 <DIR> d-------- C:\DOCUME~1\pakapipl\DANEAP~1\InstallShield
2007-08-19 09:31 <DIR> d-------- C:\WINDOWS\CSI Kryminalne zagadki Miami
2007-08-18 15:47 1 --a------ C:\WINDOWS\system32\SI.bin
2007-08-17 00:08 <DIR> d-------- C:\DOCUME~1\pakapipl\DANEAP~1\Opera
2007-08-16 19:56 <DIR> d-------- C:\Program Files\Web Photo Album
2007-08-15 09:23 <DIR> d-------- C:\Program Files\Common Files\DirectX
2007-08-13 14:08 245,760 --------- C:\WINDOWS\system32\DECO_32.DLL
2007-08-13 13:50 <DIR> d-------- C:\WINDOWS\UbiSoft
2007-08-13 13:49 12 --a------ C:\WINDOWS\bthservsdp.dat
2007-08-13 13:38 63,488 --a------ C:\WINDOWS\system32\unam4ie.exe
2007-08-13 13:38 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-08-13 13:38 38,160 --a------ C:\WINDOWS\system32\LMRTREND.dll
2007-08-13 13:38 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-08-13 13:38 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2007-08-13 13:38 182,032 --a------ C:\WINDOWS\system32\dxtmsft3.dll
2007-08-13 13:38 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-08-06 19:44 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-08-06 16:34 274,432 --------- C:\WINDOWS\TLCUninstall.exe
2007-08-06 16:34 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\The Learning Company


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-15 19:29 98304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-08-05 14:27 --------- d-------- C:\DOCUME~1\pakapipl\DANEAP~1\Switchball
2007-08-05 14:23 --------- d-------- C:\Program Files\AGEIA Technologies
2007-08-05 14:11 --------- d-------- C:\DOCUME~1\ALLUSE~1\DANEAP~1\Trymedia
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\dllcache\cdm.dll
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\dllcache\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\dllcache\wucltui.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\dllcache\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\dllcache\wups.dll
2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-07-22 13:13 295 --a------ C:\Program Files\INSTALL.LOG
2007-07-10 18:55 7680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2007-07-06 21:36 --------- d-------- C:\Program Files\Fantasysoft-Studio
2007-07-06 21:35 --------- d-------- C:\DOCUME~1\pakapipl\DANEAP~1\CoreCodec
2007-07-06 21:34 --------- d-------- C:\Program Files\Haali
2007-07-06 21:34 --------- d-------- C:\Program Files\CoreCodec
2007-06-28 18:54 180224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2007-06-28 18:52 765952 --a------ C:\WINDOWS\system32\xvidcore.dll
2007-06-26 16:15 661504 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-26 15:57 851968 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-26 08:10 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-18 14:26 32768 --a------ C:\WINDOWS\system32\INPOUT32.DLL
2007-06-18 13:00 796672 --a------ C:\WINDOWS\GPInstall.exe
2007-06-17 12:14 2368 --a------ C:\WINDOWS\system32\SVKP.sys
2007-06-16 11:06 73216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-06-16 11:06 249856 --------- C:\WINDOWS\Setup1.exe
2007-06-14 20:11 96768 --a------ C:\WINDOWS\system32\dllcache\inseng.dll
2007-06-14 20:11 616448 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-14 20:11 55808 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-14 20:11 532480 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-14 20:11 474112 --a------ C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-06-14 20:11 449024 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-14 20:11 39424 --a------ C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-06-14 20:11 357888 --a------ C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-06-14 20:11 3079680 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
2007-06-14 20:11 251392 --a------ C:\WINDOWS\system32\dllcache\iepeers.dll
2007-06-14 20:11 205312 --a------ C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-06-14 20:11 16384 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-14 20:11 151552 --a------ C:\WINDOWS\system32\dllcache\cdfview.dll
2007-06-14 20:11 1494528 --a------ C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-06-14 20:11 146432 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-14 20:11 1055744 --a------ C:\WINDOWS\system32\dllcache\danim.dll
2007-06-14 20:11 1023488 --a------ C:\WINDOWS\system32\dllcache\browseui.dll
2007-06-14 16:07 18432 --a------ C:\WINDOWS\system32\dllcache\iedw.exe
2007-06-13 15:23 1034752 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 15:23 1034752 --a------ C:\WINDOWS\explorer.exe
2007-06-10 11:01 2627 --a------ C:\WINDOWS\system32\smport.sys
2007-06-09 06:14 564224 --a------ C:\WINDOWS\system32\x264vfw.dll
2007-06-08 10:54 23 --ahs---- C:\WINDOWS\system32\dabea2_r.dll
2007-03-19 20:13 6422611 --a------ C:\Program Files\frostwire-4.13.1.6.windows.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 19:07]
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38]
"DAEMON Tools-1033"="D:\Programy\Deamon Tools\daemon.exe" [2004-08-22 17:05]
"Cmaudio"="cmicnfg.cpl" []
"avast!"="D:\Programy\Avast\ashDisp.exe" [2007-07-28 00:03]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 22:44 C:\WINDOWS\system32\bthprops.cpl]
"HP Software Update"="D:\Programy\HP F380\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 19:07]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 19:07]
"FineReader7NewsReaderPro"="D:\Programy\Finereader\AbbyyNewsReader.exe" [2003-12-10 00:19]
"TrojanScanner"="D:\Programy\Trojan Remover\Trjscan.exe" [2007-09-04 13:26]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="D:\Programy\Gadu-Gadu\gg.exe" [2007-01-30 16:58]

R1 hwinterface;hwinterface;C:\WINDOWS\system32\Drivers\hwinterface.sys
R2 SVKP;SVKP;\??\C:\WINDOWS\system32\SVKP.sys
R3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 SER120;OTI Serial port driver;C:\WINDOWS\system32\DRIVERS\SER120.sys
S3 Smport;Smport;\??\C:\WINDOWS\system32\Smport.sys
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

*Newly Created Service* - CATCHME

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 19:45:37
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 19:46:23
C:\ComboFix-quarantined-files.txt ... 2007-09-06 19:46

--- E O F ---



  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych