Skocz do zawartości


Zdjęcie

Logi - Ścinki w grach


  • Zamknięty Temat jest zamknięty
1 odpowiedź w tym temacie

#1 MythiQ

MythiQ

    Początkujący

  • 16 postów

Napisano 11 06 2008 - 12:25

Witam to znów ja tak jak mówiłem wkleję tutaj swojego loga z HJT ponieważ mój komputer nie chodzi na miarę swoich możliwości, a większość gier, w tym starych po prostu ścina się. Za wszystkie porady, DZIĘKUJĘ! DALEJ POMÓŻCIE!Dołączona grafikaDALEJ POMÓŻCIE!Dołączona grafika

LOG Z HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:24:05, on 2008-06-11
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Documents and Settings\Myth\Pulpit\System\Diskeeper Lite\DKService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/pl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0 CE\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Documents and Settings\MaQ\Pulpit\System\Diskeeper Lite\DKService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 5888 bytes

Dodam, że ostatnio zmieniłem program antywirusowy z Avasta na NODA32.

Na prośbę użytkownika timmy dołączam loga z Combo Fix, być może to coś pomoże.

LOG Z COMBO FIX

ComboFix 08-06-10.3 - MaQ 2008-06-11 13:54:41.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.621 [GMT 2:00]
Running from: C:\Documents and Settings\MaQ\Pulpit\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED Dołączona grafika
.

((((((((((((((((((((((((( Files Created from 2008-05-11 to 2008-06-11 )))))))))))))))))))))))))))))))
.

2008-06-11 12:53 . 2008-06-11 12:53 <DIR> d-------- C:\Fraps
2008-06-09 17:35 . 2008-06-09 17:37 <DIR> d-------- C:\Program Files\PhotoFiltre
2008-06-08 11:02 . 2008-06-08 11:02 <DIR> d-------- C:\Program Files\BearShare Applications
2008-06-08 11:02 . 2008-06-08 11:07 <DIR> d-------- C:\Program Files\BearShare
2008-06-08 11:02 . 2008-06-08 11:02 <DIR> d-------- C:\Documents and Settings\Myth\Dane aplikacji\BearShare
2008-06-08 11:02 . 2007-11-22 16:00 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
2008-06-07 21:24 . 2008-06-07 21:24 <DIR> d-------- C:\Program Files\ESET
2008-06-07 21:24 . 2008-06-07 21:24 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-06-05 10:54 . 2008-06-05 10:54 <DIR> d-------- C:\Program Files\Enlight Software
2008-06-05 09:00 . 2008-06-05 09:00 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-05 09:00 . 2008-06-05 09:00 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-02 17:38 . 2008-06-02 17:38 <DIR> d-------- C:\Program Files\UltraISO
2008-06-02 17:38 . 2008-06-02 17:38 <DIR> d-------- C:\Program Files\Common Files\EZB Systems
2008-05-27 14:10 . 2008-05-27 14:10 <DIR> d-------- C:\Program Files\Xvid
2008-05-27 14:10 . 2007-06-28 18:55 77,824 --a------ C:\WINDOWS\system32\xvid.ax
2008-05-27 14:05 . 2008-05-27 14:05 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-05-25 13:12 . 2003-04-09 11:28 233,472 --a------ C:\WINDOWS\system32\MafiaSetup.exe
2008-05-22 23:39 . 2008-05-23 00:07 <DIR> d-------- C:\Program Files\Tibia Auto
2008-05-22 23:37 . 2008-05-22 23:39 <DIR> d-------- C:\Program Files\Tibia
2008-05-22 23:37 . 2008-05-22 23:37 <DIR> d-------- C:\Documents and Settings\Myth\Dane aplikacji\Tibia
2008-05-18 15:49 . 2008-05-18 15:49 <DIR> d-------- C:\Program Files\Common Files\DirectX
2008-05-17 11:08 . 2008-05-17 11:11 <DIR> d-------- C:\Program Files\Valve
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-05-13 18:26 . 2008-05-13 18:26 0 --a------ C:\WINDOWS\PowerReg.dat
2008-05-13 18:23 . 2008-05-13 18:23 <DIR> d-------- C:\Program Files\Infogrames
2008-05-12 18:07 . 2002-07-30 16:42 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-05-12 18:07 . 2002-07-24 04:30 32,128 --a------ C:\WINDOWS\system32\drivers\viaagp1.sys
2008-05-12 17:52 . 2008-05-12 17:52 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\NVIDIA
2008-05-12 17:43 . 2005-04-13 18:54 331,184 --------- C:\WINDOWS\system32\difxapi.dll
2008-05-12 17:42 . 2008-04-03 15:42 53,248 --a------ C:\WINDOWS\system32\drivers\ViPrt.sys
2008-05-12 17:42 . 2007-09-21 16:28 18,432 --a------ C:\WINDOWS\system32\vIdeInst.dll
2008-05-12 17:42 . 2008-04-03 15:42 16,896 --a------ C:\WINDOWS\system32\drivers\ViBus.sys
2008-05-12 17:26 . 2006-02-23 05:39 11,264 -ra------ C:\WINDOWS\system32\drivers\xfilt.sys
2008-05-12 17:26 . 2007-09-21 17:49 9,216 --a------ C:\WINDOWS\system32\drivers\videX32.sys
2008-05-12 17:17 . 2008-06-11 13:51 81,191 --a------ C:\WINDOWS\system32\nvapps.xml
2008-05-12 17:16 . 2008-05-12 17:18 <DIR> d-------- C:\WINDOWS\nview
2008-05-12 17:16 . 2006-08-16 17:55 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2008-05-12 17:16 . 2006-08-11 15:42 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-05-12 17:16 . 2006-08-11 15:42 16,960 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-05-12 17:03 . 2008-05-12 17:03 <DIR> d-------- C:\Program Files\VIA
2008-05-12 16:46 . 2008-05-12 16:46 <DIR> d-------- C:\HXCD-ROM
2008-05-12 16:07 . 2008-06-05 09:00 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-12 15:42 . 2008-06-11 11:05 <DIR> d-------- C:\Program Files\Odkurzacz
2008-05-11 20:46 . 2008-05-11 20:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-11 18:43 . 2008-05-11 18:43 <DIR> d-------- C:\Direct 9.0c
2008-05-11 18:06 . 2008-05-11 18:21 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-05-11 18:06 . 2008-05-11 18:06 552 --a------ C:\WINDOWS\system32\d3d8caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-11 11:00 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-06-09 15:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-06-07 19:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-18 19:34 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\skypePM
2008-05-18 17:35 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\Skype
2008-05-17 17:07 --------- d-----w C:\Program Files\D-Tools
2008-05-12 13:52 --------- d-----w C:\Program Files\SopCast
2008-05-12 13:52 --------- d-----w C:\Program Files\BitComet
2008-05-12 13:52 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\Azureus
2008-05-07 06:29 2,560 ----a-w C:\WINDOWS\system32\bitcometres.dll
2008-05-06 17:56 --------- d-----w C:\Program Files\avisplit
2008-05-06 17:48 --------- d-----w C:\Program Files\Free FLV to AVI Converter
2008-05-04 16:19 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-05-04 15:59 --------- d-----w C:\Program Files\Intel
2008-05-04 15:30 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-05-04 14:02 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-04 13:57 --------- d-----w C:\Program Files\Gadu-Gadu
2008-05-03 20:41 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Azureus
2008-05-03 19:08 --------- d-----w C:\Program Files\Smallvideosoft
2008-05-02 17:44 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-05-02 17:22 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\InstallShield
2008-05-02 17:02 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\GanymedeNet
2008-04-30 17:45 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-04-29 17:38 --------- d-----w C:\Program Files\Metropolis Software
2008-04-29 16:58 --------- d-----w C:\Program Files\Alcohol Soft
2008-04-29 16:55 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-04-29 09:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 09:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 09:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-27 16:08 --------- d-----w C:\Program Files\Microsoft Application Compatibility Toolkit 5
2008-04-27 08:35 180,224 ----a-w C:\WINDOWS\system32\xvidvfw.dll
2008-04-27 08:33 765,952 ----a-w C:\WINDOWS\system32\xvidcore.dll
2008-04-26 18:11 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\fltk.org
2008-04-26 05:42 --------- d-----w C:\Program Files\Google
2008-04-25 19:03 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Ulead Systems
2008-04-24 18:58 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2008-04-24 18:56 --------- d-----w C:\Program Files\Skype
2008-04-24 18:56 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-24 18:56 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-04-22 07:21 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\Ulead Systems
2008-04-22 07:15 --------- d-----w C:\Program Files\Common Files\InterVideo
2008-04-22 07:14 --------- d-----w C:\Program Files\Windows Media Components
2008-04-19 17:06 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\Mount&Blade
2008-04-18 17:24 --------- d-----w C:\Program Files\Asprate
2008-04-18 04:21 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-18 04:19 --------- d-----w C:\Program Files\Nero
2008-04-18 04:18 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-18 04:15 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-15 15:56 --------- d-----w C:\Documents and Settings\MaQ\Dane aplikacji\Media Player Classic
2008-04-15 15:55 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-14 18:02 --------- d-----w C:\Program Files\Realtek
2008-04-14 17:41 --------- d-----w C:\Documents and Settings\Myth\Dane aplikacji\Gadu-Gadu
2008-04-14 17:07 --------- d-----w C:\Program Files\Lavalys
2008-04-14 17:06 --------- d-----w C:\Documents and Settings\MaQ\Dane aplikacji\Talkback
2008-04-14 16:56 --------- d-----w C:\Program Files\Alwil Software
2008-04-14 15:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-14 15:23 --------- d-----w C:\Program Files\Usługi online
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2004-09-28 01:00 26,240 ----a-w C:\WINDOWS\inf\RAMDSK.SYS
.

((((((((((((((((((((((((((((( snapshot@2008-05-17_19.14.39,67 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-12 15:24:17 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2008-05-22 18:45:43 53,248 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
- 2008-05-12 15:24:17 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2008-05-22 18:45:43 12,800 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
- 2008-05-12 15:24:17 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-05-22 18:45:44 473,600 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
- 2008-05-12 15:24:16 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2008-05-22 18:45:44 576,000 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2008-05-12 15:24:18 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2008-05-22 18:45:44 145,920 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
- 2008-05-12 15:24:18 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2008-05-22 18:45:44 159,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2008-05-12 15:24:18 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2008-05-22 18:45:45 364,544 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2008-05-12 15:24:18 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2008-05-22 18:45:45 178,176 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2008-05-12 15:24:17 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2008-05-22 18:45:43 223,232 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2008-05-17 17:00:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-11 11:51:00 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe
+ 2000-08-31 06:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe
+ 2008-06-07 19:24:35 10,134 ----a-r C:\WINDOWS\Installer\{45BF5088-655E-4BDB-9F63-CDEF3BA74D40}\callmsi.exe
+ 2008-06-07 19:24:35 136,448 ----a-r C:\WINDOWS\Installer\{45BF5088-655E-4BDB-9F63-CDEF3BA74D40}\egui.exe
- 1998-10-07 11:54:38 327,168 ----a-w C:\WINDOWS\IsUn0415.exe
+ 1998-11-13 11:10:18 307,200 ----a-w C:\WINDOWS\IsUn0415.exe
- 2005-03-18 14:23:10 53,248 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2005-03-18 15:23:10 53,248 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
- 2005-03-18 14:23:10 12,800 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2005-03-18 15:23:10 12,800 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
- 2005-03-18 14:23:14 473,600 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2005-03-18 15:23:14 473,600 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
- 2005-03-18 14:23:10 145,920 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2005-03-18 15:23:10 145,920 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
- 2005-03-18 14:23:10 159,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2005-03-18 15:23:10 159,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
- 2005-03-18 14:23:14 364,544 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2005-03-18 15:23:14 364,544 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
- 2005-03-18 14:23:12 178,176 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2005-03-18 15:23:12 178,176 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
- 2005-03-18 14:23:14 223,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2005-03-18 15:23:14 223,232 ----a-w C:\WINDOWS\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2008-06-07 19:23:06 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NtUser.dat
+ 2008-03-13 14:43:42 40,456 ----a-w C:\WINDOWS\system32\drivers\eamon.sys
+ 2008-03-13 14:44:36 29,704 ----a-w C:\WINDOWS\system32\drivers\easdrv.sys
+ 2008-03-13 14:52:18 33,800 ----a-w C:\WINDOWS\system32\drivers\epfwtdir.sys
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00 15360]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 18:46 217544]
"Odkurzacz-MCD"="C:\Program Files\Odkurzacz\odk_mcd.exe" [2008-03-03 14:44 266240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-12 10:58 16264192 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 12:04 2879488 C:\WINDOWS\SkyTel.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 15:43 7630848]
"nwiz"="nwiz.exe" [2006-08-11 15:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 15:43 86016]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-03-13 16:48 1443072]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-06-09 17:44:43 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 C:\Program Files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-06 18:21 21898024 C:\Program Files\Skype\Phone\Skype.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Valve\\hl.exe"=
"C:\\Program Files\\BearShare\\BearShare.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22659:TCP"= 22659:TCP:BitComet 22659 TCP
"22659:UDP"= 22659:UDP:BitComet 22659 UDP

R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2008-04-03 15:42]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-09-21 17:49]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2008-04-03 15:42]
R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 05:39]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 16:52]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-11 13:56:16
Windows 5.1.2600 Dodatek Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-11 13:56:38
ComboFix-quarantined-files.txt 2008-06-11 11:56:36
ComboFix2.txt 2008-05-17 17:14:47

Pre-Run: 63,331,659,776 bajtów wolnych
Post-Run: 63,379,963,904 bajtów wolnych

231 --- E O F --- 2008-04-30 18:38:23

Za wszystkie porady, DZIĘKUJĘ!

  • 0

#2 wncvirus

wncvirus

    Leń !

  • 851 postów

Napisano 11 06 2008 - 19:27

Odpal hjt wybierz opcję do a system scan only.Zrobi Ci się log i zaznacz kwadraty obok poniższych wpisów i daj fix

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/pl
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab

Co do logu combofix'a.

w nim czysto ale jest plik actskn45.ocx.. Są różne opinie na to, czy to usuwać, czy nie.Ten plik jest wykorzystywany np. przez Avasta.Osobiście bym usuną ten plik bo nie jest to jakiś ważny plik tylko skórka.Jeśli zdecydujesz się go usunąć możesz skorzystać z narzędzia killbox.

Instrukcja do killboxa :

1.Wciśnij pierwszy obrazek( na lewo od rączki) i wybierz powyższy plik C:\WINDOWS\system32\actskn45.ocx
2.Naciśnij czerwone kółko i zresetuj komputer.

  • 0




Użytkownicy przeglądający ten temat: 0

0 użytkowników, 0 gości, 0 anonimowych