Skocz do zawartości


tomnan

Rejestracja: 15 wrz 2008
OFFLINE Ostatnio: 18 09 2008 21:42
-----

Moje posty

W temacie: KOMPUTER SIĘ WIESZA

18 09 2008 - 14:03

dałem z combofix moze ktos zerknac

W temacie: KOMPUTER SIĘ WIESZA

16 09 2008 - 22:51

Logi z combofixa.

ComboFix 08-09-15.02 - KiT 2008-09-16 22:37:58.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.2243 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\KiT\Pulpit\ComboFix.exe
 * Utworzono nowy punkt przywracania
 * Resident AV is active


[color="red"][b]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA [img]http://www.forum.tweaks.pl/public/style_emoticons/default/excl.gif[/img][/b][/color]
.

(((((((((((((((((((((((((   Pliki utworzone od 2008-08-16 do 2008-09-16  )))))))))))))))))))))))))))))))
.

2008-09-16 22:43 . 2008-09-16 22:43	<DIR>	d--------	C:\WINDOWS\system32\xircom
2008-09-16 22:43 . 2008-09-16 22:43	<DIR>	d--------	C:\Program Files\microsoft frontpage
2008-09-16 22:12 . 2008-09-16 22:12	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\TomTom
2008-09-16 22:11 . 2008-09-16 22:11	<DIR>	d--------	C:\Program Files\TomTom HOME 2
2008-09-16 22:11 . 2008-09-16 22:11	<DIR>	d--------	C:\Documents and Settings\KiT\Dane aplikacji\TomTom
2008-09-16 20:49 . 2008-09-16 21:04	<DIR>	d--------	C:\TomTom
2008-09-16 18:27 . 2008-09-16 18:27	<DIR>	d--------	C:\Program Files\Unlocker
2008-09-16 14:22 . 2008-09-16 14:22	69	--a------	C:\WINDOWS\NeroDigital.ini
2008-09-15 18:47 . 2008-09-15 18:47	<DIR>	d--------	C:\Documents and Settings\KiT\Dane aplikacji\Ahead
2008-09-15 18:45 . 2008-09-15 18:45	<DIR>	d--------	C:\Program Files\Nero
2008-09-15 18:45 . 2008-09-15 18:48	<DIR>	d--------	C:\Program Files\Common Files\Ahead
2008-09-15 17:58 . 2008-09-15 17:58	<DIR>	d--------	C:\Program Files\Trend Micro
2008-09-15 17:40 . 2008-09-15 17:40	<DIR>	d--------	C:\Dokumente und Einstellungen
2008-09-14 21:38 . 2008-09-14 21:38	<DIR>	d--------	C:\Program Files\MoorHunt
2008-09-14 19:47 . 2008-09-14 19:47	<DIR>	d--------	C:\Program Files\TomTom DesktopSuite
2008-09-14 18:12 . 2008-09-16 18:22	<DIR>	d--------	C:\dvbdream
2008-09-14 01:22 . 2008-09-14 01:22	0	--a------	C:\WINDOWS\nsreg.dat
2008-09-12 23:56 . 2008-04-14 21:50	14,720	--a------	C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-12 23:36 . 2008-04-14 00:15	32,128	--a------	C:\WINDOWS\system32\drivers\usbccgp.sys
2008-09-12 00:02 . 2008-09-16 18:18	130	--a------	C:\WINDOWS\EurekaLog.ini
2008-09-11 23:07 . 2008-09-11 23:08	<DIR>	d--------	C:\Program Files\SubEdit-Player
2008-09-11 23:05 . 2008-09-16 20:22	<DIR>	d--------	C:\Documents and Settings\KiT\Dane aplikacji\skypePM
2008-09-11 23:05 . 2008-09-11 23:05	56	--ah-----	C:\WINDOWS\system32\ezsidmv.dat
2008-09-11 23:04 . 2008-09-11 23:04	<DIR>	d--------	C:\Program Files\Skype
2008-09-11 23:04 . 2008-09-11 23:04	<DIR>	d--------	C:\Program Files\<a href="http://www.download.net.pl/105/K-Lite-Codec-Pack/">K-Lite Codec Pack</a>
2008-09-11 23:04 . 2008-09-11 23:04	<DIR>	d--------	C:\Program Files\Common Files\Skype
2008-09-11 23:04 . 2008-09-16 22:21	<DIR>	d--------	C:\Documents and Settings\KiT\Dane aplikacji\Skype
2008-09-11 23:04 . 2008-09-11 23:04	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Skype
2008-09-11 23:00 . 2008-09-11 23:00	<DIR>	d--------	C:\Program Files\Google
2008-09-11 22:32 . 2008-09-11 22:32	<DIR>	d--------	C:\Program Files\Common Files\Adobe
2008-09-11 22:25 . 2008-09-11 22:25	<DIR>	d--------	C:\Program Files\Lavasoft
2008-09-11 22:25 . 2008-09-11 22:25	<DIR>	d--------	C:\Program Files\Common Files\Wise Installation Wizard
2008-09-11 22:25 . 2008-09-11 22:26	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-09-11 22:22 . 2008-09-11 22:22	<DIR>	d--------	C:\Program Files\Kaspersky Lab
2008-09-11 22:22 . 2008-09-16 20:21	<DIR>	d--------	C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-09-11 22:22 . 2008-09-16 22:43	1,938,976	--ahs----	C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-11 22:22 . 2008-09-11 22:59	96,976	--a------	C:\WINDOWS\system32\drivers\klin.dat
2008-09-11 22:22 . 2008-09-11 22:59	87,855	--a------	C:\WINDOWS\system32\drivers\klick.dat
2008-09-11 22:22 . 2008-09-16 22:42	74,784	--ahs----	C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-11 22:22 . 2008-09-16 22:42	30,008	--ahs----	C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-11 22:22 . 2008-09-16 22:42	8,624	--ahs----	C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-11 22:19 . 2008-09-11 22:19	<DIR>	d--------	C:\SatList
2008-09-11 22:18 . 2008-09-11 22:19	<DIR>	d--------	C:\WINDOWS\nview
2008-09-11 22:18 . 2008-08-15 23:22	453,152	--a------	C:\WINDOWS\system32\nvudisp.exe
2008-09-11 22:18 . 2008-08-15 23:22	198,941	--a------	C:\WINDOWS\system32\nvapps.nvb
2008-09-11 22:18 . 2008-09-16 22:43	193,161	--a------	C:\WINDOWS\system32\nvapps.xml
2008-09-11 22:18 . 2008-08-15 23:22	18,335	--a------	C:\WINDOWS\system32\nvdisp.nvu
2008-09-11 22:17 . 2008-09-11 22:17	<DIR>	d--------	C:\NVIDIA
2008-09-11 22:16 . 2008-09-15 20:43	<DIR>	d--------	C:\WINDOWS\system32\NtmsData
2008-09-11 22:14 . 2008-09-11 22:14	<DIR>	d--------	C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor
2008-09-11 22:13 . 2005-10-27 15:06	356,096	--a------	C:\WINDOWS\system32\drivers\rt61.sys
2008-09-11 22:12 . 2004-06-20 04:28	25,600	-ra------	C:\WINDOWS\system32\drivers\DtvVideo.sys
2008-09-11 22:12 . 2004-06-20 04:28	10,330	-ra------	C:\WINDOWS\system32\drivers\DtvAudio.sys
2008-09-11 22:03 . 2008-09-11 22:03	<DIR>	d--------	C:\Program Files\ASUS
2008-09-11 22:03 . 2006-01-10 18:50	24,576	-ra------	C:\WINDOWS\system32\AsIO.dll
2008-09-11 22:03 . 2007-12-17 19:14	12,400	-ra------	C:\WINDOWS\system32\drivers\AsIO.sys
2008-09-11 22:03 . 2008-01-04 13:34	11,832	--a------	C:\WINDOWS\system32\drivers\AsInsHelp64.sys
2008-09-11 22:03 . 2008-01-04 13:34	10,216	--a------	C:\WINDOWS\system32\drivers\AsInsHelp32.sys
2008-09-11 22:02 . 2008-09-11 22:02	666	--a------	C:\WINDOWS\setup.iss

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-11 20:59	112,144	----a-w	C:\WINDOWS\system32\drivers\kl1.sys
2008-09-11 20:14	20,747	----a-w	C:\WINDOWS\system32\drivers\AegisP.sys
2008-09-11 20:14	---------	d--h--w	C:\Program Files\InstallShield Installation Information
2008-09-11 20:02	---------	d-----w	C:\Program Files\Common Files\InstallShield
2008-09-11 19:57	---------	d-----w	C:\Program Files\profile
2008-09-11 19:57	---------	d-----w	C:\Program Files\log
2008-09-11 19:57	---------	d-----w	C:\Program Files\bin32
2008-09-11 19:51	---------	d-----w	C:\Program Files\Analog Devices
2008-09-11 17:44	---------	d-----w	C:\Program Files\Usługi online
2008-09-11 17:42	---------	d-----w	C:\Program Files\Windows Media Connect 2
2008-08-15 21:22	6,121,504	----a-w	C:\WINDOWS\system32\drivers\nv4_mini.sys
.

------- Sigcheck -------

2008-05-02 08:48  361344  8e036eec565910417ea020ce0962aa24	C:\WINDOWS\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane 
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-09-11 171448]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-08-12 21741864]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 202088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-10-09 1036288]
"NVRaidService"="C:\WINDOWS\system32\nvraidservice.exe" [2008-01-17 184864]
"Ai Nap"="C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="C:\Program Files\ASUS\Ai Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="C:\Program Files\ASUS\Ai Suite\CpuLevelUpHelp.exe" [2007-11-30 881152]
"ASUS Energy Saving"="C:\Program Files\ASUS\Ai Suite\EnergySaving\PwSave.exe" [2008-01-28 1352704]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-08-15 13570048]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-08-15 86016]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe" [2008-01-11 2684280]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"nwiz"="nwiz.exe" [2008-08-15 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-03-01 C:\WINDOWS\system32\advpack.dll]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2008-01-17 102400]
R0 nvrd32;NVIDIA nForce RAID Driver;C:\WINDOWS\system32\DRIVERS\nvrd32.sys [2008-01-17 128000]
R3 DtvVideo;DtvVideo;C:\WINDOWS\system32\DRIVERS\DtvVideo.sys [2004-06-20 25600]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 24344]
S3 DtvAudio;DtvAudio;C:\WINDOWS\system32\DRIVERS\DtvAudio.sys [2004-06-20 10330]
.
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\KiT\Dane aplikacji\Mozilla\Firefox\Profiles\53djzl9o.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.pl/
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]
Rootkit scan 2008-09-16 22:43:49
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ... 

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ... 

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\bin32\nSvcAppFlt.exe
C:\Program Files\bin32\nSv[beeep].exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Czas ukończenia: 2008-09-16 22:45:05 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt  2008-09-16 20:44:58

Przed: 32,893,132,800 bajt˘w wolnych
Po: 33,457,393,664 bajt˘w wolnych

171