
Po kilku minutach google powiedzialo ze to trojan wiec go usunalem hijackthis.
Od dluzszego czasu obserwuje coraz wolniejsze dzialanie mojego poczciwego komputera i zastanawiam sie czy nie mam czegos wiecej na nim.
oto logi
hijackthis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:19:48, on 2008-10-18
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://tibiacam.tv/cams.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-21-117609710-688789844-1547161642-500\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Administrator')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E109A208-9079-4334-A23C-20CC856D5C19}: NameServer = 213.241.79.38,213.241.79.37
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
--
End of file - 3065 bytes
i combofix
- Kod: Zaznacz wszystko
ComboFix 08-10-17.01 - mariann 2008-10-18 17:22:28.1 - NTFSx86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.380 [GMT 2:00]
Uruchomiony z: C:\Documents and Settings\mariann\Pulpit\bezp\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\myglobalsearch
.
((((((((((((((((((((((((( Pliki utworzone od 2008-09-18 do 2008-10-18 )))))))))))))))))))))))))))))))
.
2008-10-18 17:18 . 2008-10-18 17:23 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-10-18 17:18 . 2008-09-20 01:18 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-10-18 17:18 . 2008-09-19 23:24 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-10-18 17:18 . 2008-09-20 01:18 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-10-18 17:18 . 2008-09-20 01:18 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-10-18 17:18 . 2008-09-20 01:18 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-10-18 17:18 . 2008-09-20 01:18 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-10-18 17:18 . 2008-10-18 17:18 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-18 16:58 . 2008-10-18 16:58 <DIR> d-------- C:\VundoFix Backups
2008-10-18 16:33 . 2008-10-18 16:33 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-13 23:27 . 2008-10-13 23:27 <DIR> d-------- C:\Program Files\AC3Filter
2008-10-13 23:27 . 2008-07-09 10:05 421,888 --a------ C:\WINDOWS\system32\ac3filter.acm
2008-10-13 22:50 . 2008-10-13 22:51 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\gtk-2.0
2008-10-13 22:50 . 2008-10-13 22:50 <DIR> d-------- C:\Documents and Settings\mariann\.thumbnails
2008-10-13 22:46 . 2008-10-13 23:18 <DIR> d-------- C:\Documents and Settings\mariann\.gimp-2.6
2008-10-13 22:46 . 2008-10-13 22:46 <DIR> d-------- C:\Documents and Settings\mariann\.gegl-0.0
2008-10-13 22:42 . 2008-10-13 22:42 <DIR> d-------- C:\Program Files\Gimp-2.0
2008-10-10 00:31 . 2008-10-15 01:21 <DIR> d-------- C:\Program Files\BearShare
2008-10-10 00:31 . 2008-10-13 21:12 <DIR> dr------- C:\My Downloads
2008-10-09 00:59 . 2008-10-09 00:59 <DIR> d-------- C:\Program Files\Trojan Remover
2008-10-09 00:59 . 2008-10-09 00:59 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\Simply Super Software
2008-10-09 00:59 . 2008-10-09 00:59 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Simply Super Software
2008-10-09 00:59 . 2006-05-25 15:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-10-09 00:59 . 2003-02-02 20:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-10-09 00:59 . 2005-08-26 01:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-10-09 00:59 . 2002-03-06 01:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-10-09 00:59 . 2006-06-19 13:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-10-07 18:46 . 2008-10-07 18:46 <DIR> d-------- C:\Program Files\Blackd Tools
2008-10-04 10:40 . 2008-04-14 00:15 26,368 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-10-03 14:24 . 2008-10-03 14:25 <DIR> d-------- C:\Program Files\ElfBot NG
2008-10-02 00:13 . 2008-10-02 00:18 <DIR> d-------- C:\Program Files\The KMPlayer
2008-10-02 00:06 . 2008-10-02 00:27 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2008-10-01 20:57 . 2008-10-01 20:57 <DIR> d-------- C:\Program Files\Xvid
2008-10-01 20:55 . 2004-06-05 12:56 679,936 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-10-01 20:55 . 2004-06-06 12:53 155,648 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-10-01 20:55 . 2004-06-05 12:59 65,536 --a------ C:\WINDOWS\system32\xvid.ax
2008-10-01 20:53 . 2008-10-01 20:53 <DIR> d-------- C:\Program Files\KC Softwares
2008-10-01 19:33 . 2008-10-01 19:33 <DIR> d-------- C:\Downloads
2008-10-01 19:31 . 2008-10-01 20:26 <DIR> d-------- C:\Program Files\FlashGet
2008-10-01 18:38 . 2008-10-01 18:39 <DIR> d-------- C:\Program Files\Peer2Mail
2008-10-01 15:32 . 1998-06-24 00:00 140,096 --a------ C:\WINDOWS\system32\comdlg32.ocx
2008-10-01 15:30 . 2008-10-01 15:30 <DIR> d-------- C:\Program Files\Common libraries
2008-09-27 22:34 . 2008-09-27 22:34 <DIR> d-------- C:\Program Files\Asprate
2008-09-27 18:12 . 2008-09-27 18:12 <DIR> d-------- C:\Program Files\ESET
2008-09-22 21:16 . 2008-09-22 21:16 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-21 03:37 . 2008-10-09 01:00 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-21 03:37 . 2008-09-21 03:41 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Spybot - Search & Destroy
2008-09-21 03:02 . 2008-09-21 03:02 <DIR> d-------- C:\Program Files\Ventrilo
2008-09-21 03:02 . 2008-09-21 03:02 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-09-21 03:02 . 2008-09-27 17:39 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\Ventrilo
2008-09-20 19:35 . 2008-09-28 03:01 <DIR> d-------- C:\Program Files\Valve
2008-09-20 19:14 . 2008-10-03 14:21 <DIR> d-------- C:\Program Files\TibiaCam TV Lite
2008-09-20 00:39 . 2008-10-18 01:20 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\Tibia
2008-09-20 00:19 . 2008-09-20 00:19 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\Gadu-Gadu
2008-09-20 00:17 . 2008-09-20 00:17 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\ESET
2008-09-20 00:13 . 2008-09-20 00:14 <DIR> d-------- C:\Documents and Settings\mariann\Dane aplikacji\Winamp
2008-09-20 00:11 . 2008-09-20 20:32 <DIR> d-------- C:\Documents and Settings\mariann\Gadu-Gadu
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-18 13:59 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-10-17 14:19 --------- d-----w C:\Program Files\Minilyrics
2008-10-16 14:24 --------- d-----w C:\Program Files\TibiaBot NG
2008-10-11 15:57 --------- d-----w C:\Program Files\Tibia
2008-10-11 09:15 --------- d-----w C:\Program Files\Opera
2008-09-27 16:14 159,648 ----a-w C:\WINDOWS\Marsu-Fix 2.5 Uninstaller.exe
2008-09-20 17:35 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-20 17:34 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-19 22:16 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ESET
2008-09-19 22:13 --------- d-----w C:\Program Files\Winamp
2008-09-19 22:12 --------- d-----w C:\Program Files\Real Alternative
2008-09-19 22:11 --------- d-----w C:\Program Files\MarBit
2008-09-19 22:11 --------- d-----w C:\Program Files\Gadu-Gadu
2008-09-19 22:10 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-19 21:52 --------- d-----w C:\Program Files\C-Media 3D Audio
2008-09-19 21:51 --------- d-----w C:\Program Files\Intel
2008-09-19 21:44 --------- d-----w C:\Program Files\ATI Technologies
2008-09-19 21:29 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-19 21:27 --------- d-----w C:\Program Files\Usługi online
2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-10-05 967048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-07-09 23:33 36352 C:\Program Files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"27015:TCP"= 27015:TCP:cs
.
- - - - USUNIĘTO PUSTE WPISY - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Skan uzupełniający -------
.
FireFox -: Profile - C:\Documents and Settings\mariann\Dane aplikacji\Mozilla\Firefox\Profiles\5sknjmdn.default\
FF -: plugin - C:\Program Files\Opera\program\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\Opera\program\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-18 17:23:50
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
C:\DOCUME~1\mariann\USTAWI~1\Temp\RGI1.tmp
skanowanie pomyślnie ukończone
ukryte pliki: 1
**************************************************************************
.
Czas ukończenia: 2008-10-18 17:25:23
ComboFix-quarantined-files.txt 2008-10-18 15:25:11
Przed: 15 986 315 264 bajtów wolnych
Po: 15,977,115,648 bajtów wolnych
WindowsXP-KB310994-SP2-Pro-BootDisk-PLK.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
150
Z góry dzieki i pozdrawiam