
Ostatnimi czasy (3 ostatnie dni) miałem problemy z vundo.trojan'em. Usunolem go po wielkich trudach (jako że w tej kwestii jestem noobem) programem VirtumundoBeGone i zrobiłem format dla pewnosci, że na dysku będzie czysto. Jak narazie wszystko jest ok i nic sie nie dzieje ale prosze o sprawdzenie logów z programu ComboFix:
- Kod: Zaznacz wszystko
ComboFix 07-11-08.1 - Matthew 2007-11-15 19:59:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.697 [GMT 1:00]
Running from: C:\Documents and Settings\Matthew\Pulpit\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-15 19:59 51,200 --a------ C:\WINNT\NirCmd.exe
2007-11-15 19:53 <DIR> d-------- C:\Program Files\Last.fm
2007-11-15 19:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Last.fm
2007-11-15 19:47 <DIR> d-------- C:\Program Files\foobar2000
2007-11-15 19:47 <DIR> d-------- C:\Documents and Settings\Matthew\Dane aplikacji\foobar2000
2007-11-15 19:40 <DIR> d-------- C:\Documents and Settings\Matthew\Dane aplikacji\Creative
2007-11-15 19:39 41,984 --------- C:\WINNT\Ctregrun.exe
2007-11-15 19:37 44,032 --------- C:\WINNT\system32\CTSVCCDA.EXE
2007-11-15 19:37 25,088 --------- C:\WINNT\system32\CTSVCCTL.EXE
2007-11-15 19:34 <DIR> d-------- C:\WINNT\system32\Data
2007-11-15 19:34 11,264 --a------ C:\WINNT\INRES.DLL
2007-11-15 19:32 <DIR> d-------- C:\Program Files\Creative
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-15 18:59 --------- d-----w C:\Program Files\Neostrada TP
2007-11-15 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-15 18:31 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-15 15:22 --------- d-----w C:\Documents and Settings\Matthew\Dane aplikacji\Talkback
2007-11-15 15:08 --------- d-----w C:\Program Files\Ashampoo
2007-11-15 15:02 512,096 ----a-w C:\WINNT\system32\drivers\amon.sys
2007-11-15 15:02 298,104 ----a-w C:\WINNT\system32\imon.dll
2007-11-15 15:02 15,424 ----a-w C:\WINNT\system32\drivers\nod32drv.sys
2007-11-15 15:01 --------- d-----w C:\Documents and Settings\Matthew\Dane aplikacji\Tlen.pl
2007-11-15 15:00 --------- d-----w C:\Program Files\Tlen.pl
2007-11-15 14:55 23 ----a-w C:\WINNT\system32\drivers\adidsl.cfg
2007-11-15 14:55 --------- d-----w C:\Program Files\SAGEM
2007-11-15 14:55 --------- d-----w C:\Program Files\Java
2007-11-15 14:49 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 18:07]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-15 16:02]
"NvCplDaemon"="C:\WINNT\system32\NvCpl.dll" [2006-08-11 14:43]
"nwiz"="nwiz.exe" [2006-08-11 14:43 C:\WINNT\system32\nwiz.exe]
"NvMediaCenter"="C:\WINNT\system32\NvMcTray.dll" [2006-08-11 14:43]
"Ashampoo FireWall"="C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" [2007-04-05 14:57]
"CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 16:10]
"P17Helper"="P17.dll" [2005-05-03 12:38 C:\WINNT\system32\P17.dll]
"UpdReg"="C:\WINNT\UpdReg.EXE" [2000-05-11 01:00]
"CTRegRun"="C:\WINNT\CTRegRun.EXE" [1999-10-11 02:00]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINNT\system32\ctfmon.exe" [2004-08-04 01:44]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2007-11-07 15:33]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"Creative MediaSource Go"="C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" [2004-11-30 11:00]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-11-15 15:55:42]
R3 P17;Sound Blaster Audigy;C:\WINNT\system32\drivers\P17.sys
*Newly Created Service* - CATCHME
*Newly Created Service* - UMWDF
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 20:00:19
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-15 20:00:34
.
--- E O F ---