
- Kod: Zaznacz wszystko
http://forum.programosy.pl/-vp626671.html
+ dodatkowo zabija mi niektore procesy, jak np. czasami przeglądarki.
Czytalem,że to sprawka niby Backdoor.Win32.Haxdoor.bg Co robić?
Log z Combofix'a :
- Kod: Zaznacz wszystko
ComboFix 07-08-07.6 - "Eeek" 2007-09-09 15:47:27.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.200 [GMT 2:00]
((((((((((((((((((((((((( Files Created from 2007-08-09 to 2007-09-09 )))))))))))))))))))))))))))))))
2007-09-09 15:29 51,200 --a------ E:\WINDOWS\nircmd.exe
2007-09-09 12:19 3,968 --a------ E:\WINDOWS\system32\drivers\AvgArCln.sys
2007-09-09 02:08 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Media Player Classic
2007-09-08 23:26 <DIR> d-------- E:\DOCUME~1\Dom\DANEAP~1\Comodo
2007-09-08 23:25 786,432 --ah----- E:\DOCUME~1\Dom\NTUSER.DAT
2007-09-08 23:25 221,184 --a------ E:\WINDOWS\system32\wmpns.dll
2007-09-08 23:25 <DIR> dr-h----- E:\DOCUME~1\Dom\Dane aplikacji
2007-09-08 23:25 <DIR> dr------- E:\DOCUME~1\Dom\Ulubione
2007-09-08 23:25 <DIR> dr------- E:\DOCUME~1\Dom\Moje dokumenty
2007-09-08 23:25 <DIR> dr------- E:\DOCUME~1\Dom\Menu Start
2007-09-08 23:25 <DIR> d--h----- E:\DOCUME~1\Dom\Ustawienia lokalne
2007-09-08 23:25 <DIR> d--h----- E:\DOCUME~1\Dom\Szablony
2007-09-08 23:25 <DIR> d-------- E:\DOCUME~1\Dom\Pulpit
2007-09-08 22:38 163,712 --a------ E:\WINDOWS\system32\drivers\vidstub.sys
2007-09-08 22:38 <DIR> d-------- E:\Program Files\Common Files\Stardock
2007-09-08 21:17 <DIR> d--h----- E:\WINDOWS\system32\GroupPolicy
2007-09-08 18:52 639,224 --a------ E:\WINDOWS\system32\drivers\sptd.sys
2007-09-08 15:33 <DIR> d-------- E:\DOCUME~1\ALLUSE~1\DANEAP~1\Spybot - Search & Destroy
2007-09-08 12:02 <DIR> d-------- E:\Program Files\Media Player Classic
2007-09-08 12:02 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Real
2007-09-08 12:02 <DIR> d-------- E:\DOCUME~1\ALLUSE~1\DANEAP~1\Real
2007-09-08 11:43 1,136 --a------ E:\WINDOWS\mozver.dat
2007-09-08 00:42 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Comodo
2007-09-08 00:42 <DIR> d-------- E:\DOCUME~1\ALLUSE~1\DANEAP~1\Comodo
2007-09-08 00:32 <DIR> d-------- E:\WINDOWS\system32\appmgmt
2007-09-07 20:45 848 --ahs---- E:\WINDOWS\system32\KGyGaAvL.sys
2007-09-07 20:45 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Corel
2007-09-07 20:41 17,920 --a------ E:\WINDOWS\system32\mdimon.dll
2007-09-07 20:40 <DIR> d-------- E:\Program Files\Microsoft.NET
2007-09-07 20:39 <DIR> d-------- E:\WINDOWS\SHELLNEW
2007-09-07 20:32 <DIR> d-------- E:\DOCUME~1\ALLUSE~1\DANEAP~1\Corel
2007-09-07 20:30 <DIR> d-------- E:\Program Files\Common Files\Corel
2007-09-07 18:05 81,768 --a------ E:\WINDOWS\system32\xinput1_3.dll
2007-09-07 18:05 444,776 --a------ E:\WINDOWS\system32\d3dx10_35.dll
2007-09-07 18:05 443,752 --a------ E:\WINDOWS\system32\d3dx10_34.dll
2007-09-07 18:05 443,752 --a------ E:\WINDOWS\system32\d3dx10_33.dll
2007-09-07 18:05 3,727,720 --a------ E:\WINDOWS\system32\d3dx9_35.dll
2007-09-07 18:05 3,497,832 --a------ E:\WINDOWS\system32\d3dx9_34.dll
2007-09-07 18:05 3,495,784 --a------ E:\WINDOWS\system32\d3dx9_33.dll
2007-09-07 18:05 3,426,072 --a------ E:\WINDOWS\system32\d3dx9_32.dll
2007-09-07 18:05 267,112 --a------ E:\WINDOWS\system32\xactengine2_9.dll
2007-09-07 18:05 266,088 --a------ E:\WINDOWS\system32\xactengine2_8.dll
2007-09-07 18:05 261,480 --a------ E:\WINDOWS\system32\xactengine2_7.dll
2007-09-07 18:05 255,848 --a------ E:\WINDOWS\system32\xactengine2_6.dll
2007-09-07 18:05 251,672 --a------ E:\WINDOWS\system32\xactengine2_5.dll
2007-09-07 18:05 237,848 --a------ E:\WINDOWS\system32\xactengine2_4.dll
2007-09-07 18:05 18,280 --a------ E:\WINDOWS\system32\x3daudio1_2.dll
2007-09-07 18:05 15,128 --a------ E:\WINDOWS\system32\x3daudio1_1.dll
2007-09-07 18:05 1,358,192 --a------ E:\WINDOWS\system32\D3DCompiler_35.dll
2007-09-07 18:05 1,124,720 --a------ E:\WINDOWS\system32\D3DCompiler_34.dll
2007-09-07 18:05 1,123,696 --a------ E:\WINDOWS\system32\D3DCompiler_33.dll
2007-09-07 18:04 62,744 --a------ E:\WINDOWS\system32\xinput1_2.dll
2007-09-07 18:04 236,824 --a------ E:\WINDOWS\system32\xactengine2_3.dll
2007-09-07 18:04 2,414,360 --a------ E:\WINDOWS\system32\d3dx9_31.dll
2007-09-07 18:04 2,297,552 --a------ E:\WINDOWS\system32\d3dx9_26.dll
2007-09-07 18:00 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Styler
2007-09-07 17:42 <DIR> d-------- E:\DOCUME~1\Eeek\Pulpit1
2007-09-07 17:07 7,287,808 --a------ E:\WINDOWS\system32\vistaui.exe
2007-09-07 17:07 414,223 --a------ E:\WINDOWS\system32\vimc.exe
2007-09-07 17:07 <DIR> d-------- E:\Program Files\Vista Sidebar
2007-09-07 17:07 <DIR> d-------- E:\Program Files\Styler
2007-09-07 17:07 <DIR> d-------- E:\Program Files\Blaero Start Orb
2007-09-07 17:07 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Stardock
2007-09-07 17:01 <DIR> d-------- E:\WINDOWS\system32\VITrans
2007-09-07 17:01 <DIR> d-------- E:\WINDOWS\pss
2007-09-07 17:00 81,920 --a------ E:\WINDOWS\system32\closeapp.exe
2007-09-07 17:00 8,636 --a------ E:\WINDOWS\system32\modifype.exe
2007-09-07 17:00 19,968 --a------ E:\WINDOWS\system32\reico.exe
2007-09-07 17:00 111,104 --a------ E:\WINDOWS\system32\Uharc.exe
2007-09-07 17:00 <DIR> d-------- E:\VTPFiles
2007-09-07 16:55 85,376 --a------ E:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-09-07 16:55 54,784 --a------ E:\WINDOWS\system32\vfwwdm32.dll
2007-09-07 16:55 5,504 --a------ E:\WINDOWS\system32\drivers\MSTEE.sys
2007-09-07 16:55 47,616 --a------ E:\WINDOWS\system\IYUV_32.DLL
2007-09-07 16:55 19,328 --a------ E:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-09-07 16:55 17,024 --a------ E:\WINDOWS\system32\drivers\CCDECODE.sys
2007-09-07 16:55 15,360 --a------ E:\WINDOWS\system32\drivers\StreamIP.sys
2007-09-07 16:55 11,136 --a------ E:\WINDOWS\system32\drivers\SLIP.sys
2007-09-07 16:55 10,880 --a------ E:\WINDOWS\system32\drivers\NdisIP.sys
2007-09-07 16:54 515,803 --------- E:\WINDOWS\system32\drivers\Ca533av.sys
2007-09-07 16:54 131,072 --a------ E:\WINDOWS\system\SP5X_32.DLL
2007-09-07 16:54 131,072 --------- E:\WINDOWS\system32\SP5X_32.DLL
2007-09-07 16:54 11,144 --------- E:\WINDOWS\system32\drivers\Bulk533.sys
2007-09-07 16:54 <DIR> d-------- E:\WINDOWS\SETUP533
2007-09-07 16:54 <DIR> d-------- E:\Program Files\Common Files\SWF Studio
2007-09-07 16:53 59,264 --a------ E:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-09-07 16:53 31,616 --a------ E:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-07 16:49 5,632 --a------ E:\WINDOWS\system32\CNMVS53.DLL
2007-09-07 16:49 100,352 --a------ E:\WINDOWS\system32\CNMLM53.DLL
2007-09-07 16:49 <DIR> d--h----- E:\BJPrinter
2007-09-07 16:48 25,856 --a------ E:\WINDOWS\system32\drivers\usbprint.sys
2007-09-07 16:41 <DIR> d-------- E:\DOCUME~1\Eeek\DANEAP~1\Skype
2007-09-07 16:40 <DIR> d-------- E:\Program Files\Skype
2007-09-07 16:40 <DIR> d-------- E:\Program Files\Common Files\Skype
2007-09-07 16:40 <DIR> d-------- E:\DOCUME~1\ALLUSE~1\DANEAP~1\Skype
2007-09-07 16:39 765,952 --a------ E:\WINDOWS\system32\xvidcore.dll
2007-09-07 16:39 740,442 --a------ E:\WINDOWS\system32\divx.dll
2007-09-07 16:39 73,728 --a------ E:\WINDOWS\system32\dpl100.dll
2007-09-07 16:39 7,680 --a------ E:\WINDOWS\system32\ff_vfw.dll
2007-09-07 16:39 630,784 --a------ E:\WINDOWS\system32\vp7vfw.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-09-07 14:28 49492 --a------ E:\WINDOWS\system32\perfc015.dat
2007-09-07 14:28 355486 --a------ E:\WINDOWS\system32\perfh015.dat
2007-07-28 07:44 45296 --a------ E:\WINDOWS\system32\drivers\ativvpxx.vp
2007-07-28 05:37 8237056 --a------ E:\WINDOWS\system32\atioglx2.dll
2007-07-28 05:31 344064 --a------ E:\WINDOWS\system32\ATIDEMGX.dll
2007-07-28 05:24 307200 --a------ E:\WINDOWS\system32\atiiiexx.dll
2007-07-28 05:23 143360 --a------ E:\WINDOWS\system32\atipdlxx.dll
2007-07-28 05:23 122880 --a------ E:\WINDOWS\system32\Oemdspif.dll
2007-07-28 05:22 43520 --a------ E:\WINDOWS\system32\ati2edxx.dll
2007-07-28 05:22 26112 --a------ E:\WINDOWS\system32\Ati2mdxx.exe
2007-07-28 05:22 118784 --a------ E:\WINDOWS\system32\ati2evxx.dll
2007-07-28 05:21 483328 --a------ E:\WINDOWS\system32\ati2evxx.exe
2007-07-28 05:20 53248 --a------ E:\WINDOWS\system32\ATIDDC.DLL
2007-07-28 05:06 176128 --a------ E:\WINDOWS\system32\atiok3x2.dll
2007-07-28 05:01 972072 --a------ E:\WINDOWS\system32\ativva6x.dat
2007-07-28 05:01 3107788 --a------ E:\WINDOWS\system32\ativvaxx.dat
2007-07-28 05:01 3107788 --a------ E:\WINDOWS\system32\ativva5x.dat
2007-07-28 04:50 5435392 --a------ E:\WINDOWS\system32\atioglxx.dll
2007-07-28 04:47 266240 --a------ E:\WINDOWS\system32\atikvmag.dll
2007-07-28 04:46 17408 --a------ E:\WINDOWS\system32\atitvo32.dll
2007-07-28 04:45 49152 --a------ E:\WINDOWS\system32\drivers\ati2erec.dll
2007-06-12 19:30 151367 --a------ E:\WINDOWS\system32\atiicdxx.dat
--------- E:\Program Files\Usługi online
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="E:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 20:51]
"SpeedTouch USB Diagnostics"="E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 11:38]
"ccApp"="E:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-06-10 11:27]
"GhostStartTrayApp"="E:\Programy\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe" [2003-05-28 19:11]
"Symantec NetDriver Monitor"="E:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-09-07 14:55]
"DownloadAccelerator"="E:\Programy\DAP\DAP.exe" [2007-09-07 15:19]
"StartCCC"="E:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35]
"COMODO Firewall Pro"="E:\Programy\Comodo\Firewall\CPF.exe" [2007-09-08 00:40]
"BootSkin Startup Jobs"="E:\Programy\Stardock\WINCUS~1\BootSkin\BootSkin.exe" [2004-04-26 16:21]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="E:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44]
"SpybotSD TeaTimer"="E:\Programy\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"E:\Programy\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"E:\Program Files\Messenger\msmsgs.exe" /background
R0 Inspect;Comodo Network Engine;E:\WINDOWS\system32\DRIVERS\inspect.sys
R1 GhPciScan;GhostPciScanner;\??\E:\Programy\Norton SystemWorks\Norton Ghost\ghpciscan.sys
R2 sbbotdi;sbbotdi;\??\E:\Programy\SPEEDB~1\sbbotdi.sys
R3 alcan5wn;SpeedTouch USB ADSL PPP Networking Driver (NDISWAN);E:\WINDOWS\system32\DRIVERS\alcan5wn.sys
R3 GT680x;GrandTechICNameNT;E:\WINDOWS\system32\Drivers\gt680x.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\E:\WINDOWS\system32\Drivers\NPDRIVER.SYS
R3 NVENET;NVIDIA nForce Networking Controller Driver;E:\WINDOWS\system32\DRIVERS\NVENET.sys
S2 Ca533av;Cam 3200, WDM Video Capture;E:\WINDOWS\system32\Drivers\Ca533av.sys
S2 CachemanXPService;CachemanXP;E:\Programy\CACHEM~1\CachemanXP.exe
S3 SDdriver;SDdriver;\??\E:\WINDOWS\system32\Drivers\sddriver.sys
S3 USBCamera;DSC Still Image Capture (CA100);E:\WINDOWS\system32\Drivers\Bulk533.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{108e4937-5d47-11dc-bdad-806d6172696f}]
AutoRun\command- D:\start.exe
Contents of the 'Scheduled Tasks' folder
2007-09-07 15:30:00 E:\WINDOWS\Tasks\Funkcja One Button Checkup pakietu Norton SystemWorks.job
2007-09-07 18:00:13 E:\WINDOWS\Tasks\Norton AntiVirus - Skanuj komputer.job - E:\Programy\NORTON~1\NORTON~1\Navw32.exe
2007-09-08 22:00:00 E:\WINDOWS\Tasks\Symantec Drmc.job
2007-09-09 13:44:45 E:\WINDOWS\Tasks\Symantec NetDetect.job - E:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-09 15:56:48
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-09-09 15:59:12
--- E O F ---
[ Dodano: Dzisiaj o 16:35 ]
i co ciekawsze... problem ustapił, ale z doświadczenia wiem,że to chwilowe ;]
[ Dodano: Dzisiaj o 17:06 ]
jeszcze log z SmitFraudFix'a
- Kod: Zaznacz wszystko
SmitFraudFix v2.210
Scan done at 17:01:42.18, 2007-09-09
Run from C:\downloady\SmitfraudFix
OS: Microsoft Windows XP [Wersja 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\Ati2evxx.exe
E:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
E:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Programy\Comodo\Firewall\cmdagent.exe
E:\Programy\Norton SystemWorks\Norton Ghost\GhostStartService.exe
E:\Programy\Norton SystemWorks\Norton Antivirus\navapsvc.exe
E:\Programy\NORTON~1\NORTON~2\NPROTECT.EXE
E:\WINDOWS\system32\PSIService.exe
E:\Programy\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
E:\WINDOWS\System32\svchost.exe
E:\Programy\SPEEDB~1\VideoAcceleratorEngine.exe
E:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
E:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
E:\Program Files\Common Files\Symantec Shared\ccApp.exe
E:\Programy\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
E:\Programy\SPEEDB~1\VideoAccelerator.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Programy\iTunes\iTunes.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Programy\WapSter\AQQ\AQQ.exe
E:\Programy\Opera\Opera.exe
E:\WINDOWS\explorer.exe
E:\Programy\Comodo\Firewall\cpf.exe
E:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
hosts file corrupted !
127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info
»»»»»»»»»»»»»»»»»»»»»»»» E:\
»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» E:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\Eeek
»»»»»»»»»»»»»»»»»»»»»»»» E:\Documents and Settings\Eeek\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» E:\DOCUME~1\Eeek\Ulubione
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» E:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Moja bieľĄca strona g˘wna"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: WAN (PPP/SLIP) Interface
DNS Server Search Order: 194.204.159.1
DNS Server Search Order: 217.98.63.164
HKLM\SYSTEM\CCS\Services\Tcpip\..\{467783DA-5FEA-41DB-A1EC-612FB13C286A}: NameServer=194.204.159.1 217.98.63.164
HKLM\SYSTEM\CS1\Services\Tcpip\..\{467783DA-5FEA-41DB-A1EC-612FB13C286A}: NameServer=194.204.159.1 217.98.63.164
HKLM\SYSTEM\CS3\Services\Tcpip\..\{467783DA-5FEA-41DB-A1EC-612FB13C286A}: NameServer=194.204.159.1 217.98.63.164
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End