
dziś moja Avira AntiVir podczas surfowania po necie (normalne akcje) wyskoczył mi z komunikatem o wirusie. Oto on oraz czynność, jaką podjąłem (czyli denny access).
- Kod: Zaznacz wszystko
Virus or unwanted program 'TR/Downloader.Gen [trojan]'
detected in file 'C:\WINDOWS\system32\nvaux32.dll.
Action performed: Deny access
Teraz nie wiem, co z tym zrobić - usunąć? Nie usunąć?
Zrobiłem oczywiście skan ComboFixem, który zamieszczam poniżej. Jak widac, ComboFix albo nie zauważył tego pliku albo go zignorował, czy coś.
- Kod: Zaznacz wszystko
ComboFix 08-12-03.04 - User 2008-12-04 17:33:41.9 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.459 [GMT 1:00]
Uruchomiony z: c:\documents and settings\User\Pulpit\ComboFix.exe
* Utworzono nowy punkt przywracania
[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Cfx32.lic
c:\windows\system32\cfx32.ocx
c:\windows\system32\WMV9VCM.dll
.
((((((((((((((((((((((((( Pliki utworzone od 2008-11-04 do 2008-12-04 )))))))))))))))))))))))))))))))
.
2008-12-04 17:29 . 2008-12-04 17:29 147,456 --ah----- c:\windows\system32\aston.mt
2008-11-13 09:12 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-13 09:11 . 2008-09-04 18:17 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-09 15:47 . 2008-11-29 18:43 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-09 15:47 . 2008-11-09 15:47 1,409 --a------ c:\windows\QTFont.for
2008-11-08 08:15 . 2008-11-08 08:15 <DIR> d-------- c:\documents and settings\User\.borland
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-04 16:31 580,096 ----a-w c:\windows\system32\user32.DLL
2008-12-04 16:31 580,096 ----a-w c:\windows\system32\dllcache\user32.dll
2008-10-26 17:59 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Trymedia
2008-10-25 15:16 249,592 ----a-w c:\windows\system32\cssdll32.dll
2008-10-25 15:15 --------- d-----w c:\program files\COMODO
2008-10-25 15:15 --------- d-----w c:\documents and settings\User\Dane aplikacji\Comodo
2008-10-25 15:15 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\comodo
2008-10-25 09:36 --------- d-----w c:\program files\Avira
2008-10-25 09:36 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Avira
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:31 223,128 ----a-w c:\windows\system32\drivers\dtscsi.sys
2008-10-22 15:26 96,384 ----a-w c:\windows\system32\drivers\sptd9597.sys
2008-10-20 21:04 0 ----a-w c:\windows\system32\drivers\sptd.sys
2008-10-20 21:04 0 ----a-w c:\windows\system32\drivers\EagleNT.sys
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-15 17:36 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-14 10:55 110,304 ----a-w c:\windows\system32\drivers\ACEDRV09.sys
2008-10-03 18:26 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 16:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
2008-09-15 16:27 1,846,656 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 11:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2005-03-31 21:17 40,960 ----a-w c:\program files\Uninstall_CDS.exe
.
[color=red] c:\windows\system32\user32.dll ... jest zarażony !! [/color]
580,096 2008-12-04 16:31:20 c:\windows\system32\user32.DLL
580,096 2008-12-04 16:31:20 c:\windows\system32\dllcache\user32.dll
579,072 2007-03-08 16:38:48 c:\windows\$NtServicePackUninstall$\user32.dll
578,560 2004-08-04 07:44:14 c:\windows\$NtServicePackUninstall$\user32.dll.000
580,096 2008-04-14 18:20:56 c:\windows\ServicePackFiles\i386\user32.dll
578,560 2005-03-02 18:18:38 c:\windows\$hf_mig$\KB890859\SP2GDR\user32.dll
578,560 2005-03-02 18:21:08 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
579,584 2007-03-08 16:51:58 c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
578,560 2004-08-04 07:44:14 c:\windows\$NtUninstallKB890859$\user32.dll
561,664 2002-09-23 11:00:00 c:\windows\$NtUninstallKB890859_0$\user32.dll
578,560 2005-03-02 18:18:38 c:\windows\$NtUninstallKB925902$\user32.dll
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="c:\program files\ASUS\SmartDoctor\\SmartDoctor.exe" [2004-12-16 987136]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 307200]
"PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-06-10 1397760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-08 282624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
c:\documents and settings\User\Menu Start\Programy\Autostart\
WordWeb.lnk - f:\wordweb\wweb32.exe [2007-01-28 20992]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
GetRight - Tray Icon.lnk - c:\program files\GetRight\getright.exe [2006-02-14 2301952]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Uruchamianie pakietu Office.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-10-06 51984]
Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-10-06 111376]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-06 113664]
Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - c:\program files\SAGEM WiFi manager\WLANUTL.exe [2007-03-21 925696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= ctwdm32.dll
"vidc.asv2"= asusasv2.dll
"msacm.dvacm"= dvacm.acm
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\acup.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Mks_Scan]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Mks_Scan\Service]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"f:\\FileZilla\\FileZilla.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Gadu-Gadu\\ggphone\\ggphone.exe"=
"d:\\AOE2CONQ\\empires2.exe"=
"c:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
"c:\\Program Files\\FlashGet\\FLASHGET.EXE"=
"d:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Documents and Settings\\User\\Dane aplikacji\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\SopCast\\sopvod.exe"=
"c:\\Program Files\\TC PowerPack\\totalcmd.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"d:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
R2 ACEDRV09;ACEDRV09;\??\c:\windows\system32\drivers\ACEDRV09.sys [2008-10-14 110304]
R2 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys [2008-08-17 2368]
R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\DRIVERS\WlanBZXP.sys [2007-03-21 402432]
R3 Video3D;ASUS Video3D Service;c:\windows\system32\Drivers\Video3D.sys [2004-07-06 44544]
S1 acup;VPower Control Service;c:\windows\system32\acup.sys []
S1 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS [2008-10-20 0]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;d:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-09-27 1527900]
S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2008-10-14 544768]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.onet.pl/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Ściągnij przy pomocy FlashGet'a - c:\program files\FlashGet\jc_link.htm
IE: &Ściągnij wszystko przy pomocy FlashGet'a - c:\program files\FlashGet\jc_all.htm
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\weblive.exe - O16 -: {070CA17A-4BD2-4612-83B4-32B1B9159B47}
hxxp://uc.sina.com.cn/download/live/weblive2.4.0.0.cab
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\ArcaMicroScanUpdater.exe - c:\windows\system32\ArcaOnlineUninstall.exe
c:\windows\system32\ArcaOnline.dll
O16 -: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D}
hxxp://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
c:\windows\Downloaded Program Files\ArcaOnline.inf
c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55}
hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
c:\windows\Downloaded Program Files\SkanerOnline.inf
c:\windows\Downloaded Program Files\UKooPlayer.ocx - O16 -: {A903E5AB-C67E-40FB-94F1-E1305982F6E0}
hxxp://www.euchannels.net/UKooPlayer.ocx
c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
O16 -: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7}
hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
c:\windows\Downloaded Program Files\SkanerOnline.inf
FireFox -: Profile - c:\documents and settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\4hsbxv9g.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://onet.pl/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-04 17:35:33
Windows 5.1.2600 Dodatek Service Pack 3 FAT NTAPI
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-12-04 17:36:11
ComboFix2.txt 2008-10-25 14:57:48
ComboFix-quarantined-files.txt 2008-12-04 16:36:10
Przed: 2 913 796 096 bajtów wolnych
Po: 3,065,921,536 bajtów wolnych
198 --- E O F --- 2008-11-13 12:22:58
Zauważcie
c:\windows\system32\user32.dll ... jest zarażony !!
Proszę o pomoc

PS. Wkleić hijackthisa?
EDIT:
user32.dll przeskanowałem na Virustotal i takie wyniki:
- Kod: Zaznacz wszystko
Antywirus Wersja Ostatnia aktualizacja Wynik
AhnLab-V3 2008.12.5.0 2008.12.04 Win-Trojan/User32Hk
AntiVir 7.9.0.36 2008.12.04 -
Authentium 5.1.0.4 2008.12.04 -
Avast 4.8.1281.0 2008.12.03 -
AVG 8.0.0.199 2008.12.04 -
BitDefender 7.2 2008.12.04 -
CAT-QuickHeal 10.00 2008.12.04 -
ClamAV 0.94.1 2008.12.04 -
DrWeb 4.44.0.09170 2008.12.04 -
eSafe 7.0.17.0 2008.12.04 -
eTrust-Vet 31.6.6243 2008.12.04 Win32/Pruserinf
Ewido 4.0 2008.12.04 -
F-Prot 4.4.4.56 2008.12.04 -
F-Secure 8.0.14332.0 2008.12.04 Trojan.Win32.Patched.bb
Fortinet 3.117.0.0 2008.12.04 -
GData 19 2008.12.04 -
Ikarus T3.1.1.45.0 2008.12.04 -
K7AntiVirus 7.10.543 2008.12.04 -
Kaspersky 7.0.0.125 2008.12.04 Trojan.Win32.Patched.bb
McAfee 5453 2008.12.03 -
McAfee+Artemis 5453 2008.12.03 potentially unwanted program Patched User32
Microsoft 1.4205 2008.12.04 -
NOD32 3664 2008.12.04 -
Norman 5.80.02 2008.12.04 -
Panda 9.0.0.4 2008.12.04 W32/Patched.D
PCTools 4.4.2.0 2008.12.04 -
Prevx1 V2 2008.12.04 -
Rising 21.06.32.00 2008.12.04 Trojan.Win32.Patched.bi
SecureWeb-Gateway 6.7.6 2008.12.04 -
Sophos 4.36.0 2008.12.04 Troj/User32Hk-A
Sunbelt 3.1.1832.2 2008.12.01 -
Symantec 10 2008.12.04 -
TheHacker 6.3.1.2.174 2008.12.04 -
TrendMicro 8.700.0.1004 2008.12.04 Mal_Patch-1
VBA32 3.12.8.10 2008.12.03 -
ViRobot 2008.12.4.1500 2008.12.04 -
VirusBuster 4.5.11.0 2008.12.04 -