
Zamieszczam Logi
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:39:48, on 2007-01-24
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\DOCUME~1\Konrad\USTAWI~1\Temp\FPSoftware\ZF.exe
L:\FPManager\FPManager.exe
C:\DOCUME~1\Konrad\USTAWI~1\Temp\SwitchHidden.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [vamsoft] C:\WINDOWS\system32\vamsoft.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 2392 bytes
- Kod: Zaznacz wszystko
ComboFix 09-01-21.04 - Konrad 2009-01-24 16:26:52.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1045.18.2047.1683 [GMT 1:00]
Uruchomiony z: c:\documents and settings\Konrad\Pulpit\ComboFix.exe
Użyto następujących komend :: c:\documents and settings\Konrad\Pulpit\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: Zapora osobista *disabled*
* Utworzono nowy punkt przywracania
FILE ::
C:\DUP2.EXE
c:\winnt\system\cscript.exe
c:\winnt\system\gm.BAT
c:\winnt\system\Hd.vbs
c:\winnt\system\svchest.exe
c:\winnt\system\svchest.reg
c:\winnt\system32\xydzyh.exe
.
((((((((((((((((((((((((( Pliki utworzone od 2008-12-24 do 2009-01-24 )))))))))))))))))))))))))))))))
.
2009-01-24 16:14 . 2009-01-24 16:14 <DIR> d-------- c:\documents and settings\Konrad\Dane aplikacji\ESET
2009-01-24 16:14 . 2008-03-03 14:25 5,702 --ah----- c:\windows\nod32restoretemdono.reg
2009-01-24 16:14 . 2008-03-03 18:21 568 --ah----- c:\windows\nod32fixtemdono.reg
2009-01-24 16:13 . 2009-01-24 16:13 <DIR> d-------- c:\program files\ESET
2009-01-24 16:13 . 2009-01-24 16:13 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\ESET
2009-01-24 16:12 . 2009-01-24 16:12 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\DAEMON Tools Pro
2009-01-24 16:11 . 2009-01-24 16:11 <DIR> d-------- c:\documents and settings\Konrad\Dane aplikacji\DAEMON Tools Pro
2009-01-24 16:07 . 2009-01-24 16:16 95,744 -r-hs---- c:\windows\system32\nmdfgds1.dll
2009-01-24 16:06 . 2009-01-24 16:08 <DIR> d-------- c:\program files\DAEMON Tools Pro
2009-01-24 16:05 . 2009-01-24 16:05 685,816 --a------ c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-24 15:16 108,512 --sh--r c:\windows\system32\olhrwef.exe
2009-01-24 15:15 95,744 ------w c:\windows\system32\nmdfgds0.dll
2008-12-23 20:58 453,152 ----a-w c:\windows\system32\NVUNINST.EXE
.
((((((((((((((((((((((((((((( snapshot@2009-01-24_16.01.01,67 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-24 15:13:52 10,134 ----a-r c:\windows\Installer\{BFBB5FAF-FF83-4E9E-9732-77A237DB81DC}\callmsi.exe
+ 2009-01-24 15:13:52 140,544 ----a-r c:\windows\Installer\{BFBB5FAF-FF83-4E9E-9732-77A237DB81DC}\egui.exe
+ 2009-01-24 15:08:42 9,728 ----a-w c:\windows\system32\BASSMOD.dll
+ 2008-07-01 07:56:22 39,944 ----a-w c:\windows\system32\drivers\eamon.sys
+ 2008-07-01 07:57:14 53,256 ----a-w c:\windows\system32\drivers\easdrv.sys
+ 2008-07-01 08:04:34 71,688 ----a-w c:\windows\system32\drivers\epfw.sys
+ 2008-07-01 08:04:36 30,728 ----a-w c:\windows\system32\drivers\epfwndis.sys
+ 2008-07-01 08:04:38 54,280 ----a-w c:\windows\system32\drivers\epfwtdi.sys
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"cdoosoft"="c:\windows\system32\olhrwef.exe" [2009-01-24 108512]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 86016]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"nwiz"="nwiz.exe" [2008-12-26 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-13 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{BB4C402F-882A-4526-8C08-51278EA437C1}"= "c:\windows\system32\afmain0.dll" [2008-04-14 78848]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
R4 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-07-01 468224]
S3 DarkSpy;DarkSpy;c:\windows\system32\DarkSpyKernel.sys [2007-01-24 129536]
S4 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\system32\regedt32.exe [2001-10-26 3584]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\Shell\AutoRun\command - K:\autoverify.exe
.
.
------- Skan uzupełniający -------
.
FF - ProfilePath - c:\documents and settings\Konrad\Dane aplikacji\Mozilla\Firefox\Profiles\79r6ykpz.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 16:27:17
Windows 5.1.2600 Dodatek Service Pack 3 NTFS
Proszę o pomoc