a robisz formata z odlaczonym kablem od neta ?
tak z odłączonym
wykonałem wszystkie polecenia tak jak napisałeś... jeśli chodzi o CMD to przy próbie kasowania niektórych plików wyskakiwał mi komunikat że ich nie może znaleźć.. ale może ma to związek z tym że jeszcze wczoraj przeleciałem kompa Ad-awarem i może części tych plików dzięki niemu już nie miałem..
oto logi:
SDFix:
SDFix: Version 1.112
Run by Administrator on 2007-10-27 at 12:35
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Name:
kprof
MSN RAV
poof
ImagePath:
\??\C:\WINDOWS\System32\kprof
"C:\WINDOWS\system\msnrav.exe"
\??\C:\WINDOWS\System32\poof
kprof - Deleted
MSN RAV - Deleted
poof - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\4_exception.nls - Deleted
C:\WINDOWS\system32\delFSF.bat - Deleted
C:\WINDOWS\system32\drivers\symavc32.sys - Deleted
C:\WINDOWS\system32\i - Deleted
C:\WINDOWS\system32\o - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
Remaining Files:
---------------
catchme 0.3.1160 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 12:38:00
Windows 5.1.2600 Dodatek Service Pack. 1 FAT NTAPI
scanning hidden files ...
scan completed successfully
hidden files: 0
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Fri 26 Oct 2007 29,995 A..H. --- "C:\System Volume Information\_restore{08F77FD9-6D8F-42DC-A627-B0F188249B03}\RP4\A0001177.exe"
Finished!
HiJackThis:
Logfile of HijackThis v1.99.1
Scan saved at 12:40:54, on 2007-10-27
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Tlen.pl\tlen.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\przem\Pulpit\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Komunikator] C:\Program Files\Tlen.pl\tlen.exe
O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{0212C20C-0A0E-484E-9405-9F4DAB6CE6FA}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CS1\Services\Tcpip\..\{0212C20C-0A0E-484E-9405-9F4DAB6CE6FA}: NameServer = 194.204.159.1 217.98.63.164
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
ComboFix:
ComboFix 07-10-26.4 - przem 2007-10-27 12:42:40.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.1.1250.1.1045.18.155 [GMT 2:00]
Running from: C:\Documents and Settings\przem\Pulpit\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\Towy73.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_POOF
-------\LEGACY_RUNTIME
-------\LEGACY_RUNTIME2
-------\LEGACY_TOWY73
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-27 12:42 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-27 12:34 <DIR> d-------- C:\WINDOWS\ERUNT
2007-10-27 12:34 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2007-10-27 12:34 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2007-10-27 12:34 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2007-10-27 12:34 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2007-10-27 12:34 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2007-10-27 12:34 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2007-10-27 12:34 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2007-10-27 12:10 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2007-10-27 11:53 <DIR> d-------- C:\Program Files\Nero
2007-10-27 11:53 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-10-27 11:53 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Nero
2007-10-26 19:53 <DIR> d-------- C:\WINDOWS\LastGood
2007-10-26 19:43 <DIR> d-------- C:\Program Files\AutoConnect
2007-10-26 18:32 <DIR> d-------- C:\Program Files\Lavasoft
2007-10-26 18:32 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2007-10-26 18:30 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-26 18:26 <DIR> d--hs---- C:\Recycled
2007-10-26 18:08 21,760 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2007-10-26 12:59 <DIR> dr-h----- C:\$VAULT$.AVG
2007-10-26 12:57 <DIR> d-------- C:\Documents and Settings\LocalService\Dane aplikacji\AVG7
2007-10-26 12:55 116,344 --a------ C:\WINDOWS\system32\re1.exe
2007-10-26 12:24 <DIR> d-------- C:\Documents and Settings\przem\Dane aplikacji\AVG7
2007-10-26 12:24 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2007-10-26 12:24 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2007-10-26 12:24 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2007-10-26 12:23 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Grisoft
2007-10-26 12:23 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\avg7
2007-10-25 12:47 1,156 --a------ C:\WINDOWS\mozver.dat
2007-10-25 12:42 <DIR> d-------- C:\Documents and Settings\przem\Dane aplikacji\Tlen.pl
2007-10-25 12:24 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2007-10-25 12:23 <DIR> d-------- C:\WINDOWS\system32\InsFiles
2007-10-25 12:23 684,265 -ra------ C:\WINDOWS\system32\drivers\torususb.sys
2007-10-25 12:23 425,984 -ra------ C:\WINDOWS\system32\stmcfg32.dll
2007-10-25 12:23 151,552 -ra------ C:\WINDOWS\system32\stmctrl.dll
2007-10-25 12:23 102,400 -ra------ C:\WINDOWS\stmtrace.exe
2007-10-25 12:23 65,536 -ra------ C:\WINDOWS\DSLTest.exe
2007-10-25 12:23 60,255 -ra------ C:\WINDOWS\system32\drivers\stmatm.sys
2007-10-25 12:23 36,864 -ra------ C:\WINDOWS\system32\stmclean.exe
2007-10-25 12:23 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
2007-10-25 12:20 <DIR> d-------- C:\Program Files\ZTE ZXDSL 852
2007-10-25 12:19 <DIR> d-------- C:\Program Files\Java
2007-10-25 12:19 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-10-25 12:19 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-10-25 12:19 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
2007-10-25 12:19 41,068 --------- C:\WINDOWS\system32\ActPanel.dll
2007-10-25 12:19 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS
2007-10-25 12:18 <DIR> d-------- C:\WINDOWS\LastGood.Tmp
2007-10-25 12:17 <DIR> d-------- C:\Program Files\neostrada tp
2007-10-25 12:14 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-10-25 12:12 <DIR> d-------- C:\Program Files\Tlen.pl
2007-10-25 12:06 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-25 12:04 <DIR> d--hs---- C:\WINDOWS\Installer
2007-10-25 12:04 <DIR> d--h----- C:\Documents and Settings\przem\Ustawienia lokalne
2007-10-25 12:04 <DIR> dr------- C:\Documents and Settings\przem\Ulubione
2007-10-25 12:04 <DIR> d--h----- C:\Documents and Settings\przem\Szablony
2007-10-25 12:04 <DIR> d-------- C:\Documents and Settings\przem\Pulpit
2007-10-25 12:04 <DIR> dr------- C:\Documents and Settings\przem\Moje dokumenty
2007-10-25 12:04 <DIR> dr------- C:\Documents and Settings\przem\Menu Start
2007-10-25 12:04 <DIR> dr-h----- C:\Documents and Settings\przem\Dane aplikacji
2007-10-25 12:00 <DIR> d--h----- C:\Documents and Settings\NetworkService\Ustawienia lokalne
2007-10-25 12:00 <DIR> d-------- C:\Documents and Settings\NetworkService\Dane aplikacji
2007-10-25 12:00 <DIR> d--h----- C:\Documents and Settings\LocalService\Ustawienia lokalne
2007-10-25 12:00 <DIR> d-------- C:\Documents and Settings\LocalService\Dane aplikacji
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 09:54 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-25 09:47 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdslTaskBar"="stmctrl.dll" [2006-06-02 13:01 C:\WINDOWS\system32\stmctrl.dll]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-10-27 10:37]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-20 17:05]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2007-10-05 15:20]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" [2006-12-03 01:14]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 18:05]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\System32\DRIVERS\stmatm.sys
R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\System32\DRIVERS\torususb.sys
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 12:46:57
Windows 5.1.2600 Dodatek Service Pack. 1 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-27 12:47:38 - machine was rebooted
.
--- E O F ---
PS. właśnie mi się ściągnął SP2 więc po jego zainstalowaniu chciałbym wiedzieć czy wszystko jest ok.. wystarczy wrzucić tu któregoś loga czy mam się udać na inny dział?