
za chwile jakis komunikat z windowsa a mi wyskoczyl i ten plik niby z jakims trojanem znikl
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 20:59:02, on 2007-12-26
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Konnekt\konnekt.exe
C:\Program Files\AutoConnect\AutoConnect.exe
C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\admin\Pulpit\USDownloader\USDownloader.exe
C:\WINDOWS\system32\svchost.exe
D:\Programy\log\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = neostrada tp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [autoclk] autoclk.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\Deamon-Tools\daemon.exe" -lang 1045
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [KAVWks50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 5.0 for Windows Workstations\kav.exe" /minimize /chkas
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Konnekt] "C:\Program Files\Konnekt\konnekt.exe" /autostart
O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{2065E759-AF3A-475B-952E-CD6516848209}: NameServer = 194.204.159.1 217.98.63.164
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B716AED-1188-4EBE-808C-353EBA735FE6}: NameServer = 212.85.112.32,193.110.121.20
O17 - HKLM\System\CS1\Services\Tcpip\..\{2065E759-AF3A-475B-952E-CD6516848209}: NameServer = 194.204.159.1 217.98.63.164
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Usługa Kaspersky Anti-Virus (kavsvc) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 5.0 for Windows Workstations\kavsvc.exe
[ Dodano: Dzisiaj o 21:19 ]
ciagle mnie atakuja jakies trojany ale wszytko jest blokowane przez kacpersky'iego
- Kod: Zaznacz wszystko
ComboFix 07-12-21.4 - admin 2007-12-26 21:04:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.224 [GMT 1:00]
Running from: D:\Downloads\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-11-26 to 2007-12-26 )))))))))))))))))))))))))))))))
.
2007-12-25 17:15 . 2007-12-25 18:58 89 --a------ C:\WINDOWS\usdthank.ini
2007-12-25 17:15 . 2007-12-25 17:15 31 --a------ C:\WINDOWS\idc.ini
2007-12-24 14:37 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-12-24 14:30 . 2007-12-24 14:48 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2007-12-24 14:30 . 2007-12-24 14:31 <DIR> d-------- C:\Documents and Settings\admin\Dane aplikacji\Teleca
2007-12-24 14:28 . 2007-12-24 14:29 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-24 14:27 . 2007-12-24 14:27 58,288 --a------ C:\WINDOWS\system32\drivers\k510bus.sys
2007-12-24 14:27 . 2007-12-24 14:27 5,808 --a------ C:\WINDOWS\system32\drivers\k510whnt.sys
2007-12-24 14:27 . 2007-12-24 14:27 5,808 --a------ C:\WINDOWS\system32\drivers\k510wh.sys
2007-12-24 12:01 . 2007-12-25 18:13 69 --a------ C:\WINDOWS\NeroDigital.ini
2007-12-24 09:24 . 2007-12-24 09:24 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-12-24 09:24 . 2007-12-24 09:24 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Anti-Virus for Windows Workstations
2007-12-23 22:26 . 2007-12-23 22:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\ESET
2007-12-23 14:21 . 2007-12-26 19:12 <DIR> d-------- C:\Program Files\AutoConnect
2007-12-23 13:49 . 2007-12-23 13:49 <DIR> d---s---- C:\Documents and Settings\admin\UserData
2007-12-23 11:07 . 2007-12-23 11:08 <DIR> d-------- C:\Program Files\Winamp
2007-12-23 11:01 . 2007-12-23 11:05 <DIR> d-------- C:\Program Files\Winamp Remote
2007-12-23 11:01 . 2007-12-23 11:05 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\OrbNetworks
2007-12-23 10:47 . 2007-12-23 10:47 <DIR> d-------- C:\Documents and Settings\admin\.jpi_cache
2007-12-23 10:47 . 2007-12-23 10:47 <DIR> d-------- C:\Documents and Settings\admin\.java
2007-12-23 10:45 . 2005-11-10 13:03 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2007-12-23 10:44 . 2007-12-23 10:44 <DIR> d-------- C:\Program Files\Common Files\Java
2007-12-23 10:41 . 2007-12-24 14:27 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-12-23 10:41 . 2007-12-23 10:41 <DIR> d-------- C:\Program Files\Deamon-Tools
2007-12-23 10:41 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-12-23 10:41 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-12-23 10:38 . 2007-12-23 10:38 <DIR> d-------- C:\Program Files\CCleaner
2007-12-23 10:33 . 2007-12-23 10:33 <DIR> d-------- C:\Program Files\Skype
2007-12-23 10:33 . 2007-12-23 10:35 <DIR> d-------- C:\Documents and Settings\admin\Dane aplikacji\Skype
2007-12-22 22:36 . 2007-12-23 12:43 <DIR> d-------- C:\Program Files\Konnekt
2007-12-22 22:36 . 2007-12-22 22:36 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\stamina
2007-12-22 22:16 . 2007-12-22 22:16 1,158 --a------ C:\WINDOWS\mozver.dat
2007-12-22 22:05 . 2007-12-22 22:05 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-22 22:02 . 2007-12-22 22:02 <DIR> d-------- C:\Documents and Settings\admin\Dane aplikacji\Gadu-Gadu
2007-12-22 21:54 . 2007-12-22 21:54 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-12-22 21:54 . 2007-12-23 12:54 <DIR> d-------- C:\Documents and Settings\admin\Gadu-Gadu
2007-12-22 21:42 . 2007-12-22 21:42 <DIR> d-------- C:\Program Files\SAGEM
2007-12-22 21:41 . 2007-12-22 21:41 <DIR> d-------- C:\WINDOWS\system32\AlertModule
2007-12-22 21:41 . 2007-12-23 10:45 <DIR> d-------- C:\Program Files\Java
2007-12-22 21:41 . 2003-08-04 14:22 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
2007-12-22 21:41 . 2002-11-01 20:15 45,175 --------- C:\WINDOWS\system32\plugincpl140_03.cpl
2007-12-22 21:41 . 2002-11-01 20:15 41,068 --------- C:\WINDOWS\system32\ActPanel.dll
2007-12-22 21:41 . 2004-08-23 14:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
2007-12-22 21:41 . 2005-10-06 15:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
2007-12-22 21:41 . 2003-08-04 14:22 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS
2007-12-22 21:40 . 2007-12-26 19:12 <DIR> d-------- C:\Program Files\neostrada tp
2007-12-22 21:39 . 2007-12-22 21:39 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-12-22 21:36 . 2007-12-22 21:38 22 --a------ C:\WINDOWS\system32\ati64hlp.stb
2007-12-22 21:34 . 2003-09-12 21:10 114,688 --a------ C:\WINDOWS\system32\ati2sgag.exe
2007-12-22 21:33 . 2007-12-22 21:34 <DIR> d-------- C:\Program Files\ATI Technologies
2007-12-22 21:32 . 2004-05-02 09:47 23,040 -ra------ C:\WINDOWS\system32\drivers\GVCplDrv.sys
2007-12-22 20:10 . 2007-12-22 20:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-12-22 20:10 . 2007-12-22 20:10 <DIR> d-------- C:\Program Files\Ahead
2007-12-22 20:10 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-12-22 20:10 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-12-22 20:10 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-12-22 20:10 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-12-22 20:10 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-12-22 20:10 . 2004-03-02 17:37 125,184 --------- C:\WINDOWS\system32\drivers\imagesrv.sys
2007-12-22 20:10 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-12-22 20:10 . 2004-03-02 17:37 5,504 --------- C:\WINDOWS\system32\drivers\imagedrv.sys
2007-12-22 20:07 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2007-12-22 20:07 . 2007-12-22 20:07 421 --a------ C:\WINDOWS\ODBC.INI
2007-12-22 20:06 . 2007-12-22 20:06 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-12-22 20:06 . 2007-12-22 20:06 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-12-22 18:41 . 2004-08-03 23:44 278,528 --a------ C:\WINDOWS\system32\mstask.dll
2007-12-22 18:40 . 2004-08-03 23:43 561,179 --a--c--- C:\WINDOWS\system32\dllcache\dao360.dll
2007-12-22 18:39 . 2007-12-22 18:59 21,856 --a------ C:\WINDOWS\system32\emptyregdb.dat
2007-12-22 18:39 . 2007-12-22 18:39 37 --a------ C:\WINDOWS\vbaddin.ini
2007-12-22 18:39 . 2007-12-22 18:39 36 --a------ C:\WINDOWS\vb.ini
2007-12-22 18:36 . 2001-10-26 18:29 231,424 --a--c--- C:\WINDOWS\system32\dllcache\avtapi.dll
2007-12-22 18:35 . 2001-07-21 23:36 65,832 --a------ C:\WINDOWS\Stiuk z Santa Fe.bmp
2007-12-22 18:35 . 2001-07-21 23:36 26,680 --a------ C:\WINDOWS\Wachlarze.bmp
2007-12-22 18:35 . 2001-07-21 23:36 17,362 --a------ C:\WINDOWS\Rododendron.bmp
2007-12-22 18:35 . 2001-07-21 23:36 9,522 --a------ C:\WINDOWS\Indiański pled.bmp
2007-12-22 18:33 . 2001-10-26 18:29 147,456 --a--c--- C:\WINDOWS\system32\dllcache\comsnap.dll
2007-12-22 18:32 . 2004-08-03 23:44 545,792 --a--c--- C:\WINDOWS\system32\dllcache\dialer.exe
2007-12-22 18:31 . 2007-12-22 18:39 <DIR> d-------- C:\WINDOWS\system32\MsDtc
2007-12-22 18:30 . 2004-08-03 23:43 1,352,704 --a--c--- C:\WINDOWS\system32\dllcache\cimwin32.dll
2007-12-22 18:29 . 2004-08-03 23:01 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2007-12-22 18:29 . 2004-08-03 23:43 187,904 --a--c--- C:\WINDOWS\system32\dllcache\cmprops.dll
2007-12-22 18:29 . 2004-08-03 23:43 187,904 --a------ C:\WINDOWS\system32\cmprops.dll
2007-12-22 18:29 . 2004-08-04 00:44 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-26 10:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-24 13:26 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-12-22 20:42 33 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2007-12-22 18:58 --------- d-----w C:\Program Files\Real Alternative
2007-12-22 18:58 --------- d-----w C:\Program Files\Media Player Classic
2007-12-22 18:57 --------- d-----w C:\Program Files\MarBit
2007-12-22 18:56 --------- d-----w C:\Program Files\Vplayer
2007-12-22 18:55 --------- d-----w C:\Program Files\K-Lite Codec Pack
2007-12-22 18:54 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\CyberLink
2007-12-22 18:53 --------- d-----w C:\Program Files\CyberLink
2007-12-22 18:46 --------- d-----w C:\Program Files\Realtek Sound Manager
2007-12-22 18:46 --------- d-----w C:\Program Files\Gigabyte
2007-12-22 18:46 --------- d-----w C:\Program Files\AvRack
2007-12-22 18:02 --------- d-----w C:\Program Files\microsoft frontpage
2007-12-22 18:00 --------- d-----w C:\Program Files\Usługi online
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
"Konnekt"="C:\Program Files\Konnekt\konnekt.exe" [2005-05-24 22:41]
"AutoConnect"="C:\Program Files\AutoConnect\AutoConnect.exe" [2006-12-03 00:14]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-07-27 10:01 C:\WINDOWS\SOUNDMAN.EXE]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-09-12 21:10]
"autoclk"="autoclk.exe" []
"adiras"="adiras.exe" []
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 14:49]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 16:55]
"DAEMON Tools-1033"="C:\Program Files\Deamon-Tools\daemon.exe" [2004-08-22 17:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2005-12-09 07:30]
"KAVWks50"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 5.0 for Windows Workstations\kav.exe" [2006-07-12 19:18]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-12-22 21:42:14]
R1 klmc;Sterownik KLMC;C:\WINDOWS\system32\drivers\klmc.sys [2006-07-12 19:23]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-09-19 11:03]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-09-15 11:07]
S3 GVCplDrv;GVCplDrv;C:\WINDOWS\system32\drivers\GVCplDrv.sys [2004-05-02 09:47]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys [2007-12-24 14:27]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-26 21:06:24
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-26 21:07:52