w czasie przygotowywania do skanowania z combofix wyskakuje mi komunikat, ze dostep hosta do skryptow windowsa jest wylaczony na tym komputerze. Co mam z tym zrobic?[/quote]
[ Dodano: Dzisiaj o 20:00 ] ok, z tymi skryptami sobie poradzilem, ale nie mam pojecia jak zrobic tego loga combofix. Uruchamiam ten program on sie wlacza, po chwili znika mi caly pulpit i to wszystko
[ Dodano: Dzisiaj o 20:04 ] Start Time= 2008-02-07 19:57:02,60
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-02-07 16:44:32 ( .D... ) "C:\Program Files\Trend Micro"
2008-02-07 16:07:40 ( .D... ) "C:\Program Files\concept design"
2008-02-05 23:56:42 ( .D... ) "C:\Program Files\Microsoft Works"
2008-02-05 23:56:22 ( .D... ) "C:\Program Files\MSBuild"
2008-02-05 23:55:34 ( .D... ) "C:\Program Files\Common Files\DESIGNER"
2008-02-05 18:22:52 103673 ( ..SHR ) "C:\WINDOWS\system32\amvo.exe"
2008-02-05 18:22:52 103673 ( ..SHR ) "C:\188qsm.bat"
2008-02-05 17:28:36 ( .D... ) "C:\Program Files\thriXXX"
2008-02-04 16:46:14 103367 ( ..SHR ) "C:\2ifetri.cmd"
2008-01-23 17:23:28 107528 ( ..SHR ) "C:\awda2.exe"
2008-01-22 18:11:24 ( .D... ) "C:\Program Files\RndLabs"
2008-01-10 17:26:22 ( .D... ) "C:\Program Files\MSXML 4.0"
2008-01-10 14:59:08 ( .D... ) "C:\Program Files\Phoenix Technologies Ltd"
2008-01-09 12:18:18 524288 ( A.... ) "C:\WINDOWS\system32\DivXsm.exe"
2008-01-09 12:18:12 3596288 ( A.... ) "C:\WINDOWS\system32\qt-dx331.dll"
2008-01-09 12:18:08 1628920 ( ..... ) "C:\WINDOWS\system32\pxsfs.dll"
2008-01-09 12:18:08 551672 ( ..... ) "C:\WINDOWS\system32\px.dll"
2008-01-09 12:18:08 518904 ( ..... ) "C:\WINDOWS\system32\pxdrv.dll"
2008-01-09 12:18:08 379640 ( ..... ) "C:\WINDOWS\system32\pxwave.dll"
2008-01-09 12:18:08 187128 ( ..... ) "C:\WINDOWS\system32\pxmas.dll"
2008-01-09 12:18:08 120056 ( ..... ) "C:\WINDOWS\system32\pxcpyi64.exe"
2008-01-09 12:18:08 118520 ( ..... ) "C:\WINDOWS\system32\pxinsi64.exe"
2008-01-09 12:18:08 72440 ( ..... ) "C:\WINDOWS\system32\pxhpinst.exe"
2008-01-09 12:18:06 129784 ( ..... ) "C:\WINDOWS\system32\pxafs.dll"
2008-01-09 12:18:06 88824 ( ..... ) "C:\WINDOWS\system32\vxblock.dll"
2008-01-09 12:18:06 66296 ( ..... ) "C:\WINDOWS\system32\pxcpya64.exe"
2008-01-09 12:18:06 64760 ( ..... ) "C:\WINDOWS\system32\pxinsa64.exe"
2008-01-09 12:18:00 1044480 ( A.... ) "C:\WINDOWS\system32\libdivx.dll"
2008-01-09 12:18:00 200704 ( A.... ) "C:\WINDOWS\system32\ssldivx.dll"
2008-01-09 12:16:10 196608 ( A.... ) "C:\WINDOWS\system32\dtu100.dll"
2008-01-09 12:16:10 81920 ( A.... ) "C:\WINDOWS\system32\dpl100.dll"
2008-01-09 12:16:02 823296 ( A.... ) "C:\WINDOWS\system32\divx_xx0c.dll"
2008-01-09 12:16:02 823296 ( A.... ) "C:\WINDOWS\system32\divx_xx07.dll"
2008-01-09 12:16:02 802816 ( A.... ) "C:\WINDOWS\system32\divx_xx11.dll"
2008-01-09 12:16:02 682496 ( A.... ) "C:\WINDOWS\system32\DivX.dll"
2007-12-11 20:44:22 53248 ( A.... ) "C:\WINDOWS\system32\dpuGUI10.dll"
2007-12-11 20:44:20 593920 ( A.... ) "C:\WINDOWS\system32\dpuGUI11.dll"
2007-12-11 20:44:20 344064 ( A.... ) "C:\WINDOWS\system32\dpus11.dll"
2007-12-11 20:44:20 294912 ( A.... ) "C:\WINDOWS\system32\dpu11.dll"
2007-12-11 20:44:20 294912 ( A.... ) "C:\WINDOWS\system32\dpu10.dll"
2007-12-11 20:44:20 57344 ( A.... ) "C:\WINDOWS\system32\dpv11.dll"
2007-12-11 20:44:00 156992 ( A.... ) "C:\WINDOWS\system32\DivXCodecVersionChecker.exe"
2007-12-11 20:43:44 12288 ( A.... ) "C:\WINDOWS\system32\DivXWMPExtType.dll"
2007-12-04 14:04:28 837496 ( A.... ) "C:\WINDOWS\system32\aswBoot.exe"
2007-12-04 13:54:04 95608 ( A.... ) "C:\WINDOWS\system32\AvastSS.scr"
2007-11-14 08:28:56 450560 ( A.... ) "C:\WINDOWS\system32\jscript.dll"
2007-11-13 12:31:12 60416 ( ..... ) "C:\WINDOWS\system32\tzchange.exe"
2007-11-07 10:29:34 723968 ( A.... ) "C:\WINDOWS\system32\lsasrv.dll"
((((((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"Mouse Suite 98 Daemon"="ICO.EXE"
"ATIModeChange"="Ati2mdxx.exe"
"AtiPTA"="atiptaxx.exe"
"DAEMON Tools-1033"="\"C:\\Program Files\\D-Tools\\daemon.exe\" -lang 1033 -noicon"
"KernelFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,\
65,6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,6b,00
"OrderReminder"="C:\\Program Files\\Hewlett-Packard\\OrderReminder\\OrderReminder.exe"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"DataLayer"="C:\\PROGRA~1\\COMMON~1\\PCSuite\\DATALA~1\\DATALA~1.EXE"
"PCSuiteTrayApplication"="C:\\PROGRA~1\\Nokia\\NOKIAP~1\\TRAYAP~1.EXE"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\""
"NeroFilterCheck"="C:\\Program Files\\Common Files\\Ahead\\Lib\\NeroCheck.exe"
"Realtime Audio Engine"="mmrtkrnl.exe"
"FixCamera"="C:\\WINDOWS\\FixCamera.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
"Gadu-Gadu"="\"C:\\Program Files\\Gadu-Gadu\\gg.exe\" /tray"
"PeerGuardian"="C:\\Program Files\\PeerGuardian2\\pg2.exe"
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Ahead\\Lib\\NMBgMonitor.exe\""
"H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\Wcescomm.exe\""
"amva"="C:\\WINDOWS\\system32\\amvo.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Moduł wstępnego ładowania interfejsu Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Demon buforu kategorii składników"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"
Contents of the 'Scheduled Tasks' folder
Completion time: 2008-02-07 19:57:20,87
ComboFix ver 06.06.17 - This logfile is located at C:\ComboFix.txt