przez Sythev 17 Paź 2007, 15:40
witam !
daje loga bo komputer czesto sie zawiesza i po 1min znowu chodzi normalnie.. na pasku zadan np: gg zamiast czerwonego słoneczka jest czarne a inne ikony wygladaja inaczej niż 2dni temu.. skanowałem kompa ArcaOnline i nic nie wykryło,potem SpywareDoctor i Ad-Adwere i tez nic nie wykryło.. gram w Counter-Strike i na serverach miałem zawsze "ping lag" do 30..a teraz mam ponad 60.. łacze słabo chodzi może jest jakis robak na łaczu czy cos ;/ wogóle coś słabo ten komputer zaczął chodzic..
- Kod: Zaznacz wszystko
ComboFix 07-10-17.8 - Dom 2007-10-17 15:55:24.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.216 [GMT 2:00]
Running from: C:\Documents and Settings\Dom\Moje dokumenty\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2007-09-17 to 2007-10-17 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-17 13:22 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-10-17 04:37 --------- d-----w C:\Program Files\SpeedFan
2007-10-16 21:21 --------- d-----w C:\Program Files\HLSW
2007-10-16 18:54 --------- d-----w C:\Program Files\ArcaMicroScan
2007-10-10 13:47 --------- d-----w C:\Program Files\Winamp
2007-10-07 20:25 --------- d-----w C:\Program Files\Gadu-Gadu
2007-10-06 07:51 --------- d-----w C:\Program Files\Java
2007-10-03 16:05 --------- d-----w C:\Program Files\Spyware Doctor
2007-09-14 20:51 --------- d-----w C:\Program Files\SkanerOnline
2007-09-13 18:42 --------- d-----w C:\Program Files\Setup
2007-09-13 17:04 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Dane aplikacji\ArcaBit
2007-09-13 17:04 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Dane aplikacji\ArcaBit
2007-09-13 17:04 --------- d-----w C:\Program Files\RadLinker
2007-09-13 17:04 --------- d-----w C:\Program Files\MultiRes
2007-09-13 17:04 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-09-13 17:04 --------- d-----w C:\Documents and Settings\Dom\Dane aplikacji\ArcaBit
2007-09-13 16:55 --------- d-----w C:\Program Files\ArcaBit
2007-09-13 16:55 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Grisoft
2007-09-13 16:55 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\avg7
2007-09-05 17:36 1,159,168 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(2).DAT
2007-09-05 17:36 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth
2007-09-05 09:49 --------- d-----w C:\Documents and Settings\Dom\Dane aplikacji\teamspeak2
2007-08-31 15:49 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-08-29 15:12 --------- d-----w C:\Program Files\Common Files\Java
2007-08-26 20:41 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2007-08-26 19:15 --------- d-----w C:\Documents and Settings\Dom\Dane aplikacji\BearShare
2007-08-07 21:42 16,968,497 ----a-w C:\rad_w2kxp_omega_2590_7z.exe
2006-03-27 15:19 6,577,024 ----a-w C:\Program Files\sdstart.exe
2006-03-13 15:59 3,995,195 ----a-w C:\Program Files\gg76.exe
2006-02-20 08:56 1,416,944 ----a-w C:\Program Files\WM9Codecs.exe
2006-02-16 11:55 18,341,074 ----a-w C:\Program Files\klcodec284f.exe
2006-02-11 13:38 5,862,994 ----a-w C:\Program Files\ts2_client_rc2_2032.exe
2006-02-10 15:10 7,799,000 ----a-w C:\Program Files\kerio.exe
.
((((((((((((((((((((((((((((( snapshot_2007-09-15_225709,18 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-07-19 22:47:22 109,056 ----a-w C:\WINDOWS\catchme.exe
+ 2007-09-28 07:06:08 135,168 ----a-w C:\WINDOWS\catchme.exe
+ 2003-05-07 10:26:54 192,512 ----a-w C:\WINDOWS\Downloaded Program Files\CamCli.dll
+ 2003-05-07 10:26:54 180,224 ----a-w C:\WINDOWS\Downloaded Program Files\ijl11.dll
- 2007-07-11 23:22:00 135,168 ----a-w C:\WINDOWS\system32\java.exe
+ 2007-09-24 20:30:28 135,168 ----a-w C:\WINDOWS\system32\java.exe
- 2007-07-11 23:22:04 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
+ 2007-09-24 20:30:30 135,168 ----a-w C:\WINDOWS\system32\javaw.exe
- 2007-07-12 00:22:38 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
+ 2007-09-24 21:31:42 139,264 ----a-w C:\WINDOWS\system32\javaws.exe
- 2007-07-22 16:39:27 279,552 ----a-w C:\WINDOWS\system32\swreg.exe
+ 2007-10-05 08:07:31 279,552 ----a-w C:\WINDOWS\system32\swreg.exe
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 28,672 2004-09-29 09:37:26 C:\Program Files\ATI Technologies\ATI.ACE\bak\cli.exe
----a-w 28,672 2004-09-29 08:37:26 C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
----a-w 171,448 2006-03-01 16:57:56 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe
----a-w 75,520 2006-12-15 02:23:27 C:\Program Files\Java\jre1.5.0_11\bin\bak\jusched.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-01-08 20:54 C:\WINDOWS\SOUNDMAN.EXE]
"SpeedTouch USB Diagnostics"="C:\Program Files\ThomsonNetia\SpeedTouch USB\Dragdiag.exe" [2004-08-06 10:45]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2004-09-29 10:37]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 09:50 C:\WINDOWS\LOGI_MWX.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-01-30 16:58]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2007-07-03 01:37]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
ATI CATALYST System Tray.lnk - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe [2004-09-29 10:37:26]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2006-02-10 13:55:56]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{35B2861B-2B26-4691-9FF0-09083722C736}"= C:\WINDOWS\system32\RadExe.dll [2004-10-01 20:34 204800]
R0 viamraid;viamraid;C:\WINDOWS\system32\drivers\viamraid.sys
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 RadProbe;Radeon Probe Driver;C:\WINDOWS\system32\DRIVERS\RadProbe.sys
S3 Amps2prt;A4Tech PS/2 Port Mouse Driver;C:\WINDOWS\system32\DRIVERS\Amps2prt.sys
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
"2007-10-12 15:24:07 C:\WINDOWS\Tasks\1-Click Maintenance.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-17 15:58:58
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-17 16:00:51
.
--- E O F ---