avenger nie dzialal jak byl wirus, po prostu nie dal sie uruchomic (file corrupted).
Wyczyscilem natomiast wszystkie foldery system volume information i na razie przez 20 min nie ma wirusa

Zobaczymy jak dalej, log jest czysty.
W internecie dowiedzialem sie, ze ten wirus to jakas zlosliwa wersja trojana o nazwie Smitfraud. To chyba tak dzialalo: Jakis plik na komputerze powodowal zmiane rejestrow i otwieral komputer na trojany. Jak tylko laczylem sie z internetem, w managerze pojawil sie nagle retadpu21. To chyba trojan downloader, bo za pare sekund pojawialy sie inne rzeczy. W efekcie powstawaly
rozne szopki. M. in. nie moglem otworzyc notatnika, niektore programy mialy zmienione .exe na .exe~, ladowanie desktopu trwalo 3 minuty, az w koncu blokowal sie na amen i trzeba bylo ponownie instalowac.
Najgorsze jest to, ze to cholerstwo dziala mimo nowej instalacji windows.
Co do avengera, mysle , ze ten wirus zlosliwie zmienial strukture tego pliku.
Bo raz zainstalowalem na nowo system i kliknalem na "stara" wypakowana .exe
i cala szopka zaczynala sie od nowa.
Nie wiem co teraz zrobic, czy skasowac wszystkie dane na komputerze aby przez przypadek nie natrafic na zainfekowany plik, czy moze cos innego.
Chcialbym prosic o rade w tej sprawie. W zalaczeniu log z combo fixa:
- Kod: Zaznacz wszystko
ComboFix 07-08-17.2 - "USER" 2007-08-25 20:58:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.916 [GMT -7:00]
((((((((((((((((((((((((( Files Created from 2007-07-26 to 2007-08-26 )))))))))))))))))))))))))))))))
2007-08-25 20:57 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-22 22:06 14 --a------ C:\DOCUME~1\USER\getfile.dat
2007-08-22 21:58 0 --a------ C:\WINDOWS\nsreg.dat
2007-08-22 21:55 90,112 -r------- C:\WINDOWS\soundman.exe
2007-08-22 21:55 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe
2007-08-22 21:55 3,786,944 -r------- C:\WINDOWS\system32\drivers\alcxwdm.sys
2007-08-22 21:55 157,184 -r------- C:\WINDOWS\system32\RtlCPAPI.dll
2007-08-22 21:55 10,459,648 -r------- C:\WINDOWS\system32\RTLCPL.exe
2007-08-22 21:54 307,200 -r------- C:\WINDOWS\alcupd.exe
2007-08-22 21:54 217,088 -r------- C:\WINDOWS\alcrmv.exe
2007-08-22 21:54 <DIR> d-------- C:\Program Files\Realtek AC97
2007-08-22 21:53 46,892 --a------ C:\WINDOWS\system32\adadix16.dll
2007-08-22 21:53 46,167 --a------ C:\WINDOWS\system32\drivers\adildr.sys
2007-08-22 21:53 4,981 --a------ C:\WINDOWS\system32\adadix2k.dll
2007-08-22 21:53 22,395 --a------ C:\WINDOWS\system32\drivers\fpga.bin
2007-08-22 21:53 155,648 --a------ C:\WINDOWS\system32\adadix32.dll
2007-08-22 21:53 143,360 --a------ C:\WINDOWS\autoclk.exe
2007-08-22 21:53 135,168 --a------ C:\WINDOWS\system32\unaddrv.exe
2007-08-22 21:53 127,497 --a------ C:\WINDOWS\system32\drivers\adiusbaw.sys
2007-08-22 21:53 127,456 --a------ C:\WINDOWS\system32\ipdetect.exe
2007-08-22 21:53 126,976 --a------ C:\WINDOWS\system32\coclassfast.dll
2007-08-22 21:53 1,531,904 --a------ C:\WINDOWS\adiras.exe
2007-08-22 21:53 <DIR> d-------- C:\Program Files\SAGEM
2007-08-22 21:50 516,096 --------- C:\WINDOWS\system32\ati2sgag.exe
2007-08-22 21:48 451,072 --a------ C:\WINDOWS\Radeon Omega Drivers v3.8.291 Uninstall.exe
2007-08-22 21:47 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2007-08-22 21:47 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL
2007-08-22 21:47 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2007-08-22 21:47 16,877 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-08-22 21:45 9,216 -ra------ C:\WINDOWS\system32\drivers\videX32.sys
2007-08-22 21:45 331,184 --------- C:\WINDOWS\system32\difxapi.dll
2007-08-22 21:45 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2007-08-22 21:45 <DIR> d-------- C:\WINDOWS\system32\ReinstallBackups
2007-08-22 21:45 <DIR> d-------- C:\Program Files\VIA
2007-08-22 21:45 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-08-22 21:39 24,816 --a------ C:\WINDOWS\system32\mdimon.dll
2007-08-22 21:38 <DIR> d-------- C:\Program Files\Microsoft.NET
2007-08-22 21:38 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2007-08-22 21:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2007-08-22 21:35 786,432 --ah----- C:\DOCUME~1\USER\NTUSER.DAT
2007-08-22 21:35 32,336 --a------ C:\DOCUME~1\USER\XviD.reg
2007-08-22 21:35 <DIR> d-------- C:\Program Files\TGTSoft
2007-08-22 21:35 <DIR> d-------- C:\DOCUME~1\USER\ff_temp
2007-08-22 21:35 <DIR> d-------- C:\DOCUME~1\USER\APPLIC~1\VMware
2007-08-22 21:35 <DIR> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\VMware
2007-08-22 21:34 557,056 --ah----- C:\DOCUME~1\NETWOR~1\NTUSER.DAT
2007-08-22 21:34 557,056 --ah----- C:\DOCUME~1\LOCALS~1\NTUSER.DAT
2007-08-22 21:34 <DIR> d-------- C:\WINDOWS\Prefetch
2007-08-22 21:30 557,056 ---h----- C:\DOCUME~1\DEFAUL~1\NTUSER.DAT
2007-08-22 21:30 <DIR> d-------- C:\WINDOWS\system32\xircom
2007-08-22 21:30 <DIR> d-------- C:\WINDOWS\system32\restore
2007-08-22 21:30 <DIR> d-------- C:\Program Files\microsoft frontpage
2007-08-22 21:29 673,546 --a------ C:\WINDOWS\unins000.exe
2007-08-22 21:29 2,643 --a------ C:\WINDOWS\unins000.dat
2007-08-22 21:29 <DIR> d-------- C:\Program Files\OpenOffice2
2007-08-22 21:29 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\APPLIC~1\VMware
2007-08-22 21:28 9,600 -ra------ C:\WINDOWS\system32\drivers\vmnetadapter.sys
2007-08-22 21:28 5,120 -ra------ C:\WINDOWS\system32\vnetinst.dll
2007-08-22 21:28 385,024 --a------ C:\WINDOWS\system32\vnetlib.dll
2007-08-22 21:28 15,616 --a------ C:\WINDOWS\system32\drivers\vmnetuserif.sys
2007-08-22 21:28 135,168 --a------ C:\WINDOWS\system32\vmnat.exe
2007-08-22 21:28 106,496 --a------ C:\WINDOWS\system32\vmnetdhcp.exe
2007-08-22 21:28 10,240 -ra------ C:\WINDOWS\system32\drivers\vmnet.sys
2007-08-22 21:28 <DIR> d-------- C:\Program Files\VMware
2007-08-22 21:28 <DIR> d-------- C:\Program Files\Common Files\VMware
2007-08-22 21:28 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\VMware
2007-08-22 21:27 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-08-22 21:27 2,925 --a------ C:\WINDOWS\mozver.dat
2007-08-22 21:27 107,132 --a------ C:\WINDOWS\UninstallFirefox.exe
2007-08-22 21:27 <DIR> d-------- C:\WINDOWS\tmp0000490a
2007-08-22 21:27 <DIR> d-------- C:\Program Files\Webteh
2007-08-22 21:27 <DIR> d-------- C:\Program Files\QuickTime Alternative
2007-08-22 21:27 <DIR> d-------- C:\Program Files\Opera
2007-08-22 21:27 <DIR> d-------- C:\Program Files\FireTune
2007-08-22 21:27 <DIR> d-------- C:\DOCUME~1\DEFAUL~1\ff_temp
2007-08-22 21:27 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-22 21:26 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2007-08-22 21:26 0 -rahs---- C:\MSDOS.SYS
2007-08-22 21:26 0 -rahs---- C:\IO.SYS
2007-08-22 21:26 0 --a------ C:\CONFIG.SYS
2007-08-22 21:26 0 --a------ C:\AUTOEXEC.BAT
2007-08-22 21:25 <DIR> dr------- C:\WINDOWS\Offline Web Pages
2007-08-22 21:25 <DIR> d--hs---- C:\DOCUME~1\ALLUSE~1\DRM
2007-08-22 21:25 <DIR> d--h----- C:\Program Files\WindowsUpdate
2007-08-22 21:25 <DIR> d---s---- C:\WINDOWS\Downloaded Program Files
2007-08-22 21:24 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2007-08-22 21:24 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2007-08-22 21:24 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2007-08-22 21:24 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2007-08-22 21:24 <DIR> d---s---- C:\WINDOWS\Tasks
2007-08-22 21:24 <DIR> d-------- C:\WINDOWS\system32\DirectX
2007-08-22 21:24 <DIR> d-------- C:\Program Files\Online Services
2007-08-22 21:24 <DIR> d-------- C:\Program Files\Common Files\MSSoap
2007-08-22 21:23 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2007-08-22 21:23 81,920 --a------ C:\WINDOWS\system32\ils.dll
2007-08-22 21:23 8,192 --a------ C:\WINDOWS\system32\bitsprx2.dll
2007-08-22 21:23 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2007-08-22 21:23 7,168 --a------ C:\WINDOWS\system32\bitsprx3.dll
2007-08-22 21:23 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2007-08-22 21:23 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-22 21:53 23 --a------ C:\WINDOWS\system32\drivers\adidsl.cfg
2007-08-22 21:25 8738 --a------ C:\WINDOWS\pchealth\helpctr\Config\Cntstore.bin
2007-08-22 21:25 2112 --a------ C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDMCon"="C:\Program Files\Softwin\BitDefender8\bdmcon.exe" [2005-06-20 12:10]
"BDNewsAgent"="C:\Program Files\Softwin\BitDefender8\bdnagent.exe" [2005-05-09 12:19]
"AtiPTA"="atiptaxx.exe" [2006-02-21 17:05 C:\WINDOWS\system32\atiptaxx.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 05:45 C:\WINDOWS\soundman.exe]
"TrueImageMonitor.exe"="D:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" []
"AcronisTimounterMonitor"="D:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" []
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-02-09 20:39]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-08-22 21:53:11]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoSMHelp"=1 (0x1)
"StartMenuLogoff"=1 (0x1)
"ForceStartMenuLogoff"=0 (0x0)
"NoSMMyDocs"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoUserNameInStartMenu"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoSMHelp"=1 (0x1)
"StartMenuLogoff"=1 (0x1)
"ForceStartMenuLogoff"=0 (0x0)
"NoSMMyDocs"=1 (0x1)
"NoSMConfigurePrograms"=1 (0x1)
"NoUserNameInStartMenu"=1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
S3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-25 20:58:46
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-25 20:59:16
[/list]
Raczej wszystko ok.