
nie wiem czy tak powinno byc czy nie, ale poki co, po tym przeskanowaniu, wszystko chodzi...tylko tapeta zniknela=)
to jest log jakiego dostalem:
- Kod: Zaznacz wszystko
ComboFix 09-06-15.07 - Lester 2009-06-16 20:17.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.48.1045.18.502.302 [GMT 2:00]
Uruchomiony z: c:\documents and settings\Lester\Pulpit\ComboFix.exe
AV: avast! antivirus 4.7.1043 [VPS 090616-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !!
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\systemntmi.sys
c:\documents and settings\Lester\Dane aplikacji\wiaserva.log
c:\documents and settings\Lester\Lester.exe
c:\documents and settings\Lester\Menu Start\Programy\Autostart\rncsys32.exe
c:\documents and settings\Lester\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\documents and settings\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\system32\drivers\amd64si.sys
c:\windows\Temp\log.txt
.
((((((((((((((((((((((((((((((((((((((( Sterowniki/Usługi )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SYSTEMNTMI
-------\Service_systemntmi
-------\Legacy_amd64si
-------\Service_amd64si
((((((((((((((((((((((((( Pliki utworzone od 2009-05-16 do 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 17:43 . 2009-06-16 17:43 -------- d-sh--w- C:\FOUND.000
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\program files\QuickTime
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Apple Computer
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\documents and settings\Lester\Ustawienia lokalne\Dane aplikacji\Apple
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\program files\Apple Software Update
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\documents and settings\All Users\Dane aplikacji\Apple
2009-06-05 09:04 . 2009-06-05 09:04 -------- d-----w- c:\documents and settings\Lester\Ustawienia lokalne\Dane aplikacji\Apple Computer
2009-05-28 07:56 . 2009-05-28 07:56 -------- d-s---w- c:\documents and settings\Lester\UserData
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 17:36 . 2009-03-23 18:24 1 ----a-w- c:\documents and settings\Lester\Dane aplikacji\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-05-12 21:46 . 2009-05-12 21:46 -------- d-----w- c:\program files\ffdshow
2009-05-07 15:44 . 1979-12-31 22:00 346112 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 09:04 . 2009-05-06 09:04 -------- d-----w- c:\documents and settings\Lester\Dane aplikacji\U3
2009-04-29 04:53 . 1979-12-31 22:00 662016 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:53 . 1979-12-31 22:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-19 20:11 . 1979-12-31 22:00 1846912 ----a-w- c:\windows\system32\win32k.sys
2009-04-16 22:31 . 1979-12-31 22:00 50656 ----a-w- c:\windows\system32\perfc015.dat
2009-04-16 22:31 . 1979-12-31 22:00 357564 ----a-w- c:\windows\system32\perfh015.dat
2009-04-15 15:18 . 1979-12-31 22:00 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2009-03-27 21:32 . 2009-03-23 18:05 1303 ----a-w- c:\windows\mozver.dat
2009-03-25 23:02 . 2009-03-25 23:02 737280 ----a-w- c:\windows\iun6002.exe
2009-03-25 18:38 . 2009-03-25 18:38 503808 ----a-w- c:\documents and settings\Lester\Dane aplikacji\Sun\Java\Deployment\cache\6.0\38\39ba6e6-63201938-n\msvcp71.dll
2009-03-25 18:38 . 2009-03-25 18:38 499712 ----a-w- c:\documents and settings\Lester\Dane aplikacji\Sun\Java\Deployment\cache\6.0\38\39ba6e6-63201938-n\jmc.dll
2009-03-25 18:38 . 2009-03-25 18:38 348160 ----a-w- c:\documents and settings\Lester\Dane aplikacji\Sun\Java\Deployment\cache\6.0\38\39ba6e6-63201938-n\msvcr71.dll
2009-03-25 18:37 . 2009-03-25 18:37 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-03-25 18:37 . 2009-03-25 18:37 152576 ----a-w- c:\documents and settings\Lester\Dane aplikacji\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-25 10:12 . 2004-10-04 16:29 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-23 19:31 . 2009-03-23 19:29 59 ----a-w- c:\windows\wpd99.drv
2009-03-23 19:29 . 2009-03-23 19:29 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2009-03-23 19:29 . 2009-03-23 19:29 249856 ----a-w- c:\windows\system32\pdfmona.dll
2009-03-23 18:34 . 2009-03-23 18:34 38808 ----a-w- c:\documents and settings\Lester\Ustawienia lokalne\Dane aplikacji\GDIPFONTCACHEV1.DAT
2009-03-23 17:53 . 2009-03-23 17:53 0 ----a-w- c:\windows\nsreg.dat
2009-03-23 17:49 . 2005-07-13 13:57 1024 ---h--r- c:\windows\system32\NTIBUN4.dll
2009-03-23 17:48 . 2005-07-13 13:56 1024 ---h--r- c:\windows\system32\NTIMPEG2.dll
2009-03-23 17:48 . 2005-07-13 13:56 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-03-23 17:48 . 2005-07-13 13:56 1024 ---h--r- c:\windows\system32\NTIFCD3.dll
2009-03-23 17:48 . 2005-07-13 13:56 1024 ---h--r- c:\windows\system32\NTICDMK7.dll
2009-03-23 17:48 . 2005-07-13 13:56 6144 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys
2009-03-25 22:27 . 2009-03-23 17:52 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-03-25 22:27 . 2009-03-23 17:52 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-03-25 22:27 . 2009-03-23 17:52 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-03-25 22:27 . 2009-03-23 17:52 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-03-25 22:27 . 2009-03-23 17:52 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2008-11-24 869888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"preload"="c:\windows\RUNXMLPL.exe" [2005-05-19 32768]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 102490]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 708698]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-06-01 192512]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-15 2893824]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"PowerKey"="c:\program files\Launch Manager\PowerKey.exe" [2002-08-30 94208]
"LManager"="c:\program files\Launch Manager\HotkeyApp.exe" [2005-06-06 69632]
"CtrlVol"="c:\program files\Launch Manager\CtrlVol.exe" [2003-09-16 20480]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2005-07-25 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2005-07-25 81920]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-29 352256]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 79224]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-25 148888]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2005-04-15 77824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R3 POWERKEY;POWERKEY;c:\program files\Launch Manager\POWERKEY.SYS [2009-03-23 2343]
S1 mailKmd;mailKmd; [x]
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://global.acer.com/
uInternet Connection Wizard,ShellNext = hxxp://www.freeware995.com/promo/aa.htm
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 20:23
Windows 5.1.2600 Dodatek Service Pack 2 FAT NTAPI
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
--------------------- Pliki DLL ładowane pod uruchomionymi procesami ---------------------
- - - - - - - > 'explorer.exe'(2280)
c:\program files\CyberLink\Shared Files\CLRCEngine.dll
c:\windows\system32\msi.dll
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\acer\eManager\anbmServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Czas ukończenia: 2009-06-16 20:25 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2009-06-16 18:25
Przed: 8 999 682 048 bajtów wolnych
Po: 9 000 468 480 bajtów wolnych
152 --- E O F --- 2009-06-14 22:59
wklej.org/id/107339/
i nie wiem co dalej=)
z gory dzieki za pomoc=)