
Mialem taki problem jak kolega kilka tematow nizej ze nie moglem wejsc normalnie na dysk klikajac 2xPPM tylko poprzez 'eksploruj'. Troche sie pospieszylem (nie wiem czy dobrze) i polecialem z combofixem. Dopiero teraz przeczytalem ze nie powinno sie go uzywac jako pierwszego. Coz mi nic nie uszkodzil w systemie, wrecz odwrotnie usunal bledy i juz moge normalnie wchodzic na dyski. Chcialem pokazac jakie avast wykryl mi wirusy, o to i one:
komunikat
komunikat2
komunikat3
juz sie nie pojawiaja po przeskanowaniu combofixem. Po restarcie avast znow cos wykryl a dokladnie to: komunikat4 . Tego pliku jak i poprzednich nie moglem usunac avastem. Dzis dopiero przeczytalem ze lepiej nie ruszac combofixa wiec teraz sie wstrzymam i prosze o pomoc i sprawdzenie loga bo chce wyeliminowac calkowicie brud z komputera. Powiedzcie mi tez czy stracilem jakies pliki juz na zawsze i czy format jest niezbedny.
- Kod: Zaznacz wszystko
DDS (Ver_09-05-14.01) - NTFSx86
Run by Administrator at 10:43:27,56 on 2009-06-24
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1250.48.1045.18.2047.1495 [GMT 2:00]
============== Running Processes ===============
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\SOUNDMAN.EXE
C:\Java\jre6\bin\jusched.exe
D:\WINDOWS\system32\oodtray.exe
D:\Program Files\Drive Space Indicator\DrvSpace.exe
D:\Program Files\winamp\winampa.exe
C:\Java\jre6\bin\jqs.exe
D:\Program Files\Alwil Software\Avast4\ashDisp.exe
D:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\oodag.exe
D:\Program Files\Microsoft IntelliPoint\ipoint.exe
D:\WINDOWS\system32\RunDLL32.exe
D:\Documents and Settings\Administrator.BOMBELEK\wsk32.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\Utilities\VisualTaskTips\VisualTaskTips.exe
D:\Documents and Settings\Administrator.BOMBELEK\Ustawienia lokalne\Dane aplikacji\Google\Update\GoogleUpdate.exe
D:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
D:\WINDOWS\system32\ctfmon.exe
svchost.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Documents and Settings\Administrator.BOMBELEK\Pulpit\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: FG2CatchUrl: {1f364306-aa45-47b5-9f9d-39a8b94e7ef1} - c:\flashget universal\comdlls\bhoCATCH.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: IEPluginBHO Class: {f5cc7f02-6f4e-4462-b5b1-394a57fd3e0d} - d:\documents and settings\administrator.bombelek\dane aplikacji\nowe gadu-gadu\_userdata\ggbho.1.dll
uRun: [VisualTaskTips] d:\program files\utilities\visualtasktips\VisualTaskTips.exe
uRun: [Google Update] "d:\documents and settings\administrator.bombelek\ustawienia lokalne\dane aplikacji\google\update\GoogleUpdate.exe" /c
uRun: [Nowe Gadu-Gadu] "c:\nowe gadu-gadu\gg.exe"
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [Windows Network Data Management System Service] "d:\documents and settings\administrator.bombelek\wsk32.exe" *
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [SunJavaUpdateSched] "c:\java\jre6\bin\jusched.exe"
mRun: [OODefragTray] d:\windows\system32\oodtray.exe
mRun: [DriveSpace] d:\program files\drive space indicator\DrvSpace.exe
mRun: [AdobeCS4ServiceManager] "d:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [WinampAgent] "d:\program files\winamp\winampa.exe"
mRun: [avast!] "d:\program files\alwil software\avast4\ashDisp.exe"
mRun: [NeroFilterCheck] d:\windows\system32\NeroCheck.exe
mRun: [IntelliPoint] "d:\program files\microsoft intellipoint\ipoint.exe"
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [QuickTime Task] "c:\quicktime\QTTask.exe" -atboottime
mRun: [Windows Network Data Management System Service] "d:\documents and settings\administrator.bombelek\wsk32.exe" *
mRunOnce: [Del e:\dexter.s03.hdtv.xvid.happy.new.year-ht\dexter.s03e05.hdtv.xvid-0tv\dexter.305.hdtv-0tv.avi onnextreboot] cmd.exe /c del /f /q "e:\dexter.s03.hdtv.xvid.happy.new.year-ht\dexter.s03e05.hdtv.xvid-0tv\dexter.305.hdtv-0tv.avi"
dRun: [VisualTaskTips] d:\program files\utilities\visualtasktips\VisualTaskTips.exe
dRun: [EPSON Stylus Photo RX520 Series] d:\windows\system32\spool\drivers\w32x86\3\E_FATIAGE.EXE /P31 "EPSON Stylus Photo RX520 Series" /M "Stylus Photo RX520" /EF "HKCU"
dRunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
uPolicies-explorer: NoSMHelp = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
uPolicies-explorer: NoResolveTrack = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoSMHelp = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
dPolicies-explorer: NoResolveTrack = 1 (0x1)
IE: &Download All by FlashGet - c:\flashget universal\comdlls\Bhoall.htm
IE: &Download by FlashGet - c:\flashget universal\comdlls\Bholink.htm
IE: E&ksport do programu Microsoft Excel - c:\microsoft office\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\microsoft office\office11\REFIEBAR.DLL
Trusted Zone: google.com\mail
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\Skype4COM.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - d:\docume~1\admini~1.bom\daneap~1\mozilla\firefox\profiles\7r1bljh0.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - plugin: c:\java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\java\jre6\bin\new_plugin\npjp2.dll
FF - plugin: c:\quicktime\plugins\npqtplugin.dll
FF - plugin: c:\quicktime\plugins\npqtplugin2.dll
FF - plugin: c:\quicktime\plugins\npqtplugin3.dll
FF - plugin: c:\quicktime\plugins\npqtplugin4.dll
FF - plugin: c:\quicktime\plugins\npqtplugin5.dll
FF - plugin: c:\quicktime\plugins\npqtplugin6.dll
FF - plugin: c:\quicktime\plugins\npqtplugin7.dll
FF - plugin: c:\real alternative\browser\plugins\nppl3260.dll
FF - plugin: c:\real alternative\browser\plugins\nprpjplug.dll
FF - plugin: d:\documents and settings\administrator.bombelek\dane aplikacji\mozilla\firefox\profiles\7r1bljh0.default\extensions\battlefieldheroespatcher@ea.com\platform\winnt_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: d:\documents and settings\administrator.bombelek\dane aplikacji\nowe gadu-gadu\_userdata\npgg.1.dll
FF - plugin: d:\documents and settings\administrator.bombelek\ustawienia lokalne\dane aplikacji\google\update\1.2.145.5\npGoogleOneClick8.dll
============= SERVICES / DRIVERS ===============
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;d:\windows\system32\drivers\nvcchflt.sys [2009-4-13 16640]
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2009-4-15 114768]
R1 vcdrom;Virtual CD-ROM Device Driver;d:\program files\system\cpl bonus\vcdrom.sys [2009-4-13 8576]
R2 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2009-4-15 20560]
R2 avast! Antivirus;avast! Antivirus;d:\program files\alwil software\avast4\ashServ.exe [2009-4-15 138680]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;d:\program files\nvidia corporation\performance drivers\nvPDsvc.exe [2008-12-11 3575808]
R3 avast! Mail Scanner;avast! Mail Scanner;d:\program files\alwil software\avast4\ashMaiSv.exe [2009-4-15 254040]
R3 avast! Web Scanner;avast! Web Scanner;d:\program files\alwil software\avast4\ashWebSv.exe [2009-4-15 352920]
S3 ggflt;SEMC USB Flash Driver Filter;d:\windows\system32\drivers\ggflt.sys [2009-4-22 13224]
=============== Created Last 30 ================
2009-06-24 10:18 <DIR> --d----- d:\windows\system32\dllcache\cache
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\xircom
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\wbem\snmp
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\oobe
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\npp
2009-06-24 10:15 <DIR> --d----- d:\windows\srchasst
2009-06-24 10:15 <DIR> --d----- d:\program files\windows nt
2009-06-24 10:15 <DIR> --d----- d:\program files\common files\speechengines
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\inetsrv
2009-06-24 10:15 <DIR> --d----- d:\windows\system32\ime
2009-06-24 10:15 <DIR> --d----- d:\windows\msagent
2009-06-24 10:15 <DIR> --d----- d:\program files\msn gaming zone
2009-06-24 10:09 161,792 a------- d:\windows\SWREG.exe
2009-06-24 10:09 155,136 a------- d:\windows\PEV.exe
2009-06-24 10:09 98,816 a------- d:\windows\sed.exe
2009-06-13 17:30 765,952 a------- d:\windows\system32\xvidcore.dll
2009-06-13 17:30 180,224 a------- d:\windows\system32\xvidvfw.dll
2009-06-13 17:30 77,824 a------- d:\windows\system32\xvid.ax
2009-06-13 17:30 <DIR> --d----- d:\program files\Xvid
2009-06-10 11:30 585,216 -------- d:\windows\system32\dllcache\rpcrt4.dll
2009-06-06 12:57 30,720 -------- d:\documents and settings\administrator.bombelek\wsk32.exe
2009-06-05 00:53 447,752 a----r-- d:\windows\system32\vp6vfw.dll
2009-06-05 00:53 <DIR> --d----- d:\program files\Microsoft WSE
2009-06-04 00:58 <DIR> --d----- d:\program files\Damian Pasternak
2009-06-02 23:20 87,552 a----r-- d:\windows\system\url.dll
2009-06-02 23:20 9,728 a----r-- d:\windows\system\rnaph.dll
2009-06-02 23:20 <DIR> --d----- d:\windows\wb
2009-06-02 23:15 0 a------- d:\windows\DXT373.tmp
2009-06-02 23:15 <DIR> --d----- d:\program files\directx
2009-05-29 22:21 9,728 a------- d:\windows\system32\UnInstall Exploding Bikini.exe
2009-05-29 12:30 <DIR> --d----- d:\docume~1\alluse~1\daneap~1\Codemasters
2009-05-29 12:25 <DIR> --d----- d:\program files\OpenAL
2009-05-29 12:25 805,400 a----r-- d:\windows\system32\tmpFF.tmp
2009-05-29 12:25 805,400 a----r-- d:\windows\system32\tmp100.tmp
2009-05-28 20:59 <DIR> --d----- d:\program files\SystemRequirementsLab
2009-05-28 20:58 <DIR> --d----- d:\documents and settings\administrator.bombelek\SystemRequirementsLab
2009-05-26 17:18 90,112 a------- d:\windows\system32\QuickTimeVR.qtx
2009-05-26 17:18 57,344 a------- d:\windows\system32\QuickTime.qts
==================== Find3M ====================
2009-05-29 12:25 444,952 a------- d:\windows\system32\wrap_oal.dll
2009-05-29 12:25 109,080 a------- d:\windows\system32\OpenAL32.dll
2009-05-15 19:00 60,416 a------- d:\windows\ALCFDRTM.EXE
2009-05-07 17:34 347,648 a------- d:\windows\system32\localspl.dll
2009-05-07 17:34 347,648 -------- d:\windows\system32\dllcache\localspl.dll
2009-04-28 11:59 70,656 -------- d:\windows\system32\dllcache\ie4uinit.exe
2009-04-28 11:59 13,824 -------- d:\windows\system32\dllcache\ieudinit.exe
2009-04-25 07:27 636,088 -------- d:\windows\system32\dllcache\iexplore.exe
2009-04-25 07:26 161,792 -------- d:\windows\system32\dllcache\ieakui.dll
2009-04-22 21:52 1,107,296 a------- d:\windows\system32\WdfCoInstaller01007.dll
2009-04-19 21:51 1,847,424 a------- d:\windows\system32\win32k.sys
2009-04-19 21:51 1,847,424 -------- d:\windows\system32\dllcache\win32k.sys
2009-04-15 16:54 585,216 a------- d:\windows\system32\rpcrt4.dll
2009-04-13 18:22 410,984 a------- d:\windows\system32\deploytk.dll
2009-04-13 16:12 438,688 a------- d:\windows\system32\perfh015.dat
2009-04-13 16:12 71,846 a------- d:\windows\system32\perfc015.dat
2009-04-13 16:01 21,856 a------- d:\windows\system32\emptyregdb.dat
2009-03-27 10:03 1,560,576 a------- d:\windows\system32\nvcuda.dll
2009-03-27 10:03 453,152 a------- d:\windows\system32\nvudisp.exe
2009-03-27 10:03 401,408 a------- d:\windows\system32\nvcuvid.dll
2009-03-27 08:14 453,152 a------- d:\windows\system32\nvuninst.exe
2007-08-08 00:49 100,247 a------- d:\documents and settings\administrator.bombelek\xmlUpdater.exe
============= FINISH: 10:43:49,35 ===============
p.s. posiadam takze loga z: combofix'a, hijakcthis. Jezeli jest potrzebny to wkleje, prosze pisac.
Z gory dziekuje. pozdrawiam