
damian20008 napisał(a):ystępują także inne objawy typowe dla tego witusa, jak brak możliwości oglądania plików ukrytych itp. Pliku amvo.exe nie ma już na moim kompie a Kaspersky go przeskanował i nic więcej nie znalazł, jednak dalej nie mogę otwierać dysków. Proszę o pomoc.
damian20008 napisał(a):Okazuje się, że czasami sam windows może sobie poradzić z własnymi problemami. W moim przypadku wystarczył gruntowny skan Kasperskym 7.0 i Przywrócenie systemu do wcześniejszego stanu, co pozwoliło na przywrócenie możliwości otwierania zawartości dysków w Momi Komputerze. Niemniej jednak dziękuję za udzieloną pomoc. Pozdrawiam.
Logfile of Trend Micro HijackThis v2.0.2ComboFix 08-06-03.4 - Damian 2008-06-04 20:38:44.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1045.18.410 [GMT 2:00]
Running from: E:\Damian\Internet\Antywirusy\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-04 20:05 . 2008-06-04 20:06 <DIR> d-------- C:\Program Files\BitComet
2008-06-04 20:05 . 2008-06-04 20:05 <DIR> d-------- C:\Downloads
2008-06-04 20:05 . 2008-06-04 20:05 2,560 --a------ C:\WINDOWS\system32\bitcometres.dll
2008-06-03 23:43 . 2008-06-03 23:43 74,240 -r-hs---- C:\WINDOWS\system32\amvo2.dll
2008-06-03 21:10 . 2008-06-03 21:10 <DIR> d-------- C:\Documents and Settings\Damian.DAMIAN-FF61F570\Dane aplikacji\skypePM
2008-06-03 21:06 . 2008-06-03 23:51 <DIR> d-------- C:\Documents and Settings\Damian.DAMIAN-FF61F570\Dane aplikacji\Skype
2008-06-03 20:40 . 2008-02-07 17:10 <DIR> d--h----- C:\ckis
2008-06-03 16:01 . 2008-06-03 20:36 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-03 16:01 . 2008-06-03 20:36 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-03 16:00 . 2008-06-04 19:47 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Kaspersky Lab
2008-06-03 16:00 . 2008-06-04 20:49 6,470,944 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-03 16:00 . 2008-06-04 19:08 89,288 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-03 16:00 . 2008-06-04 20:49 61,216 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-03 16:00 . 2008-06-04 19:08 7,376 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-03 15:25 . 2008-06-03 15:25 <DIR> d-------- C:\Documents and Settings\Damian.DAMIAN-FF61F570\Dane aplikacji\Symantec
2008-06-03 14:54 . 2007-03-28 20:49 128,104 --a------ C:\WINDOWS\system32\drivers\WimFltr.sys
2008-06-03 14:54 . 2007-03-28 20:12 109,360 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-06-03 14:54 . 2007-03-28 20:29 37,864 --a------ C:\WINDOWS\system32\drivers\v2imount.sys
2008-06-03 14:54 . 2007-03-28 20:12 15,664 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-06-03 14:54 . 2007-03-28 20:23 14,072 --a------ C:\WINDOWS\system32\drivers\vproeventmonitor.sys
2008-06-03 14:53 . 2008-06-03 14:54 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-06-03 14:53 . 2007-03-28 20:29 131,944 --a------ C:\WINDOWS\system32\drivers\symsnap.sys
2008-06-03 14:52 . 2008-06-03 14:52 <DIR> d-------- C:\Program Files\Symantec
2008-06-03 14:52 . 2008-06-03 14:52 <DIR> d-------- C:\Program Files\Norton Ghost
2008-06-03 14:52 . 2008-06-03 14:53 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-06-03 14:52 . 2008-06-03 15:14 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Symantec
2008-06-03 14:52 . 2007-03-21 20:39 1,060,864 --a------ C:\WINDOWS\system32\MFC71.DLL
2008-06-03 13:44 . 2008-06-03 14:09 <DIR> d-------- C:\KAV
2008-06-03 13:42 . 2008-06-03 20:38 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-05-30 20:13 . 2008-05-30 20:13 <DIR> d-------- C:\Program Files\Arcade Race - Crash
2008-05-29 22:14 . 2008-05-29 22:14 <DIR> d-------- C:\Program Files\IQ Publishing
2008-05-27 19:38 . 2008-06-03 22:17 <DIR> d-------- C:\Documents and Settings\Teresa\Dane aplikacji\skypePM
2008-05-27 19:35 . 2008-06-03 22:19 <DIR> d-------- C:\Documents and Settings\Teresa\Dane aplikacji\Skype
2008-05-17 19:57 . 2008-05-17 19:57 1,409 --a------ C:\WINDOWS\system32\tmp52D72.FOT
2008-05-16 11:40 . 2008-06-03 13:30 <DIR> d-------- C:\Program Files\mks_vir_2007
2008-05-15 22:54 . 2008-05-15 22:55 <DIR> d-------- C:\Program Files\555
2008-05-12 12:10 . 2008-05-12 12:10 <DIR> d-------- C:\Documents and Settings\DOMINI~1~DAM\USTAWI~1
2008-05-12 12:10 . 2008-05-12 12:10 <DIR> d-------- C:\Documents and Settings\DOMINI~1~DAM
2008-05-12 12:10 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-05-12 11:52 . 2008-05-12 12:52 <DIR> d-------- C:\Documents and Settings\Dominik.DAMIAN-FF61F570\Dane aplikacji\Skype
2008-05-11 16:45 . 2008-05-11 16:45 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\The Learning Company
2008-05-11 16:45 . 2002-05-07 07:09 274,432 --a------ C:\WINDOWS\TLCUNINSTALL.EXE
2008-05-11 16:43 . 2008-05-11 16:43 0 --a------ C:\WINDOWS\SETUP32.INI
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-04 17:57 --------- d-----w C:\Program Files\neostrada tp
2008-06-04 17:57 --------- d-----w C:\Program Files\Kalendarz XP
2008-06-04 17:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-04 16:58 --------- d-----w C:\Program Files\Ubisoft
2008-06-04 16:23 196,608 ----a-w C:\WINDOWS\system32\drivers\nAsmedia.bin
2008-06-03 18:36 112,144 ----a-w C:\WINDOWS\system32\drivers\kl1.sys
2008-06-03 13:49 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\Kaspersky Lab Setup Files
2008-06-03 11:06 --------- d-----w C:\Program Files\Opera
2008-05-01 17:48 --------- d-----w C:\Program Files\XEROX M940
2008-05-01 16:40 --------- d-----w C:\Documents and Settings\Waldek.DAMIAN-FF61F570\Dane aplikacji\Xerox
2008-04-24 19:27 --------- d-----w C:\Documents and Settings\Dominik.DAMIAN-FF61F570\Dane aplikacji\AdobeUM
2008-04-22 21:32 --------- d-----w C:\Program Files\ZTE ZXDSL 852
2008-04-21 16:52 --------- d-----w C:\Documents and Settings\Waldek.DAMIAN-FF61F570\Dane aplikacji\Skype
2008-04-20 15:23 --------- d-----w C:\Documents and Settings\Waldek.DAMIAN-FF61F570\Dane aplikacji\AdobeUM
2008-04-20 15:21 --------- d-----w C:\Documents and Settings\Waldek.DAMIAN-FF61F570\Dane aplikacji\Winamp
2008-04-16 19:06 --------- d-----w C:\Documents and Settings\martusia_2\Dane aplikacji\DAEMON Tools
2008-04-16 19:06 --------- d-----w C:\Documents and Settings\martusia_2\Dane aplikacji\ATI
2008-03-25 10:30 32 ----a-w C:\Documents and Settings\All Users.WINDOWS\Dane aplikacji\ezsid.dat
2008-03-25 04:52 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:52 178,976 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,504 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 19:12 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-03-15 14:46 298,104 ----a-w C:\WINDOWS\system32\imon.dll
.
((((((((((((((((((((((((((((( snapshot@2008-06-04_ 2.09.53,39 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 00:01:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-04 17:45:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-05-15 19:34:18 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-06-04 12:31:44 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-05-15 19:34:18 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
+ 2008-06-04 12:31:44 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\index.dat
- 2008-05-15 19:34:18 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-04 12:31:44 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-04 11:58:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6f8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2005-01-19 17:34 128000]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2007-12-19 22:13 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-19 16:34 16858112 C:\WINDOWS\RTHDCPL.exe]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 13:17 61440]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [2006-11-15 16:25 363008]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2004-08-23 13:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\GestMaj.exe" [2004-10-14 15:55 32768]
"AdslTaskBar"="stmctrl.dll" [2006-06-02 13:01 151552 C:\WINDOWS\system32\stmctrl.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 16:38 39264]
C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\
DAEMON Tools Lite.lnk - C:\Program Files\DAEMON Tools Lite\daemon.exe [2007-12-19 22:13:05 486856]
Kalendarz XP.lnk - C:\Program Files\Kalendarz XP\Kalendarz.exe [2007-12-21 15:25:31 882176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^Action Manager 32.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\Action Manager 32.lnk
backup=C:\WINDOWS\pss\Action Manager 32.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users.WINDOWS\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
--a------ 2008-03-22 01:22 221184 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
--a------ 2007-08-28 11:58 380928 C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AWWFSPU]
--a------ 2006-12-18 13:19 712781 C:\Program Files\ASUS WiFi-AP Solo\AWWFSPU.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C62 Series]
--a------ 2002-04-10 04:00 74240 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 16:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 12.0]
--a------ 2007-03-28 20:41 2037352 C:\Program Files\Norton Ghost\Agent\VProTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
--a------ 2008-01-07 22:02 495616 C:\Program Files\Winamp Remote\bin\OrbTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26098:TCP"= 26098:TCP:BitComet 26098 TCP
"26098:UDP"= 26098:UDP:BitComet 26098 UDP
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"10172:TCP"= 10172:TCP:BitComet 10172 TCP
"10172:UDP"= 10172:UDP:BitComet 10172 UDP
"24098:TCP"= 24098:TCP:BitComet 24098 TCP(ED2K)
"24098:UDP"= 24098:UDP:BitComet 24098 UDP(ED2K)
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 16:23]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-08-28 11:58]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-08-12 16:51]
R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2006-05-25 17:28]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-08-28 11:58]
S3 AR2425;AzureWave AR5006 Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\aw5006.sys [2006-12-18 12:30]
S3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-10-31 21:10]
S3 GT680xNT;USB Scanner Driver;C:\WINDOWS\system32\drivers\gt680x.sys [2002-10-04 03:32]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c84dc9f-3169-11dd-a75c-c7fba8aabe6a}]
\Shell\AutoRun\command - jdwx.exe
\Shell\explore\Command - jdwx.exe
\Shell\open\Command - jdwx.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 17:48:47 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 20:50:11
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-04 20:53:58
ComboFix-quarantined-files.txt 2008-06-04 18:53:52
ComboFix2.txt 2008-06-04 00:10:37
Pre-Run: 9,155,383,296 bajtów wolnych
Post-Run: 9,752,805,376 bajtów wolnych
195 --- E O F --- 2008-05-29 20:00:47
[code][/code]
File::
C:\WINDOWS\system32\amvo2.dll
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0c84dc9f-3169-11dd-a75c-c7fba8aabe6a}]
damian20008 napisał(a):C:\WINDOWS\system32\amvo2.dll
damian20008 napisał(a):C:\WINDOWS\system32\imon.dll
damian20008 napisał(a):A ta biblioteka NOD-a to ta ścieżka, którą podałeś?
Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 2 gości