
Pozwolę sobie przykleić log z combofixa, bo go nie rozumiem:
- Kod: Zaznacz wszystko
((((((((((((((((((((((((( Pliki utworzone od 2008-10-07 do 2008-11-07 )))))))))))))))))))))))))))))))
.
2008-11-04 13:22 . 2008-11-04 13:22 <DIR> d-------- c:\program files\Lavasoft
2008-11-04 13:22 . 2008-11-04 13:22 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\Lavasoft
2008-11-04 13:00 . 2008-11-06 14:01 <DIR> d-------- c:\program files\mks_vir_2007
2008-11-04 12:59 . 2008-11-06 14:01 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-24 08:46 . 2008-10-15 17:36 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 00:52 . 2008-08-14 14:26 2,190,464 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 00:52 . 2008-08-14 14:26 2,146,816 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 00:52 . 2008-08-14 14:26 2,067,328 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 00:52 . 2008-08-14 14:26 2,025,472 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 00:52 . 2008-09-15 16:27 1,846,656 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-15 00:52 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-10 10:58 . 2008-10-10 10:58 <DIR> d-------- c:\documents and settings\kaczmarek.OEM-3486B681F49\Dane aplikacji\ESET
2008-10-10 10:57 . 2008-10-10 10:57 <DIR> d-------- c:\documents and settings\All Users\Dane aplikacji\ESET
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 16:32 90,112 ----a-w c:\windows\DUMP26a2.tmp
2008-11-06 14:31 90,112 ----a-w c:\windows\DUMP23b4.tmp
2008-11-06 14:06 90,112 ----a-w c:\windows\DUMP251c.tmp
2008-11-04 10:52 90,112 ----a-w c:\windows\DUMP2b17.tmp
2008-10-03 05:26 --------- d-----w c:\program files\TeamViewer3
2008-09-22 12:56 --------- d-----w c:\program files\Java
2008-09-22 12:56 --------- d-----w c:\program files\Common Files\Java
2008-09-15 15:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-20 05:11 668,672 ----a-w c:\windows\system32\wininet.dll
2008-08-14 13:26 2,146,816 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:26 2,025,472 ----a-w c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-06-28 8466432]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-06-28 81920]
"AnuTest"="c:\program files\AplusC\uplook\Agent\AnuTest.exe" [2005-10-26 421888]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-06-28 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-08 113664]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\TeamViewer3\\TeamViewer.exe"=
"c:\\Program Files\\AplusC\\uplook\\Agent\\AnuTest.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\VD_FileDisk.sys [2006-01-13 15872]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe [2008-04-14 14336]
R2 TeamViewer;TeamViewer 3;c:\program files\TeamViewer3\TeamViewer_Host.exe [2007-12-06 90112]
R2 uplook agent tracer;uplook agent tracer;c:\program files\AplusC\uplook\Agent\svuhost.exe [2005-09-23 61440]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08bb0da8-69ed-11dd-a8fe-001a4d8d197a}]
\Shell\AutoRun\command - F:\
\Shell\open\Command - rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08bb0da9-69ed-11dd-a8fe-001a4d8d197a}]
\Shell\AutoRun\command - G:\USBNB.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f4cfaac-022b-11dd-a8e3-001a4d8d197a}]
\Shell\Auto\command - UFO.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3a9245e0-69d8-11dd-a8fd-001a4d8d197a}]
\Shell\AutoRun\command - F:\
\Shell\open\Command - rundll32.exe .\desktop.dll,InstallM
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{85fe853a-a886-11dc-a8ba-001a4d8d197a}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe f
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f
*Newly Created Service* - PROCEXP90
.
Proszę szanownych użytkowników o odpowiedź, qe pasa?
Jeżeli niechcący naruszyłam jakieś skomplikowane prawidła internetu tym zapytaniem, przepraszam.
Dodano Dzisiaj, 12:56:
Znalazłam jeszcze jeden...
Win32: Trojan-gen
I avast nie potrafi sobie z nim trwale poradzić, g...o wraca.