
dziś moja Avira AntiVir podczas surfowania po necie (normalne akcje) wyskoczył mi z komunikatem o wirusie. Oto on oraz czynność, jaką podjąłem (czyli denny access).
- Kod: Zaznacz wszystko
- Virus or unwanted program 'TR/Downloader.Gen [trojan]'
 detected in file 'C:\WINDOWS\system32\nvaux32.dll.
 Action performed: Deny access
Teraz nie wiem, co z tym zrobić - usunąć? Nie usunąć?
Zrobiłem oczywiście skan ComboFixem, który zamieszczam poniżej. Jak widac, ComboFix albo nie zauważył tego pliku albo go zignorował, czy coś.
- Kod: Zaznacz wszystko
- ComboFix 08-12-03.04 - User 2008-12-04 17:33:41.9 - [color=red][b]FAT32[/b][/color]x86
 Microsoft Windows XP Home Edition 5.1.2600.3.1250.1.1045.18.459 [GMT 1:00]
 Uruchomiony z: c:\documents and settings\User\Pulpit\ComboFix.exe
 * Utworzono nowy punkt przywracania
 [COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
 .
 ((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
 .
 c:\windows\system32\Cfx32.lic
 c:\windows\system32\cfx32.ocx
 c:\windows\system32\WMV9VCM.dll
 .
 ((((((((((((((((((((((((( Pliki utworzone od 2008-11-04 do 2008-12-04 )))))))))))))))))))))))))))))))
 .
 2008-12-04 17:29 . 2008-12-04 17:29 147,456 --ah----- c:\windows\system32\aston.mt
 2008-11-13 09:12 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
 2008-11-13 09:11 . 2008-09-04 18:17 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
 2008-11-09 15:47 . 2008-11-29 18:43 54,156 --ah----- c:\windows\QTFont.qfn
 2008-11-09 15:47 . 2008-11-09 15:47 1,409 --a------ c:\windows\QTFont.for
 2008-11-08 08:15 . 2008-11-08 08:15 <DIR> d-------- c:\documents and settings\User\.borland
 .
 (((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 2008-12-04 16:31 580,096 ----a-w c:\windows\system32\user32.DLL
 2008-12-04 16:31 580,096 ----a-w c:\windows\system32\dllcache\user32.dll
 2008-10-26 17:59 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Trymedia
 2008-10-25 15:16 249,592 ----a-w c:\windows\system32\cssdll32.dll
 2008-10-25 15:15 --------- d-----w c:\program files\COMODO
 2008-10-25 15:15 --------- d-----w c:\documents and settings\User\Dane aplikacji\Comodo
 2008-10-25 15:15 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\comodo
 2008-10-25 09:36 --------- d-----w c:\program files\Avira
 2008-10-25 09:36 --------- d-----w c:\documents and settings\All Users\Dane aplikacji\Avira
 2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
 2008-10-22 15:31 223,128 ----a-w c:\windows\system32\drivers\dtscsi.sys
 2008-10-22 15:26 96,384 ----a-w c:\windows\system32\drivers\sptd9597.sys
 2008-10-20 21:04 0 ----a-w c:\windows\system32\drivers\sptd.sys
 2008-10-20 21:04 0 ----a-w c:\windows\system32\drivers\EagleNT.sys
 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
 2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
 2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
 2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
 2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
 2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
 2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
 2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
 2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
 2008-10-15 17:36 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
 2008-10-14 10:55 110,304 ----a-w c:\windows\system32\drivers\ACEDRV09.sys
 2008-10-03 18:26 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
 2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
 2008-09-15 16:27 1,846,656 ----a-w c:\windows\system32\win32k.sys
 2008-09-15 16:27 1,846,656 ------w c:\windows\system32\dllcache\win32k.sys
 2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
 2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
 2008-09-08 11:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
 2008-09-04 17:17 1,106,944 ----a-w c:\windows\system32\msxml3.dll
 2005-03-31 21:17 40,960 ----a-w c:\program files\Uninstall_CDS.exe
 .
 [color=red] c:\windows\system32\user32.dll ... jest zarażony !! [/color]
 580,096 2008-12-04 16:31:20 c:\windows\system32\user32.DLL
 580,096 2008-12-04 16:31:20 c:\windows\system32\dllcache\user32.dll
 579,072 2007-03-08 16:38:48 c:\windows\$NtServicePackUninstall$\user32.dll
 578,560 2004-08-04 07:44:14 c:\windows\$NtServicePackUninstall$\user32.dll.000
 580,096 2008-04-14 18:20:56 c:\windows\ServicePackFiles\i386\user32.dll
 578,560 2005-03-02 18:18:38 c:\windows\$hf_mig$\KB890859\SP2GDR\user32.dll
 578,560 2005-03-02 18:21:08 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
 579,584 2007-03-08 16:51:58 c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
 578,560 2004-08-04 07:44:14 c:\windows\$NtUninstallKB890859$\user32.dll
 561,664 2002-09-23 11:00:00 c:\windows\$NtUninstallKB890859_0$\user32.dll
 578,560 2005-03-02 18:18:38 c:\windows\$NtUninstallKB925902$\user32.dll
 ((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
 .
 .
 *Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
 REGEDIT4
 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "ASUS SmartDoctor"="c:\program files\ASUS\SmartDoctor\\SmartDoctor.exe" [2004-12-16 987136]
 "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 307200]
 "PeerGuardian"="c:\program files\PeerGuardian2\pg2.exe" [2005-09-18 1421824]
 "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
 "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
 "RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
 "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-06-10 1397760]
 "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
 "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
 "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
 "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-08-08 282624]
 "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
 "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
 "nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
 c:\documents and settings\User\Menu Start\Programy\Autostart\
 WordWeb.lnk - f:\wordweb\wweb32.exe [2007-01-28 20992]
 c:\documents and settings\All Users\Menu Start\Programy\Autostart\
 GetRight - Tray Icon.lnk - c:\program files\GetRight\getright.exe [2006-02-14 2301952]
 Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
 Uruchamianie pakietu Office.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1997-10-06 51984]
 Microsoft Find Fast.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1997-10-06 111376]
 Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-06-06 113664]
 Program sieciowy dla SAGEM Wi-Fi 11g USB adapter.lnk - c:\program files\SAGEM WiFi manager\WLANUTL.exe [2007-03-21 925696]
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
 "AppInit_DLLs"=
 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
 "aux"= ctwdm32.dll
 "vidc.asv2"= asusasv2.dll
 "msacm.dvacm"= dvacm.acm
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\acup.sys]
 @="Driver"
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Mks_Scan]
 @=""
 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Mks_Scan\Service]
 @=""
 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
 "%windir%\\system32\\sessmgr.exe"=
 "c:\\Program Files\\Gadu-Gadu\\gg.exe"=
 "c:\\Program Files\\eMule\\emule.exe"=
 "f:\\FileZilla\\FileZilla.exe"=
 "c:\\WINDOWS\\System32\\dpvsetup.exe"=
 "c:\\Program Files\\Gadu-Gadu\\ggphone\\ggphone.exe"=
 "d:\\AOE2CONQ\\empires2.exe"=
 "c:\\Program Files\\Mozilla Firefox\\FIREFOX.EXE"=
 "c:\\Program Files\\FlashGet\\FLASHGET.EXE"=
 "d:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
 "c:\\Program Files\\SopCast\\SopCast.exe"=
 "c:\\Documents and Settings\\User\\Dane aplikacji\\SopCast\\adv\\SopAdver.exe"=
 "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
 "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
 "c:\\Program Files\\SopCast\\sopvod.exe"=
 "c:\\Program Files\\TC PowerPack\\totalcmd.exe"=
 "c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
 "d:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
 R2 ACEDRV09;ACEDRV09;\??\c:\windows\system32\drivers\ACEDRV09.sys [2008-10-14 110304]
 R2 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys [2008-08-17 2368]
 R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\DRIVERS\WlanBZXP.sys [2007-03-21 402432]
 R3 Video3D;ASUS Video3D Service;c:\windows\system32\Drivers\Video3D.sys [2004-07-06 44544]
 S1 acup;VPower Control Service;c:\windows\system32\acup.sys []
 S1 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS [2008-10-20 0]
 S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;d:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-09-27 1527900]
 S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2008-10-14 544768]
 .
 .
 ------- Skan uzupełniający -------
 .
 uStart Page = hxxp://www.onet.pl/
 uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
 uInternet Connection Wizard,ShellNext = iexplore
 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
 IE: &Ściągnij przy pomocy FlashGet'a - c:\program files\FlashGet\jc_link.htm
 IE: &Ściągnij wszystko przy pomocy FlashGet'a - c:\program files\FlashGet\jc_all.htm
 IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
 IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
 O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
 c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
 O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
 c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
 c:\windows\Downloaded Program Files\weblive.exe - O16 -: {070CA17A-4BD2-4612-83B4-32B1B9159B47}
 hxxp://uc.sina.com.cn/download/live/weblive2.4.0.0.cab
 c:\windows\Downloaded Program Files\setup.inf
 c:\windows\system32\ArcaMicroScanUpdater.exe - c:\windows\system32\ArcaOnlineUninstall.exe
 c:\windows\system32\ArcaOnline.dll
 O16 -: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D}
 hxxp://slimak.onet.pl/_m/wirusy/ArcaOnline.cab
 c:\windows\Downloaded Program Files\ArcaOnline.inf
 c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
 O16 -: {68282C51-9459-467B-95BF-3C0E89627E55}
 hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
 c:\windows\Downloaded Program Files\SkanerOnline.inf
 c:\windows\Downloaded Program Files\UKooPlayer.ocx - O16 -: {A903E5AB-C67E-40FB-94F1-E1305982F6E0}
 hxxp://www.euchannels.net/UKooPlayer.ocx
 c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
 O16 -: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7}
 hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
 c:\windows\Downloaded Program Files\SkanerOnline.inf
 FireFox -: Profile - c:\documents and settings\User\Dane aplikacji\Mozilla\Firefox\Profiles\4hsbxv9g.default\
 FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://onet.pl/
 .
 **************************************************************************
 catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
 Rootkit scan 2008-12-04 17:35:33
 Windows 5.1.2600 Dodatek Service Pack 3 FAT NTAPI
 skanowanie ukrytych procesów ...
 skanowanie ukrytych wpisów autostartu ...
 skanowanie ukrytych plików ...
 skanowanie pomyślnie ukończone
 ukryte pliki: 0
 **************************************************************************
 .
 Czas ukończenia: 2008-12-04 17:36:11
 ComboFix2.txt 2008-10-25 14:57:48
 ComboFix-quarantined-files.txt 2008-12-04 16:36:10
 Przed: 2 913 796 096 bajtów wolnych
 Po: 3,065,921,536 bajtów wolnych
 198 --- E O F --- 2008-11-13 12:22:58
Zauważcie
c:\windows\system32\user32.dll ... jest zarażony !!
Proszę o pomoc

PS. Wkleić hijackthisa?
EDIT:
user32.dll przeskanowałem na Virustotal i takie wyniki:
- Kod: Zaznacz wszystko
- Antywirus Wersja Ostatnia aktualizacja Wynik
 AhnLab-V3 2008.12.5.0 2008.12.04 Win-Trojan/User32Hk
 AntiVir 7.9.0.36 2008.12.04 -
 Authentium 5.1.0.4 2008.12.04 -
 Avast 4.8.1281.0 2008.12.03 -
 AVG 8.0.0.199 2008.12.04 -
 BitDefender 7.2 2008.12.04 -
 CAT-QuickHeal 10.00 2008.12.04 -
 ClamAV 0.94.1 2008.12.04 -
 DrWeb 4.44.0.09170 2008.12.04 -
 eSafe 7.0.17.0 2008.12.04 -
 eTrust-Vet 31.6.6243 2008.12.04 Win32/Pruserinf
 Ewido 4.0 2008.12.04 -
 F-Prot 4.4.4.56 2008.12.04 -
 F-Secure 8.0.14332.0 2008.12.04 Trojan.Win32.Patched.bb
 Fortinet 3.117.0.0 2008.12.04 -
 GData 19 2008.12.04 -
 Ikarus T3.1.1.45.0 2008.12.04 -
 K7AntiVirus 7.10.543 2008.12.04 -
 Kaspersky 7.0.0.125 2008.12.04 Trojan.Win32.Patched.bb
 McAfee 5453 2008.12.03 -
 McAfee+Artemis 5453 2008.12.03 potentially unwanted program Patched User32
 Microsoft 1.4205 2008.12.04 -
 NOD32 3664 2008.12.04 -
 Norman 5.80.02 2008.12.04 -
 Panda 9.0.0.4 2008.12.04 W32/Patched.D
 PCTools 4.4.2.0 2008.12.04 -
 Prevx1 V2 2008.12.04 -
 Rising 21.06.32.00 2008.12.04 Trojan.Win32.Patched.bi
 SecureWeb-Gateway 6.7.6 2008.12.04 -
 Sophos 4.36.0 2008.12.04 Troj/User32Hk-A
 Sunbelt 3.1.1832.2 2008.12.01 -
 Symantec 10 2008.12.04 -
 TheHacker 6.3.1.2.174 2008.12.04 -
 TrendMicro 8.700.0.1004 2008.12.04 Mal_Patch-1
 VBA32 3.12.8.10 2008.12.03 -
 ViRobot 2008.12.4.1500 2008.12.04 -
 VirusBuster 4.5.11.0 2008.12.04 -


 
	


 
 
 
	 -
 -