MUTOPOMPKA napisał(a):żaden skan nie pomoże, bo nic niw wykruje (tak mi się zdaje). Wystarczy wyłączyć podgląd miniatur. A czemu?
Podczas otwierania katalogu z filmem, system "skanuje: plik w celu wyświetlenia miniatury. Wystarczy to wyłączyć i powinno być ok.
Ale jak włąncze film to samo system pada
[ Dodano: Dzisiaj o 18:39 ] SDFix: Version 1.114
Run by SaXo on 2007-11-15 at 18:29
Microsoft Windows XP [Wersja 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
No Trojan Files Found
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 18:32:37
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c]
"Order"=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,..
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
Remaining Files:
---------------
Files with Hidden Attributes:
Wed 14 Nov 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1738c621b33e51e95e7a1d6339d42049\BIT1.tmp"
Finished!
Logfile of HijackThis v1.99.1
Scan saved at 18:34:52, on 2007-11-15
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Mozilla Firefox\firefox.exe
C:\Documents and Settings\SaXo\Pulpit\hijackthis_199\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FD752B2-BA8B-4F79-8AB1-3283007472DA}: NameServer = 192.168.18.193
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FD752B2-BA8B-4F79-8AB1-3283007472DA}: NameServer = 192.168.18.193
O17 - HKLM\System\CS2\Services\Tcpip\..\{3FD752B2-BA8B-4F79-8AB1-3283007472DA}: NameServer = 192.168.18.193
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
ComboFix 07-11-08.1 - SaXo 2007-11-15 18:35:12.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.293 [GMT 1:00]
Running from: C:\Documents and Settings\SaXo\Pulpit\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-15 to 2007-11-15 )))))))))))))))))))))))))))))))
.
2007-11-15 18:29 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-15 17:59 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-15 15:09 <DIR> d-------- C:\Program Files\NAPI-PROJEKT
2007-11-15 14:30 <DIR> d-------- C:\Program Files\Common Files\Ahead
2007-11-15 14:30 <DIR> d-------- C:\Program Files\Ahead
2007-11-15 14:30 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2007-11-15 14:30 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2007-11-15 14:30 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2007-11-15 14:30 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-11-15 14:30 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2007-11-15 14:30 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2007-11-15 14:30 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2007-11-15 14:30 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-11-14 21:38 3,979,892 --a------ C:\WINDOWS\system32\libgtk-win32-2.0-0.dll
2007-11-14 21:38 3,979,892 --a------ C:\WINDOWS\libgtk-win32-2.0-0.dll
2007-11-12 23:27 2,181,632 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2007-11-12 23:27 2,137,600 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2007-11-12 23:27 2,058,880 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2007-11-12 15:28 <DIR> d-------- C:\Program Files\uTorrent
2007-11-12 01:07 <DIR> d---s---- C:\Documents and Settings\SaXo\UserData
2007-11-12 01:00 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-11-12 01:00 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-11 20:55 <DIR> d-------- C:\Documents and Settings\SaXo\Dane aplikacji\uTorrent
2007-11-11 17:08 <DIR> d-------- C:\Documents and Settings\SaXo\Phone Browser
2007-11-11 17:08 <DIR> d-------- C:\Documents and Settings\SaXo\Dane aplikacji\Datalayer
2007-11-11 17:04 <DIR> d-------- C:\Documents and Settings\SaXo\Dane aplikacji\Nokia
2007-11-11 17:02 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-11-11 17:02 <DIR> d-------- C:\Program Files\Nokia
2007-11-11 17:02 <DIR> d-------- C:\Program Files\DIFX
2007-11-11 17:02 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2007-11-11 17:02 <DIR> d-------- C:\Program Files\Common Files\Nokia
2007-11-11 17:02 <DIR> d-------- C:\Documents and Settings\SaXo\Dane aplikacji\PC Suite
2007-11-11 17:02 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\PC Suite
2007-11-11 17:02 127,488 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-11 17:02 50,688 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2007-11-11 17:02 30,720 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-11 17:02 13,312 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-11 17:02 8,704 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-11 17:02 4,608 --a------ C:\WINDOWS\system32\nmwcdlog.dll
2007-11-11 17:01 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Downloaded Installations
2007-11-10 18:50 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2007-11-10 18:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-10 13:40 <DIR> d--h----- C:\Documents and Settings\Pub\Ustawienia lokalne
2007-11-10 13:40 <DIR> dr------- C:\Documents and Settings\Pub\Ulubione
2007-11-10 13:40 <DIR> d--h----- C:\Documents and Settings\Pub\Szablony
2007-11-10 13:40 <DIR> d-------- C:\Documents and Settings\Pub\Pulpit
2007-11-10 13:40 <DIR> dr------- C:\Documents and Settings\Pub\Moje dokumenty
2007-11-10 13:40 <DIR> dr------- C:\Documents and Settings\Pub\Menu Start
2007-11-10 13:40 <DIR> dr-h----- C:\Documents and Settings\Pub\Dane aplikacji
2007-11-10 13:40 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-11-10 10:42 <DIR> d-------- C:\WINDOWS\Sun
2007-11-10 10:41 <DIR> d-------- C:\Program Files\Java
2007-11-10 10:37 <DIR> d-------- C:\Program Files\Common Files\Java
2007-11-10 10:16 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-11-10 00:27 <DIR> d-------- C:\Documents and Settings\SaXo\Dane aplikacji\Media Player Classic
2007-11-10 00:26 <DIR> d-------- C:\K-Lite Codec Pack
2007-11-10 00:26 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2007-11-09 23:53 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-09 22:15 <DIR> d--hs---- C:\WINDOWS\ftpcache
2007-11-09 22:08 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\NVIDIA
2007-11-09 21:53 <DIR> d-------- C:\WINDOWS\pss
2007-11-09 20:21 20,640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-11-09 20:18 <DIR> d-------- C:\Winamp
2007-11-09 20:18 <DIR> d-------- C:\Program Files\Winamp
2007-11-09 20:14 <DIR> d-------- C:\PreMule
2007-11-09 20:10 1,438 --a------ C:\WINDOWS\mozver.dat
2007-11-09 20:08 <DIR> d-------- C:\Mozilla Firefox
2007-11-09 20:08 0 --a------ C:\WINDOWS\nsreg.dat
2007-11-09 20:05 <DIR> d-------- C:\Program Files\TGTSoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 18:58 --------- d-----w C:\Program Files\AIDA32 - Personal System Information
2007-11-09 18:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-11-09 17:49 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-09 17:47 --------- d-----w C:\Program Files\Usługi online
2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-15_18.01.18,43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-13 22:40:48 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2007-11-15 17:29:32 1,896,448 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2007-11-15 17:29:33 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2007-11-13 22:40:48 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2007-11-15 17:29:26 1,896,448 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2007-11-15 17:29:26 147,456 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-09-27 07:44 C:\WINDOWS\SOUNDMAN.EXE]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 14:43]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 14:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 12:36]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Konnekt]
"F:\Konnekt\konnekt.exe" /autostart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"F:\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-15 18:35:55
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-15 18:36:32
C:\ComboFix2.txt ... 2007-11-15 18:02
.
--- E O F ---
[/quote]
[ Dodano: Dzisiaj o 8:29 ] No I co jakies rady ??