
Komputer jak z podpisu.
System: Win. 7
Mam antywira Avire.
Wczoraj kumpel poslal mi paczke RA2 i postanowilismy pograc po sieci. Wylaczylem w tym celu zapore oraz antywira ponieważ ciągle coś blokowało dostęp. Okazało się to błędem. Dzisiaj rano włączam komputer i widze "100tys. wirów". Wiekszość naprawiłem, pousuwałem lub dałem do kwarantanny.
Nie wszystko jednak poszło tak prosto. Avira ciągle wyświetla mi komunikat ,że zablokowano dostęp plikom C://Autorun.inf ,F://Autorun.inf, E://Autorun.inf
ponieważ mogą one był "złośliwe". Probowałem usunąć - Nic to nie daje bo pojawiają się od nowa.
Użyłem combofixa:
- Kod: Zaznacz wszystko
ComboFix 11-02-24.05 - Lucky 2011-02-25 10:57:25.1.3 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.48.1045.18.2047.1159 [GMT 1:00]
Uruchomiony z: c:\users\Lucky\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Utworzono nowy punkt przywracania
.
((((((((((((((((((((((((((((((((((((((( Usunięto )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\users\Lucky\AppData\Roaming\EurekaLog
c:\windows\system32\Cache
c:\windows\system32\Cache\activity.opr
c:\windows\system32\Cache\dcache4.url
c:\windows\system32\Cache\g_003B\opr005VN.tmp
c:\windows\system32\Cache\g_004F\opr02BNZ.tmp
c:\windows\system32\Cache\g_004F\opr02BO0.tmp
c:\windows\system32\Cache\g_004F\opr02BO4.tmp
c:\windows\system32\Cache\g_004F\opr02BO5.tmp
c:\windows\system32\Cache\sesn\opr02BO1.tmp
c:\windows\system32\Icons
c:\windows\system32\Icons\http%3A%2F%2F0.s-nk.pl%2Fimg%2Ffavicon_2010.ico
c:\windows\system32\Icons\http%3A%2F%2Fforums.d2jsp.org%2Fimages%2Fd2jsp.ico
c:\windows\system32\Icons\http%3A%2F%2Fs.ytimg.com%2Fyt%2Ffavicon-vfl147246.ico
c:\windows\system32\Icons\http%3A%2F%2Fwww.google.pl%2Ffavicon.ico
c:\windows\system32\Icons\https%3A%2F%2Fmail.google.com%2Fmail%2Fimages%2Ffavicon.ico
C:\yxtxjp.pif
E:\autorun.inf
E:\kcyly.pif
E:\lqhlf.pif
F:\autorun.inf
F:\uiqoe.pif
F:\ykxoot.pif
.
((((((((((((((((((((((((( Pliki utworzone od 2011-01-25 do 2011-02-25 )))))))))))))))))))))))))))))))
.
2011-02-25 10:03 . 2011-02-25 10:06 -------- d-----w- c:\users\Lucky\AppData\Local\temp
2011-02-25 09:02 . 2011-02-25 09:51 103140 --sha-w- C:\hbjgx.exe
2011-02-24 21:16 . 2011-02-24 23:46 -------- d-----w- c:\users\Lucky\AppData\Roaming\Hamachi
2011-02-24 21:16 . 2011-02-24 21:16 -------- d-----w- c:\program files\Hamachi
2011-02-24 21:16 . 2011-02-24 21:16 17480 ----a-w- c:\windows\system32\drivers\hamachi.sys
2011-02-20 13:08 . 2003-02-27 15:12 696320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2011-02-20 13:08 . 2002-12-05 13:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2011-02-20 13:08 . 2002-12-02 14:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2011-02-20 13:08 . 2002-12-02 12:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2011-02-20 13:08 . 2002-12-02 12:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2011-02-20 13:08 . 2011-02-20 13:08 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2011-02-20 13:08 . 2011-02-20 13:08 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2011-02-13 21:05 . 2011-02-13 21:05 -------- d-----w- c:\program files\Deluxe Ski Jump 4
2011-01-28 10:51 . 2011-01-28 10:51 -------- d-----w- c:\users\Lucky\AppData\Local\Geckofx
2011-01-28 10:51 . 2011-01-28 10:51 -------- d-----w- c:\users\Lucky\AppData\Roaming\Firefly Studios
2011-01-28 10:49 . 2011-01-28 10:49 -------- d-----w- c:\programdata\Firefly Studios
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-28 10:35 . 2010-04-14 15:47 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-01-28 10:35 . 2010-04-14 15:21 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-01-28 10:35 . 2010-04-14 15:21 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-01-28 10:32 . 2010-04-14 15:21 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-01-24 11:37 . 2010-04-14 15:21 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-12-21 07:39 . 2010-04-08 20:22 135096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-12-16 20:10 . 2010-09-07 14:04 22328 ----a-w- c:\users\Lucky\AppData\Roaming\PnkBstrK.sys
2010-12-15 13:17 . 2010-12-15 13:17 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2010-12-15 13:17 . 2010-12-15 13:17 109080 ----a-w- c:\windows\system32\OpenAL32.dll
.
------- Sigcheck -------
[-] 2009-07-14 . 8626F0C30D4E3564FFDD25C90F4426F1 . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-12-12 395640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
"Diamondback"="c:\program files\Razer\Diamondback\razerhid.exe" [2007-02-14 147456]
"HDAudDeck"="c:\program files\VIA\VIAudioi\VDeck\VDeck.exe" [2009-10-28 1701888]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
c:\users\Lucky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Warkeys Update.lnk - c:\program files\Warkeys\AutoWarkey\AutoHotkey\AutoHotkey.exe [2009-9-25 324608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)
"MemCheckBoxInRunDlg"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoWelcomeScreen"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
[HKLM\~\startupfolder\C:^Users^Lucky^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk]
path=c:\users\Lucky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk
backup=c:\windows\pss\Tworzenie wycinków ekranu i uruchamianie programu OneNote 2007.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 11:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-02-25 09:53 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 02:44 500208 ------w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2011-02-25 09:01 406992 ----a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AQQ]
2011-02-07 11:56 8993280 ----a-w- e:\programy\WAPSTE~1\AQQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- e:\programy\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- e:\programy\office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 08:16 2433024 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SandboxieControl]
2010-02-03 10:40 394984 ----a-w- e:\programy\sandbox\SbieCtrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-12-12 07:54 395640 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 WatAdminSvc;Usługa Technologie aktywacji systemu Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-25 1343400]
R4 HssWd;Hotspot Shield Monitoring Service;c:\program files\Hotspot Shield\bin\hsswd.exe [2010-01-08 285744]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-04-08 691696]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-03 135336]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-08-20 189440]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-10-21 1102848]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 08:14 525600 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://fullarticles.net
IE: E&ksportuj do programu Microsoft Excel - e:\programy\office\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Lucky\AppData\Roaming\Mozilla\Firefox\Profiles\jc3fsfiy.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
- - - - USUNIĘTO PUSTE WPISY - - - -
MSConfigStartUp-ALLUpdate - c:\program files\ALLPlayer\ALLUpdate.exe
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe
MSConfigStartUp-Steam - d:\program files\Steam\Steam.exe
AddRemove-ALLPlayer_is1 - c:\program files\ALLPlayer\unins000.exe
AddRemove-AP Tuner 3.08 - c:\program files\AP Tuner\AP Tuner 3.08\uninstall.exe
AddRemove-Blobby Volley 2.0 Alpha 6_is1 - c:\program files\Blobby Volley 2.0 Alpha 6\unins000.exe
AddRemove-{D1D632A2-E249-466D-A094-B1B934D37645}_is1 - c:\program files\Firefly Studios\Stronghold Kingdoms\unins000.exe
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\program files\NVIDIA Corporation\Display\NvXDSync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\windows\system32\conhost.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Czas ukończenia: 2011-02-25 11:09:23 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt 2011-02-25 10:09
Przed: 3 584 364 544 bajtów wolnych
Po: 3 463 188 480 bajtów wolnych
- - End Of File - - 94AA5A40CD8E2774C5D3C2C5C2CD4CD2
Ten plik nadal jest na każdym dysku ale avira już nie krzyczy ta często o tym problemie jak wcześniej.
Co robić?