• Ogłoszenie:

Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 07 Sty 2009, 08:59

reklama
Po włączeniu systemu wyskakuje setki małych okienek z komunikatami, zmienia sie kolor pulpitu na jaskrawo-czerwony i pojawiają się komunikaty bezpieczeństwa.

Proszę o pomoc.

Kod: Zaznacz wszystko
ComboFix 08-07-21.2 - krzysiek 2009-01-07  7:48:45.9 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.584 [GMT 1:00]
Running from: D:\Programy\Problemy z kompem\Rejestr\ComboFix.exe

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
- REDUCED FUNCTIONALITY MODE -
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\runsql.exe
C:\WINDOWS\sv.exe
C:\WINDOWS\svc.exe
C:\WINDOWS\svhoster.exe
C:\WINDOWS\svw.exe
C:\WINDOWS\svx.exe
C:\WINDOWS\svzip.exe
C:\WINDOWS\system32\a.exe
C:\WINDOWS\vlc.exe
C:\WINDOWS\wdmon.exe

.
(((((((((((((((((((((((((   Files Created from 2008-12-07 to 2009-01-07  )))))))))))))))))))))))))))))))
.

2009-01-06 17:29 . 2009-01-06 17:29   233,984   --a------   C:\WINDOWS\odb.exe
2009-01-06 17:29 . 2009-01-06 17:29   40,960   -r-hs----   C:\WINDOWS\system32\apcupsf.exe
2009-01-06 17:29 . 2009-01-06 17:30   109   --ahs----   C:\WINDOWS\system32\1750862046.dat
2008-12-13 20:28 . 2008-12-13 20:28   <DIR>   d--------   C:\Program Files\VirtualDJ
2008-12-12 13:38 . 2008-12-12 13:38   118   --a------   C:\WINDOWS\ConverterCore.INI
2008-12-12 13:37 . 2008-12-12 13:39   <DIR>   d--------   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\SolidDocuments
2008-12-12 13:35 . 2008-12-12 13:35   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\SolidDocuments
2008-12-12 13:35 . 2008-08-01 18:32   21,240   --a------   C:\WINDOWS\system32\solidlocalmon.dll
2008-12-12 13:35 . 2008-08-01 18:32   13,560   --a------   C:\WINDOWS\system32\solidlocalui.dll
2008-12-10 06:47 . 2008-10-03 11:04   247,326   ---------   C:\WINDOWS\system32\dllcache\strmdll.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 06:52   ---------   d-----w   C:\Program Files\lg_fwupdate
2009-01-07 06:49   53,248   ----a-w   C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\ntuser.dat
2009-01-07 06:49   53,248   ----a-w   C:\Documents and Settings\NetworkService.ZARZąDZANIE NT\ntuser.dat
2009-01-07 06:49   53,248   ----a-w   C:\Documents and Settings\LocalService.ZARZąDZANIE NT\ntuser.dat
2009-01-07 06:49   53,248   ----a-w   C:\Documents and Settings\LocalService.ZARZąDZANIE NT\ntuser.dat
2009-01-06 22:22   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\MegauploadToolbar
2008-12-26 13:59   ---------   d-----w   C:\Program Files\DOSBox-0.72
2008-12-14 15:52   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-12-13 06:28   3,594,752   ------w   C:\WINDOWS\system32\dllcache\mshtml.dll
2008-12-03 10:46   ---------   d-----w   C:\Program Files\Common Files\Ahead
2008-12-03 10:46   ---------   d-----w   C:\Program Files\Ahead
2008-12-01 22:55   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\foobar2000
2008-11-30 16:03   ---------   d-----w   C:\Program Files\Skype
2008-11-30 15:43   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\skypePM
2008-11-19 13:39   ---------   d-----w   C:\Program Files\CDCover 4
2008-11-18 23:01   ---------   d-----w   C:\Program Files\Intelore
2008-11-18 22:36   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\ImgBurn
2008-11-17 15:32   ---------   d-----w   C:\Program Files\ImgBurn
2008-11-11 17:27   ---------   d-----w   C:\Program Files\foobar2000
2008-11-10 20:04   133,296   ----a-w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-10-24 11:21   455,296   ------w   C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-10-23 12:42   286,720   ----a-w   C:\WINDOWS\system32\gdi32.dll
2008-10-23 12:42   286,720   ------w   C:\WINDOWS\system32\dllcache\gdi32.dll
2008-10-16 13:13   202,776   ----a-w   C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13   202,776   ----a-w   C:\WINDOWS\system32\dllcache\wuweb.dll
2008-10-16 13:13   1,809,944   ----a-w   C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:13   1,809,944   ----a-w   C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-10-16 13:12   561,688   ----a-w   C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:12   561,688   ----a-w   C:\WINDOWS\system32\dllcache\wuapi.dll
2008-10-16 13:12   323,608   ----a-w   C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:12   323,608   ----a-w   C:\WINDOWS\system32\dllcache\wucltui.dll
2008-10-16 13:09   92,696   ----a-w   C:\WINDOWS\system32\dllcache\cdm.dll
2008-10-16 13:09   92,696   ----a-w   C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09   51,224   ----a-w   C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09   51,224   ----a-w   C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-10-16 13:09   43,544   ----a-w   C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08   34,328   ----a-w   C:\WINDOWS\system32\wups.dll
2008-10-16 13:08   34,328   ----a-w   C:\WINDOWS\system32\dllcache\wups.dll
2008-10-16 12:46   70,656   ------w   C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-10-16 12:46   13,824   ------w   C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-15 16:36   337,408   ------w   C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 06:34   633,632   ------w   C:\WINDOWS\system32\dllcache\iexplore.exe
2008-10-15 06:33   161,792   ------w   C:\WINDOWS\system32\dllcache\ieakui.dll
2008-07-27 11:25   1,378   ----a-w   C:\Program Files\uninstal.log
2008-06-15 19:33   32   ----a-w   C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2001-08-13 13:51   1,396,337   ----a-w   C:\Program Files\Captura.exe
2002-01-02 00:48   32,768   --sha-w   C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012002010220020103\index.dat
.

------- Sigcheck -------

2007-10-30 17:53  360832  64798ecfa43d78c7178375fcdd16d8c8   C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 12:51  361600  9aefa14bd6b182d61e3119fa5f436d3d   C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59  361600  ad978a1b783b5719720cff204b666c8e   C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 11:44  360960  744e57c99232201ae98c49168b918f48   C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2007-10-16 00:19  360576  0fb6743e937c7bb248b2530a5a77abc6   C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 20:20  361344  93ea8d04ec73a85db02eb8805988f733   C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 18:20  360064  90caff4b094573449a0872a0f919b178   C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 20:20  361344  accf5a9a1ffaa490f33dba1c632b95e1   C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   C:\WINDOWS\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((   snapshot@2009-01-06_17.52.38.07   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-07 06:51:04   16,384   ----atw   C:\WINDOWS\temp\Perflib_Perfdata_5dc.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:21 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 11:04 2127296]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 18:21 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22 7618560]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 03:28 144784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 16:38 583048]
"Nod32CC"="C:\WINDOWS\system32\nod32cc.exe" [2002-01-11 13:37 235008]
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" [2005-04-12 10:11 229376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"odb"="C:\WINDOWS\odb.exe" [2009-01-06 17:29 233984]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-17 19:20 16844800 C:\WINDOWS\RTHDCPL.EXE]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 10:22 86016 C:\WINDOWS\system32\nvmctray.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 18:21 15360]

C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMHelp"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{020487CC-FC04-4B1E-863F-D9801796230B}"= "C:\DOCUME~1\KRZYSI~1.PRI\USTAWI~1\Temp\wndutl32.dll" [BU]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages   REG_MULTI_SZ      msv1_0 C:\WINDOWS\system32\iifCSMdd
UpdateWin   REG_SZ            C:\WINDOWS\system32\apcupsf.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Photosmart Premier - Szybkie uruchomienie.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Photosmart Premier - Szybkie uruchomienie.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier - Szybkie uruchomienie.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-07-22 19:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-03-20 11:04 2127296 C:\Program Files\Gadu-Gadu\gg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 15:24 54840 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
--a------ 2008-03-13 08:34 81920 C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 09:47 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
--a------ 2006-06-23 17:26 3706368 C:\Program Files\ASUS\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-06-01 10:22 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23042:TCP"= 23042:TCP:BitComet 23042 TCP
"23042:UDP"= 23042:UDP:BitComet 23042 UDP
"24284:TCP"= 24284:TCP:BitComet 24284 TCP
"24284:UDP"= 24284:UDP:BitComet 24284 UDP

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 15:35]
R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 14:00]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 15:37]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-09-13 13:54]
R2 NOD32ControlCenter;NOD32 Control Center Service;C:\WINDOWS\system32\nod32cc.exe [2002-01-11 13:37]
R2 NOD32Service;NOD32 Service;C:\WINDOWS\system32\nod32m2.exe [2001-04-10 09:19]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 19:45]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 19:45]
.
Contents of the 'Scheduled Tasks' folder
"2008-12-29 07:42:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -

SharedTaskScheduler-IPC Configuration Utility - (no file)


.
------- Supplementary Scan -------
.
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-Internet Settings,ProxyServer = socks=
O8 -: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 -: E&ksport do programu Microsoft Excel - C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 -: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206

O16 -: {68282C51-9459-467B-95BF-3C0E89627E55} - hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
C:\WINDOWS\Downloaded Program Files\SkanerOnline.inf
C:\WINDOWS\system32\SkanerOnlineUninstall.exe
C:\WINDOWS\system32\SkanerOnline.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-07 07:51:23
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2009-01-07  7:55:40 - machine was rebooted
ComboFix-quarantined-files.txt  2009-01-07 06:55:36
ComboFix2.txt  2009-01-06 16:56:55
ComboFix3.txt  2008-10-19 12:30:52

Pre-Run: 9,976,070,144 bajtów wolnych
Post-Run: 10,054,451,200 bajt˘w wolnych

252   --- E O F ---   2008-12-18 06:01:26


Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:56, on 2009-01-07
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20935)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\nod32cc.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\WINDOWS\odb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\nod32m2.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Nod32CC] "C:\WINDOWS\system32\nod32cc.exe" -DONTSHOW
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [odb] C:\WINDOWS\odb.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Windows Installer Class - {020487CC-FC04-4B1E-863F-D9801796230B} - C:\DOCUME~1\KRZYSI~1.PRI\USTAWI~1\Temp\wndutl32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Harmonogram automatycznej usługi LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NOD32 Control Center Service (NOD32ControlCenter) - Unknown owner - C:\WINDOWS\system32\nod32cc.exe
O23 - Service: NOD32 Service (NOD32Service) - Unknown owner - C:\WINDOWS\system32\nod32m2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9234 bytes
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez wojtas 07 Sty 2009, 17:07

masz 2 antywirusy :D wywal jeden najlepiej avasta i zostaw noda 32

skasuj:

O4 - HKLM\..\Run: [odb] C:\WINDOWS\odb.exe
O22 - SharedTaskScheduler: Windows Installer Class - {020487CC-FC04-4B1E-863F-D9801796230B} - C:\DOCUME~1\KRZYSI~1.PRI\USTAWI~1\Temp\wndutl32.dll (file missing)


wklej do notatnika:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=-
"Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
00


w notatniku u góry>>>plik zapisz jako>>>Zmien rozszerzenie z TXT na Wszystkie pliki *.* >>> Zapisz pod nazwą FIX.REG

Klikasz dwa razy na powstały plik fix i dodajesz go do rejestru....


Otworz notatnik i wklej w nim to:

File::
C:\WINDOWS\odb.exe
C:\WINDOWS\system32\apcupsf.exe
C:\WINDOWS\system32\1750862046.dat

>>Plik>>Zapisz jako... >>> CFScript
Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe
-->Image
Ma się rozpocząć usuwanie. (i powstanie log).Daj ten log, który powstanie w trakcie usuwania.
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 07 Sty 2009, 18:26

Kod: Zaznacz wszystko
ComboFix 08-07-21.2 - krzysiek 2009-01-07 17:23:08.11 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.653 [GMT 1:00]
Running from: C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Pulpit\ComboFix.exe
Command switches used :: C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Pulpit\CFScript.txt
* Created a new restore point

[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
- REDUCED FUNCTIONALITY MODE -

FILE ::
C:\WINDOWS\odb.exe
C:\WINDOWS\system32\1750862046.dat
C:\WINDOWS\system32\apcupsf.exe
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\odb.exe
C:\WINDOWS\system32\1750862046.dat
C:\WINDOWS\system32\apcupsf.exe

.
(((((((((((((((((((((((((   Files Created from 2008-12-07 to 2009-01-07  )))))))))))))))))))))))))))))))
.

2009-01-07 11:28 . 2009-01-07 11:33   <DIR>   d--------   C:\PS2_Mademan_bk
2008-12-13 20:28 . 2008-12-13 20:28   <DIR>   d--------   C:\Program Files\VirtualDJ
2008-12-12 13:38 . 2008-12-12 13:38   118   --a------   C:\WINDOWS\ConverterCore.INI
2008-12-12 13:37 . 2008-12-12 13:39   <DIR>   d--------   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\SolidDocuments
2008-12-12 13:35 . 2008-12-12 13:35   <DIR>   d--------   C:\Documents and Settings\All Users\Dane aplikacji\SolidDocuments
2008-12-12 13:35 . 2008-08-01 18:32   21,240   --a------   C:\WINDOWS\system32\solidlocalmon.dll
2008-12-12 13:35 . 2008-08-01 18:32   13,560   --a------   C:\WINDOWS\system32\solidlocalui.dll
2008-12-10 06:47 . 2008-10-03 11:04   247,326   ---------   C:\WINDOWS\system32\dllcache\strmdll.dll

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-07 16:02   ---------   d-----w   C:\Program Files\lg_fwupdate
2009-01-06 22:22   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\MegauploadToolbar
2008-12-26 13:59   ---------   d-----w   C:\Program Files\DOSBox-0.72
2008-12-14 15:52   ---------   d--h--w   C:\Program Files\InstallShield Installation Information
2008-12-13 06:28   3,594,752   ------w   C:\WINDOWS\system32\dllcache\mshtml.dll
2008-12-03 10:46   ---------   d-----w   C:\Program Files\Common Files\Ahead
2008-12-03 10:46   ---------   d-----w   C:\Program Files\Ahead
2008-12-01 22:55   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\foobar2000
2008-11-30 16:03   ---------   d-----w   C:\Program Files\Skype
2008-11-30 15:43   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\skypePM
2008-11-19 13:39   ---------   d-----w   C:\Program Files\CDCover 4
2008-11-18 23:01   ---------   d-----w   C:\Program Files\Intelore
2008-11-18 22:36   ---------   d-----w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\ImgBurn
2008-11-17 15:32   ---------   d-----w   C:\Program Files\ImgBurn
2008-11-11 17:27   ---------   d-----w   C:\Program Files\foobar2000
2008-11-10 20:04   133,296   ----a-w   C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-10-24 11:21   455,296   ------w   C:\WINDOWS\system32\dllcache\mrxsmb.sys
2008-10-23 12:42   286,720   ----a-w   C:\WINDOWS\system32\gdi32.dll
2008-10-23 12:42   286,720   ------w   C:\WINDOWS\system32\dllcache\gdi32.dll
2008-10-16 13:13   202,776   ----a-w   C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13   202,776   ----a-w   C:\WINDOWS\system32\dllcache\wuweb.dll
2008-10-16 13:13   1,809,944   ----a-w   C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:13   1,809,944   ----a-w   C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-10-16 13:12   561,688   ----a-w   C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:12   561,688   ----a-w   C:\WINDOWS\system32\dllcache\wuapi.dll
2008-10-16 13:12   323,608   ----a-w   C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:12   323,608   ----a-w   C:\WINDOWS\system32\dllcache\wucltui.dll
2008-10-16 13:09   92,696   ----a-w   C:\WINDOWS\system32\dllcache\cdm.dll
2008-10-16 13:09   92,696   ----a-w   C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09   51,224   ----a-w   C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09   51,224   ----a-w   C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-10-16 13:09   43,544   ----a-w   C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08   34,328   ----a-w   C:\WINDOWS\system32\wups.dll
2008-10-16 13:08   34,328   ----a-w   C:\WINDOWS\system32\dllcache\wups.dll
2008-10-16 12:46   70,656   ------w   C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-10-16 12:46   13,824   ------w   C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-15 16:36   337,408   ------w   C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-15 06:34   633,632   ------w   C:\WINDOWS\system32\dllcache\iexplore.exe
2008-10-15 06:33   161,792   ------w   C:\WINDOWS\system32\dllcache\ieakui.dll
2008-07-27 11:25   1,378   ----a-w   C:\Program Files\uninstal.log
2008-06-15 19:33   32   ----a-w   C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
2001-08-13 13:51   1,396,337   ----a-w   C:\Program Files\Captura.exe
2002-01-02 00:48   32,768   --sha-w   C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012002010220020103\index.dat
.

------- Sigcheck -------

2007-10-30 17:53  360832  64798ecfa43d78c7178375fcdd16d8c8   C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 12:51  361600  9aefa14bd6b182d61e3119fa5f436d3d   C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59  361600  ad978a1b783b5719720cff204b666c8e   C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 11:44  360960  744e57c99232201ae98c49168b918f48   C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2007-10-16 00:19  360576  0fb6743e937c7bb248b2530a5a77abc6   C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-04-13 20:20  361344  93ea8d04ec73a85db02eb8805988f733   C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys
2007-10-30 18:20  360064  90caff4b094573449a0872a0f919b178   C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 20:20  361344  accf5a9a1ffaa490f33dba1c632b95e1   C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   C:\WINDOWS\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 18:21 15360]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2008-03-20 11:04 2127296]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 18:21 1695232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22 7618560]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 03:28 144784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 16:38 583048]
"Nod32CC"="C:\WINDOWS\system32\nod32cc.exe" [2002-01-11 13:37 235008]
"LGODDFU"="C:\Program Files\lg_fwupdate\fwupdate.exe" [2005-04-12 10:11 229376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-17 19:20 16844800 C:\WINDOWS\RTHDCPL.EXE]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 10:22 86016 C:\WINDOWS\system32\nvmctray.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 18:21 15360]

C:\Documents and Settings\krzysiek.PRIVATE-28C405B\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 18:16:50 113664]

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMHelp"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
UpdateWin   REG_SZ            C:\WINDOWS\system32\apcupsf.exe

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Photosmart Premier - Szybkie uruchomienie.lnk]
path=C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\HP Photosmart Premier - Szybkie uruchomienie.lnk
backup=C:\WINDOWS\pss\HP Photosmart Premier - Szybkie uruchomienie.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-07-22 19:42 116040 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-03-20 11:04 2127296 C:\Program Files\Gadu-Gadu\gg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 15:24 54840 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
--a------ 2008-03-13 08:34 81920 C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 09:47 289064 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
--a------ 2006-06-23 17:26 3706368 C:\Program Files\ASUS\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-06-01 10:22 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23042:TCP"= 23042:TCP:BitComet 23042 TCP
"23042:UDP"= 23042:UDP:BitComet 23042 UDP
"24284:TCP"= 24284:TCP:BitComet 24284 TCP
"24284:UDP"= 24284:UDP:BitComet 24284 UDP

R1 VD_FileDisk;VD_FileDisk;C:\WINDOWS\system32\drivers\VD_FileDisk.sys [2006-01-13 14:00]
R2 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe [2006-09-13 13:54]
R2 NOD32ControlCenter;NOD32 Control Center Service;C:\WINDOWS\system32\nod32cc.exe [2002-01-11 13:37]
R2 NOD32Service;NOD32 Service;C:\WINDOWS\system32\nod32m2.exe [2001-04-10 09:19]
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 19:45]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 19:45]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-12-29 07:42:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-07 17:23:17
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-01-07 17:24:08
ComboFix-quarantined-files.txt  2009-01-07 16:24:02
ComboFix2.txt  2009-01-07 16:12:52
ComboFix3.txt  2009-01-07 06:55:41
ComboFix4.txt  2009-01-06 16:56:55
ComboFix5.txt  2009-01-07 16:22:42

Pre-Run: 5,493,911,552 bajtów wolnych
Post-Run: 5,481,820,160 bajtów wolnych

208   --- E O F ---   2008-12-18 06:01:26
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez wojtas 07 Sty 2009, 23:01

start>uruchom>Regedit> wejdz do klucza:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]


i skasuj w nim :

UpdateWin REG_SZ C:\WINDOWS\system32\apcupsf.exe


czesc pogrubiona


1. Ściągnij OTMoveIt i go włacz i odpal go z opcji CleanUp :) oraz skasuj folder C:\Qoobox
2. wykonaj optymalizację windowsa
3.sciagnij ATF_Cleaner
zaznacz
Windows Temp
All users Temp
Temporary internet files
Recycle Bin
i wcisnij EMPTY SELECTED
4.Wyłącz przywracanie systemu ( właściwości mój komputer-zakładka przywracanie - wyłącz przywracanie na wszystkich dyskach). Po chwili włącz je powrotem
5.Przeskanuj obszar mojego komputera http://www.kaspersky.pl/virusscanner.html (uruchom przez IE) Daj raport z niego na forum.

i tym:

FixIEDef.
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 12 Sty 2009, 11:04

Zrobilem co kazales, ale nie chce mi odpalic kasperskiego (przez IE). Widoczne objawy zawirusowania znikly, ale teraz jest problem z logowaniem do poczty i przy startowaniu systemu od czasu do czasu pojawia sie czarny ekran......

Co mam zrobic?
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez Okocza 12 Sty 2009, 11:22

gus napisał(a):jest problem z logowaniem do poczty


tzn? jakiś błąd?

gus napisał(a):przy startowaniu systemu od czasu do czasu pojawia sie czarny ekran


włóż płytę od windowsa, zbootuj ją, wejdź w konsolę odzyskiwania i wpisz:

chkdsk x: /p


gdzie x to litera partycji na której jest system
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 13 Sty 2009, 02:16

Co do błędu poczty to dzieje sie to tylko u mnie na kompie. Na innych poczta mi chodzi. Oto link do screenu z błędu:

http://www.wrzuta.pl/obraz/konFmzb9T7/

Mam plyte do win XP, gdzie jedyna mozliwoscia wyboru odzyskiwania systemu jest automatyczny (za pomoca F2). Jak mam zatem zrobic chkdsk?

Combofix takze przestal dzialac.....

Zainstalowalem kasperskiego, ale nie chce sie polaczyc z jego aktualizacjami. W czym moze byc problem?
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez Okocza 13 Sty 2009, 09:51

Narzędzia - wyczyść prywatne dane - zaznaczasz wszystko

Daj log z RSITa - możliwe że coś zostało i blokuje aktualizacje.
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 13 Sty 2009, 10:14

Problem w tym, ze nie chca mi wejsc linki do RSITa combofixa itp... Nie idzie sciagnac tego nigdzie z neta bo nie wyswietlaja sie ich strony (nawet linki z tego forum). Mam na dysku combofixa i sie nie odpala

Idzie mi za to hijack:

Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:18, on 2009-01-13
Platform: Windows XP Dodatek SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20935)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Odkurzacz-MCD] C:\Program Files\Odkurzacz\odk_mcd.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Indexing Service (CiSvc) - Unknown owner - C:\WINDOWS\system32\cisvc.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Harmonogram automatycznej usługi LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Usługa iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8761 bytes
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez Okocza 13 Sty 2009, 10:19

gus napisał(a):Mam na dysku combofixa i sie nie odpala


próbowałeś w awaryjnym go odpalić? instalowałeś jakieś oprogramowanie antywirusowe poza Kasperskym? miałeś jakiś problem z aplikacjami które rzekomo usuwają trojany itp?
eMachines E730G - Core i5-430M, 2GiB RAM, ATI Mobility Radeon HD5470, WD 320GiB; Cort Z-44,DR 0.09-0.42, Peavey Backstage
Mac OS X 10.7.4 Lion // Windows 7 Professional x64 // NIE POMAGAM NA PW/GG/E-MAIL
Image
"Moje Ego i Anima spotykają się i wymieniają przepisami na ciasteczka" - Maynard James Keenan
Awatar użytkownika
Okocza
~user
 
Posty: 8001
Dołączenie: 19 Mar 2006, 11:53
Pochwały: 406



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 13 Sty 2009, 10:52

wczesniej mialem tez avasta. chyba znow go zainstaluje, bo kaspersky nie chce sciagnac tych aktualizacji. nie instalowalem zadnych spy removerow itp - tylko to co polecaliscie na forum. sprawdzilem rowniez przed chwila w trybie awaryjnym - combofix nadal sie nie odpala (jest przez chwile klepsydra a potem nic).
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez wojtas 13 Sty 2009, 13:18

pobierz z tad:

http://www.sendspace.com/file/pgtrnt

i odpal :)
jesli nie to zmien jego nazwe i odpal wtedy i daj loga
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 13 Sty 2009, 17:40

Poszedl ten nieszczesny combofix (po sciagnieciu i zmianie nazwy).

Log:

Kod: Zaznacz wszystko
ComboFix 09-01-11.04 - krzysiek 2009-01-13 16:32:09.12 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1250.1.1045.18.1023.753 [GMT 1:00]
Uruchomiony z: c:\documents and settings\krzysiek.PRIVATE-28C405B\Pulpit\aaa.exe

[COLOR=RED][B]UWAGA - TEN KOMPUTER NIE MA ZAINSTALOWANEJ KONSOLI ODZYSKIWANIA !![/B][/COLOR]
.

(((((((((((((((((((((((((((((((((((((((   Usunięto   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\~tmp.html
c:\windows\BM6b6f3bed.txt
c:\windows\system32\drivers\TDSSpaxt.sys
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log

.
(((((((((((((((((((((((((((((((((((((((   Sterowniki/Usługi   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys
-------\Legacy_ISODRIVE
-------\Service_ISODrive


(((((((((((((((((((((((((   Pliki utworzone od 2008-12-13 do 2009-01-13  )))))))))))))))))))))))))))))))
.

2009-01-13 02:35 . 2009-01-13 09:07   <DIR>   d--------   c:\program files\Odkurzacz
2009-01-13 01:28 . 2009-01-13 01:28   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2009-01-11 18:28 . 2009-01-11 18:28   <DIR>   d--------   c:\program files\NOS
2009-01-11 18:28 . 2009-01-11 18:28   <DIR>   d--------   c:\documents and settings\All Users\Dane aplikacji\NOS
2009-01-07 11:28 . 2009-01-07 11:33   <DIR>   d--------   C:\PS2_Mademan_bk

.
((((((((((((((((((((((((((((((((((((((((   Sekcja Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-13 15:35   ---------   d-----w   c:\program files\lg_fwupdate
2009-01-13 01:31   ---------   d-----w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\MegauploadToolbar
2009-01-13 00:29   ---------   d-----w   c:\program files\ESET
2009-01-13 00:27   ---------   d-----w   c:\program files\SkanerOnline
2009-01-13 00:27   ---------   d-----w   c:\program files\Movie Label 2009
2009-01-13 00:26   ---------   d-----w   c:\program files\Antenna
2009-01-11 17:42   ---------   d-----w   c:\program files\DOSBox-0.72
2008-12-14 15:52   ---------   d--h--w   c:\program files\InstallShield Installation Information
2008-12-12 12:39   ---------   d-----w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\SolidDocuments
2008-12-12 12:35   ---------   d-----w   c:\documents and settings\All Users\Dane aplikacji\SolidDocuments
2008-12-03 10:46   ---------   d-----w   c:\program files\Common Files\Ahead
2008-12-03 10:46   ---------   d-----w   c:\program files\Ahead
2008-12-01 22:55   ---------   d-----w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\foobar2000
2008-11-30 16:03   ---------   d-----w   c:\program files\Skype
2008-11-30 15:43   ---------   d-----w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\skypePM
2008-11-19 13:39   ---------   d-----w   c:\program files\CDCover 4
2008-11-18 23:01   ---------   d-----w   c:\program files\Intelore
2008-11-18 22:36   ---------   d-----w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\ImgBurn
2008-11-17 15:32   ---------   d-----w   c:\program files\ImgBurn
2008-11-10 20:04   133,296   -c--a-w   c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\GDIPFONTCACHEV1.DAT
2008-07-27 11:25   1,378   -c--a-w   c:\program files\uninstal.log
2008-06-15 19:33   32   -c--a-w   c:\documents and settings\All Users\Dane aplikacji\ezsid.dat
2001-08-13 13:51   1,396,337   ----a-w   c:\program files\Captura.exe
2002-01-02 00:48   32,768   -csha-w   c:\windows\system32\config\systemprofile\Ustawienia lokalne\Historia\History.IE5\MSHist012002010220020103\index.dat
.

------- Sigcheck -------

2007-10-30 17:53  360832  64798ecfa43d78c7178375fcdd16d8c8   c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 12:51  361600  9aefa14bd6b182d61e3119fa5f436d3d   c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 12:59  361600  ad978a1b783b5719720cff204b666c8e   c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2008-06-20 11:44  360960  744e57c99232201ae98c49168b918f48   c:\windows\$NtServicePackUninstall$\tcpip.sys
2007-10-16 00:19  360576  0fb6743e937c7bb248b2530a5a77abc6   c:\windows\$NtUninstallKB941644$\tcpip.sys
2008-04-13 20:20  361344  93ea8d04ec73a85db02eb8805988f733   c:\windows\$NtUninstallKB951748$\tcpip.sys
2007-10-30 18:20  360064  90caff4b094573449a0872a0f919b178   c:\windows\$NtUninstallKB951748_0$\tcpip.sys
2008-04-13 20:20  361344  accf5a9a1ffaa490f33dba1c632b95e1   c:\windows\ServicePackFiles\i386\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   c:\windows\system32\dllcache\tcpip.sys
2008-06-20 12:51  361600  9425b72f40257b45d45d24773273dad0   c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((((((((((   Wpisy startowe rejestru   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Gadu-Gadu"="c:\program files\Gadu-Gadu\gg.exe" [2008-03-20 2127296]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Odkurzacz-MCD"="c:\program files\Odkurzacz\odk_mcd.exe" [2008-08-16 264704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 144784]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2005-04-12 229376]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-17 c:\windows\RTHDCPL.EXE]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 c:\windows\system32\nvmctray.dll]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\krzysiek.PRIVATE-28C405B\Menu Start\Programy\Autostart\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

c:\documents and settings\All Users\Menu Start\Programy\Autostart\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMHelp"= 1 (0x1)

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Start^Programy^Autostart^HP Photosmart Premier - Szybkie uruchomienie.lnk]
path=c:\documents and settings\All Users\Menu Start\Programy\Autostart\HP Photosmart Premier - Szybkie uruchomienie.lnk
backup=c:\windows\pss\HP Photosmart Premier - Szybkie uruchomienie.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
--a------ 2008-07-22 19:42 116040 c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadu-Gadu]
--a------ 2008-03-20 11:04 2127296 c:\program files\Gadu-Gadu\gg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 15:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon]
--a------ 2008-03-13 08:34 81920 c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-07-30 09:47 289064 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Launch Ai Booster]
--a------ 2006-06-23 17:26 3706368 c:\program files\ASUS\Ai Booster\OverClk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 19:24 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-06-01 10:22 1519616 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Gadu-Gadu\\gg.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"23042:TCP"= 23042:TCP:BitComet 23042 TCP
"23042:UDP"= 23042:UDP:BitComet 23042 UDP
"24284:TCP"= 24284:TCP:BitComet 24284 TCP
"24284:UDP"= 24284:UDP:BitComet 24284 UDP

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-13 111184]
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [2006-01-13 15872]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-13 20560]
R4 Harmonogram automatycznej usługi LiveUpdate;Harmonogram automatycznej usługi LiveUpdate;c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-06-03 198336]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-11 33752]
.
Zawartość folderu 'Zaplanowane zadania'

2008-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:57]
.
.
------- Skan uzupełniający -------
.
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = socks=
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000

c:\windows\system32\SkanerOnlineUninstall.exe - c:\windows\system32\SkanerOnline.dll
O16 -: {68282C51-9459-467B-95BF-3C0E89627E55}
hxxp://www.mks.com.pl/skaner/SkanerOnline.cab
c:\windows\Downloaded Program Files\SkanerOnline.inf
FF - ProfilePath - c:\documents and settings\krzysiek.PRIVATE-28C405B\Dane aplikacji\Mozilla\Firefox\Profiles\[u]0[/u]jnjom52.default\
FF - prefs.js: browser.startup.homepage - google.pl
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 16:35:43
Windows 5.1.2600 Dodatek Service Pack 3 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...

skanowanie pomyślnie ukończone
ukryte pliki: 0

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_USERS\S-1-5-21-2000478354-1659004503-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\d*& ]
@Class="Shell"
"a"="d:\\Firma\\Suplementy\\Spedycja\\Inspekcja\\Nowy folder\\7511 Precision Iso-Pro Low Carb Vanilla Drink Mix Powder.d…"
"MRUList"="a"

[HKEY_USERS\S-1-5-21-2000478354-1659004503-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*d*& ]
@Class="Shell"

[HKEY_USERS\S-1-5-21-2000478354-1659004503-682003330-1003_Classes\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*d*& \OpenWithList]
@Class="Shell"
"a"="PDFCreator.exe"
"MRUList"="a"
.
------------------------ Pozostałe uruchomione procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\rundll32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Czas ukończenia: 2009-01-13 16:37:57 - komputer został uruchomiony ponownie
ComboFix-quarantined-files.txt  2009-01-13 15:37:54

Przed: 6,161,072,128 bajtów wolnych
Po: 6,092,386,304 bajtów wolnych

Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
230   --- E O F ---   2008-12-18 06:01:26
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53



Setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez wojtas 13 Sty 2009, 19:42

tu nic wiecej nie widac.. sprobuj teraz skana zrobić :)
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Re: setki okienek, kolorowy pulpit, alerty bezpieczeństwa

Postprzez gus 13 Sty 2009, 23:21

Wyglada na to, ze na razie sie naprawilo (po oczyszczeniu jeszcze wszystkiego Avastem).

Dzieki!
gus
~user
 
Posty: 36
Dołączenie: 23 Lip 2008, 08:53




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 13 gości