
wszystkie w jednym folderze
C:\DOCUME~1\Admin\USTAWI~1\Temp\ac8zt2\main_uninstaller.
C:\DOCUME~1\Admin\USTAWI~1\Temp\ac8zt2\msmdev.dll
C:\DOCUME~1\Admin\USTAWI~1\Temp\ac8zt2\nsduo.dll
C:\DOCUME~1\Admin\USTAWI~1\Temp\ac8zt2\rmv.exe
C:\DOCUME~1\Admin\USTAWI~1\Temp\ac8zt2\main_uninstaller.exe
Zrobiłem log w hijacku i cobofix , proszę o pomoc.
- Kod: Zaznacz wszystko
Logfile of HijackThis v1.99.1
Scan saved at 12:28:55, on 2007-10-27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\KAMILU~1\USTAWI~1\Temp\Rar$EX00.940\HijackThis.exe
C:\WINDOWS\explorer.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: MSVPS System - {90CF5384-7C70-4CD6-A30D-B2F14537B5C3} - C:\WINDOWS\movctrlwxq.dll
O3 - Toolbar: The nssfrch - {7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC} - C:\WINDOWS\nssfrch.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: bxsbang - {9F8B9BC5-EE31-49A8-A479-7BC5CCEF6789} - C:\WINDOWS\bxsbang.dll
O21 - SSODL: ocgrep - {8B292382-A44C-4750-8CA2-518495EF008A} - C:\WINDOWS\ocgrep.dll (file missing)
O21 - SSODL: msmhost - {704043D0-9493-48F9-A185-5159AAEF5072} - C:\WINDOWS\msmhost.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
- Kod: Zaznacz wszystko
ComboFix 07-10-26.4 - Kamilunia 2007-10-27 12:11:14.1 - NTFSx86
Running from: C:\Documents and Settings\Kamilunia\Pulpit\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\VideoAccessCodec
C:\WINDOWS\dat.txt
C:\WINDOWS\msmhost.dll
C:\WINDOWS\nsduo.dll
.
((((((((((((((((((((((((( Files Created from 2007-09-27 to 2007-10-27 )))))))))))))))))))))))))))))))
.
2007-10-27 12:09 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-27 11:34 <DIR> d-------- C:\Documents and Settings\Kamilunia\Dane aplikacji\Corel
2007-10-27 11:30 <DIR> d-------- C:\WINDOWS\Corel
2007-10-27 11:10 311,296 --a------ C:\WINDOWS\movctrlwxq.dll
2007-10-27 11:10 270,336 --a------ C:\WINDOWS\bxsbang.dll
2007-10-27 11:10 101,376 --a------ C:\WINDOWS\kthemup.exe
2007-10-27 11:10 79,872 --a------ C:\WINDOWS\nssfrch.dll
2007-10-27 10:54 <DIR> d-------- C:\Program Files\InstallShield Installation Information
2007-10-27 10:53 <DIR> d-------- C:\Program Files\Common Files\Vbox
2007-10-27 10:46 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2007-10-26 23:03 <DIR> d-------- C:\Program Files\Picasa2
2007-10-26 22:58 <DIR> d-------- C:\Documents and Settings\Kamilunia\Dane aplikacji\Gadu-Gadu
2007-10-26 22:57 <DIR> d-------- C:\Program Files\Winamp
2007-10-26 22:57 <DIR> d-------- C:\Documents and Settings\Kamilunia\Dane aplikacji\Winamp
2007-10-26 22:56 <DIR> d-------- C:\Program Files\Gadu-Gadu
2007-10-26 22:56 <DIR> d-------- C:\Documents and Settings\Kamilunia\Gadu-Gadu
2007-10-26 22:44 <DIR> d-------- C:\Program Files\Alwil Software
2007-10-26 22:32 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2007-10-26 22:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-10-26 22:27 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-26 22:19 <DIR> d--h----- C:\Documents and Settings\Kamilunia\Ustawienia lokalne
2007-10-26 22:19 <DIR> dr------- C:\Documents and Settings\Kamilunia\Ulubione
2007-10-26 22:19 <DIR> d--h----- C:\Documents and Settings\Kamilunia\Szablony
2007-10-26 22:19 <DIR> d-------- C:\Documents and Settings\Kamilunia\Pulpit
2007-10-26 22:19 <DIR> dr------- C:\Documents and Settings\Kamilunia\Moje dokumenty
2007-10-26 22:19 <DIR> dr------- C:\Documents and Settings\Kamilunia\Menu Start
2007-10-26 22:19 <DIR> dr-h----- C:\Documents and Settings\Kamilunia\Dane aplikacji
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 15:49 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-26 15:44 --------- d-----w C:\Program Files\Usługi online
2007-09-06 10:09 801,144 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-21 06:18 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{90CF5384-7C70-4CD6-A30D-B2F14537B5C3}]
2007-10-26 19:20 311296 --a------ C:\WINDOWS\movctrlwxq.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC}"= C:\WINDOWS\nssfrch.dll [2007-10-26 19:20 79872]
[HKEY_CLASSES_ROOT\CLSID\{7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC}]
[HKEY_CLASSES_ROOT\nssfrch.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{7AB4A8AD-FE74-4870-9EE2-9AC715FD4661}]
[HKEY_CLASSES_ROOT\nssfrch.ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-04-20 01:17]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 09:39]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bxsbang"= {9F8B9BC5-EE31-49A8-A479-7BC5CCEF6789} - C:\WINDOWS\bxsbang.dll [2007-10-26 19:20 270336]
"ocgrep"= {8B292382-A44C-4750-8CA2-518495EF008A} - C:\WINDOWS\ocgrep.dll [ ]
R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys
S3 NtApm;Sterownik interfejsu NT Apm/Legacy;C:\WINDOWS\system32\DRIVERS\NtApm.sys
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 12:17:24
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-27 12:23:26 - machine was rebooted
.
--- E O F ---