Kaspersky wykryl pare trojanów na moim kompie cześć usunął ale pare pozostalo i nie wiem jak ich sie pozbyc. Jeden z nich to napewno not-a-virus:AdWare.Win32.EShoper. Załaczam log z combofixa. jesli wiecie jak mi pomoc to prosze o rade. Z gory wielkie dzienki!!!
ComboFix 08-06-12.2 - Anna 2008-06-16 0:23:21.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.1530 [GMT 2:00]
Running from: C:\Documents and Settings\Anna\Pulpit\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-05-15 to 2008-06-15 )))))))))))))))))))))))))))))))
.
2008-06-16 00:18 . 2008-06-16 00:18 <DIR> d-------- C:\WINDOWS\LastGood
2008-06-15 13:37 . 2008-06-16 00:24 <DIR> d--h----- C:\Documents and Settings\Administrator\Ustawienia lokalne
2008-06-15 13:37 . 2007-09-29 18:04 <DIR> d-------- C:\Documents and Settings\Administrator\Ulubione
2008-06-15 13:37 . 2007-09-29 16:15 <DIR> d--h----- C:\Documents and Settings\Administrator\Szablony
2008-06-15 13:37 . 2007-09-29 18:04 <DIR> d-------- C:\Documents and Settings\Administrator\Pulpit
2008-06-15 13:37 . 2007-09-29 18:04 <DIR> d-------- C:\Documents and Settings\Administrator\Moje dokumenty
2008-06-15 13:37 . 2007-09-29 18:04 <DIR> dr------- C:\Documents and Settings\Administrator\Menu Start
2008-06-15 13:37 . 2007-09-29 16:57 <DIR> d-------- C:\Documents and Settings\Administrator\Dane aplikacji\Intel
2008-06-15 13:37 . 2007-09-29 16:57 <DIR> dr-h----- C:\Documents and Settings\Administrator\Dane aplikacji
2008-06-15 13:37 . 2008-06-15 13:37 <DIR> d-------- C:\Documents and Settings\Administrator
2008-06-14 12:17 . 2008-06-14 12:17 96,966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-06-14 12:17 . 2008-06-14 12:17 88,774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-06-14 12:16 . 2008-06-15 14:03 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-06-14 12:16 . 2008-06-15 13:54 1,340,448 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-06-14 12:16 . 2008-06-15 13:57 270,368 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-06-14 12:16 . 2008-06-15 13:54 11,552 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-06-14 12:16 . 2008-06-15 13:57 2,004 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-06-02 18:28 . 2008-06-02 18:28 <DIR> d-------- C:\Program Files\Two Site Mix
2008-05-31 14:58 . 2008-05-31 14:58 259 --a------ C:\WINDOWS\madagascar.ini
2008-05-30 21:51 . 2008-05-30 21:50 724,992 --a------ C:\WINDOWS\iun6002.exe
2008-05-30 20:29 . 2008-05-30 20:29 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\SpinTop Games
2008-05-30 20:25 . 2008-06-12 19:29 10 --ah----- C:\WINDOWS\popcinfo.dat
2008-05-30 19:58 . 2008-05-30 19:58 <DIR> d-------- C:\Documents and Settings\Anna\Dane aplikacji\SpinTop
2008-05-30 19:58 . 2008-05-30 21:11 <DIR> d-a------ C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-05-30 18:37 . 2008-05-30 18:37 <DIR> d-------- C:\Documents and Settings\Anna\Dane aplikacji\Zylom
2008-05-30 18:37 . 2008-05-30 18:37 <DIR> d-------- C:\Documents and Settings\All Users\Dane aplikacji\Zylom
2008-05-26 16:53 . 2008-05-26 16:53 <DIR> d-------- C:\Program Files\directx
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-15 22:18 --------- d-----w C:\Program Files\SkanerOnline
2008-06-15 19:59 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\Skype
2008-06-15 19:54 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\skypePM
2008-06-15 09:05 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-06-14 12:38 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Apple Computer
2008-06-14 10:14 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Avira
2008-06-14 10:10 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-06-12 19:01 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\BearShare
2008-06-02 16:29 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\Two Site Mix
2008-06-02 16:29 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Meow Intra Bait Face
2008-05-31 13:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-29 08:29 --------- d-----w C:\Program Files\BitComet
2008-05-25 19:35 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Lavasoft
2008-05-25 19:34 12,632 ----a-w C:\windows\system32\lsdelete.exe
2008-04-26 15:52 --------- d-----w C:\Documents and Settings\Anna\Dane aplikacji\Outlook AutoConfig
2008-04-25 16:22 206,088 ----a-w C:\windows\system32\klogon.dll
2008-04-25 16:21 26,964 ----a-w C:\windows\system32\drivers\klopp.dat
2008-04-16 12:23 112,144 ----a-w C:\windows\system32\drivers\kl1.sys
2008-04-14 09:38 86,016 ----a-w C:\windows\system32\OpenAL32.dll
2008-04-14 09:38 413,696 ----a-w C:\windows\system32\wrap_oal.dll
2008-03-30 17:21 32 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\ezsid.dat
.
------- Sigcheck -------
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\windows\system32\dllcache\tcpip.sys
2004-08-03 23:14 359040 6a603809f598332dbedd535bdbce313e C:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-15_13.56.50.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-19 07:40:42 89,088 ----a-w C:\windows\LastGood\system32\SkanerOnlineUninstall.exe
- 2008-06-15 11:50:23 43,074 ----a-w C:\windows\system32\perfc009.dat
+ 2008-06-15 11:59:04 43,074 ----a-w C:\windows\system32\perfc009.dat
- 2008-06-15 11:50:23 52,658 ----a-w C:\windows\system32\perfc015.dat
+ 2008-06-15 11:59:04 52,658 ----a-w C:\windows\system32\perfc015.dat
- 2008-06-15 11:50:23 318,604 ----a-w C:\windows\system32\perfh009.dat
+ 2008-06-15 11:59:04 318,604 ----a-w C:\windows\system32\perfh009.dat
- 2008-06-15 11:50:23 362,734 ----a-w C:\windows\system32\perfh015.dat
+ 2008-06-15 11:59:04 362,734 ----a-w C:\windows\system32\perfh015.dat
+ 2007-03-15 10:00:36 466,432 ----a-w C:\windows\system32\SkanerOnline.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="D:\Programy\Alcohol 120\axcmd.exe" [ ]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:26 22014760]
"Gadu-Gadu"="C:\Program Files\Gadu-Gadu\gg.exe" [2007-07-09 09:39 2119104]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2006-02-13 19:02 2678784]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 21:43 95800]
"Mpeg Settings"="C:\DOCUME~1\Anna\DANEAP~1\TWOSIT~1\ITCHBUILD.exe" [2008-06-02 18:28 484352]
"i8kfangui"="C:\Program Files\I8kfanGUI\I8kfanGUI.exe" [2007-02-16 18:58 856064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-07-25 16:32 823296]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-07-25 16:30 974848]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Spik"="D:\Programy\Spik\Spik.exe" [2007-10-08 15:11 103912]
"Sony Ericsson PC Suite"="D:\Programy\Sony Ericsson\Application Launcher\Application Launcher.exe" [2007-01-26 13:36 495616]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-23 16:04 1544192]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-19 19:19 49152]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-08-21 19:04 155648]
"bait face type axis"="C:\Documents and Settings\All Users\Dane aplikacji\Meow Intra Bait Face\title find.exe" [2008-06-15 16:29 936448]
"AVP"="D:\Programy\Kaspersky antivir\avp.exe" [2008-04-25 18:21 201992]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 19:28:28 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"VIDC.YV12"= yv12vfw.dll
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"D:\\Programy\\FlashGet\\flashget.exe"=
"D:\\Programy\\VoipDiscount\\VoipDiscount.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Gadu-Gadu\\gg.exe"=
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 fanio;FanIO driver;C:\windows\system32\drivers\fanio.sys [2007-02-16 11:05]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\windows\system32\DRIVERS\klim5.sys [2008-03-25 20:07]
S3 sea1bus;Sony Ericsson Device 0A1 driver (WDM);C:\windows\system32\DRIVERS\sea1bus.sys [2007-02-08 12:55]
S3 sea1mdfl;Sony Ericsson Device 0A1 USB WMC Modem Filter;C:\windows\system32\DRIVERS\sea1mdfl.sys [2007-02-08 12:55]
S3 sea1mdm;Sony Ericsson Device 0A1 USB WMC Modem Driver;C:\windows\system32\DRIVERS\sea1mdm.sys [2007-02-08 12:55]
S3 sea1mgmt;Sony Ericsson Device 0A1 USB WMC Device Management Drivers (WDM);C:\windows\system32\DRIVERS\sea1mgmt.sys [2007-02-08 12:56]
S3 sea1nd5;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (NDIS);C:\windows\system32\DRIVERS\sea1nd5.sys [2007-02-08 12:56]
S3 sea1obex;Sony Ericsson Device 0A1 USB WMC OBEX Interface;C:\windows\system32\DRIVERS\sea1obex.sys [2007-02-08 12:56]
S3 sea1unic;Sony Ericsson Device 0A1 USB Ethernet Emulation SEMCA1 (WDM);C:\windows\system32\DRIVERS\sea1unic.sys [2007-02-08 12:56]
S3 usbscan;Sterownik skanera USB;C:\windows\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Sterownik magazynu masowego USB;C:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 zlportio;zlportio;D:\Programy\UltraSongs\UltraStar Deluxe\zlportio.sys []
.
Contents of the 'Scheduled Tasks' folder
"2008-06-15 22:00:00 C:\windows\Tasks\B1966020906A1440.job"
- c:\docume~1\anna\daneap~1\twosit~1\Surf bike fork.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-16 00:24:38
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-16 0:25:26
ComboFix-quarantined-files.txt 2008-06-15 22:25:15
Pre-Run: 5,358,678,016 bajtów wolnych
Post-Run: 5,351,784,448 bajtów wolnych
155


Zaplanowane zadania 

