witam. moj problem wynika nastepujaco: komp nie laczy mi sie z siecia. tzn laczy sie w trybie awaryjnym, ewentualnie. wtedy pingi wracaja bardzo ladnie. lacze sie z lokalnym serwerem, i z innymi uzytkownikami sieci. tylko ze swiatem nie.
uzylam combofixa zgodnie z rada doswiadczonej kolezanki, ie za bardzo wiedzac, co robie, i w jakim celu. wolalabym uniknac formatowania dysku, a opcja ta zbliza sie nieuchronnie.
ComboFix 08-06-30.2 - Administrator 2008-07-02 10:04:31.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.447 [GMT 2:00]
Running from: F:\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-06-02 to 2008-07-02 )))))))))))))))))))))))))))))))
.
2008-07-02 06:23 . 2008-07-02 06:23 <DIR> d--h----- C:\$AVG8.VAULT$
2008-06-20 08:31 . 2008-06-20 08:31 <DIR> d-------- C:\Program Files\PDFCreator Toolbar
2008-06-20 08:31 . 2008-06-20 08:31 253,116 --a------ C:\WINDOWS\PDFCreator_Toolbar_Uninstaller_5953.exe
2008-06-20 08:31 . 2008-06-20 08:31 14,290 --a------ C:\Program Files\settings.dat
2008-06-20 08:30 . 2008-06-20 08:31 <DIR> d-------- C:\Program Files\PDFCreator
2008-06-20 08:30 . 2005-10-15 12:32 196,608 --a------ C:\WINDOWS\system32\pdfcmnnt.dll
2008-06-20 08:30 . 1998-06-24 00:00 137,000 --a------ C:\WINDOWS\system32\MSMAPI32.OCX
2008-06-20 08:30 . 1998-07-06 00:00 23,552 --a------ C:\WINDOWS\system32\MSMPIDE.DLL
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-01 17:06 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\The Bat!
2008-06-29 08:57 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\uTorrent
2008-06-28 19:49 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\Tlen.pl
2008-06-22 12:03 --------- d-----w C:\Documents and Settings\Administrator\Dane aplikacji\foobar2000
2008-05-28 08:10 --------- d-----w C:\Program Files\Soulseek
2008-05-26 09:00 96,520 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-26 09:00 75,272 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-26 09:00 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-05-26 09:00 --------- d-----w C:\Program Files\AVG
2008-05-26 09:00 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\avg8
2008-05-21 13:36 --------- d-----w C:\Program Files\Java
2008-05-21 13:35 --------- d-----w C:\Program Files\e-PDF Converter and Creator v2.1
2008-05-18 20:46 --------- d-----w C:\Program Files\uTorrent
2008-05-18 20:16 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-18 20:16 --------- d-----w C:\Program Files\LizardTech
2008-05-05 17:57 --------- d-----w C:\Program Files\Google
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
"Komunikator"="C:\Program Files\Tlen.pl\tlen.exe" [2008-01-15 17:09 6290944]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 22:32 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 22:32 455168]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2006-08-10 17:10 110592]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-11 22:03 708697]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 12:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 12:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 12:10 114688]
"Power_Gear"="C:\Program Files\Generic\Power4 Gear\BatteryLife.exe" [2004-09-21 17:55 81920]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-08-13 20:05 2532576]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-26 11:00 1177368]
"Skrót do strony właściwości High Definition Audio"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 16:09 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-13 16:47 2806272 C:\WINDOWS\ALCWZRD.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 14:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2008-05-05 19:57 29744 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2006-08-02 01:32 696320 C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2006-08-02 01:38 802816 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Komunikator]
--a------ 2008-01-15 17:09 6290944 C:\Program Files\Tlen.pl\tlen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 19:43 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Soulseek\\slsk.exe"=
"C:\\Program Files\\Tlen.pl\\tlen.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-26 11:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-26 11:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-26 11:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-26 11:00]
R3 SynMini;USB2.0 1.3M Web Cam;C:\WINDOWS\system32\Drivers\SynMini.sys [2005-04-22 17:34]
R3 SynScan;USB2.0 1.3M Web Cam Still Image;C:\WINDOWS\system32\Drivers\SynScan.sys [2005-04-19 16:16]
S3 GoogleDesktopManager-022208-143751;Menedżer Google Desktop 5.7.802.22438;"C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-05 19:57]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b023fa44-3c61-11dd-b173-0013d4bf9716}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-02 10:05:58
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\vsdatant]
"ImagePath"=""
.
Completion time: 2008-07-02 10:06:44
ComboFix-quarantined-files.txt 2008-07-02 08:06:40
Pre-Run: 7,419,789,312 bajtów wolnych
Post-Run: 7,484,289,024 bajtów wolnych
117