Od pewnego czasu mam problem z trojanami, Kaspersky cos tam pokasowal, teraz pokazuje ze komp czysty, ale co jakis czas uruchamia mi sie iexplore.exe (nie otwieraja sie zadne okienka) i zaczyna pobierac pliki typu gif (np down.gif russ.gif) Kaspersky blokuje je ale nie lokalizuje przyczyny pojawiania sie tego. Do tego zrobilem format calego dysku, nic to nie dalo, objawy takie same jak przed formatem.
Log z HijackThis:
- Kod: Zaznacz wszystko
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:57:05, on 2008-05-27
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\Kaspersky Internet Security 7.0\avp.exe
C:\Kaspersky Internet Security 7.0\avp.exe
C:\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVP] "C:\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Dodaj do blokowanych banerów - C:\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Statystyki dla ochrony WWW - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\KASPER~1.0\adialhk.dll
O21 - SSODL: JavaView - {DA191DE0-AA86-D04E-4B87-2A3D4928BE99} - C:\WINDOWS\AppPatch\Jview.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Kaspersky Internet Security 7.0\avp.exe
--
End of file - 3239 bytes
Log z ComboFix:
- Kod: Zaznacz wszystko
ComboFix 08-05-26.2 - ati 2008-05-27 20:32:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.299 [GMT 2:00]
Running from: C:\Documents and Settings\ati\Pulpit\ComboFix.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ijatnaw.cfg
C:\WINDOWS\system32\ijatnaw.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-27 to 2008-05-27 )))))))))))))))))))))))))))))))
.
2008-05-27 20:22 . 2008-05-27 20:23 <DIR> d-------- C:\HijackThis
2008-05-26 22:44 . 2008-05-26 22:44 <DIR> d-------- C:\Reader 8.0
2008-05-26 22:44 . 2008-05-26 22:44 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-05-26 21:40 . 2008-05-26 21:40 <DIR> d-------- C:\Documents and Settings\ati\Dane aplikacji\Gadu-Gadu
2008-05-26 21:20 . 2008-05-26 21:20 <DIR> d-------- C:\Documents and Settings\NetworkService\Dane aplikacji\Xfire
2008-05-26 21:19 . 2008-05-27 14:58 <DIR> d-------- C:\Documents and Settings\ati\Dane aplikacji\Xfire
2008-05-26 21:18 . 2008-05-26 21:21 <DIR> d-------- C:\Xfire
2008-05-26 20:57 . 2008-05-26 20:57 <DIR> d-------- C:\Gadu-Gadu
2008-05-26 20:57 . 2008-05-26 21:40 <DIR> d-------- C:\Documents and Settings\ati\Gadu-Gadu
2008-05-26 20:37 . 2008-05-26 20:37 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-26 20:35 . 2004-08-04 00:44 130,048 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-05-26 20:35 . 2004-08-04 00:44 130,048 --a--c--- C:\WINDOWS\system32\dllcache\ksproxy.ax
2008-05-26 20:35 . 2004-08-03 23:08 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-05-26 20:35 . 2004-08-03 23:08 60,288 --a--c--- C:\WINDOWS\system32\dllcache\drmk.sys
2008-05-26 20:35 . 2004-11-18 10:42 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-05-26 20:35 . 2004-08-04 00:44 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-05-26 20:35 . 2004-08-04 00:44 4,096 --a--c--- C:\WINDOWS\system32\dllcache\ksuser.dll
2008-05-26 20:34 . 2008-05-26 20:34 <DIR> d-------- C:\WinRAR
2008-05-26 20:26 . 2008-05-12 10:49 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-05-26 20:25 . 2008-05-26 20:25 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-05-26 20:24 . 2008-05-26 20:24 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-05-26 20:24 . 2008-05-26 20:24 <DIR> d-------- C:\ATI
2008-05-26 20:18 . 2008-05-26 20:18 1,212 --a------ C:\WINDOWS\mozver.dat
2008-05-14 03:28 . 2008-05-14 03:28 41,296 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-05-12 18:30 . 2008-05-12 18:30 3,007,488 --a------ C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-05-12 18:30 . 2008-05-12 18:30 3,007,488 --a--c--- C:\WINDOWS\system32\dllcache\ati2mtag.sys
2008-05-12 17:56 . 2008-05-12 17:56 397,312 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 17:54 . 2008-05-12 17:54 305,152 --a--c--- C:\WINDOWS\system32\dllcache\ati2dvag.dll
2008-05-12 17:54 . 2008-05-12 17:54 305,152 --a------ C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 17:53 . 2008-05-12 17:53 307,200 --a------ C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 17:45 . 2008-05-12 17:45 180,224 --a------ C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 17:45 . 2008-05-12 17:45 139,264 --a------ C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 17:45 . 2008-05-12 17:45 43,520 --a------ C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 17:45 . 2008-05-12 17:45 26,112 --a------ C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 17:44 . 2008-05-12 17:44 139,264 --a------ C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 17:43 . 2008-05-12 17:43 10,153,984 --a------ C:\WINDOWS\system32\atioglx2.dll
2008-05-12 17:43 . 2008-05-12 17:43 540,672 --a------ C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 17:41 . 2008-05-12 17:41 53,248 --a------ C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 17:32 . 2008-05-12 17:32 3,203,168 --a--c--- C:\WINDOWS\system32\dllcache\ati3duag.dll
2008-05-12 17:32 . 2008-05-12 17:32 3,203,168 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-05-12 17:22 . 2008-05-12 17:22 3,107,788 --a------ C:\WINDOWS\system32\ativvaxx.dat
2008-05-12 17:22 . 2008-05-12 17:22 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat
2008-05-12 17:22 . 2008-05-12 17:22 1,999,616 --a--c--- C:\WINDOWS\system32\dllcache\ativvaxx.dll
2008-05-12 17:22 . 2008-05-12 17:22 1,999,616 --a------ C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 17:22 . 2008-05-12 17:22 887,724 --a------ C:\WINDOWS\system32\ativva6x.dat
2008-05-12 17:09 . 2008-05-12 17:09 47,104 --a------ C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 17:05 . 2008-05-12 17:05 5,439,488 --a------ C:\WINDOWS\system32\atioglxx.dll
2008-05-12 17:05 . 2008-05-12 17:05 327,680 --a------ C:\WINDOWS\system32\atikvmag.dll
2008-05-12 17:03 . 2008-05-12 17:03 19,968 --a------ C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 17:03 . 2008-05-12 17:03 17,408 --a------ C:\WINDOWS\system32\atitvo32.dll
2008-05-12 17:02 . 2008-05-12 17:02 241,664 --a------ C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 17:02 . 2008-05-12 17:02 49,152 --a------ C:\WINDOWS\system32\drivers\ati2erec.dll
2008-05-12 16:57 . 2008-05-12 16:57 548,864 --a--c--- C:\WINDOWS\system32\dllcache\ati2cqag.dll
2008-05-12 16:57 . 2008-05-12 16:57 548,864 --a------ C:\WINDOWS\system32\ati2cqag.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 18:34 648,736 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-27 18:34 27,424 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-27 18:32 9,216 ----a-w C:\WINDOWS\AppPatch\AcXtrnel.dll
2008-05-27 16:29 4,448 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-05-27 16:29 13,412 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-05-27 15:29 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab
2008-05-26 17:36 --------- d-----w C:\Documents and Settings\ati\Dane aplikacji\Talkback
2008-05-26 16:58 96,645 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-05-26 16:58 87,941 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-05-26 16:36 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files
2008-05-26 16:30 13,824 ----a-w C:\WINDOWS\AppPatch\Jview.dll
2008-05-26 16:13 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-26 16:08 --------- d-----w C:\Program Files\Usługi online
2004-08-03 22:44 32,024 --sh--w C:\WINDOWS\system32\ghjkdr.dll
2004-08-03 22:44 9,216 --sha-w C:\WINDOWS\system32\ghrst.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"Adobe Reader Speed Launcher"="C:\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:44 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"JavaView"= {DA191DE0-AA86-D04E-4B87-2A3D4928BE99} - C:\WINDOWS\AppPatch\Jview.dll [2008-05-26 18:30 13824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\KASPER~1.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-27 20:34:49
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-27 20:36:58
ComboFix-quarantined-files.txt 2008-05-27 18:36:55
Pre-Run: 7,594,827,776 bajtów wolnych
Post-Run: 7,594,557,440 bajtów wolnych
128