i przez to mi żaden komunikator nie chce smigac m.in. gg Pomożecie??????? proszę
UA:
i przez to mi żaden komunikator nie chce smigac m.in. gg Pomożecie??????? proszę
UA:
logi z hijackthis :huber2t napisał(a):Daj logi z Hijackthis a następnie logi z Combofix

UA:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll

UA:
pp3088 napisał(a):R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
Fix checked, kosmetyka.
Daj log z Combofixa, bo dałeś 2 razy HJT, więc usunąłem powtórke.
Usuń plik:
C:\Windows\SYSTEM32\avgwlntf.dll

UA:
macin85 napisał(a):pp3088 napisał(a):R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
Fix checked, kosmetyka.
Daj log z Combofixa, bo dałeś 2 razy HJT, więc usunąłem powtórke.
Usuń plik:
C:\Windows\SYSTEM32\avgwlntf.dll
ComboFix 08-04-24.1 - Marcin 2008-04-27 21:47:53.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1250.1.1045.18.246 [GMT 2:00]
Running from: C:\Users\Marcin\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-03-27 to 2008-04-27 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-27 19:44 --------- d-----w C:\Program Files\Trend Micro
2008-04-27 19:43 --------- d---a-w C:\ProgramData\TEMP
2008-04-27 19:38 --------- d-----w C:\Program Files\Spyware Doctor
2008-04-27 19:35 --------- d-----w C:\Users\Marcin\AppData\Roaming\PC Tools
2008-04-27 09:21 --------- d-----w C:\Program Files\Windows Mail
2008-04-27 08:33 --------- d-----w C:\Users\Marcin\AppData\Roaming\AVG7
2008-04-26 08:56 --------- d-----w C:\Program Files\Real
2008-04-26 08:53 --------- d-----w C:\Program Files\Real Alternative
2008-04-26 08:49 --------- d-----w C:\Program Files\Gadu-Gadu
2008-04-21 19:24 --------- d-----w C:\Program Files\AusLogics Registry Defrag
2008-04-21 19:18 --------- d-----w C:\Program Files\Essentials Codec Pack
2008-04-21 19:05 --------- d-----w C:\Program Files\SubEdit-Player
2008-04-21 18:54 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-04-21 18:54 --------- d-----w C:\ProgramData\Ashampoo
2008-04-21 18:54 --------- d-----w C:\Program Files\Ashampoo
2008-04-20 10:58 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-06 15:59 --------- d-----w C:\Users\Marcin\AppData\Roaming\Media Player Classic
2008-03-29 11:09 --------- d-----w C:\Program Files\OpenNETCF
2008-03-21 11:25 --------- d-----w C:\Users\Marcin\AppData\Roaming\FlashGet
2008-03-21 11:25 --------- d-----w C:\Program Files\Google
2008-03-21 11:25 --------- d-----w C:\Program Files\FlashGet
2008-03-20 11:40 --------- d-----w C:\ProgramData\Bluetooth
2008-03-20 11:35 --------- d-----w C:\Program Files\IVT Corporation
2008-03-12 16:37 --------- d-----w C:\Program Files\Yahoo!
2008-03-12 16:37 --------- d-----w C:\Program Files\CCleaner
2008-03-12 08:20 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-12 08:19 --------- d-----w C:\Program Files\Common Files\Real
2008-03-08 09:36 --------- d-----w C:\Program Files\EA SPORTS
2008-03-07 16:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-07 16:24 --------- d-----w C:\Program Files\AutoMapa EU
2008-03-05 07:53 --------- d-----w C:\ProgramData\avg7
2008-03-04 20:50 --------- d-----w C:\Users\Marcin\AppData\Roaming\Toshiba
2008-03-04 14:05 174 --sha-w C:\Program Files\desktop.ini
2008-03-04 14:01 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-04 14:01 --------- d-----w C:\Program Files\Windows Calendar
2008-03-04 13:15 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-03-04 13:15 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-03-04 13:15 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-03-04 13:15 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-03-04 13:15 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-03-04 13:15 299,008 ----a-w C:\Windows\System32\wlansec.dll
2008-03-04 13:15 289,280 ----a-w C:\Windows\System32\wlanmsm.dll
2008-03-04 13:15 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
2008-03-04 13:15 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
2008-03-04 13:15 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-03-04 13:15 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
2008-03-04 13:15 2,923,520 ----a-w C:\Windows\explorer.exe
2008-03-04 13:15 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
2008-03-04 13:10 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-03-04 13:10 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-03-04 13:10 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-03-04 13:10 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-04 13:10 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-03-04 13:09 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-04 13:09 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-03-04 13:09 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-04 13:09 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-04 13:09 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-04 13:09 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
2008-03-04 13:09 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-04 13:09 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-04 13:09 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-03-04 13:08 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-03-04 13:08 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-03-04 13:08 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-03-04 13:08 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
2008-03-04 13:08 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-03-04 13:08 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-04 13:08 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
2008-03-04 13:08 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-03-04 13:08 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-03-04 13:08 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-04 13:07 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-03-04 13:07 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-03-04 13:07 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-03-04 13:07 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-03-04 13:07 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-03-04 13:07 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-03-04 13:06 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-04 13:06 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-03-04 13:06 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-03-04 13:06 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-03-04 13:06 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-03-04 13:06 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-03-04 13:06 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-03-04 13:06 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-03-04 13:06 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-03-04 13:06 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-03-04 13:06 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-03-04 13:06 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-03-04 13:05 2,048 ----a-w C:\Windows\System32\msxml6r.dll
2008-03-04 13:05 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-03-04 13:03 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-03-04 13:03 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-03-04 13:03 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-04 13:02 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
2008-03-04 13:02 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2008-03-04 13:02 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
2008-03-04 13:02 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-04 13:02 152,576 ----a-w C:\Windows\System32\imagehlp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-05-16 10:32 435768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-21 13:25 171448]
"UIWatcher"="C:\Program Files\Ashampoo\Ashampoo Magical UnInstall\UIWatcher.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-06-01 14:15 1006264]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-04-04 15:26 138008]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-04-04 15:26 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-04-04 15:26 133912]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-13 16:19 861744]
"NDSTray.exe"="NDSTray.exe" []
"topi"="C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 12:48 577536]
"Toshiba Registration"="C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe" [2007-05-04 13:05 571024]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-04 14:37 579072]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 10:56 185896]
"Flashget"="C:\Program Files\FlashGet\FlashGet.exe" [2007-09-25 10:10 2007088]
"MagUninstall"="C:\Program Files\Ashampoo\Ashampoo Magical UnInstall\MagicalUnInstall.exe" [2007-11-02 15:58 1743712]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" [2007-04-08 18:44 303104]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-04 14:37 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-03-04 14:37 9216 C:\Windows\System32\avgwlntf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D3621200-1B6B-4DDD-BA93-7A30723BD74F}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{3A5D9404-A7AE-4477-B42C-F5C61835EFE5}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3661BE45-4973-40C2-9A6F-56548EEA2107}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{4F95F46E-BC04-4CD1-8B09-40343FC76AAC}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B4A4C243-801D-4AD2-8AB1-BA387B1A90F5}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3763A761-638F-4927-B9E7-C26FBF638F12}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"{DE58917E-6AF8-4FED-8F11-FE1F6F55D0C7}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
"TCP Query User{B495DF94-7670-454C-ACF5-B0DAB98A3734}C:\\program files\\flashget\\flashget.exe"= UDP:C:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{4B7BCEAF-2A50-40EA-AA24-0396FCE30F4F}C:\\program files\\flashget\\flashget.exe"= TCP:C:\program files\flashget\flashget.exe:FlashGet
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 tos_sps32;TOSHIBA tos_sps32 Service;C:\Windows\system32\DRIVERS\tos_sps32.sys [2007-04-27 20:13]
R2 TNaviSrv;TOSHIBA Navi Support Service;C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe [2007-04-27 20:15]
R3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-02-28 19:04]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-03-30 11:57]
R3 tdcmdpst;TOSHIBA Writing Engine Filter Driver;C:\Windows\system32\DRIVERS\tdcmdpst.sys [2006-10-18 12:50]
S4 KR10I;KR10I;C:\Windows\system32\drivers\kr10i.sys [2007-01-18 16:40]
S4 KR10N;KR10N;C:\Windows\system32\drivers\kr10n.sys [2007-01-18 16:47]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{883a2db0-e78c-11dc-9611-806e6f6e6963}]
\shell\AutoRun\command - F:\pcformat.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8ff1adf4-ea22-11dc-9e0c-001a92fc70ec}]
\shell\Auto\command - UFO.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - IKFILESEC
*Newly Created Service* - IKSYSFLT
*Newly Created Service* - IKSYSSEC
*Newly Created Service* - MCHINJDRV
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-27 21:51:42
Windows 6.0.6000 NTFS
detected NTDLL code modification:
ZwClose
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i?????d?4 9???X?@???@???@???@?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-27 21:53:16
ComboFix-quarantined-files.txt 2008-04-27 19:53:04
ComboFix2.txt 2008-04-26 08:38:40
System nie może znaleźć komunikatu dla numeru komunikatu 0x2379 w pliku komunikatów dla Application.
System nie może znaleźć komunikatu dla numeru komunikatu 0x2379 w pliku komunikatów dla Application.
200 --- E O F --- 2008-04-27 08:40:48

UA:
File::
C:\Windows\SYSTEM32\avgwlntf.dll
C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
F:\pcformat.exe
zapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)

UA:
pp3088 napisał(a):Wklej do notatnika:File::
C:\Windows\SYSTEM32\avgwlntf.dll
C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
F:\pcformat.exe
Plikzapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu
Powinno się rozpocząć usuwanie i powstanie log, daj ten log na forum.
Jeśli wszystko pójdzie dobrze, to po restarcie usuń ręcznie folder C: \Qoobox
Start >>> Uruchom >>> regedit i w kluczu:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
skasować z prawo kliku odpowiedni podlkucz

UA:
macin85 napisał(a):pp3088 napisał(a):Wklej do notatnika:File::
C:\Windows\SYSTEM32\avgwlntf.dll
C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
F:\pcformat.exe
Plikzapisz jako
CFScript.txt (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe)
Przeciągnij i upuść ikonkę CFScript.txt na ikonkę ComboFix.exe tak jak tu
Powinno się rozpocząć usuwanie i powstanie log, daj ten log na forum.
Jeśli wszystko pójdzie dobrze, to po restarcie usuń ręcznie folder C: \Qoobox
Start >>> Uruchom >>> regedit i w kluczu:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
skasować z prawo kliku odpowiedni podlkucz
mam problem bo po odpaleniu Combo wyskakuje komunikat CFScript Name Error

UA:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
Plik
Zapisz jako
Zmień rozszerzenie z .txt na wszystkie pliki
zapisz pod nazwą Fix.reg

UA:

Zarejestrowani użytkownicy: Bing [Bot]