włącza sie usługa posłaniec ... i domyślam sie ze jest więcej wirusów.. proszę o pomoc w ich zwalczeniu...
log z combo fix!! .........
ComboFix 08-04-18.3 - Joanna 2008-04-20 13:39:08.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.811 [GMT 2:00]
Running from: C:\Documents and Settings\Joanna\Pulpit\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system\svchost.exe
C:\WINDOWS\system32\csrs.exe
C:\WINDOWS\update.exe
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-20 13:37 . 2008-04-20 13:37 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-20 10:55 . 2008-04-20 13:34 160,012 --a------ C:\WINDOWS\Apr_19_2008__11_26_09.jpg
2008-04-19 11:25 . 2008-04-20 13:34 390,840 --a------ C:\WINDOWS\Apr_18_2008__16_34_41.jpg
2008-04-19 11:25 . 2008-04-20 13:34 374,966 --a------ C:\WINDOWS\Apr_18_2008__16_24_36.jpg
2008-04-19 11:25 . 2008-04-20 13:34 320,792 --a------ C:\WINDOWS\Apr_18_2008__16_04_35.jpg
2008-04-19 11:25 . 2008-04-20 13:34 288,134 --a------ C:\WINDOWS\Apr_18_2008__16_14_36.jpg
2008-04-18 15:58 . 2008-04-20 13:34 265,803 --a------ C:\WINDOWS\Apr_18_2008__14_19_47.jpg
2008-04-18 09:58 . 2008-04-20 13:33 502,944 --a------ C:\WINDOWS\Mar_25_2008__16_36_25.jpg
2008-04-18 09:57 . 2008-04-20 13:32 561,893 --a------ C:\WINDOWS\Mar_11_2008__00_27_58.jpg
2008-04-18 09:56 . 2008-04-20 13:31 4,970,438 --a------ C:\WINDOWS\System32NELM.005.tmp
2008-04-15 20:13 . 2000-12-08 21:59 122,880 --a------ C:\WINDOWS\UnGins.exe
2008-04-02 18:04 . 2008-04-02 18:05 <DIR> d-------- C:\matura20082
2008-03-29 12:52 . 2008-03-29 12:52 204,656 --a------ C:\WINDOWS\Mar_29_2008__11_09_09.jpg
2008-03-29 12:04 . 2008-03-29 12:51 502,213 --a------ C:\WINDOWS\Mar_17_2008__22_01_14.jpg
2008-03-29 12:03 . 2008-03-29 12:50 561,893 --a------ C:\WINDOWS\Mar_10_2008__22_27_58.jpg
2008-03-29 12:02 . 2008-03-29 12:50 404,783 --a------ C:\WINDOWS\Mar_08_2008__09_00_18.jpg
2008-03-28 20:30 . 2008-04-05 10:37 38 --a------ C:\WINDOWS\AviSplitter.INI
2008-03-26 14:02 . 2008-03-26 14:04 <DIR> d-------- C:\matura20081
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 11:34 --------- d-----w C:\Program Files\Neostrada TP
2008-04-20 11:31 720,132 ----a-w C:\WINDOWS\System32NELM.002.tmp
2008-04-20 11:30 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\Hamachi
2008-04-19 17:17 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\Image Zone Express
2008-04-15 15:39 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\BearShare
2008-03-30 14:56 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\Tibia
2008-03-04 15:07 444,416 --sh--r C:\WINDOWS\system32\upds.exe
2008-03-02 11:28 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-02 11:28 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ABBYY
2008-03-02 11:24 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\ABBYY
2008-03-02 10:41 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2008-03-02 10:37 --------- d-----w C:\Documents and Settings\Joanna\Dane aplikacji\Pegasys Inc
2008-02-20 18:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-19 08:46 60,416 ----a-w C:\WINDOWS\ALCFDRTM.EXE
2008-02-12 17:59 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-02-12 17:59 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-01-31 12:29 482,816 ----a-w C:\WINDOWS\System32NELM.exe
2008-01-31 12:29 402,944 ----a-w C:\WINDOWS\System32AKV.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-10-26 19:29 13312]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 23:18 443968]
"Gadu-Gadu"="D:\Gadu-Gadu\gg.exe" [2006-11-14 10:12 1849032]
"scvhost"="c:\windows\system\scvhost.exe" [2008-01-31 14:45 182784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2006-06-01 11:22 7618560]
"nwiz"="nwiz.exe" [2006-06-01 11:22 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 11:22 86016 C:\WINDOWS\system32\nvmctray.dll]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"SoundMan"="SOUNDMAN.EXE" [2006-06-20 23:42 577536 C:\WINDOWS\soundman.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"WooCnxMon"="C:\PROGRA~1\NEOSTR~1\CnxMon.exe" [2003-10-16 18:07 24576]
"WOOWATCH"="C:\PROGRA~1\NEOSTR~1\Watch.exe" [2003-10-16 18:07 20480]
"WOOTASKBARICON"="C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe" [2003-10-16 18:07 53248]
"System32NELM Agent"="C:\WINDOWS\System32NELM.exe" [2008-01-31 14:29 482816]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-12 19:59 185896]
"Client Server Runtime Process"="C:\WINDOWS\System32\csrs.exe" [ ]
"Windows System Update Tools"="upds.exe" [2008-03-04 17:07 444416 C:\WINDOWS\system32\upds.exe]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windows System Update Tools"="upds.exe" [2008-03-04 17:07 444416 C:\WINDOWS\system32\upds.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-10-26 19:29 13312]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 23:18 443968]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-08-27 12:11:14 962661]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\System32\\upds.exe"=
R0 AFPAnsi;G-DATA Ukrywacz Ansi;C:\WINDOWS\System32\Drivers\AFPAnsi.sys [2002-10-09 14:53]
R0 ALLOW-IO;ALLOW-IO;C:\WINDOWS\System32\Drivers\ALLOW-IO.sys [2005-06-21 16:47]
R0 FO_PAnt;FotoOffice VirtualDisc Driver;C:\WINDOWS\System32\Drivers\FO_PAnt.sys [2003-07-17 13:56]
R2 ABBYY.Licensing.FineReader.Professional.9.0;Usługa licencjonowania programu ABBYY FineReader 9.0;D:\Program\NetworkLicenseServer.exe [2007-09-24 16:11]
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-17 12:33:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 13:39:59
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-20 13:40:19
ComboFix-quarantined-files.txt 2008-04-20 11:40:17
Pre-Run: 12,260,392,960 bajtów wolnych
Post-Run: 12,251,664,384 bajtów wolnych
114
log z HijackThis...............
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:46:30, on 2008-04-20
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\NEOSTR~1\CnxMon.exe
C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\upds.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Program\NetworkLicenseServer.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\windows\system\scvhost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRA~1\NEOSTR~1\NeostradaTP.exe
C:\PROGRA~1\NEOSTR~1\ComComp.exe
C:\PROGRA~1\NEOSTR~1\Watch.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL
R3 - URLSearchHook: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
R3 - URLSearchHook: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: XBTP01621 Class - {F6104497-54FD-4688-9162-5115CC8AB0FB} - C:\PROGRA~1\BEARSH~1\BEARSH~2\MediaBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare applications\BearShare MediaBar\MediaBar.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\NEOSTR~1\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\NEOSTR~1\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\NEOSTR~1\TaskbarIcon.exe
O4 - HKLM\..\Run: [System32NELM Agent] C:\WINDOWS\System32NELM.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Client Server Runtime Process] C:\WINDOWS\System32\csrs.exe
O4 - HKLM\..\Run: [Windows System Update Tools] upds.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunServices: [Windows System Update Tools] upds.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Gadu-Gadu] "D:\Gadu-Gadu\gg.exe" /tray
O4 - HKCU\..\Run: [scvhost] c:\windows\system\scvhost.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA LOKALNA')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'USŁUGA SIECIOWA')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{C0C55FA4-AC93-424A-A0BB-C617C20014F7}: NameServer = 194.204.159.1 217.98.63.164
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Usługa licencjonowania programu ABBYY FineReader 9.0 (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - D:\Program\NetworkLicenseServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
--
End of file - 6404 bytes
PS: tibia do usuniecia