witam ponownie
pozwole sobie z racji weekendu odswiezyc temat
troche zeby bylo jasniej wkleje wam poprostu moj problem
moze cos to ulatwi
mam łącze dzielone na 1 stacionarny komputer i laptop poprzez router dir 300 dlink
na stacionarnym jest xp i wszystko dziala
pod laptopem pracuje vista (format nie wchodzi w gre poniewaz nie mam tutaj orginalnych plyt do niego )
i otóż ta vistavio powoduje dziwna sytulacjęłączy bowiem mnie z internetem tylko przez IE oraz gg i aplikacje typu komunikatory wszlakiej masci
mozilla mówi że nie ma połączenia z siecia
googlechrome przy probie instalacji tez tak twierdzi
tak samo jak DC i inne programy chcace sie polaczyc z siecia
aktualizacje do visty sa sciagniete kasperski online nie wykrywa wirow
zaraz zapodam logi z combofixa
prosze o jakies sugestje jak by sobie z tym poradzic
logi:
Kod: Zaznacz cały
((((((((((((((((((((((((( Pliki utworzone od 2008-10-22 do 2008-11-22 )))))))))))))))))))))))))))))))
.
Nie utworzono żadnych nowych plików w tym okresie
.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-22 14:08 --------- d-----w c:\programdata\Google Updater
2008-11-20 01:18 --------- d-----w c:\programdata\Microsoft Help
2008-11-20 01:11 --------- d-----w c:\users\bernadettka84\AppData\Roaming\BitTorrent
2008-11-19 23:15 --------- d-----w c:\program files\Google
2008-11-19 23:00 --------- d-----w c:\program files\CONEXANT
2008-11-19 00:43 262,144 ----a-w C:\ntuser.dat
2008-11-19 00:36 --------- d-----w c:\programdata\Symantec
2008-11-17 21:23 --------- d-----w c:\program files\Real
2008-11-17 21:23 --------- d-----w c:\program files\Common Files\xing shared
2008-11-17 21:23 --------- d-----w c:\program files\Common Files\Real
2008-11-17 20:49 --------- d-----w c:\users\bernadettka84\AppData\Roaming\BESTplayer
2008-11-17 19:37 --------- d-----w c:\users\bernadettka84\AppData\Roaming\Media Player Classic
2008-11-17 11:36 --------- d-----w c:\program files\Alwil Software
2008-11-17 10:14 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-17 10:12 --------- d-----w c:\users\bernadettka84\AppData\Roaming\InstallShield
2008-11-17 01:00 --------- d-----w c:\program files\ToniArts
2008-11-17 00:59 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-17 00:36 --------- d-----w c:\programdata\Hagel Technologies
2008-11-17 00:36 --------- d-----w c:\program files\DU Meter
2008-11-16 23:11 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-16 21:59 --------- d-----w c:\users\bernadettka84\AppData\Roaming\Skype
2008-11-16 21:12 --------- d-----w c:\users\bernadettka84\AppData\Roaming\skypePM
2008-11-16 15:17 --------- d-----w c:\program files\Cossacks
2008-11-16 14:02 --------- d-----w c:\program files\Ubisoft
2008-11-15 16:48 --------- d-----w c:\users\bernadettka84\AppData\Roaming\PeerNetworking
2008-11-15 00:44 --------- d-----w c:\users\bernadettka84\AppData\Roaming\InterVideo
2008-11-15 00:21 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-15 00:03 --------- d-----w c:\programdata\Kaspersky Lab Setup Files
2008-11-09 23:54 --------- d-----w c:\program files\Binboy
2008-11-09 22:21 --------- d-----w c:\program files\Symcom
2008-11-09 20:16 --------- d-----w c:\users\bernadettka84\AppData\Roaming\GHISLER
2008-11-09 17:24 --------- d-----w c:\users\bernadettka84\AppData\Roaming\mojosoft
2008-11-09 17:24 --------- d-----w c:\program files\MOJOSOFT
2008-11-05 21:47 --------- d-----w c:\program files\Common Files\Adobe
2008-11-04 02:37 410,624 ----a-w c:\windows\System32\XAudio32.dll
2008-11-04 02:32 8,704 ----a-w c:\windows\system32\drivers\XAudio32.sys
2008-11-03 13:39 --------- d-----w c:\users\bernadettka84\AppData\Roaming\HP
2008-11-03 13:39 --------- d-----w c:\programdata\HP
2008-11-03 13:39 --------- d-----w c:\programdata\Hewlett-Packard
2008-10-29 21:32 --------- d-----w c:\program files\SkanerOnline
2008-10-29 20:35 --------- d-----w c:\program files\BitTorrent
2008-10-27 21:39 --------- d-----w c:\program files\Digital Image Recovery
2008-10-27 20:49 --------- d-----w c:\program files\Windows Calendar
2008-10-27 09:38 95,056 ----a-w c:\users\bernadettka84\DSETUP.dll
2008-10-27 09:37 1,692,496 ----a-w c:\users\bernadettka84\dsetup32.dll
2008-10-27 09:36 526,160 ----a-w c:\users\bernadettka84\DXSETUP.exe
2008-10-26 14:55 --------- d-----w c:\program files\MSXML 4.0
2008-10-26 11:24 --------- d-----w c:\program files\MSBuild
2008-10-26 11:24 --------- d-----w c:\program files\Microsoft Works
2008-10-26 11:21 --------- d-----w c:\program files\Microsoft.NET
2008-10-26 11:16 --------- d-----w c:\program files\Microsoft Visual Studio 8
2008-10-26 08:12 --------- d-----w c:\program files\Common Files\Ahead
2008-10-26 08:09 --------- d-----w c:\programdata\Nero
2008-10-26 08:09 --------- d-----w c:\program files\Nero
2008-10-26 07:56 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-10-26 07:56 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-10-26 07:56 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-10-25 17:21 268,800 ----a-w c:\windows\System32\es.dll
2008-10-25 16:15 56 ---ha-w c:\users\All Users\ezsidmv.dat
2008-10-25 16:15 56 ---ha-w c:\programdata\ezsidmv.dat
2008-10-25 16:14 --------- d-----w c:\programdata\Skype
2008-10-25 16:14 --------- d-----w c:\program files\Skype
2008-10-25 16:14 --------- d-----w c:\program files\Common Files\Skype
2008-10-25 09:16 --------- d-----w c:\program files\Java
2008-10-24 19:15 174 --sha-w c:\program files\desktop.ini
2008-10-24 19:11 --------- d-----w c:\program files\Windows Mail
2008-10-24 19:11 --------- d-----w c:\program files\Windows Defender
2008-10-24 19:10 --------- d-----w c:\program files\Windows Sidebar
2008-10-24 19:05 61,440 ----a-w c:\windows\System32\winipsec.dll
2008-10-24 19:05 361,984 ----a-w c:\windows\System32\IPSECSVC.DLL
2008-10-24 19:05 28,672 ----a-w c:\windows\System32\FwRemoteSvr.dll
2008-10-24 19:05 272,896 ----a-w c:\windows\System32\polstore.dll
2008-10-24 19:04 537,600 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-10-24 19:04 449,536 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-10-24 19:04 4,247,552 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-24 19:04 28,160 ----a-w c:\windows\System32\Apphlpdm.dll
2008-10-24 19:04 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-24 19:04 2,144,256 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-10-24 19:04 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-24 19:04 1,686,528 ----a-w c:\windows\System32\gameux.dll
2008-10-24 19:03 87,040 ----a-w c:\windows\System32\msoert2.dll
2008-10-24 19:03 39,424 ----a-w c:\windows\System32\ACCTRES.dll
2008-10-24 19:03 205,824 ----a-w c:\windows\System32\msoeacct.dll
2008-10-24 19:00 49,664 ----a-w c:\windows\System32\csrsrv.dll
2008-10-24 19:00 376,320 ----a-w c:\windows\System32\winsrv.dll
2008-10-24 18:55 1,060,920 ----a-w c:\windows\system32\drivers\ntfs.sys
2008-10-24 18:54 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-24 18:53 374,456 ----a-w c:\windows\System32\mcupdate_GenuineIntel.dll
2008-10-24 18:53 303,616 ----a-w c:\windows\System32\wmpeffects.dll
2008-10-24 18:52 414,208 ----a-w c:\windows\System32\msscp.dll
2008-10-24 18:52 2,027,520 ----a-w c:\windows\System32\win32k.sys
2008-10-24 18:51 8,147,968 ----a-w c:\windows\System32\wmploc.DLL
2008-10-24 18:51 7,680 ----a-w c:\windows\System32\spwmp.dll
2008-10-24 18:51 4,096 ----a-w c:\windows\System32\dxmasf.dll
2008-10-24 18:51 356,864 ----a-w c:\windows\System32\MediaMetadataHandler.dll
2008-10-24 18:50 86,016 ----a-w c:\windows\System32\icfupgd.dll
2008-10-24 18:50 63,488 ----a-w c:\windows\system32\drivers\mpsdrv.sys
2008-10-24 18:50 61,952 ----a-w c:\windows\System32\cmifw.dll
2008-10-24 18:50 396,800 ----a-w c:\windows\System32\MPSSVC.dll
2008-10-24 18:50 392,192 ----a-w c:\windows\System32\FirewallAPI.dll
.
((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-10-24 1232896]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-20 39408]
"DU Meter"="c:\program files\DU Meter\DUMeter.exe" [2008-06-09 2645528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2828990388-3076444081-2392421145-1000]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{15E2DE79-6DC7-47B8-A104-0DEF5C43C6C7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{D222E873-DEBF-47CE-A80B-249A08787E11}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{DF366921-53EE-49EB-B911-4266334CEA93}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{65795FDB-92CE-43F4-8F79-FE7E498E3467}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{F7D179EE-8204-453A-A2E3-19F2D90658A1}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C4C4CA64-8416-4B19-AC94-EB5AE0AD69EC}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{312E7AEC-5E9E-4D18-933B-B8C402BC05FC}"= UDP:d:\warrock\WRLauncher.exe:Launch WRLauncher.exe
"{C36BEFB2-BA55-4D43-AAEE-F86AEE21D31A}"= TCP:d:\warrock\WRLauncher.exe:Launch WRLauncher.exe
"{BBBCAC9E-33CA-4884-BA73-B55FCBCD7FD5}"= UDP:d:\warrock\WRUpdater.exe:Launch WRUpdater.exe
"{8B150CDE-026C-44A9-998F-1ADEF06BC32A}"= TCP:d:\warrock\WRUpdater.exe:Launch WRUpdater.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
"DisabledInterfaces"= {3E0A3671-BE92-4E6A-AD71-D451C0F3B3EF},{89E42E5B-906D-4DB1-9025-E2028FB50C93}
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20081112.002\IDSvix86.sys [2008-11-15 270384]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R2 DUMeterSvc;DU Meter Service;c:\program files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService [2008-11-17 1386008]
R2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe -k HsfXAudioService [2006-11-02 22016]
R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;c:\windows\system32\DRIVERS\fetnd6v.sys [2008-09-22 43520]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-10-03 37936]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HsfXAudioService REG_MULTI_SZ HsfXAudioService
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{970c892c-a717-11dd-aca1-00140b349440}]
\shell\AutoRun\command - F:\setupSNK.exe
*Newly Created Service* - PROCEXP90
.
- - - - USUNIĘTO PUSTE WPISY - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Skan uzupełniający -------
.
FireFox -: Profile - c:\users\bernadettka84\AppData\Roaming\Mozilla\Firefox\Profiles\j7d4h3zv.default\
FF -: plugin - c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [url="http://www.gmer.net"]http://www.gmer.net[/url]
Rootkit scan 2008-11-22 15:46:24
Windows 6.0.6000 NTFS
skanowanie ukrytych procesów ...
skanowanie ukrytych wpisów autostartu ...
skanowanie ukrytych plików ...
skanowanie pomyślnie ukończone
ukryte pliki: 0
**************************************************************************
.
Czas ukończenia: 2008-11-22 15:47:43
ComboFix-quarantined-files.txt 2008-11-22 14:47:38
Przed: System nie może znaleźć komunikatu dla numeru komunikatu 0x2379 w pliku komunikatów dla Application.
Po: 23,728,283,648 bajtów wolnych
200 --- E O F --- 2008-11-20 23:33:18