WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
Helo,how are u! heres the systemlook:


SystemLook v1.0 by jpshortstuff (29.08.09)
Log created at 21:24 on 16/12/2009 by Grzesiek (Administrator - Elevation successful)

========== filefind ==========

Searching for "atapi.sys"
C:\Windows\ERDNT\cache\atapi.sys --a--- 19944 bytes [17:37 11/12/2009] [06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys --a--- 19944 bytes [19:51 20/10/2009] [06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys --a--- 19048 bytes [10:25 02/11/2006] [09:49 02/11/2006] 4F4FCB8B6EA06784FB6D475B7EC7300F
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys --a--- 21560 bytes [12:00 02/10/2008] [21:41 18/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\System32\drivers\atapi.sys --a--- 19944 bytes [19:51 20/10/2009] [06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys --a--- 21560 bytes [12:00 02/10/2008] [21:41 18/01/2008] 2D9C903DC76A66813D350A562DE40ED9
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys --a--- 19944 bytes [19:51 20/10/2009] [06:32 11/04/2009] 1F05B78AB91C9075565A9D8A4B880BC4

-=End Of File=-

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
Hello.
Do you have your Vista repair disc in case something goes wrong?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
win32:fake alert fc now malware please help! - Page 1 DXwU4
win32:fake alert fc now malware please help! - Page 1 VvYDg

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
yes i do,do u think its going to go wrong? Smile...

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz

  • Download combofix from here
    Link 1

1. If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

2. During the download, rename Combofix to svchost as follows:

win32:fake alert fc now malware please help! - Page 1 CF_download_FF

win32:fake alert fc now malware please help! - Page 1 2aflf5z

3. It is important you rename Combofix during the download, but not after.
4. Please do not rename Combofix to other names, but only to the one indicated.
5. Close any open browsers.
6. We need to disable your local AV (Anti-virus) before running Combofix.

  • See HERE for how to disable your AV.
  • Double click on svchost.exe.
  • Follow the prompts. NOTE:
  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouse click combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
win32:fake alert fc now malware please help! - Page 1 DXwU4
win32:fake alert fc now malware please help! - Page 1 VvYDg

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
ComboFix 09-12-16.05 - Grzesiek 2009-12-17 20:59:11.5.2 - x86
Microsoft®️ Windows Vista™️ Home Basic 6.0.6002.2.1250.48.1045.18.2047.944 [GMT 1:00]
Uruchomiony z: c:\users\Grzesiek\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Pliki utworzone od 2009-11-17 do 2009-12-17 )))))))))))))))))))))))))))))))
.

2009-12-17 20:07 . 2009-12-17 20:08 -------- d-----w- c:\users\Grzesiek\AppData\Local\temp
2009-12-17 20:07 . 2009-12-17 20:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-17 20:07 . 2009-12-17 20:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-13 08:46 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-10 06:57 . 2009-11-03 19:41 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-10 06:57 . 2009-11-03 21:43 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-10 06:57 . 2009-11-03 21:42 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-10 06:56 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-08 18:39 . 2009-12-08 18:39 -------- d-----w- c:\program files\PlayReady
2009-12-08 15:40 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-12-08 15:40 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-12-08 15:40 . 2008-11-06 16:37 3596288 ----a-w- c:\windows\system32\qt-dx331.dll
2009-12-08 15:40 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-12-08 15:40 . 2009-07-14 00:15 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-12-08 15:40 . 2009-07-14 00:15 685056 ----a-w- c:\windows\system32\divx.dll
2009-12-08 15:40 . 2009-11-09 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-12-08 15:26 . 2009-06-11 21:52 892928 ----a-w- c:\windows\system32\iconv.dll
2009-12-08 14:14 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-12-08 13:37 . 2009-12-08 13:40 -------- d-----w- c:\program files\VistaCodecPack
2009-12-08 13:36 . 2009-12-08 13:40 -------- d-----w- c:\programdata\VistaCodecs
2009-12-08 11:57 . 2009-12-08 11:57 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-08 11:57 . 2009-12-08 12:01 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\Winamp
2009-12-08 11:57 . 2009-12-08 11:57 -------- d-----w- c:\program files\Winamp
2009-12-07 20:35 . 2009-12-07 20:35 258048 ----a-w- c:\windows\system32\libFLAC.dll
2009-12-07 20:33 . 2009-12-07 20:33 75264 ----a-w- c:\programdata\ALLPlayer\LIVE\APE\MACDec.dll
2009-12-07 20:32 . 2009-12-07 20:32 108032 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\avi.dll
2009-12-07 20:32 . 2009-12-07 20:32 246784 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\dxr.dll
2009-12-07 20:32 . 2009-12-07 20:32 141312 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\mp4.dll
2009-12-07 20:32 . 2009-12-07 20:32 148480 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\mkx.dll
2009-12-07 20:32 . 2009-12-07 20:32 159744 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\mmfinfo.dll
2009-12-07 20:31 . 2009-12-07 20:31 120832 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\ogm.dll
2009-12-07 20:31 . 2009-12-07 20:31 163840 ----a-w- c:\programdata\ALLPlayer\LIVE\HAALI\ts.dll
2009-12-07 20:31 . 2009-12-07 20:31 79360 ----a-w- c:\windows\system32\mkzlib.dll
2009-12-07 20:31 . 2009-12-07 20:31 23552 ----a-w- c:\windows\system32\mkunicode.dll
2009-12-07 20:29 . 2009-12-07 20:29 1410004 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ffmpegmt.dll
2009-12-07 20:28 . 2009-12-07 20:28 557003 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\libmplayer.dll
2009-12-07 20:28 . 2009-12-07 20:28 146098 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\libmpeg2_ff.dll
2009-12-07 20:28 . 2009-12-07 20:28 4455865 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\libavcodec.dll
2009-12-07 20:26 . 2009-12-07 20:26 98304 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_wmv9.dll
2009-12-07 20:26 . 2009-12-07 20:26 113152 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_unrar.dll
2009-12-07 20:26 . 2009-12-07 20:26 183296 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_samplerate.dll
2009-12-07 20:26 . 2009-12-07 20:26 178688 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_libmad.dll
2009-12-07 20:26 . 2009-12-07 20:26 484864 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_libfaad2.dll
2009-12-07 20:26 . 2009-12-07 20:26 257024 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_libdts.dll
2009-12-07 20:26 . 2009-12-07 20:26 142848 ----a-w- c:\programdata\ALLPlayer\LIVE\FFDSHOW\ff_liba52.dll
2009-12-07 20:26 . 2009-12-07 20:26 2041363 ----a-w- c:\programdata\ALLPlayer\LIVE\X264\x264vfw.dll
2009-12-07 20:25 . 2009-12-07 20:25 237568 ----a-w- c:\programdata\ALLPlayer\LIVE\OGG\OggDS.dll
2009-12-07 20:25 . 2009-12-07 20:25 921600 ----a-w- c:\programdata\ALLPlayer\LIVE\OGG\vorbisenc.dll
2009-12-07 20:24 . 2009-12-07 20:24 188416 ----a-w- c:\programdata\ALLPlayer\LIVE\OGG\vorbis.dll
2009-12-07 20:24 . 2009-12-07 20:24 45056 ----a-w- c:\programdata\ALLPlayer\LIVE\OGG\ogg.dll
2009-12-07 20:24 . 2009-12-07 20:24 245760 ----a-w- c:\programdata\ALLPlayer\LIVE\MPEG2\mplvpx.dll
2009-12-07 20:24 . 2009-12-07 20:24 9216 ----a-w- c:\programdata\ALLPlayer\LIVE\MPEG2\cpuinf32.dll
2009-12-07 20:24 . 2009-12-07 20:24 5064836 ----a-w- c:\programdata\ALLPlayer\temp\ra.exe
2009-12-07 20:14 . 2009-06-11 21:52 892928 ----a-w- c:\programdata\ALLPlayer\LIVE\DOLBY\iconv.dll
2009-12-07 20:14 . 2009-05-29 21:31 881664 ----a-w- c:\programdata\ALLPlayer\LIVE\XVID\xvidcore.dll
2009-12-07 20:14 . 2008-04-14 21:50 1291776 ----a-w- c:\programdata\ALLPlayer\LIVE\QUARTZ\quartzXP.dll
2009-12-07 20:14 . 2009-12-08 15:26 -------- d-----w- c:\programdata\ALLPlayer
2009-12-07 20:14 . 2008-11-13 03:25 740442 ----a-w- c:\programdata\ALLPlayer\LIVE\DIVX\DivX.dll
2009-11-30 16:14 . 2009-11-30 16:18 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
2009-11-30 16:14 . 2006-07-24 15:05 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2009-11-26 08:51 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 08:19 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 08:19 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-24 13:59 . 2009-11-24 13:59 -------- d-----w- c:\program files\TomTom International B.V
2009-11-22 08:39 . 2009-12-03 13:02 -------- d-----w- C:\zdjecia
2009-11-19 17:41 . 2009-11-19 17:41 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\Gearbox Software
2009-11-19 17:36 . 2009-11-19 17:36 -------- d-----w- c:\program files\Ubisoft
2009-11-19 17:14 . 2009-11-19 17:14 -------- d-----w- c:\program files\EA GAMES
2009-11-18 13:14 . 2009-11-18 13:14 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 08:57 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-18 08:57 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-11-18 08:57 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-11-18 08:55 . 2009-10-01 01:01 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-11-18 08:55 . 2009-10-01 01:01 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-11-18 08:55 . 2009-10-01 01:01 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-11-18 08:55 . 2009-10-01 01:01 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-11-18 08:55 . 2009-10-01 01:02 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-11-18 08:55 . 2009-10-01 01:01 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-11-18 08:55 . 2009-10-01 01:02 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-11-18 08:55 . 2009-10-01 01:02 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-11-18 08:55 . 2009-10-01 01:01 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-11-18 08:55 . 2009-10-01 01:01 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-11-18 08:55 . 2009-10-01 01:01 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-11-18 08:55 . 2009-10-01 01:01 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-11-18 08:55 . 2009-10-01 01:01 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-11-18 08:52 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-11-18 08:52 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-18 08:52 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll

.
(((((((((((((((((((((((((((((((((((((((( Sekcja Find3M ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-17 19:45 . 2009-10-02 19:49 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\ipla
2009-12-14 20:23 . 2009-11-11 19:18 -------- d-----w- c:\program files\BitComet
2009-12-13 08:46 . 2009-12-11 18:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-12 08:57 . 2009-12-12 08:13 -------- d-----w- c:\program files\Enigma Software Group
2009-12-12 08:42 . 2009-11-05 13:54 -------- d-----w- c:\program files\CasinoOnNet
2009-12-11 18:30 . 2009-12-11 18:30 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\Malwarebytes
2009-12-11 18:30 . 2009-12-11 18:30 -------- d-----w- c:\programdata\Malwarebytes
2009-12-10 10:42 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-10 09:59 . 2008-10-02 10:44 -------- d-----w- c:\programdata\Microsoft Help
2009-12-10 06:52 . 2009-11-01 09:13 -------- d-----w- c:\programdata\OpenFM
2009-12-09 08:22 . 2008-10-01 14:41 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-08 18:39 . 2009-10-02 19:49 -------- d-----w- c:\programdata\ipla
2009-12-08 18:37 . 2009-10-02 19:49 -------- d-----w- c:\program files\ipla
2009-12-08 15:41 . 2008-12-29 18:14 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-12-08 15:26 . 2008-12-29 18:38 -------- d-----w- c:\program files\ALLPlayer
2009-12-08 15:08 . 2009-01-01 17:08 -------- d-----w- c:\programdata\WinZip
2009-12-08 15:07 . 2009-11-15 13:07 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-12-08 15:06 . 2008-12-29 18:38 -------- d-----w- c:\program files\NAPI-PROJEKT
2009-12-08 13:37 . 2008-12-29 18:35 -------- d-----w- c:\program files\Real Alternative
2009-12-03 15:13 . 2009-12-13 08:46 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-03 13:03 . 2006-12-05 05:19 665166 ----a-w- c:\windows\system32\perfh015.dat
2009-12-03 13:03 . 2006-12-05 05:19 127958 ----a-w- c:\windows\system32\perfc015.dat
2009-11-29 13:13 . 2008-12-27 12:55 99864 ----a-w- c:\users\Grzesiek\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-29 10:29 . 2008-10-02 10:46 -------- d-----w- c:\program files\Microsoft Works
2009-11-24 23:54 . 2009-12-12 12:49 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:50 . 2009-12-12 12:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-12-12 12:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-12-12 12:49 53328 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2009-11-24 23:49 . 2009-12-12 12:50 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-12-12 12:50 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-12-12 12:50 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-24 13:59 . 2008-12-28 10:14 -------- d-----w- c:\program files\TomTom HOME 2
2009-11-21 06:40 . 2009-12-10 06:58 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 06:58 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-10 06:58 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-10 06:58 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 13:14 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 13:14 . 2009-11-18 13:14 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 13:13 . 2009-11-18 13:13 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-15 13:14 . 2009-11-15 13:06 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\DAEMON Tools Lite
2009-11-15 13:07 . 2009-11-15 13:07 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-15 13:06 . 2009-11-15 13:06 -------- d-----w- c:\programdata\DAEMON Tools Lite
2009-11-15 12:45 . 2009-11-15 12:45 -------- d-----w- c:\program files\WinZipm
2009-11-07 19:46 . 2009-11-07 19:45 -------- d-----w- c:\programdata\SSScanAppDataDir
2009-11-07 19:46 . 2009-11-07 19:46 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\Canon
2009-11-07 19:45 . 2009-11-07 19:45 -------- d-----w- c:\programdata\MSScanAppDataDir
2009-11-02 19:42 . 2009-10-03 04:48 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 09:13 . 2009-11-01 09:13 -------- d-----w- c:\users\Grzesiek\AppData\Roaming\OpenFM
2009-11-01 09:11 . 2009-03-10 12:26 -------- d-----w- c:\program files\Nowe Gadu-Gadu
2009-10-22 14:34 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-10-22 14:34 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-10-22 14:34 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-10-22 14:34 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-22 14:34 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-10-02 19:49 . 2009-10-02 19:49 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2009-10-01 01:02 . 2009-11-18 08:56 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-18 08:56 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-18 08:56 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-09-25 02:10 . 2009-11-18 08:56 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-18 08:56 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-18 08:56 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-18 08:56 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-18 08:56 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-18 08:56 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-18 08:56 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-18 08:56 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-18 08:56 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-18 08:56 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-18 08:56 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-18 08:56 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-18 08:56 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-18 08:56 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-18 08:56 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-18 08:56 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-18 08:56 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-18 08:56 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-18 08:56 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-18 08:56 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-18 08:56 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-18 08:56 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-18 08:56 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-18 08:56 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-18 08:56 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-18 08:56 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-18 08:56 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
.

((((((((((((((((((((((((((((((((((((( Wpisy startowe rejestru ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Uwaga* puste wpisy oraz domyślne, prawidłowe wpisy nie są pokazane
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-11-13 247144]
"ALLUpdate"="c:\program files\ALLPlayer\ALLUpdate.exe" [2009-11-11 870400]
"IPLA!"="c:\program files\ipla\ipla.exe" [2009-12-08 14067096]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):0d,aa,6d,93,25,53,ca,01

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-12-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-12-12 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-12-12 53328]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [2009-11-15 691696]
S3 FontCache;Usług systemu Windows buforowania czcionek;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-10-02 21504]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
------- Skan uzupełniający -------
.
uStart Page = hxxp://www.google.pl/
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&ksport do programu Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: E&ksportuj do programu Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
FF - ProfilePath - c:\users\Grzesiek\AppData\Roaming\Mozilla\Firefox\Profiles\zipuiywz.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www2.firesearch.com/
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-17 21:07
Windows 6.0.6002 Service Pack 2 NTFS

skanowanie ukrytych procesów ...

skanowanie ukrytych wpisów autostartu ...

skanowanie ukrytych plików ...


c:\windows\TEMP\TMP000000362CE8A20D45C638DA 524288 bytes executable

skanowanie pomyślnie ukończone
ukryte pliki: 1

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x85046618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x82f9fd24
\Driver\ACPI -> acpi.sys @ 0x80694d68
\Driver\atapi -> ataport.SYS @ 0x807a3a2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK

**************************************************************************
.
--------------------- ZABLOKOWANE KLUCZE REJESTRU ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Czas ukończenia: 2009-12-17 21:10:14
ComboFix-quarantined-files.txt 2009-12-17 20:10

Przed: 86 618 968 064 bajtów wolnych
Po: 86 612 209 664 bajtów wolnych

- - End Of File - - 3200AFD5917A63075AF1F6B12EE31778

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
Hmm, still having problems?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
win32:fake alert fc now malware please help! - Page 1 DXwU4
win32:fake alert fc now malware please help! - Page 1 VvYDg

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
I didnt have any reports from avast since yesterday so its looking good.hope it will stay that way.thanks for your help and time.take care

descriptionwin32:fake alert fc now malware please help! - Page 1 EmptyRe: win32:fake alert fc now malware please help!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum