Microfoft Visual C++ Runtime Library
Mam pytanie dziś załączając sopcast wyskoczył mi taki komunikat:
Microfoft Visual C++ Runtime Library
Runtime Error!
Program:C:\Program Files\SopCast\SopCast.exe
This application has requsted the Runtime to terminale it in an unusual way.
Niby program mi działa ,jak tej wiadomości nie zamknę ale o co z tym chodzi.Przedtem tego nie miałem..?Coś mi wywaliło w systemie........?
Odpowiedzi: 3
Poza C:\WINDOWS\system32\3A41439FC3.sys i C:\Program Files\SexKamery.info nic nie widac.
Próbowałes przeinstalowac soft ??
Temat do programów przenosze.
oto log z combofix
[quote]ComboFix 07-12-09.1 - artur 2007-12-10 22:29:53.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.652 [GMT 1:00]
Running from: C:\Documents and Settings\artur\Pulpit\etype\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-11-10 to 2007-12-10 )))))))))))))))))))))))))))))))
.
2007-12-10 22:24 . 2007-12-10 22:24 d-------- C:\Program Files\Eurobarre
2007-12-09 18:42 . 2007-12-09 18:43 d-------- C:\Program Files\SopCast
2007-12-09 18:14 . 2007-12-09 18:14 d-------- C:\Documents and Settings\artur\Dane aplikacji\SopCast
2007-12-09 00:41 . 2007-12-09 00:41 d-------- C:\Program Files\Alcohol Soft
2007-12-09 00:07 . 2007-12-09 00:07 d-------- C:\Program Files\illusion
2007-12-02 19:20 . 2007-12-02 19:21 371,536 --a------ C:\mecz.amv
2007-12-02 13:33 . 2007-12-02 14:25 d-------- C:\Program Files\Guitar FX BOX 2.6
2007-11-28 20:06 . 2007-11-28 20:06 15,872 --------- C:\WINDOWS\system32\winskfr.dll
2007-11-25 11:56 . 2007-11-15 18:46 87,352 --a------ C:\WINDOWS\system32\LMIinit.dll
2007-11-25 11:56 . 2007-11-15 18:46 83,288 --a------ C:\WINDOWS\system32\LMIRfsClientNP.dll
2007-11-25 11:56 . 2007-08-03 15:09 46,112 --a------ C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2007-11-25 11:56 . 2007-11-15 18:46 21,496 --a------ C:\WINDOWS\system32\LMIport.dll
2007-11-25 11:56 . 2007-11-25 11:56 1,024 --a------ C:\.rnd
2007-11-22 18:50 . 2007-11-22 18:50 d-------- C:\Program Files\MP3 Player Utilities 4.09
2007-11-17 19:59 . 2007-11-17 19:59 d-------- C:\WINDOWS\Lhsp
2007-11-17 15:58 . 2007-11-17 16:07 1,011 --a------ C:\WINDOWS\vampire.ini
2007-11-15 18:46 . 2007-11-15 18:46 23,736 --a------ C:\WINDOWS\system32\lmimirr.dll
2007-11-15 18:46 . 2007-11-15 18:46 10,040 --a------ C:\WINDOWS\system32\lmimirr2.dll
2007-11-14 23:18 . 2007-11-14 23:18 d-------- C:\Program Files\SlySoft
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-10 17:14 --------- d-----w C:\Program Files\NAPI-PROJEKT
2007-12-10 17:09 --------- d-----w C:\Program Files\English Translator 3
2007-12-10 16:33 --------- d-----w C:\Program Files\AntiVir PersonalEdition Premium
2007-12-08 23:34 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-12-04 02:12 --------- d-----w C:\Program Files\Total Video Converter
2007-11-30 17:18 --------- d-----w C:\Program Files\8BallClub
2007-11-19 05:16 --------- d-----w C:\Program Files\Java
2007-11-18 12:17 --------- d-----w C:\Program Files\Winamp
2007-11-14 23:20 --------- d-----w C:\Program Files\eMule
2007-11-02 22:48 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-02 22:48 --------- d-----w C:\Program Files\SexKamery.info
2007-11-02 18:27 --------- d-----w C:\Program Files\ReflexiveArcade
2007-11-02 17:31 --------- d-----w C:\Program Files\Kliper
2007-11-01 16:00 --------- d-----w C:\Documents and Settings\artur\Dane aplikacji\Skype
2007-11-01 15:59 --------- d-----w C:\Program Files\Skype
2007-11-01 15:59 --------- d-----w C:\Program Files\Common Files\Skype
2007-11-01 15:59 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Skype
2007-11-01 09:22 --------- d-----w C:\Program Files\Globe Software
2007-10-21 19:04 --------- d-----w C:\Program Files\Opera
2007-10-21 18:01 --------- d-----w C:\Documents and Settings\artur\Dane aplikacji\BitTorrent DNA
2007-10-21 17:54 --------- d-----w C:\Documents and Settings\artur\Dane aplikacji\BitTorrent
2007-10-21 13:11 --------- d-----w C:\Program Files\Game Over in Machinimation
2007-10-21 12:26 --------- d-----w C:\Documents and Settings\artur\Dane aplikacji\Armagetron
2007-10-21 12:25 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Armagetron
2007-10-20 16:16 --------- d-----w C:\Program Files\Registry Shower 2007
2007-10-14 22:51 --------- d---a-w C:\Documents and Settings\All Users\Dane aplikacji\TEMP
2007-10-05 20:02 1,243,680 ----a-w C:\WINDOWS\system32\AutoPartNt.exe
2007-10-03 22:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
2007-09-13 21:09 138,220 ----a-w C:\Documents and Settings\All Users\Dane aplikacji\firstlsp.reg.dat
2006-10-09 19:03 81,920 ----a-w C:\Documents and Settings\artur\Dane aplikacji\ezpinst.exe
2006-10-09 19:03 47,360 ----a-w C:\Documents and Settings\artur\Dane aplikacji\pcouffin.sys
2006-06-17 16:43 323,048 --sha-r C:\Program Files\serial.tde
2006-05-28 15:46 397,306 --sha-r C:\Program Files\wunauclt.zip
2006-05-28 15:46 397,306 --sha-r C:\Program Files\wunauclt.tbe
2006-05-28 13:45 115,459 --sha-r C:\Program Files\andame.zip
2006-05-28 13:45 115,459 --sha-r C:\Program Files\andame.tde
2003-12-22 15:51 777 ----a-w C:\Program Files\trial_setup.ini
2003-12-22 15:51 40,448 ----a-w C:\Program Files\trial_setup.exe
2003-12-22 15:51 4,297,728 ----a-w C:\Program Files\trial_setup.msi
2002-08-27 09:41 75,536 ----a-w C:\Program Files\viewsonicinstruct_xp.pdf
2007-08-05 07:52 88 --sh--r C:\WINDOWS\system32\3A41439FC3.sys
2005-07-14 10:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
2005-06-26 13:32 616,448 --sha-r C:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
2007-08-05 07:52 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2005-09-10 20:28 845,312 --sha-r C:\WINDOWS\system32\Smab.dll
2005-02-28 11:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C2B76CD-BF26-BEAC-7BE6-B09EF1675FCA}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD0646C8-9212-8A9C-56D4-85B3C85572FD}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 00:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:44]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2007-07-02 11:27]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]
"Ad-watch"="C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe" [2003-01-27 04:15]
"Ad-aware"="C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" [2003-01-27 09:42]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-05-06 12:13]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-03 23:44 C:\WINDOWS\system32\rundll32.exe]
"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-09-28 12:16]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-10-11 11:45]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54]
"nwiz"="nwiz.exe" [2005-12-10 03:06 C:\WINDOWS\system32\nwiz.exe]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe" [2007-10-10 19:19]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 14:47]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:44]
C:\Documents and Settings\All Users\Menu Start\Programy\AutostartMicrosoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 19:05:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
LMIinit.dll 2007-11-15 18:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioHQ]
1998-07-16 00:00 191488 --a------ C:\Program Files\Creative\SBLive\AudioHQ\AHQTB.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-03-14 18:05 257088 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odkurzacz-MCD]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tppoll]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
R2 AntiVirMailService;AntiVir PersonalEdition Premium MailGuard;"C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe"
R2 AVEService;AntiVir PersonalEdition Premium MailGuard helper service;"C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe"
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
R3 lmimirr;lmimirr;C:\WINDOWS\system32\DRIVERS\lmimirr.sys
S2 LMIInfo;LogMeIn Kernel Information Provider;\??\C:\Program Files\LogMeIn\x86\RaInfo.sys
S3 DCamUSBIntel;USB Video Camera;C:\WINDOWS\system32\Drivers\TP6800.sys
S3 usbscan;Sterownik skanera USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\StartSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\StartSetup.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 07:13:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\DOCUME~1\artur\USTAWI~1\Temp\ppesohjnP.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-10 22:32:30
Windows 5.1.2600 Dodatek Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-10 22:33:43
.
--- E O F ---
[/quote]
Czy to czasem nie jest to barachło przez którego drzwiami i oknami syf sie pcha ??
Pokaz loga Combofixa ....
Strona 1 / 1