-
Проблем с rootkit [РЕШЕН]
Засега се държи много добре,но ако имам проблеми знам къде и към кого да се обърна.Здрав да си братле,благодаря много за отделеното време.Много як форум!
-
Проблем с rootkit [РЕШЕН]
Ето го .log-a All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-842925246-436374069-1177238915-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found. ADS C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13 deleted successfully. ========== FILES ========== C:\WINDOWS\000001_.tmp moved successfully. C:\WINDOWS\SET3.tmp moved successfully. C:\WINDOWS\SET4.tmp moved successfully. C:\WINDOWS\SET8.tmp moved successfully. C:\WINDOWS\System32\CONFIG.TMP moved successfully. File\Folder C:\Documents and Settings\Goran\Desktop\gmer.exe not found. File\Folder C:\Documents and Settings\Goran\Desktop\gmer.zip not found. C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite folder moved successfully. C:\Documents and Settings\Goran\Application Data\DAEMON Tools Lite\IconsCache folder moved successfully. C:\Documents and Settings\Goran\Application Data\DAEMON Tools Lite folder moved successfully. C:\Documents and Settings\Goran\Application Data\DAEMON Tools Pro folder moved successfully. C:\RECYCLER\S-1-5-21-842925246-436374069-1177238915-1003 folder moved successfully. C:\RECYCLER folder moved successfully. D:\RECYCLER\S-1-5-21-842925246-436374069-1177238915-1003 folder moved successfully. D:\RECYCLER\S-1-5-21-1935655697-1425521274-1177238915-1003 folder moved successfully. D:\RECYCLER folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Goran ->Temp folder emptied: 828574 bytes ->Temporary Internet Files folder emptied: 1425975 bytes ->Java cache emptied: 13689353 bytes ->FireFox cache emptied: 117543699 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 505 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 127,00 mb OTL by OldTimer - Version 3.1.30.1 log created on 02242010_203137 Files\Folders moved on Reboot... Registry entries deleted on Reboot...
-
Проблем с rootkit [РЕШЕН]
GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-02-23 22:22:00 Windows 5.1.2600 Service Pack 3 Running: gmer.exe; Driver: C:\DOCUME~1\Goran\LOCALS~1\Temp\pfqorfob.sys ---- System - GMER 1.0.15 ---- SSDT 86BC78A0 ZwAssignProcessToJobObject SSDT 86BC6CB0 ZwOpenProcess SSDT 86BC70D0 ZwOpenThread SSDT 86BC76D0 ZwSuspendProcess SSDT 86BC74F0 ZwSuspendThread SSDT 86BC6EE0 ZwTerminateProcess SSDT 86BC7310 ZwTerminateThread ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[120] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00] ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET) AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET) AttachedDevice \FileSystem\Fastfat \Fat eamon.sys (Amon monitor/ESET) ---- Threads - GMER 1.0.15 ---- Thread System [4:396] 86BC5930 ---- EOF - GMER 1.0.15 ---- OTL.Txt Extras.Txt
-
Проблем с rootkit [РЕШЕН]
Сканирах с НОД32-не откри нищо,но и преди понякога беше така,а после сам го засичаше и айде в карантината.Благодарности B-boy[styLe],спести ми часове пред компютъра за преинсталиране и настройки!Искам да те питам мога ли да изтрия папките и .log-те саздадени от програмите в процеса на почистване на системата ми в C:\,както и тези от работния ми плот?Нали мога да използвам и DAEMON Tools Lite отново?
-
Проблем с rootkit [РЕШЕН]
Не ми изписа,че SP3 е инсталиран.Прикачвам .log-а
-
Проблем с rootkit [РЕШЕН]
18:27:50:734 3408 TDSS rootkit removing tool 2.2.4 Feb 15 2010 19:38:31 18:27:50:734 3408 ================================================================================ 18:27:50:734 3408 SystemInfo: 18:27:50:734 3408 OS Version: 5.1.2600 ServicePack: 3.0 18:27:50:734 3408 Product type: Workstation 18:27:50:734 3408 ComputerName: GORAN-B3D59AFC2 18:27:50:734 3408 UserName: Goran 18:27:50:734 3408 Windows directory: C:\WINDOWS 18:27:50:734 3408 Processor architecture: Intel x86 18:27:50:734 3408 Number of processors: 1 18:27:50:734 3408 Page size: 0x1000 18:27:50:734 3408 Boot type: Normal boot 18:27:50:734 3408 ================================================================================ 18:27:50:750 3408 UnloadDriverW: NtUnloadDriver error 2 18:27:50:750 3408 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 18:27:50:750 3408 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000 18:27:50:843 3408 UtilityInit: KLMD drop and load success 18:27:50:843 3408 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201010) 18:27:50:843 3408 UtilityInit: KLMD open success 18:27:50:843 3408 UtilityInit: Initialize success 18:27:50:843 3408 18:27:50:843 3408 Scanning Services ... 18:27:50:843 3408 CreateRegParser: Registry parser init started 18:27:50:843 3408 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127 18:27:50:843 3408 CreateRegParser: DisableWow64Redirection error 18:27:50:843 3408 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system 18:27:50:843 3408 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\system) returned status C0000043 18:27:50:843 3408 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:27:50:843 3408 wfopen_ex: Trying to KLMD file open 18:27:50:843 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\system 18:27:50:843 3408 wfopen_ex: File opened ok (Flags 2) 18:27:50:843 3408 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\system) init success: 3A4C48 18:27:50:843 3408 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software 18:27:50:843 3408 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\config\software) returned status C0000043 18:27:50:843 3408 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 18:27:50:843 3408 wfopen_ex: Trying to KLMD file open 18:27:50:843 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\config\software 18:27:50:843 3408 wfopen_ex: File opened ok (Flags 2) 18:27:50:843 3408 CreateRegParser: HIVE_ADAPTER(C:\WINDOWS\system32\config\software) init success: 3A4CF0 18:27:50:843 3408 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127 18:27:50:843 3408 CreateRegParser: EnableWow64Redirection error 18:27:50:843 3408 CreateRegParser: RegParser init completed 18:27:51:078 3408 GetAdvancedServicesInfo: Raw services enum returned 345 services 18:27:51:078 3408 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system 18:27:51:078 3408 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software 18:27:51:078 3408 18:27:51:078 3408 Scanning Kernel memory ... 18:27:51:078 3408 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 18:27:51:078 3408 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 86770858 18:27:51:078 3408 DetectCureTDL3: KLMD_GetDeviceObjectList returned 3 DevObjects 18:27:51:078 3408 18:27:51:078 3408 DetectCureTDL3: DEVICE_OBJECT: 867649D0 18:27:51:078 3408 KLMD_GetLowerDeviceObject: Trying to get lower device object for 867649D0 18:27:51:078 3408 KLMD_ReadMem: Trying to ReadMemory 0x867649D0[0x38] 18:27:51:078 3408 DetectCureTDL3: DRIVER_OBJECT: 86770858 18:27:51:078 3408 KLMD_ReadMem: Trying to ReadMemory 0x86770858[0xA8] 18:27:51:078 3408 KLMD_ReadMem: Trying to ReadMemory 0xE15D89C8[0x18] 18:27:51:078 3408 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_CREATE : F7875BB0 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_CLOSE : F7875BB0 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_READ : F786FD1F 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_WRITE : F786FD1F 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_QUERY_EA : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SET_EA : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : F78702E2 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : F78703BB 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : F7873F28 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SHUTDOWN : F78702E2 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_CLEANUP : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_POWER : F7871C82 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : F787699E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804FA88E 18:27:51:078 3408 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804FA88E 18:27:51:078 3408 TDL3_FileDetect: Processing driver: Disk 18:27:51:078 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:078 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:093 3408 TDL3_FileDetect: Processing driver: Disk 18:27:51:093 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:093 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:093 3408 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean 18:27:51:093 3408 18:27:51:093 3408 DetectCureTDL3: DEVICE_OBJECT: 8678FC68 18:27:51:093 3408 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8678FC68 18:27:51:093 3408 KLMD_ReadMem: Trying to ReadMemory 0x8678FC68[0x38] 18:27:51:093 3408 DetectCureTDL3: DRIVER_OBJECT: 86770858 18:27:51:093 3408 KLMD_ReadMem: Trying to ReadMemory 0x86770858[0xA8] 18:27:51:093 3408 KLMD_ReadMem: Trying to ReadMemory 0xE15D89C8[0x18] 18:27:51:093 3408 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_CREATE : F7875BB0 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_CLOSE : F7875BB0 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_READ : F786FD1F 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_WRITE : F786FD1F 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_QUERY_EA : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SET_EA : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : F78702E2 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : F78703BB 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : F7873F28 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SHUTDOWN : F78702E2 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_CLEANUP : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_POWER : F7871C82 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : F787699E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804FA88E 18:27:51:093 3408 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804FA88E 18:27:51:093 3408 TDL3_FileDetect: Processing driver: Disk 18:27:51:109 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:109 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:109 3408 TDL3_FileDetect: Processing driver: Disk 18:27:51:109 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:109 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\disk.sys 18:27:51:109 3408 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean 18:27:51:109 3408 18:27:51:109 3408 DetectCureTDL3: DEVICE_OBJECT: 8672F608 18:27:51:109 3408 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8672F608 18:27:51:109 3408 DetectCureTDL3: DEVICE_OBJECT: 8672F2A0 18:27:51:109 3408 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8672F2A0 18:27:51:109 3408 DetectCureTDL3: DEVICE_OBJECT: 86768940 18:27:51:109 3408 KLMD_GetLowerDeviceObject: Trying to get lower device object for 86768940 18:27:51:109 3408 KLMD_ReadMem: Trying to ReadMemory 0x86768940[0x38] 18:27:51:109 3408 DetectCureTDL3: DRIVER_OBJECT: 8676A210 18:27:51:109 3408 KLMD_ReadMem: Trying to ReadMemory 0x8676A210[0xA8] 18:27:51:109 3408 KLMD_ReadMem: Trying to ReadMemory 0xE100F0F8[0x1A] 18:27:51:109 3408 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_CREATE : F777C6F2 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_CLOSE : F777C6F2 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_READ : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_WRITE : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_QUERY_INFORMATION : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SET_INFORMATION : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_QUERY_EA : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SET_EA : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_FLUSH_BUFFERS : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_DIRECTORY_CONTROL : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_DEVICE_CONTROL : F777C712 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_INTERNAL_DEVICE_CONTROL : F7778852 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SHUTDOWN : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_LOCK_CONTROL : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_CLEANUP : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_CREATE_MAILSLOT : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_QUERY_SECURITY : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SET_SECURITY : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_POWER : F777C73C 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SYSTEM_CONTROL : F7783336 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_DEVICE_CHANGE : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_QUERY_QUOTA : 804FA88E 18:27:51:109 3408 DetectCureTDL3: IRP_MJ_SET_QUOTA : 804FA88E 18:27:51:109 3408 TDL3_FileDetect: Processing driver: atapi 18:27:51:109 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys 18:27:51:109 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys 18:27:51:109 3408 KLMD_ReadMem: Trying to ReadMemory 0xF7779864[0x400] 18:27:51:109 3408 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0 18:27:51:109 3408 TDL3_FileDetect: Processing driver: atapi 18:27:51:109 3408 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\DRIVERS\atapi.sys 18:27:51:109 3408 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\DRIVERS\atapi.sys 18:27:51:109 3408 TDL3_FileDetect: C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean 18:27:51:109 3408 18:27:51:109 3408 Completed 18:27:51:109 3408 18:27:51:109 3408 Results: 18:27:51:125 3408 Memory objects infected / cured / cured on reboot: 0 / 0 / 0 18:27:51:125 3408 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 18:27:51:125 3408 File objects infected / cured / cured on reboot: 0 / 0 / 0 18:27:51:125 3408 18:27:51:125 3408 MyNtCreateFileW: NtCreateFile(\??\C:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000 18:27:51:125 3408 UtilityDeinit: KLMD(ARK) unloaded successfully Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xF7C31C51]<< kernel: MBR read successfully user & kernel MBR OK
-
Проблем с rootkit [РЕШЕН]
ComboFix 10-02-22.04 - Goran 02.2010 г. 17:53:06.2.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.689 [GMT 2:00] Running from: c:\documents and settings\Goran\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Goran\Desktop\CFScript.txt AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} FILE :: "c:\windows\popcinfo.dat" "c:\windows\system32\1459.tmp" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\McAfee c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\PartnerCustom\SSScheduler\SSScheduler000.log c:\program files\Sophos c:\windows\popcinfo.dat . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_MEMSWEEP2 -------\Legacy_SPTD -------\Service_sptd ((((((((((((((((((((((((( Files Created from 2010-01-23 to 2010-02-23 ))))))))))))))))))))))))))))))) . 2010-02-22 13:08 . 2009-11-12 08:11 27192 ----a-w- c:\windows\system32\drivers\rspSanity32.sys 2010-02-22 11:53 . 2010-02-22 11:53 -------- d-----w- c:\program files\ESET 2010-02-21 17:01 . 2010-02-21 17:02 -------- d-----w- c:\documents and settings\Goran\dwhelper 2010-02-18 09:41 . 2010-02-18 22:12 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Yandex 2010-02-18 09:41 . 2010-02-18 21:19 -------- d-----w- c:\documents and settings\Goran\Application Data\Yandex 2010-02-17 21:23 . 2010-02-17 21:23 -------- d-----w- c:\documents and settings\Goran\Application Data\ESET 2010-02-11 14:33 . 2010-02-11 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2010-02-11 08:39 . 2010-02-11 12:59 -------- d-----w- c:\windows\SxsCaPendDel 2010-02-10 18:34 . 2010-02-10 18:34 -------- d-----w- c:\documents and settings\Goran\Application Data\Apple Computer 2010-02-10 10:19 . 2009-11-27 17:11 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll 2010-02-10 10:19 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll 2010-02-10 10:19 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll 2010-02-09 17:34 . 2010-02-11 08:41 -------- d-----w- c:\program files\QuickTime 2010-02-09 17:34 . 2010-02-09 17:34 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Apple 2010-02-09 17:34 . 2010-02-09 17:34 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Apple Computer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-23 15:42 . 2009-11-08 17:54 -------- d-----w- c:\documents and settings\Goran\Application Data\Skype 2010-02-23 15:41 . 2009-11-08 17:54 -------- d-----w- c:\documents and settings\Goran\Application Data\skypePM 2010-02-23 15:37 . 2009-11-08 16:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-02-23 10:54 . 2009-11-08 16:04 196608 ----a-w- c:\windows\system32\drivers\aStandard.bin 2010-02-23 10:39 . 2009-11-08 18:27 -------- d-----w- c:\documents and settings\Goran\Application Data\uTorrent 2010-02-23 10:38 . 2009-11-08 18:27 -------- d-----w- c:\program files\uTorrent 2010-02-18 11:45 . 2009-11-08 16:30 -------- d-----w- c:\documents and settings\Goran\Application Data\BSplayer PRO 2010-02-17 21:22 . 2009-11-08 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2010-02-17 17:39 . 2009-11-08 17:09 -------- d-----w- c:\program files\JAM2 2010-02-17 16:16 . 2009-11-08 17:59 117760 ----a-w- c:\documents and settings\Goran\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-02-11 14:23 . 2009-11-08 17:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-11 14:23 . 2009-11-08 17:52 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2010-01-07 14:07 . 2009-11-08 17:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 14:07 . 2009-11-08 17:50 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-01-04 18:37 . 2009-11-13 07:18 -------- d-----w- c:\documents and settings\Goran\Application Data\PlayFirst 2010-01-03 16:52 . 2009-11-18 15:43 -------- d-----w- c:\documents and settings\Goran\Application Data\TeamViewer 2009-12-31 16:50 . 2008-04-14 00:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-26 10:50 . 2009-12-26 10:50 -------- d-----w- c:\program files\The Weather Channel Toolbar 2009-12-26 07:23 . 2009-12-26 07:23 -------- d-----w- c:\program files\Yahoo! 2009-12-21 19:14 . 2008-07-26 10:41 916480 ------w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2009-11-08 15:30 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2008-04-14 05:41 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27 . 2008-04-14 00:57 2189184 ------w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2008-04-13 21:01 2066048 ------w- c:\windows\system32\ntkrnlpa.exe 2009-12-04 18:22 . 2008-04-14 00:47 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2009-11-30 10:27 . 2009-12-06 11:28 123280 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2009-11-30 10:27 . 2009-12-06 11:28 41616 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2009-11-30 10:27 . 2009-11-30 10:27 133648 ------w- c:\windows\system32\VBoxNetFltNotify.dll 2009-11-30 10:27 . 2009-11-30 10:27 100048 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2009-11-27 17:11 . 2008-07-26 17:41 1291776 ----a-w- c:\windows\system32\quartz.dll 2009-11-27 17:11 . 2008-04-14 02:42 17920 ----a-w- c:\windows\system32\msyuv.dll 2009-11-27 16:07 . 2001-08-23 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll 2009-11-27 16:07 . 2001-08-17 19:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:07 . 2008-04-14 05:42 11264 ----a-w- c:\windows\system32\msrle32.dll 2009-11-27 16:07 . 2008-04-14 05:41 84992 ----a-w- c:\windows\system32\avifil32.dll 2009-11-27 16:07 . 2008-04-14 02:41 48128 ----a-w- c:\windows\system32\iyuv_32.dll . (((((((((((((((((((((((((((((((((((((((((( SR_Search )))))))))))))))))))))))))))))))))))))))))))))))))))))))) [7] 2F625D11385B1A94360BFC70AAEFDEE1 105344 c:\windows\system32\dllcache\mup.sys [7] 2F625D11385B1A94360BFC70AAEFDEE1 105344 \RP131\A0053585.sys [7] 2F625D11385B1A94360BFC70AAEFDEE1 105344 \RP153\A0055947.sys [7] 2F625D11385B1A94360BFC70AAEFDEE1 105344 c:\windows\system32\drivers\mup.sys [7] 2F625D11385B1A94360BFC70AAEFDEE1 105344 \RP127\A0052308.sys [-] 86C5EEB9F43C8F138A992F569901B57B 105344 \RP156\A0057273.sys . ------- Sigcheck ------- [-] 2008-07-26 . 6CDB0EB2C6D05ACE8C29C9B1B82C377B . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((( SnapShot@2010-02-23_08.40.37 ))))))))))))))))))))))))))))))))))))))))) . + 2010-02-23 15:57 . 2010-02-23 15:57 16384 c:\windows\temp\Perflib_Perfdata_704.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] "LClock"="c:\program files\LClock\lclock.exe" [2004-09-19 65536] "YahooWidgets"="c:\program files\Yahoo!\Widgets\YahooWidgets.exe" [2008-03-19 4742184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-08-01 16049664] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 г. 09:03 108792] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 г. 09:06 96408] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23.6.2009 г. 11:01 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23.6.2009 г. 11:01 72944] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 г. 09:04 735960] S3 FBAccess;FBAccess;\??\c:\documents and settings\Goran\Desktop\FBAccess.sys --> c:\documents and settings\Goran\Desktop\FBAccess.sys [?] S3 rspSanity;rspSanity;c:\windows\system32\drivers\rspSanity32.sys [22.2.2010 г. 15:08 27192] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23.6.2009 г. 11:01 7408] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [30.11.2009 г. 12:27 100048] S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2010-02-19 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 20:39] . . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {04077EFC-0146-4C89-859C-59F7CEE78885} = 77.71.61.1,77.71.63.225 FF - ProfilePath - c:\documents and settings\Goran\Application Data\Mozilla\Firefox\Profiles\6ngvkbw8.default\ FF - prefs.js: browser.startup.homepage - hxxp://bg.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:bg:official FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-23 17:57 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xF7C31C51]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf7873f28 \Driver\ACPI -> ACPI.sys @ 0xf77e6cb8 \Driver\atapi -> atapi.sys @ 0xf7778852 IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7685bd4 PacketIndicateHandler -> NDIS.sys @ 0xf7691a21 SendHandler -> NDIS.sys @ 0xf7685d44 user & kernel MBR OK ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(640) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(1636) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\wpdshserviceobj.dll c:\windows\system32\portabledevicetypes.dll c:\windows\system32\portabledeviceapi.dll c:\program files\LClock\LC.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\windows\ATKKBService.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\RTHDCPL.EXE c:\program files\Skype\Plugin Manager\skypePM.exe . ************************************************************************** . Completion time: 2010-02-23 17:59:48 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-23 15:59 ComboFix2.txt 2010-02-23 08:41 Pre-Run: 20 946 014 208 bytes free Post-Run: 20 836 876 288 bytes free - - End Of File - - 5E20D81237C951AEDFF1952C2D875F90
-
Проблем с rootkit [РЕШЕН]
Въобще не съм инсталирал Alcohol 120%,няма го в Control Panel => Add or remove programs.Имам инсталиран DAEMON Tools Lite 4.30.4.
-
Проблем с rootkit [РЕШЕН]
Незнам аз ли не направих нещо както трябва с ComboFix или така трябва да е,но НОД32 току що отново ми сложи в карантината същият файл???
-
Проблем с rootkit [РЕШЕН]
ComboFix 10-02-22.04 - Goran 02.2010 г. 10:37:05.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.1023.528 [GMT 2:00] Running from: c:\documents and settings\Goran\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\tmp.reg c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\WS2Fix.exe ----- BITS: Possible infected sites ----- hxxp://soft.export.yandex.ru . ((((((((((((((((((((((((( Files Created from 2010-01-23 to 2010-02-23 ))))))))))))))))))))))))))))))) . 2010-02-22 13:08 . 2009-11-12 08:11 27192 ----a-w- c:\windows\system32\drivers\rspSanity32.sys 2010-02-22 11:53 . 2010-02-22 11:53 -------- d-----w- c:\program files\ESET 2010-02-21 17:01 . 2010-02-21 17:02 -------- d-----w- c:\documents and settings\Goran\dwhelper 2010-02-18 22:12 . 2010-02-18 22:12 -------- d-----w- c:\program files\Sophos 2010-02-18 09:41 . 2010-02-18 22:12 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Yandex 2010-02-18 09:41 . 2010-02-18 21:19 -------- d-----w- c:\documents and settings\Goran\Application Data\Yandex 2010-02-17 21:23 . 2010-02-17 21:23 -------- d-----w- c:\documents and settings\Goran\Application Data\ESET 2010-02-11 14:41 . 2010-02-11 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee 2010-02-11 14:33 . 2010-02-11 14:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2010-02-11 08:39 . 2010-02-11 12:59 -------- d-----w- c:\windows\SxsCaPendDel 2010-02-10 18:34 . 2010-02-10 18:34 -------- d-----w- c:\documents and settings\Goran\Application Data\Apple Computer 2010-02-10 10:19 . 2009-11-27 17:11 17920 -c----w- c:\windows\system32\dllcache\msyuv.dll 2010-02-10 10:19 . 2009-11-27 16:07 8704 -c----w- c:\windows\system32\dllcache\tsbyuv.dll 2010-02-10 10:19 . 2009-11-27 16:07 48128 -c----w- c:\windows\system32\dllcache\iyuv_32.dll 2010-02-09 17:34 . 2010-02-11 08:41 -------- d-----w- c:\program files\QuickTime 2010-02-09 17:34 . 2010-02-09 17:34 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Apple 2010-02-09 17:34 . 2010-02-09 17:34 -------- d-----w- c:\documents and settings\Goran\Local Settings\Application Data\Apple Computer . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-23 08:29 . 2009-11-08 17:54 -------- d-----w- c:\documents and settings\Goran\Application Data\Skype 2010-02-23 08:17 . 2009-11-08 17:54 -------- d-----w- c:\documents and settings\Goran\Application Data\skypePM 2010-02-22 20:15 . 2009-11-08 16:04 196608 ----a-w- c:\windows\system32\drivers\aStandard.bin 2010-02-22 16:52 . 2009-11-09 16:14 10 ----a-w- c:\windows\popcinfo.dat 2010-02-22 13:57 . 2009-11-08 16:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-02-22 13:56 . 2009-11-08 18:27 -------- d-----w- c:\documents and settings\Goran\Application Data\uTorrent 2010-02-18 11:45 . 2009-11-08 16:30 -------- d-----w- c:\documents and settings\Goran\Application Data\BSplayer PRO 2010-02-17 21:22 . 2009-11-08 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET 2010-02-17 17:39 . 2009-11-08 17:09 -------- d-----w- c:\program files\JAM2 2010-02-17 16:16 . 2009-11-08 17:59 117760 ----a-w- c:\documents and settings\Goran\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-02-11 14:23 . 2009-11-08 17:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-02-11 14:23 . 2009-11-08 17:52 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2010-02-09 16:49 . 2009-11-08 18:27 -------- d-----w- c:\program files\uTorrent 2010-01-07 14:07 . 2009-11-08 17:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 14:07 . 2009-11-08 17:50 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-01-04 18:37 . 2009-11-13 07:18 -------- d-----w- c:\documents and settings\Goran\Application Data\PlayFirst 2010-01-03 16:52 . 2009-11-18 15:43 -------- d-----w- c:\documents and settings\Goran\Application Data\TeamViewer 2009-12-31 16:50 . 2008-04-14 00:45 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-26 10:50 . 2009-12-26 10:50 -------- d-----w- c:\program files\The Weather Channel Toolbar 2009-12-26 07:23 . 2009-12-26 07:23 -------- d-----w- c:\program files\Yahoo! 2009-12-21 19:14 . 2008-07-26 10:41 916480 ----a-w- c:\windows\system32\wininet.dll 2009-12-16 18:43 . 2009-11-08 15:30 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08 . 2008-04-14 05:41 33280 ----a-w- c:\windows\system32\csrsrv.dll 2009-12-08 19:27 . 2008-04-14 00:57 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 18:43 . 2008-04-13 21:01 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-04 18:22 . 2008-04-14 00:47 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2009-11-30 10:27 . 2009-12-06 11:28 123280 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2009-11-30 10:27 . 2009-12-06 11:28 41616 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2009-11-30 10:27 . 2009-11-30 10:27 133648 ------w- c:\windows\system32\VBoxNetFltNotify.dll 2009-11-30 10:27 . 2009-11-30 10:27 100048 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2009-11-27 17:11 . 2008-07-26 17:41 1291776 ----a-w- c:\windows\system32\quartz.dll 2009-11-27 17:11 . 2008-04-14 02:42 17920 ----a-w- c:\windows\system32\msyuv.dll 2009-11-27 16:07 . 2001-08-23 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll 2009-11-27 16:07 . 2001-08-17 19:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll 2009-11-27 16:07 . 2008-04-14 05:42 11264 ----a-w- c:\windows\system32\msrle32.dll 2009-11-27 16:07 . 2008-04-14 05:41 84992 ----a-w- c:\windows\system32\avifil32.dll 2009-11-27 16:07 . 2008-04-14 02:41 48128 ----a-w- c:\windows\system32\iyuv_32.dll . ------- Sigcheck ------- [-] 2008-07-26 . 6CDB0EB2C6D05ACE8C29C9B1B82C377B . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] "LClock"="c:\program files\LClock\lclock.exe" [2004-09-19 65536] "YahooWidgets"="c:\program files\Yahoo!\Widgets\YahooWidgets.exe" [2008-03-19 4742184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-08-01 16049664] "SkyTel"="SkyTel.EXE" [2006-05-16 2879488] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-11-16 2054360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoSecurityTab"= 1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoSecurityTab"= 1 (0x1) [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [16.11.2009 г. 09:03 108792] R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [16.11.2009 г. 09:06 96408] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23.6.2009 г. 11:01 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23.6.2009 г. 11:01 72944] R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [16.11.2009 г. 09:04 735960] S3 FBAccess;FBAccess;\??\c:\documents and settings\Goran\Desktop\FBAccess.sys --> c:\documents and settings\Goran\Desktop\FBAccess.sys [?] S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\1459.tmp --> c:\windows\system32\1459.tmp [?] S3 rspSanity;rspSanity;c:\windows\system32\drivers\rspSanity32.sys [22.2.2010 г. 15:08 27192] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23.6.2009 г. 11:01 7408] S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [30.11.2009 г. 12:27 100048] S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys --> c:\windows\system32\DRIVERS\VBoxNetFlt.sys [?] S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [08.11.2009 г. 20:16 721904] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the 'Scheduled Tasks' folder 2010-02-19 c:\windows\Tasks\1-Click Maintenance.job - c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 20:39] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yandex.ru/?clid=47355 uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {04077EFC-0146-4C89-859C-59F7CEE78885} = 77.71.61.1,77.71.63.225 FF - ProfilePath - c:\documents and settings\Goran\Application Data\Mozilla\Firefox\Profiles\6ngvkbw8.default\ FF - prefs.js: browser.startup.homepage - hxxp://bg.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:bg:official FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-23 10:40 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0xF7C31C51]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xf7873f28 \Driver\ACPI -> ACPI.sys @ 0xf77e6cb8 \Driver\atapi -> atapi.sys @ 0xf7778852 IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598 ParseProcedure -> ntoskrnl.exe @ 0x8056ea15 NDIS: Realtek RTL8139 Family PCI Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf7685bd4 PacketIndicateHandler -> NDIS.sys @ 0xf7691a21 SendHandler -> NDIS.sys @ 0xf7685d44 user & kernel MBR OK ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2] "ImagePath"="\??\c:\windows\system32\1459.tmp" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(636) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll c:\windows\system32\Ati2evxx.dll . Completion time: 2010-02-23 10:41:48 ComboFix-quarantined-files.txt 2010-02-23 08:41 Pre-Run: 21 028 741 120 bytes free Post-Run: 21 050 822 656 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - 3EA7F85C6186CF5B6750707F12F3E1EC
-
Проблем с rootkit [РЕШЕН]
Ето линка: http://rapidshare.de/files/49184961/mup.sys.html Има ли начин да махна тая гадина???Много ще съм благодарен!
-
Проблем с rootkit [РЕШЕН]
Malwarebytes' Anti-Malware 1.44 Database version: 3753 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 22.2.2010 г. 16:16:27 mbam-log-2010-02-22 (16-16-27).txt Scan type: Full Scan (C:\|) Objects scanned: 171297 Time elapsed: 17 minute(s), 58 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:21:10, on 22.2.2010 г. Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\LClock\lclock.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe C:\WINDOWS\ATKKBService.exe C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\HJT\Kaldata.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=47355 F2 - REG:system.ini: UserInit=\\.\globalroot\systemroot\system32\userinit.exe, O2 - BHO: Помощник за връзки на Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [skyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [LClock] C:\Program Files\LClock\lclock.exe O4 - HKCU\..\Run: [YahooWidgets] C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user') O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1257709920921 O17 - HKLM\System\CCS\Services\Tcpip\..\{04077EFC-0146-4C89-859C-59F7CEE78885}: NameServer = 77.71.61.1,77.71.63.225 O17 - HKLM\System\CS1\Services\Tcpip\..\{04077EFC-0146-4C89-859C-59F7CEE78885}: NameServer = 77.71.61.1,77.71.63.225 O17 - HKLM\System\CS2\Services\Tcpip\..\{04077EFC-0146-4C89-859C-59F7CEE78885}: NameServer = 77.71.61.1,77.71.63.225 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6136 bytes
-
Проблем с rootkit [РЕШЕН]
От няколко дни моя NOD32 4.0.474.0 ми засича някаква гадина Rootkit в c:\WINDOWS\system32\drivers\Mup.sys .NOD32 го слага в карантина-трия го от там,но след рестарт отново го засича и пак в карантината.Скоро забекязах,че и въпреки че и в карантина при рестарт NOD32 отново го регистрира.Как и може ли да се премахне тая гад,явно че NOD32 не се справя???Благодаря предварително!!!
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.