Всичко публикувано от DanielzZz
-
Не мога да премахна Autorun.Agend.UD
Нищо важно.И между другото за сега не се е появявал warning...Изписа,че MSRT е премахнал заплахата... Ще пробвам и с klwk,когато имам време Благодаря за помощта,иначе!
-
Не мога да премахна Autorun.Agend.UD
--------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.17, March 2011 Started On Mon Apr 18 19:53:42 2011 ->Scan ERROR: resource process://pid:1768 (code 0x00000005 (5)) ->Scan ERROR: resource process://pid:4824 (code 0x00000490 (1168)) ->Scan ERROR: resource process://pid:5396 (code 0x00000490 (1168)) Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Mon Apr 18 19:55:31 2011 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.18, April 2011 Started On Tue Apr 19 21:19:45 2011 Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Tue Apr 19 21:20:59 2011 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.18, April 2011 Started On Thu Apr 28 03:01:54 2011 ->Scan ERROR: resource process://pid:3108 (code 0x00000490 (1168)) ->Scan ERROR: resource process://pid:824 (code 0x00000490 (1168)) Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Thu Apr 28 03:04:00 2011 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.18, April 2011 Started On Fri Apr 29 16:26:32 2011 ->Scan ERROR: resource process://pid:4952 (code 0x00000490 (1168)) Results Summary: ---------------- No infection found. Microsoft Windows Malicious Software Removal Tool Finished On Fri Apr 29 16:27:49 2011 Return code: 0 (0x0) --------------------------------------------------------------------------------------- Microsoft Windows Malicious Software Removal Tool v3.18, April 2011 Started On Fri Apr 29 16:28:11 2011 Extended Scan Results ---------------- ->Scan ERROR: resource process://pid:4996 (code 0x00000490 (1168)) ->Scan ERROR: resource file://C:\hiberfil.sys (code 0x00000020 (32)) ->Scan ERROR: resource file://C:\pagefile.sys (code 0x00000020 (32)) ->Scan ERROR: resource file://C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752} (code 0x00000005 (5)) ->Scan ERROR: resource file://C:\System Volume Information\{e2977cdc-70de-11e0-8a27-0023cdb26dd9}{3808876b-c176-4e48-b7ae-04046e6cc752} (code 0x00000005 (5)) Threat detected: TrojanDownloader:Win32/Renos.JH containerfile://C:\Users\Public\AppData\AppData.exe file://C:\Users\Public\AppData\AppData.exe->(VFS:liswwozwgkk.exe#1) SigSeq: 0x00005F7860916F09 SHA1: ED51C54104CF0A07279F94CAEA85992F497171FC Extended Scan Removal Results ---------------- Start 'remove' for file://\\?\C:\Users\Public\AppData\AppData.exe->(VFS:liswwozwgkk.exe#1) Operation succeeded ! Results Summary: ---------------- Found TrojanDownloader:Win32/Renos.JH and Removed! Microsoft Windows Malicious Software Removal Tool Finished On Fri Apr 29 21:59:08 2011 Return code: 6 (0x6)
-
Не мога да премахна Autorun.Agend.UD
All processes killed ========== FILES ========== autorun.inf not found in C:\ autorun.inf not found in D:\ autorun.exe not found in C:\ autorun.exe not found in D:\ recycler not found in C:\ recycler not found in D:\ < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Users\Daniel\Desktop\cmd.bat deleted successfully. C:\Users\Daniel\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Daniel ->Temp folder emptied: 4606450 bytes ->Temporary Internet Files folder emptied: 2390736 bytes ->FireFox cache emptied: 248964182 bytes ->Flash cache emptied: 15559 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56466 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 7748 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 244,00 mb [EMPTYFLASH] User: All Users User: Daniel ->Flash cache emptied: 0 bytes User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 04292011_161931 Files\Folders moved on Reboot... Registry entries deleted on Reboot... Това е от OTL. За съжаление след рестарта вируса все още се опитва да атакува(НОД32 го спира). Сега правя пълно сканиране с Malicious Software Removal Tool ще кача лога след като е готов .
-
Не мога да премахна Autorun.Agend.UD
Заповядай ! Extras.Txt OTL.Txt
-
Не мога да премахна Autorun.Agend.UD
Здравейте.Компютъра се бави адски много!Пробвах да премахна проклетия вирус с НОД32 чрез смарт скан,но не успях.Явно се размножава някъде из файловете. Ето лог файловете от DDS: . DDS (Ver_11-03-05.01) - NTFSx86 Run by Daniel at 11:58:17,26 on ЇҐв 29.04.2011 Ј. Internet Explorer: 8.0.7601.17514 Microsoft Windows 7 Ultimate 6.1.7601.1.1251.359.1033.18.1022.215 [GMT 3:00] . AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} SP: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\system32\conhost.exe C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe C:\Windows\system32\nvvsvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe C:\Windows\system32\sppsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\OEM02Mon.exe C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe C:\Windows\WindowsMobile\wmdc.exe C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE C:\Program Files\Dell\DELL Webcam Manager\DellWMgr.exe C:\Program Files\Synaptics\SynTP\SynTPHelper.exe C:\Windows\System32\alg.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\SearchIndexer.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Windows\system32\wuauclt.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\AUDIODG.EXE D:\Games\Live for Speed\LFS.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Winamp\winamp.exe D:\Games\Live for Speed\RevBouncerV262.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Users\Daniel\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll uRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start mRun: [synTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe mRun: [broadcom Wireless Manager UI] c:\program files\dell\dw wlan card\WLTRAY.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\windows\windowsmobile\INetRepl.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\daniel\appdata\roaming\mozilla\firefox\profiles\9x3nsc5m.default\ FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll . ============= SERVICES / DRIVERS =============== . R1 uzexnjgx;AVZ-RK Kernel Driver;c:\windows\system32\drivers\uzexnjgx.sys [2011-4-27 11264] R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128] R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-7-29 136632] R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2010-8-12 810144] R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2010-7-29 96920] R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-4-14 45736] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-4-16 15872] S3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\drivers\VSTAZL3.SYS [2009-7-14 207360] S3 SrvHsfV92;SrvHsfV92;c:\windows\system32\drivers\VSTDPV3.SYS [2009-7-14 980992] S3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\drivers\VSTCNXT3.SYS [2009-7-14 661504] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-4-16 52224] S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-10-18 1343400] . =============== Created Last 30 ================ . 2011-04-27 14:11:44 11264 ----a-w- c:\windows\system32\drivers\uzexnjgx.sys 2011-04-26 13:07:32 -------- d-sh--w- C:\$RECYCLE.BIN 2011-04-26 13:07:27 -------- d-----w- c:\users\daniel\appdata\local\temp 2011-04-20 14:31:28 -------- d-----w- c:\progra~2\Skype Extras 2011-04-20 14:30:08 -------- d-----w- c:\windows\system32\appmgmt 2011-04-19 15:15:05 -------- d-----w- c:\users\daniel\appdata\local\ESET 2011-04-19 10:50:33 7071056 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{1d1199ae-e22e-4e6e-9286-8c94a1dfa4b1}\mpengine.dll 2011-04-19 10:45:01 7071056 ------w- c:\progra~2\microsoft\windows defender\definition updates\updates\mpengine.dll 2011-04-18 16:49:43 -------- d-----w- c:\program files\Tunatic 2011-04-17 18:54:31 140096 ------r- c:\windows\system32\COMDLG32.OCX 2011-04-17 18:54:30 -------- d-----w- c:\program files\Technitium 2011-04-17 18:54:22 1071088 --s---r- c:\windows\system32\MSCOMCTL.OCX 2011-04-16 14:15:59 666624 ----a-w- c:\windows\system32\mssvp.dll 2011-04-16 14:14:44 -------- d-----w- c:\windows\system32\SPReview 2011-04-16 14:14:16 -------- d-----w- c:\windows\system32\EventProviders 2011-04-15 18:24:24 311808 ----a-w- c:\windows\system32\drivers\srv.sys 2011-04-15 18:24:24 310272 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-04-15 18:24:23 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-15 18:24:06 428032 ----a-w- c:\windows\system32\vbscript.dll 2011-04-15 18:23:58 28672 ----a-w- c:\windows\system32\dnscacheugc.exe 2011-04-15 18:23:58 132608 ----a-w- c:\windows\system32\dnsrslvr.dll 2011-04-15 18:23:50 34304 ----a-w- c:\windows\system32\atmlib.dll 2011-04-15 18:23:50 294912 ----a-w- c:\windows\system32\atmfd.dll 2011-04-15 18:23:23 2333184 ----a-w- c:\windows\system32\win32k.sys 2011-04-15 18:23:16 191488 ----a-w- c:\windows\system32\FXSCOVER.exe 2011-04-15 18:23:15 802304 ----a-w- c:\windows\system32\WFS.exe 2011-04-15 18:23:09 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-04-15 18:20:06 741376 ----a-w- c:\windows\system32\inetcomm.dll 2011-04-15 18:20:00 1164288 ----a-w- c:\windows\system32\mfc42u.dll 2011-04-15 18:20:00 1137664 ----a-w- c:\windows\system32\mfc42.dll 2011-04-15 18:19:42 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-15 18:19:42 69632 ----a-w- c:\windows\system32\drivers\bowser.sys 2011-04-15 18:19:42 223232 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-15 18:19:42 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-15 13:39:20 1090952 ----a-w- c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll 2011-04-15 10:19:36 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-04-15 10:19:36 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-04-15 10:19:36 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll 2011-04-15 10:19:36 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll 2011-04-15 10:19:36 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-04-15 10:19:35 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll 2011-04-15 10:19:35 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll 2011-04-15 10:19:35 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll 2011-04-15 06:45:59 -------- d-----w- c:\program files\CCleaner 2011-04-04 17:03:00 -------- d-----w- c:\program files\Cisco 2011-04-04 17:01:05 6656 ----a-w- c:\windows\system32\bcmwlrc.dll 2011-04-04 17:01:04 18496 ----a-w- c:\windows\system32\drivers\bcm42rly.sys 2011-04-04 17:01:03 52224 ----a-w- c:\windows\system32\wltrynt.dll 2011-04-04 17:01:03 4526080 ----a-w- c:\windows\system32\bcmttls.dll 2011-04-04 17:01:02 7533568 ----a-w- c:\windows\system32\BCMWLCPL.CPL 2011-04-04 17:00:55 3874816 ----a-w- c:\windows\system32\bcmihvsrv.dll 2011-04-04 17:00:55 3563520 ----a-w- c:\windows\system32\bcmihvui.dll 2011-04-04 17:00:54 4245568 ----a-w- c:\windows\system32\drivers\BCMWL6.SYS 2011-04-03 21:14:07 642048 ----a-w- c:\windows\system32\CPFilters.dll 2011-04-03 21:14:06 850944 ----a-w- c:\windows\system32\sbe.dll 2011-04-03 21:14:06 534528 ----a-w- c:\windows\system32\EncDec.dll 2011-04-03 21:14:05 199680 ----a-w- c:\windows\system32\mpg2splt.ax 2011-04-03 08:19:08 165376 ----a-w- c:\windows\system32\unrar.dll 2011-04-03 08:19:00 -------- d-----w- c:\program files\K-Lite Codec Pack 2011-04-03 08:14:30 -------- d-----w- c:\program files\Cheat Engine 6 2011-03-31 19:23:47 -------- d-----w- c:\users\daniel\appdata\local\ElevatedDiagnostics . ==================== Find3M ==================== . 2011-04-16 14:49:33 152576 ----a-w- c:\windows\system32\msclmd.dll 2011-04-04 17:00:32 457 ----a-w- c:\windows\system32\vcredist_x86.bat 2011-04-04 17:00:32 2682880 ----a-w- c:\windows\system32\vcredist_x86.exe 2011-04-04 17:00:22 1051136 ----a-w- c:\windows\system32\BCMLogon.dll 2011-02-02 15:11:20 222080 ------w- c:\windows\system32\MpSigStub.exe . ============= FINISH: 11:58:59,97 ===============
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.