Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Моля за анализ на логовете ми [Решен]

Featured Replies

1во - антивирус -

Malwarebytes' Anti-Malware 1.40

Версия на базата от данни: 2708

Windows 5.1.2600 Service Pack 3 (Safe Mode)

28.8.2009 г. 14:29:52

mbam-log-2009-08-28 (14-29-52).txt

Тип сканиране: Пълно сканиране (A:\|C:\|D:\|E:\|F:\|)

Сканирани обекти: 116332

Изминало време: 21 minute(s), 14 second(s)

Заразени процеси в паметта: 0

Заразени модули в паметта: 0

Заразени ключове в регистратурата: 20

Заразени стойности в регистратурата: 4

Заразени информационни обекти в регистратурата: 3

Заразени папки: 0

Заразени файлове: 1

Заразени процеси в паметта:

(Не бяха открити заплахи)

Заразени модули в паметта:

(Не бяха открити заплахи)

Заразени ключове в регистратурата:

HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Заразени стойности в регистратурата:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\Microsoft Driver Setup (Worm.Palevo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Driver Setup (Worm.Palevo) -> Quarantined and deleted successfully.

Заразени информационни обекти в регистратурата:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Заразени папки:

(Не бяха открити заплахи)

Заразени файлове:

C:\WINDOWS\mslsrv.exe (Worm.Palevo) -> Quarantined and deleted successfully.

2ро - хайджак

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:39:41, on 28.8.2009 г.

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Boot mode: Safe mode with network support

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\user\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

D:\Programs\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.garena.com/portal/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll

O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

O4 - HKLM\..\Run: [bigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [bluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [universal Bus device] usb_drv.exe

O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Programs\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [uTorrent] "D:\Programs\u torrent\uTorrent.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://optisprint.net/VatDec.cab

O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab

O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://games.myspace.com/Gameshell/GameHos...ronGameHost.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: VCL MySQL Database Server - Unknown owner - D:\Programs\Chemistry Lab\mysql\bin\mysqld.exe

--

End of file - 6977 bytes

и ако някои може да ми помогне с

Здравейте xaxatix,

Аз съм B-boy[styLe] и ще Ви помагам да почистите вашата система от зловреден софтуер. Анализа на логовете, както и премахването на зловредния софтуер, може да отнеме време, затова моля бъдете търпеливи. Моля, имайте предвид следното:

  • Аз ще Ви помагам главно за почистването на вашата система от зловреден софтуер. За всякакви други проблеми, моля създайте нова тема в съответния форум и опишете детайлно проблема Ви.
  • Инструкциите се отнасят само за този проблем и само за този компютър.
  • Следвайте инструкциите ми стриктно, докато не Ви кажа, че системата Ви е напълно чиста. Това, че симптомите са изчезнали, не значи че всичко е наред.
  • Ако не разбирате нещо, моля Ви попитайте ме, а не рискувайте. По-добре е малко да се позабавим, отколкото да усложним нещата.
  • Цялата кореспонденция минава през тази тема, не създавайте нова тема и не използвайте друга тема за тази цел.

Стъпка 1:

Моля отворете HijackThis и натиснете "Do a system scan only"

Сложете отметки пред следните редове и изберете "Fix Checked"

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [universal Bus device] usb_drv.exe

Стъпка 2:

Проверете системата си с TrendMicro Sysclean

header-logo.gif

Изтеглете следните 3-части:

[*]Sysclean Package

[*]Virus Pattern Files - Official Pattern Release

[*]Spyware Pattern Files - Detection and Cleanup (Trend Micro Anti-Spyware) – Ssapiptn.Da5

Направете папка на дял C:\ (или място по-избор) с име TrendMicro

Копирайте там и 3-те изтеглени файлове.

Разархивирайте вирусните и антишпионските дефиниции.

Стартирайте sysclean.com => уверете се, че следните отметки са поставени:

74939363qc7.jpg

Изберете бутона SCAN.

След края на проверката, отворете отново папката C:\TrendMicro и проверете съдържанието на лог файла sysclean.log

Публикувайте го в следващия си пост.

  • Автор

Ето и от тренд микро!

/--------------------------------------------------------------\

| Trend Micro System Cleaner |

| Copyright 2009-2010, Trend Micro, Inc. |

| http://www.trendmicro.com |

\--------------------------------------------------------------/

2009-08-28, 15:15:03, Auto-clean mode specified.

2009-08-28, 15:15:04, Failed to initialize Rootkit Driver.

2009-08-28, 15:15:04, Running scanner "C:\Program Files\TrendMicro\TSC.BIN"...

2009-08-28, 15:15:38, Scanner "C:\Program Files\TrendMicro\TSC.BIN" has finished running.

2009-08-28, 15:15:38, TSC Log:

яюD a m a g e C l e a n u p E n g i n e ( D C E ) 6 . 1 ( B u i l d 1 0 2 7 ) ( R C M : D r i v e r n o t r e a d y ! )

W i n d o w s X P ( B u i l d 2 6 0 0 : S e r v i c e P a c k 3 )

S t a r t t i m e : ?5BJ: 23CAB 2 8 2 0 0 9 1 5 : 1 5 : 0 5

L o a d D a m a g e C l e a n u p T e m p l a t e ( D C T ) " C : \ P r o g r a m F i l e s \ T r e n d M i c r o \ T M R D C T . p t n " ( v e r s i o n ) [ f a i l ]

L o a d D a m a g e C l e a n u p T e m p l a t e ( D C T ) " C : \ P r o g r a m F i l e s \ T r e n d M i c r o \ t s c . p t n " ( v e r s i o n 1 0 5 8 ) [ s u c c e s s ]

C o m p l e t e t i m e : ?5BJ: 23CAB 2 8 2 0 0 9 1 5 : 1 5 : 3 8

E x e c u t e p a t t e r n c o u n t ( 3 0 6 0 ) , V i r u s f o u n d c o u n t ( 0 ) , V i r u s c l e a n c o u n t ( 0 ) , C l e a n f a i l e d c o u n t ( 0 )

2009-08-28, 15:15:38, Running scanner "C:\Program Files\TrendMicro\VSCANTM.BIN"...

2009-08-28, 15:41:53, Scanner "C:\Program Files\TrendMicro\VSCANTM.BIN" has finished running.

2009-08-28, 15:41:53, VSCANTM Log:

2009-08-28, 15:41:53, Files Detected:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:15:38

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

C:\WINDOWS\msdriver32.exe [TROJ_BUZUS.APV]

C:\WINDOWS\system32\05.scr [Cryp_Neb-2]

C:\WINDOWS\system32\27.scr [Cryp_Neb-2]

C:\WINDOWS\system32\44.scr [Cryp_Neb-2]

C:\WINDOWS\system32\57.scr [Cryp_Neb-2]

C:\WINDOWS\system32\77.scr [TROJ_BUZUS.APV]

C:\WINDOWS\system32\80.scr [Cryp_Neb-2]

29569 files have been read.

29569 files have been checked.

29531 files have been scanned.

100728 files have been scanned. (including files in archived)

7 files containing viruses.

Found 7 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:41:51 26 minutes 12 seconds (1571.72 seconds) has elapsed.(53.154 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:41:53, Files Clean:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:15:38

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

29569 files have been read.

29569 files have been checked.

29531 files have been scanned.

100728 files have been scanned. (including files in archived)

7 files containing viruses.

Found 7 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:41:51 26 minutes 12 seconds (1571.72 seconds) has elapsed.(53.154 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:41:53, Clean Fail:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:15:38

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR C:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

29569 files have been read.

29569 files have been checked.

29531 files have been scanned.

100728 files have been scanned. (including files in archived)

7 files containing viruses.

Found 7 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:41:51 26 minutes 12 seconds (1571.72 seconds) has elapsed.(53.154 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:41:53, Running scanner "C:\Program Files\TrendMicro\VSCANTM.BIN"...

2009-08-28, 15:50:57, Scanner "C:\Program Files\TrendMicro\VSCANTM.BIN" has finished running.

2009-08-28, 15:50:57, VSCANTM Log:

2009-08-28, 15:50:57, Files Detected:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:41:54

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

3213 files have been read.

3213 files have been checked.

3212 files have been scanned.

30451 files have been scanned. (including files in archived)

0 files containing viruses.

Found 0 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:50:57 9 minutes 2 seconds (541.81 seconds) has elapsed.(168.631 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:50:57, Files Clean:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:41:54

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

3213 files have been read.

3213 files have been checked.

3212 files have been scanned.

30451 files have been scanned. (including files in archived)

0 files containing viruses.

Found 0 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:50:57 9 minutes 2 seconds (541.81 seconds) has elapsed.(168.631 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:50:57, Clean Fail:

Copyright © 1990 - 2006 Trend Micro Inc.

Report Date : 8/28/2009 15:41:54

VSAPI Engine Version : 8.950-1092

VSCANTM Version : 3.00-1018 (Official Build)

VSGetVirusPatternInformation is invoked

Virus Pattern Version : 401 (465217/465217 Patterns) (2009/08/27) (640100)

Command Line: C:\Program Files\TrendMicro\VSCANTM.BIN /NBPM /S /CLEANALL /LD /LC /LCF /NM /NB /DCEGENCLEAN /HIDEDCECONSOLE /C /ACTIVEACTION=5 /VSBKENC+ /BK /LR D:\*.* /P=C:\Program Files\TrendMicro\lpt$vpn.401

3213 files have been read.

3213 files have been checked.

3212 files have been scanned.

30451 files have been scanned. (including files in archived)

0 files containing viruses.

Found 0 viruses totally.

Maybe 0 viruses totally.

Stop At: 8/28/2009 15:50:57 9 minutes 2 seconds (541.81 seconds) has elapsed.(168.631 msec/file)

---------*---------*---------*---------*---------*---------*---------*---------*

2009-08-28, 15:50:57, Running SSAPI scanner ""...

2009-08-28, 16:09:06, SSAPI Log:

SSAPI Scanner Version: 1.0.1003

SSAPI Engine Version: 5.2.1032

SSAPI Pattern Version: 8.15

SSAPI Anti-Rootkit Version: <Failed>

Spyware Scan Started: 08/28/2009 15:51:02

Detected: 0 items.

Spyware Scan Ended: 08/28/2009 16:09:05

Scan Complete. Time=1087.460327.

*. Временно спри защитата на антивирусната си програма в реално време.

*. Изтегли Combofix.

*. Запази го на ДЕСКТОПА.

*. Въведи следната команда:

Start => run => въведи

"%userprofile%\desktop\combofix.exe" /stepdel

killall.JPG

*. По времето на сканиране от страна на ComboFix не стартирай никакви други приложения, не натискай клавиши от клавиатурата и не мести мишката !

*. Публикувай лог файла в следващия си пост.

СТЪПКА 1

Отворете notepad и чрез copy/paste въведете:

KILLALL::


Driver::

jnv4_mib


File::

c:\windows\system32\36.scr

c:\windows\usb_drv.exe

c:\windows\system32\Ms14.exe

c:\docume~1\user\LOCALS~1\Temp\jnv4_mib.sys


Folder::

c:\program files\TrendMicro

Запазете файла с име CFScript.txt и чрез copy/paste го провлачете в ComboFix.exe

cfscriptyr1.gif

Публикувайте лог файла в следващия си пост.

СТЪПКА 2

Изтеглете Security Check от screen317 от тук или тук и го запазете на вашия десктоп.

  • Стартирайте SecurityCheck.exe и следвайте инструкциите от новопоявилия се диалогов прозорец.
  • Анализа на вашата система може да отнеме време, затова моля бъдете търпеливи.
  • Накрая, автоматично ще се отвори текстов документ наречен checkup.txt, моля поставете съдържанието му в следващия Ви коментар в тази тема.

  • Автор

Ето :

Results of screen317's Security Check version 0.98.9

Windows XP Service Pack 3

``````````````````````````````

Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!

Windows Firewall Enabled!

WMIC entry does not exist for antivirus; attempting automatic update.

``````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

HijackThis 2.0.2

CCleaner (remove only)

Java 6 Update 15

Adobe Flash Player 10

Adobe Reader 9.1.2 - Bulgarian

``````````````````````````````

Process Check:

objlist.exe by Laurent

``````````````````````````````

DNS Vulnerability Check:

POOR! (Vulnerable to DNS cache poisoning!!-- Consider OPENDNS)

`````````End of Log```````````

А къде е лога от Combofix след изпълнението на CFScript-a ?

Изтеглете JavaRa и го разархивирайте на Вашия десктоп.

***! Преди да започнете с процедурата, затворете Internet Explorer !***

Кликнете два пъти върху JavaRa.exe, за да стартирате програмата

От падащото меню, изберете English ...и изберете Select.

JavaRa ще се стартира; Изберете Remove Older Versions, за да премахнете по-старата версия от компютъра.

Посочете Yes, когато бъдете попитан. Когато JavaRa приключи успешно премахването на старата версия, ще получите съобщение, че лог файла от извършената процедура е създаден. Изберете OK.

Лог файлът ще появи. Запазете го на десктопа.

Копирайте съдържанито му в следващия си пост.

Може да изтеглите актуална версия на JAVA оттук => Java SE Runtime Environment 6 Update 16

Adobe Reader 9.1.2 - Bulgarian => можете да го замените с по-безопасния Foxit Reader 3.1 Build 0824

Бих ви посъветвал и да проверите дали ще можете да използвате алтернативен DNS адрес (но това трябва да обсъдите с Вашия интернет доставчик).

OpenDNS.

  • Автор

А къде е лога от Combofix след изпълнението на CFScript-a ?

Изтеглете JavaRa и го разархивирайте на Вашия десктоп.

***! Преди да започнете с процедурата, затворете Internet Explorer !***

Кликнете два пъти върху JavaRa.exe, за да стартирате програмата

От падащото меню, изберете English ...и изберете Select.

JavaRa ще се стартира; Изберете Remove Older Versions, за да премахнете по-старата версия от компютъра.

Посочете Yes, когато бъдете попитан. Когато JavaRa приключи успешно премахването на старата версия, ще получите съобщение, че лог файла от извършената процедура е създаден. Изберете OK.

Лог файлът ще появи. Запазете го на десктопа.

Копирайте съдържанито му в следващия си пост.

Може да изтеглите актуална версия на JAVA оттук => Java SE Runtime Environment 6 Update 16

Adobe Reader 9.1.2 - Bulgarian => можете да го замените с по-безопасния Foxit Reader 3.1 Build 0824

Бих ви посъветвал и да проверите дали ще можете да използвате алтернативен DNS адрес (но това трябва да обсъдите с Вашия интернет доставчик).

OpenDNS.

Ето това е (без скрипта)

ComboFix 09-08-27.A0 - user 08.2009 г. 16:28.1.1 - NTFSx86 NETWORK

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.503.324 [GMT 3:00]

Running from: c:\documents and settings\user\desktop\combofix.exe

Command switches used :: /killall

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\logfile32.txt

c:\windows\system32\i

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_Irmon

-------\Service_Irmon

((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))

.

2009-08-28 12:12 . 2009-08-28 13:10 -------- d-----w- c:\program files\TrendMicro

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes

2009-08-28 11:06 . 2009-08-03 10:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-08-28 11:06 . 2009-08-03 10:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-08-28 10:50 . 2009-08-28 10:50 82432 ----a-w- c:\windows\system32\36.scr

2009-08-27 16:58 . 2009-08-27 16:57 114688 --sh--r- c:\windows\usb_drv.exe

2009-08-27 16:57 . 2009-08-27 16:57 114688 ----a-w- c:\windows\system32\Ms14.exe

2009-08-27 15:15 . 2009-08-27 15:15 127 ----a-w- c:\documents and settings\user\Local Settings\Application Data\fusioncache.dat

2009-08-27 15:15 . 2009-08-27 15:15 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\ApplicationHistory

2009-08-27 15:12 . 2009-08-28 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-08-24 14:48 . 2009-08-24 14:48 -------- d-----w- c:\windows\PIF

2009-08-24 14:29 . 2009-08-24 14:29 7168 ----a-w- c:\documents and settings\user\Application Data\Thinstall\EVEREST Ultimate Edition v4.60\40000022900002i\everest_mondiag.dll

2009-08-24 14:26 . 2009-08-24 14:26 -------- d-----w- c:\documents and settings\user\Application Data\Thinstall

2009-08-19 18:03 . 2009-08-19 18:03 -------- d-----w- c:\program files\JoWooD

2009-08-10 12:32 . 2009-08-10 12:32 -------- d-----w- c:\documents and settings\All Users\Application Data\2BrightSparks

2009-08-06 07:09 . 2009-08-06 07:09 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_15\lzma.dll

2009-07-30 10:56 . 2009-07-30 10:56 531 ----a-w- c:\windows\eReg.dat

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-28 05:23 . 2009-07-06 11:30 -------- d-----w- c:\documents and settings\user\Application Data\uTorrent

2009-08-24 17:00 . 2009-02-07 11:29 -------- d-----w- c:\documents and settings\user\Application Data\Skype

2009-08-24 17:00 . 2009-02-07 11:29 -------- d-----w- c:\documents and settings\user\Application Data\skypePM

2009-08-06 07:10 . 2009-02-07 02:30 -------- d-----w- c:\program files\Java

2009-07-25 02:23 . 2009-02-07 02:30 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-07-15 11:19 . 2009-06-28 11:12 -------- d-----w- c:\program files\NCH Swift Sound

2009-07-15 11:19 . 2009-06-28 11:14 -------- d-----w- c:\documents and settings\user\Application Data\NCH Swift Sound

2009-07-15 07:39 . 2009-02-04 18:02 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-07-09 10:28 . 2009-07-09 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn

2009-07-07 15:10 . 2009-07-07 12:58 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield Installation Information

2009-07-04 12:02 . 2009-07-04 12:02 -------- d-----w- c:\documents and settings\user\Application Data\BitCometLite

2009-06-29 05:08 . 2009-06-29 05:08 60416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\OpenAL32.dll

2009-06-29 05:08 . 2009-06-29 05:08 4214784 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\ThinkTanks.exe

2009-06-29 05:08 . 2009-06-29 05:08 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\fmodex.dll

2009-06-29 05:08 . 2009-06-29 05:08 1338728 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx9_33.dll

2009-06-29 05:08 . 2009-06-29 05:08 971544 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx9_31.dll

2009-06-29 05:08 . 2009-06-29 05:08 270336 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx8dll.dll

2009-06-28 18:21 . 2009-06-28 18:21 61136 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\xinput9_1_0.dll

2009-06-28 18:21 . 2009-06-28 18:21 4308992 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\marbleBlast.exe

2009-06-28 18:21 . 2009-06-28 18:21 3495784 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\d3dx9_33.dll

2009-06-28 18:21 . 2009-06-28 18:21 319488 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\d3dx8dll.dll

2009-06-28 18:21 . 2009-06-28 18:21 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\fmodex.dll

2009-06-28 17:50 . 2009-06-28 17:50 4608 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\w9xpopen.exe

2009-06-28 17:50 . 2009-06-28 17:50 438272 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_image.dll

2009-06-28 17:50 . 2009-06-28 17:50 364544 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL.dll

2009-06-28 17:50 . 2009-06-28 17:50 348160 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\MSVCR71.dll

2009-06-28 17:50 . 2009-06-28 17:50 34304 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\main.exe

2009-06-28 17:50 . 2009-06-28 17:50 282624 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_mixer.dll

2009-06-28 17:50 . 2009-06-28 17:50 274432 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_ttf.dll

2009-06-28 17:50 . 2009-06-28 17:50 2113536 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\python25.dll

2009-06-28 17:50 . 2009-06-28 17:50 204800 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\smpeg.dll

2009-06-28 17:38 . 2009-06-28 17:38 68888 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\xinput1_3.dll

2009-06-28 17:38 . 2009-06-28 17:38 3026944 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\Zap.exe

2009-06-28 17:38 . 2009-06-28 17:38 60416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\OpenAL32.dll

2009-06-28 17:38 . 2009-06-28 17:38 2319568 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\d3dx9_27.dll

2009-06-28 17:38 . 2009-06-28 17:38 184320 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\d3dx8dll.dll

2009-06-28 17:23 . 2009-06-28 17:23 626688 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\msvcr80.dll

2009-06-28 17:23 . 2009-06-28 17:23 3403776 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\Rokkitball.exe

2009-06-28 17:23 . 2009-06-28 17:23 229376 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\tbb.dll

2009-06-28 17:23 . 2009-06-28 17:23 3727720 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\d3dx9_35.dll

2009-06-28 17:23 . 2009-06-28 17:23 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\fmodex.dll

2009-06-28 17:23 . 2009-06-28 17:23 2414360 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\d3dx9_31.dll

2009-06-28 17:16 . 2009-06-28 17:16 4878336 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\Legions.exe

2009-06-28 17:16 . 2009-06-28 17:16 3727720 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\d3dx9_35.dll

2009-06-28 17:16 . 2009-06-28 17:16 345088 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\fmodex.dll

2009-06-09 08:03 . 2009-02-26 18:10 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll

2009-06-05 05:29 . 2009-06-05 05:29 323584 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\7FF925F91B164F79B5B60CF131390434\swt-win32-3232.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-17 39408]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]

"DAEMON Tools Lite"="d:\programs\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]

"Google Update"="c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-14 133104]

"uTorrent"="d:\programs\u torrent\uTorrent.exe" [2009-07-06 288048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]

"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-29 4620288]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-03 188416]

"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]

"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

"GrpConv"="grpconv -o" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"d:\\Games\\Garena\\Garena.exe"=

"d:\\Programs\\u torrent\\uTorrent.exe"=

"d:\\Games\\Warcraft 3\\Warcraft III.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"17370:TCP"= 17370:TCP:BitComet 17370 TCP

"17370:UDP"= 17370:UDP:BitComet 17370 UDP

"10766:TCP"= 10766:TCP:BitCometLite 10766 TCP

"10766:UDP"= 10766:UDP:BitCometLite 10766 UDP

"24074:TCP"= 24074:TCP:BitCometLite 24074 TCP

"24074:UDP"= 24074:UDP:BitCometLite 24074 UDP

S2 VCL MySQL Database Server;VCL MySQL Database Server;d:\programs\Chemistry Lab\mysql\bin\mysqld.exe [18.4.2009 г. 19:33 3956736]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp --> c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp [?]

S3 jnv4_mib;jnv4_mib;\??\c:\docume~1\user\LOCALS~1\Temp\jnv4_mib.sys --> c:\docume~1\user\LOCALS~1\Temp\jnv4_mib.sys [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

S3 ZSMC0305;CANYON CN-WCAM23 PC-Camera;c:\windows\system32\drivers\usbVM305.sys [07.2.2009 г. 01:17 392316]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - MESSENGER

.

Contents of the 'Scheduled Tasks' folder

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-2052111302-725345543-1003Core.job

- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-14 17:12]

2009-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-2052111302-725345543-1003UA.job

- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-14 17:12]

.

- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cmaudio - cmicnfg.cpl

HKLM-RunOnce-<NO NAME> - (no file)

.

------- Supplementary Scan -------

.

uStart Page = about:blank

mStart Page = about:blank

IE: &Search

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://optisprint.net/VatDec.cab

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-28 16:34

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

Completion time: 2009-08-28 16:37 - machine was rebooted

ComboFix-quarantined-files.txt 2009-08-28 13:37

Pre-Run: 22 292 320 256 bytes free

Post-Run: 22 208 663 552 bytes free

175 --- E O F --- 2009-02-25 15:21

Това е със него

ComboFix 09-08-27.A0 - user 08.2009 г. 17:15.2.1 - NTFSx86 NETWORK

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.503.339 [GMT 3:00]

Running from: c:\documents and settings\user\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\user\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::

"c:\docume~1\user\LOCALS~1\Temp\jnv4_mib.sys"

"c:\windows\system32\36.scr"

"c:\windows\system32\Ms14.exe"

"c:\windows\usb_drv.exe"

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\program files\TrendMicro

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_34_50_578_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_22_765_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_24_937_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_26_812_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_28_546_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_30_406_035.DAT

c:\program files\TrendMicro\backup\TSC_GENCLEAN_2009_08_28_15_38_32_312_035.DAT

c:\program files\TrendMicro\debug\TSCDebug.log

c:\program files\TrendMicro\lpt$vpn.401

c:\program files\TrendMicro\lpt401.zip

c:\program files\TrendMicro\REPORT.LOG

c:\program files\TrendMicro\ssapiptn.da5

c:\program files\TrendMicro\ssapiptn815.zip

c:\program files\TrendMicro\sysclean.com

c:\program files\TrendMicro\sysclean.log

c:\program files\TrendMicro\TSC_Temp\backup\DEADLINK_NOVIRUS_2009_08_28_16_26_54_359_035.DAT

c:\program files\TrendMicro\TSC_Temp\DEADLINKS.INI

c:\program files\TrendMicro\TSC_Temp\debug\TSCDebug.log

c:\program files\TrendMicro\TSC_Temp\MARK_TEMP.INI

c:\program files\TrendMicro\TSC_Temp\report\20090828.log

c:\program files\TrendMicro\TSC_Temp\tsc.exe

c:\program files\TrendMicro\TSC_Temp\tsc.ini

c:\program files\TrendMicro\TSC_Temp\tsc.ptn

c:\program files\TrendMicro\whatsnew.txt

c:\windows\system32\36.scr

c:\windows\system32\Ms14.exe

c:\windows\usb_drv.exe

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_JNV4_MIB

-------\Service_jnv4_mib

((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))

.

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\documents and settings\user\Application Data\Malwarebytes

2009-08-28 11:06 . 2009-08-03 10:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-08-28 11:06 . 2009-08-03 10:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-08-28 11:06 . 2009-08-28 11:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-08-27 15:15 . 2009-08-27 15:15 127 ----a-w- c:\documents and settings\user\Local Settings\Application Data\fusioncache.dat

2009-08-27 15:15 . 2009-08-27 15:15 -------- d-----w- c:\documents and settings\user\Local Settings\Application Data\ApplicationHistory

2009-08-27 15:12 . 2009-08-28 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-08-24 14:48 . 2009-08-24 14:48 -------- d-----w- c:\windows\PIF

2009-08-24 14:29 . 2009-08-24 14:29 7168 ----a-w- c:\documents and settings\user\Application Data\Thinstall\EVEREST Ultimate Edition v4.60\40000022900002i\everest_mondiag.dll

2009-08-24 14:26 . 2009-08-24 14:26 -------- d-----w- c:\documents and settings\user\Application Data\Thinstall

2009-08-19 18:03 . 2009-08-19 18:03 -------- d-----w- c:\program files\JoWooD

2009-08-10 12:32 . 2009-08-10 12:32 -------- d-----w- c:\documents and settings\All Users\Application Data\2BrightSparks

2009-08-06 07:09 . 2009-08-06 07:09 152576 ----a-w- c:\documents and settings\user\Application Data\Sun\Java\jre1.6.0_15\lzma.dll

2009-07-30 10:56 . 2009-07-30 10:56 531 ----a-w- c:\windows\eReg.dat

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-08-28 05:23 . 2009-07-06 11:30 -------- d-----w- c:\documents and settings\user\Application Data\uTorrent

2009-08-24 17:00 . 2009-02-07 11:29 -------- d-----w- c:\documents and settings\user\Application Data\Skype

2009-08-24 17:00 . 2009-02-07 11:29 -------- d-----w- c:\documents and settings\user\Application Data\skypePM

2009-08-06 07:10 . 2009-02-07 02:30 -------- d-----w- c:\program files\Java

2009-07-25 02:23 . 2009-02-07 02:30 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-07-15 11:19 . 2009-06-28 11:12 -------- d-----w- c:\program files\NCH Swift Sound

2009-07-15 11:19 . 2009-06-28 11:14 -------- d-----w- c:\documents and settings\user\Application Data\NCH Swift Sound

2009-07-15 07:39 . 2009-02-04 18:02 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-07-09 10:28 . 2009-07-09 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\LogMeIn

2009-07-07 15:10 . 2009-07-07 12:58 -------- d-----w- c:\documents and settings\user\Application Data\InstallShield Installation Information

2009-07-04 12:02 . 2009-07-04 12:02 -------- d-----w- c:\documents and settings\user\Application Data\BitCometLite

2009-06-29 05:08 . 2009-06-29 05:08 60416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\OpenAL32.dll

2009-06-29 05:08 . 2009-06-29 05:08 4214784 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\ThinkTanks.exe

2009-06-29 05:08 . 2009-06-29 05:08 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\fmodex.dll

2009-06-29 05:08 . 2009-06-29 05:08 1338728 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx9_33.dll

2009-06-29 05:08 . 2009-06-29 05:08 971544 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx9_31.dll

2009-06-29 05:08 . 2009-06-29 05:08 270336 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\101\install\d3dx8dll.dll

2009-06-28 18:21 . 2009-06-28 18:21 61136 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\xinput9_1_0.dll

2009-06-28 18:21 . 2009-06-28 18:21 4308992 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\marbleBlast.exe

2009-06-28 18:21 . 2009-06-28 18:21 3495784 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\d3dx9_33.dll

2009-06-28 18:21 . 2009-06-28 18:21 319488 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\d3dx8dll.dll

2009-06-28 18:21 . 2009-06-28 18:21 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\100\install\fmodex.dll

2009-06-28 17:50 . 2009-06-28 17:50 4608 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\w9xpopen.exe

2009-06-28 17:50 . 2009-06-28 17:50 438272 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_image.dll

2009-06-28 17:50 . 2009-06-28 17:50 364544 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL.dll

2009-06-28 17:50 . 2009-06-28 17:50 348160 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\MSVCR71.dll

2009-06-28 17:50 . 2009-06-28 17:50 34304 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\main.exe

2009-06-28 17:50 . 2009-06-28 17:50 282624 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_mixer.dll

2009-06-28 17:50 . 2009-06-28 17:50 274432 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\SDL_ttf.dll

2009-06-28 17:50 . 2009-06-28 17:50 2113536 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\python25.dll

2009-06-28 17:50 . 2009-06-28 17:50 204800 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\9500\install\dist\smpeg.dll

2009-06-28 17:38 . 2009-06-28 17:38 68888 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\xinput1_3.dll

2009-06-28 17:38 . 2009-06-28 17:38 3026944 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\Zap.exe

2009-06-28 17:38 . 2009-06-28 17:38 60416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\OpenAL32.dll

2009-06-28 17:38 . 2009-06-28 17:38 2319568 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\d3dx9_27.dll

2009-06-28 17:38 . 2009-06-28 17:38 184320 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\7000\install\d3dx8dll.dll

2009-06-28 17:23 . 2009-06-28 17:23 626688 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\msvcr80.dll

2009-06-28 17:23 . 2009-06-28 17:23 3403776 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\Rokkitball.exe

2009-06-28 17:23 . 2009-06-28 17:23 229376 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\tbb.dll

2009-06-28 17:23 . 2009-06-28 17:23 3727720 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\d3dx9_35.dll

2009-06-28 17:23 . 2009-06-28 17:23 316416 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\fmodex.dll

2009-06-28 17:23 . 2009-06-28 17:23 2414360 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\103\install\d3dx9_31.dll

2009-06-28 17:16 . 2009-06-28 17:16 4878336 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\Legions.exe

2009-06-28 17:16 . 2009-06-28 17:16 3727720 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\d3dx9_35.dll

2009-06-28 17:16 . 2009-06-28 17:16 345088 ----a-w- c:\documents and settings\user\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\fmodex.dll

2009-06-09 08:03 . 2009-02-26 18:10 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll

2009-06-05 05:29 . 2009-06-05 05:29 323584 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\7FF925F91B164F79B5B60CF131390434\swt-win32-3232.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-17 39408]

"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]

"DAEMON Tools Lite"="d:\programs\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]

"Google Update"="c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-14 133104]

"uTorrent"="d:\programs\u torrent\uTorrent.exe" [2009-07-06 288048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]

"Persistence"="c:\windows\system32\igfxpers.exe" [2005-04-05 114688]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-29 4620288]

"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2002-11-03 188416]

"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]

"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"d:\\Games\\Garena\\Garena.exe"=

"d:\\Programs\\u torrent\\uTorrent.exe"=

"d:\\Games\\Warcraft 3\\Warcraft III.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"17370:TCP"= 17370:TCP:BitComet 17370 TCP

"17370:UDP"= 17370:UDP:BitComet 17370 UDP

"10766:TCP"= 10766:TCP:BitCometLite 10766 TCP

"10766:UDP"= 10766:UDP:BitCometLite 10766 UDP

"24074:TCP"= 24074:TCP:BitCometLite 24074 TCP

"24074:UDP"= 24074:UDP:BitCometLite 24074 UDP

S2 VCL MySQL Database Server;VCL MySQL Database Server;d:\programs\Chemistry Lab\mysql\bin\mysqld.exe [18.4.2009 г. 19:33 3956736]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp --> c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

S3 ZSMC0305;CANYON CN-WCAM23 PC-Camera;c:\windows\system32\drivers\usbVM305.sys [07.2.2009 г. 01:17 392316]

.

Contents of the 'Scheduled Tasks' folder

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-2052111302-725345543-1003Core.job

- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-14 17:12]

2009-08-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-796845957-2052111302-725345543-1003UA.job

- c:\documents and settings\user\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-06-14 17:12]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

mStart Page = about:blank

IE: &Search

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} - hxxp://optisprint.net/VatDec.cab

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-08-28 17:21

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

BigDog305 = c:\windows\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)???????????????????0?????????@??????????????

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\user\LOCALS~1\Temp\OMT18.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1916)

c:\windows\system32\ieframe.dll

c:\windows\system32\OneX.DLL

c:\windows\system32\eappprxy.dll

.

Completion time: 2009-08-28 17:25 - machine was rebooted

ComboFix-quarantined-files.txt 2009-08-28 14:25

ComboFix2.txt 2009-08-28 13:37

Pre-Run: 22 213 943 296 bytes free

Post-Run: 22 158 274 560 bytes free

201 --- E O F --- 2009-02-25 15:21

JAVATA

JavaRa 1.15 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Fri Aug 28 18:06:02 2009

Found and removed: C:\Documents and Settings\user\Application Data\Sun\Java\jre1.6.0_11

Found and removed: C:\Documents and Settings\user\Application Data\Sun\Java\jre1.6.0_12

Found and removed: C:\Documents and Settings\user\Application Data\Sun\Java\jre1.6.0_13

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

------------------------------------

Finished reporting.

Редактирано от xaxatix (преглед на промените)

Стъпка 1

Моля, архивирайте папката C:\Qoobox и я качете на следния адрес => http://www.4storing.com/

След това деинсталирайте Combofix с командата :

Start => Run => въведете =>

combofix /

Натиснете Enter.

Clipboard0combofixu.gif

Стъпка 2

Моля изтеглете Windows Worms Doors Cleaner v1.4.1 и го стартирайте.

Ако не използвате домашна мрежа или отдалечено администриране затворете всички уязвимости докато програмата не ги покаже в зелен цвят.

Може да се наложи да рестартирате компютъра си за да влезнат промените в сила.

Стъпка 3

Така вече е по-добре, но искам да направите една финална проверка преди да приключим.

Изтеглете Dr.WEB CureIt! 5.00.0 ,стартирайте програмата

Натиснете клавиша F9 и направете следните настройки:

В категория "Проверка" се придвижете до "Списък с изключени файлове".

Маркирайте ги всичките и изберете "Изтрий". Потвърдете с "Apply",след което натиснете "ОК".

27h3psrmr01c5t5sizka.jpg

Отидете до категорията "Действия". Приложете настройките от снимката и натиснете "Apply"

6ezwrifdxe4ns2mhkub8.jpg

Направете пълна проверка на системата си и публикувайте лог файла (който се намира в папка %USERPROFILE%\DoctorWeb).

Т.е. в адресната лента на My Computer или Windows Explorer въведете %USERPROFILE%\DoctorWeb и ще видите папката на Dr.Web с лог файла.

Нещо линка не е в ред или само при мен е така..?

Времемнно има проблем с линка. Нов линк => http://4storing.com/lvkggm/9dde8a8a373b94b...c85cabe245.html

помощ.....кво да направя .

Всичко е нормално. След рестарт всички елементи ще "светнат" в зелен цвят.

Не се паникьосвайте толкова. Почти сме на финала. След проверката с Dr.Web ще ви дам инструкции за инсталирането на антивирусен продукт.

Поздрави :speak:

Ето B-boy[styLe] това е групата с 2та файла (те са C,D) 2 различни документа са!

C + D!

Успях да изтегля само по-малкия файл, а на големия ми се налага да изчакам:

"Моля, опитайте отново по-късно или използвайте екстра трафик."

Както и да е. Има ли нещо в папката %USERPROFILE%\DoctorWeb\Quarantine ?

Изтрийте направо цялата папка на Dr.Web.

Стъпка 1

Изтеглете OTM.exe от oldtimer

Стартирайте файла OTM.exe и натиснете CleanUp (както е показано на снимката)

arp01uvjvahuk8szjhcphzybu3wrlcmn5xpjotux.jpg

Стъпка 2

Изтеглете Avira AntiVir Personal 9.0.0.407

Направете следните настройки на приложението => Коментар № 19

Обновете вирусните дефиниции и направете пълна проверка на системата си.

Имате ли все още симптомите описани в първия пост ? Поздрави !

  • Автор

Това ми излиза (постоянно) от CCleaner (registry check) - вирус ли е?

Не, не е вирус. Това е ключ от антивирусната програма Avira.

Можеш да го поставиш в изключенията на програмата по този начин и повече няма да се засича:

Стартирай CCleaner => Options => Exclude => Add Registry => HKCR => {80b8c23c-16e0-4cd8-bbc3-cecec9a78b79} => OK

;)

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.