Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Проблем с вирус/spyware

Featured Replies

Здравейте. От онзи ден лаптопът ми е заразен. Най-напред при стартиране на операционата система тапетът на работния плот изчезна и се появи надпис, че системата ми е инфектирана. При опит да стартирам приложение, ми изписваше, че не може да го отвори, защото файлът е заразен. Оравих проблемът като свалих Malwarebytes' Anti-Malware в сейф мод и направих сканировка. Сега приложенията се отварят, но при стартап системата зарежда много бавно и същият тапет продължава да си стои, съобщавайки ми, че системата ми е инфектирана. Свалих аваст, направих скан и изттрих три вируса. Свалих и спайуеър доктър, с които също сканирах и изтрих зловредния софтуер. Уж всичко е наред, но не ми харесва как работи системата ми. Почетох написаното във важната тема и поствам резултата от HijackThis. Ето лог файла

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:50:00, on 17.2.2010 г.

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

D:\WINDOWS\System32\smss.exe

D:\WINDOWS\system32\csrss.exe

D:\WINDOWS\system32\winlogon.exe

D:\WINDOWS\system32\services.exe

D:\WINDOWS\system32\lsass.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\System32\svchost.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\system32\svchost.exe

D:\WINDOWS\system32\spoolsv.exe

D:\WINDOWS\Explorer.EXE

D:\Program Files\Spyware Doctor\pctsTray.exe

D:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe

D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

D:\Program Files\Spyware Doctor\pctsAuxs.exe

D:\Program Files\Spyware Doctor\pctsSvc.exe

D:\WINDOWS\System32\alg.exe

D:\WINDOWS\system32\wscntfy.exe

D:\Program Files\Maxthon2\Maxthon.exe

D:\WINDOWS\system32\wbem\wmiprvse.exe

C:\HijackThis.exe

D:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ask.com/?o=15709&l=dis

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=15709&l=dis

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - D:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll

O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - D:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll

O4 - HKLM\..\Run: [iSTray] "D:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: Send to &Bluetooth Device... - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: d:\windows\system32\helpers32.dll

O10 - Unknown file in Winsock LSP: d:\windows\system32\helpers32.dll

O15 - Trusted Zone: http://*.buy-security-essentials.com

O15 - Trusted Zone: http://*.download-soft-package.com

O15 - Trusted Zone: http://*.download-software-package.com

O15 - Trusted Zone: http://*.get-key-se10.com

O15 - Trusted Zone: http://*.is-software-download.com

O15 - Trusted Zone: http://*.buy-security-essentials.com (HKLM)

O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)

O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll

O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - D:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\pctsSvc.exe

--

End of file - 3925 bytes

Редактирано от vodafoneo (преглед на промените)

Обновете MalwareBytes' Anti-Malware и направете бързо сканиране. Накрая публикувайте лог файла, заедно с нов лог файл от HiJackThis.

  • Автор

Oбнових програмата, но при бързо сканиране забива и не може да го завърши.

От онзи ден лаптопът ми е заразен.

Прочети написаното в постове #17, 18 и 19 - цък От личен опит - направи си архив на всичко от С:, формат и нова инсталация. Успех wink.gif

Oбнових програмата, но при бързо сканиране забива и не може да го завърши.

Не бързайте с формата, а изчакайте съветите на колегата @MANIAC и следвайте неговите инструкции !

Нека опитаме следното:

Стъпка 1:

Изтеглете ComboFix от някой от следните линкове:

Линк 1

Линк 2

* ВАЖНО !!! Запазете ComboFix.exe на вашия десктоп

  • Изключете вашата антивирусна и антишпионска програма, обикновено това става чрез натискане на десния бутон на мишката върху иконата на програма в системния трей.

Бележка: Ако не можете я спрете или не сте сигурни коя програма да изключите, моля прегледайте информацията от този линк: How to Disable your Security Programs

  • Преименувайте ComboFix.exe на Tool.exe

  • Стартирайте Tool.exe и следвайте инструкциите.

Бележка: ComboFix ще се стартира без инсталирана Recovery Console.

  • Като част от неговата работа, ComboFix ще провери дали Microsoft Windows Recovery Console е инсталирана. Предвид бързо развиващия се зловреден софтуер е силно препоръчително да бъде инсталирана преди премахването на зловредния софтуер. Това ще Ви позволи да влезете в специален recovery/repair режим, който ще ни позволи по-лесно да решите проблем, който би могъл да възникне при премахване на зловредния софтуер.

  • Следвайте инструкциите, за да позволите на ComboFix да изтегли и инсталира Microsoft Windows Recovery Console. В един момент ще бъдете попитани дали сте съгласни с лицензното споразумение. Необходимо е да потвърдите, че сте съгласни, за да инсталирате Microsoft Windows Recovery Console.

** Забележете: Ако Microsoft Windows Recovery Console е вече инсталирана, ComboFix ще продължи към процеса по премахване на зловредния софтуер.

RcAuto1.gif

След като Microsoft Windows Recovery Console е инсталирана, използвайки ComboFix, Вие ще видите следното съобщение:

whatnext.png

Изберете Yes, за да продължи сканирането за зловреден софтуер.

Когато процесът приключи успешно, инструментът ще създаде лог файл. Моля, включете съдържанието на C:\ComboFix.txt в следващия Ви коментар в тази тема.

Бележка:

  1. Моля, не движете мишката, докато ComboFix работи. Това може да наруши процеса на работа.
  2. ComboFix ще нулира всички настройки на Microsoft Internet Explorer, включително да направи IE браузър по подразбиране.
  3. ComboFix ще изключи autorun функцията на ВСИЧКИ CD, Floppy и USB устройства, за да помогне при премахването на зловредния софтуер и Ви защити от бъдещи вируси/заплахи, които поразяват чрез autorun. Ако това е проблем за вас - моля, уведомете ме.
  4. ComboFix ще изключи вашата интернет връзка. Интернет връзката ще се възстанови автоматично, преди ComboFix да завърши процеса на работа. При проблем, той ще прекрати интернет връзката. За да възстановите интернет връзката си, рестартирайте компютъра си.
  5. В случай на проблем с ComboFix, той може да създаде лог файл. Моля, включете съдържанието на C:\BUG.txt в следващия Ви коментар в тази тема.

Работата на ComboFix, може да отнеме до 20-30 минути, за да завърши, моля имайте търпение.

Моля, не прикачвайте лог файла/овете от програмата, а го/ги копирайте и поставете в следващия Ви коментар в тази тема.

Стъпка 2:

  • Стартирайте HijackThis, кликнете на Config, а след това върху Misc Tools
  • Отворете Open Uninstall Manager
  • Цъкнете на Save List (това ще генерира uninstall_list.txt)
  • Изберете Save, а накрая копирайте и поставете резултатите в следващия Ви пост.

  • Автор

Combofix:

ComboFix 10-02-16.03 - Damian 02.2010 г. 23:23:08.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.502.172 [GMT 2:00]

Running from: d:\documents and settings\Damian\Desktop\Tool.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

D:\autorun.inf

d:\documents and settings\Administrator\Desktop\Security essentials 2010.lnk

d:\documents and settings\Administrator\Start Menu\Security essentials 2010.lnk

d:\documents and settings\Damian\Desktop\Security essentials 2010.lnk

d:\documents and settings\Damian\Start Menu\Security essentials 2010.lnk

d:\program files\Securityessentials2010

d:\program files\Securityessentials2010\SE2010.exe

d:\recycler\S-1-5-21-1405731246-2230613064-150930554-1006

d:\recycler\S-1-5-21-682003330-963894560-2146954855-1003

d:\windows\system32\18467.exe

d:\windows\system32\26500.exe

d:\windows\system32\6334.exe

d:\windows\system32\helpers32.dll

d:\windows\system32\warnings.html

.

((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))

.

2010-02-17 18:49 . 2010-02-17 18:49 -------- d-----w- d:\program files\Trend Micro

2010-02-16 17:51 . 2010-02-16 17:51 -------- d-----w- d:\documents and settings\Damian\Local Settings\Application Data\Threat Expert

2010-02-15 20:25 . 2009-11-10 08:26 767952 ----a-w- d:\windows\BDTSupport.dll

2010-02-15 20:25 . 2009-11-10 08:28 149456 ----a-w- d:\windows\SGDetectionTool.dll

2010-02-15 20:25 . 2009-11-10 08:28 1640400 ----a-w- d:\windows\PCTBDCore.dll

2010-02-15 20:25 . 2009-10-27 23:36 1152444 ----a-w- d:\windows\UDB.zip

2010-02-15 20:25 . 2008-11-26 10:08 131 ----a-w- d:\windows\IDB.zip

2010-02-15 20:25 . 2009-11-10 08:28 165840 ----a-w- d:\windows\PCTBDRes.dll

2010-02-15 20:19 . 2009-10-30 09:11 233136 ----a-w- d:\windows\system32\drivers\pctgntdi.sys

2010-02-15 20:18 . 2009-11-09 09:20 207792 ----a-w- d:\windows\system32\drivers\PCTCore.sys

2010-02-15 20:18 . 2009-10-06 14:31 87784 ----a-w- d:\windows\system32\drivers\PCTAppEvent.sys

2010-02-15 20:17 . 2009-09-03 07:45 70408 ----a-w- d:\windows\system32\drivers\pctplsg.sys

2010-02-15 20:17 . 2010-02-17 21:17 -------- d-----w- d:\program files\Spyware Doctor

2010-02-15 20:17 . 2010-02-15 20:25 -------- d-----w- d:\program files\Common Files\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\Damian\Application Data\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\All Users\Application Data\PC Tools

2010-02-15 20:16 . 2010-02-17 21:18 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP

2010-02-15 20:02 . 2010-02-15 20:02 -------- d-----w- d:\documents and settings\All Users\Application Data\Alwil Software

2010-02-15 19:52 . 2010-02-15 19:52 -------- d-----w- d:\documents and settings\Damian\Application Data\Malwarebytes

2010-02-15 19:37 . 2010-02-15 19:37 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Adobe

2010-02-15 18:32 . 2010-02-15 18:32 -------- d-----w- d:\documents and settings\Administrator\Application Data\Malwarebytes

2010-02-15 18:32 . 2010-01-07 14:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys

2010-02-15 18:25 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Microsoft

2010-02-15 18:25 . 2010-02-15 18:25 -------- d-----w- d:\documents and settings\Administrator

2010-02-15 15:21 . 2010-02-15 15:21 52224 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-02-15 15:21 . 2010-02-15 15:21 117760 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\SUPERAntiSpyware

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard

2010-02-15 15:06 . 2010-02-15 15:06 43520 ----a-w- d:\program files\lookCitesIpsum.exe

2010-02-08 06:13 . 2010-02-08 06:13 -------- d-----w- d:\program files\XLS Converter

2010-02-07 15:34 . 2010-02-17 21:58 -------- d-----w- d:\documents and settings\Damian\Application Data\MxBoost

2010-02-07 15:34 . 2010-02-11 17:56 -------- d-----w- d:\program files\Maxthon2

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-15 20:20 . 2009-10-05 18:10 -------- d-----w- d:\documents and settings\Damian\Application Data\uTorrent

2010-02-15 20:02 . 2009-04-12 11:56 -------- d-----w- d:\program files\Alwil Software

2010-02-15 18:32 . 2010-02-15 18:31 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware

2010-02-15 18:31 . 2010-02-15 18:31 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-15 18:31 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Application Data\MxBoost

2010-02-15 18:26 . 2010-02-15 18:26 -------- d-----w- d:\documents and settings\Administrator\Application Data\Avant Profiles

2010-02-10 18:53 . 2009-10-05 16:53 -------- d-----w- d:\program files\Avant Browser

2010-02-07 15:50 . 2009-11-09 19:18 -------- d-----w- d:\program files\TVAnts

2010-01-14 04:29 . 2009-04-12 12:12 21072 ----a-w- d:\documents and settings\Damian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-07 14:07 . 2010-02-15 18:31 19160 ----a-w- d:\windows\system32\drivers\mbam.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=d:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-02-27 14:10 35696 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- d:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

2005-12-21 12:02 53248 ------w- d:\program files\Realtek\InstallShield\AzMixerSel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 00:56 15360 ------w- d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

2006-03-23 09:13 77824 ----a-w- d:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

2006-03-23 09:17 118784 ----a-w- d:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

2006-03-23 09:17 94208 ----a-w- d:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

2004-08-03 22:32 208952 ----a-w- d:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-03 22:06 1667584 ------w- d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 07:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2006-06-28 11:54 16248320 ----a-w- d:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

2006-05-16 15:04 2879488 ----a-w- d:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

2010-01-05 05:56 2002160 ----a-w- d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2006-03-03 10:07 761946 ----a-w- d:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\uTorrent\\uTorrent.exe"=

"d:\\Program Files\\TVAnts\\Tvants.exe"=

R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [15.2.2010 г. 22:18 207792]

R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [05.1.2010 г. 07:56 9968]

R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.1.2010 г. 07:56 74480]

R2 Browser Defender Update Service;Browser Defender Update Service;d:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [15.2.2010 г. 22:25 112592]

S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [15.2.2010 г. 20:32 38224]

S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [05.1.2010 г. 07:56 7408]

S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [15.2.2010 г. 22:17 359624]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=15709&l=dis

IE: Send to &Bluetooth Device... - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

Trusted Zone: buy-security-essentials.com

Trusted Zone: download-soft-package.com

Trusted Zone: download-software-package.com

Trusted Zone: get-key-se10.com

Trusted Zone: is-software-download.com

Trusted Zone: buy-security-essentials.com

Trusted Zone: get-key-se10.com

.

- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Security essentials 2010 - d:\program files\Securityessentials2010\SE2010.exe

AddRemove-Български интерфейс за Nero Burning Rom v6.6.1.4 - c:\program files\Ahead\Uninstall BG interface.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-18 07:45

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

@DACL=(02 0000)

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

@DACL=(02 0000)

"NoChange"="1"

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

@DACL=(02 0000)

"Installed"="1"

@=""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(884)

d:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2616)

d:\windows\system32\shdoclc.dll

.

------------------------ Other Running Processes ------------------------

.

d:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

d:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2010-02-18 07:46:28 - machine was rebooted

ComboFix-quarantined-files.txt 2010-02-18 05:46

Pre-Run: 27 519 488 512 bytes free

Post-Run: 31 190 450 688 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 40A4C02AD6608D783C5C5630F9155D4B

HJT:

Adobe Flash Player 10 ActiveX

Adobe Reader 9.1

Avant Browser (remove only)

Browser Defender 2.0.6.11

BS.Player PRO

BSPlayer

Bulgarian Keyboards XP by G. Atanasov

HDAUDIO Soft Data Fax Modem with SmartCP

High Definition Audio Driver Package - KB888111

HijackThis 2.0.2

Intel® Graphics Media Accelerator Driver

K-Lite Codec Pack 2.50 Full

Malwarebytes' Anti-Malware

Maxthon2

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

Microsoft Word Viewer 97

MV2Player (remove only)

Nero 6 Ultra Edition

Realtek High Definition Audio Driver

SA Dictionary 2005 T2

SMSC IrCC V5.1.3600.5 SP2

Spyware Doctor 7.0

SUPERAntiSpyware Free Edition

Synaptics Pointing Device Driver

The KMPlayer 2.9.4.1434

TVAnts 1.0

WIDCOMM Bluetooth Software

WinRAR archiver

WinZip 12.0

XLS Converter 1.7.2

Стъпка 1:

Моля, отидете на Start --> Settings --> Control Panel --> Add or Remove Programs, и деинсталирайте следните програми (Ако присъстват в списъка):

Adobe Reader 9.1

След като приключим нашата работа, изтеглете и инсталирайте последната версия на Adobe Reader от:

http://www.kaldata.com/comments.php?catid=1&id=50513

Стъпка 2:

Отворете Notepad и чрез комбинацията copy/paste поставете следния текст:

Killall::


Folder::

d:\documents and settings\All Users\Application Data\Alwil Software

d:\program files\Alwil Software


DDS::

uStart Page = hxxp://www.ask.com/?o=15709&l=dis

Trusted Zone: buy-security-essentials.com

Trusted Zone: download-soft-package.com

Trusted Zone: download-software-package.com

Trusted Zone: get-key-se10.com

Trusted Zone: is-software-download.com

Trusted Zone: buy-security-essentials.com

Trusted Zone: get-key-se10.com

Запазете файла с името CFScript.txt и го поставете върху ComboFix.

CFScriptB-4.gif

След като, програмата приключи ще Ви изведе лог файла. Отново чрез комбинацията от Copy/Paste поставете информацията тук.

  • Автор

ComboFix 10-02-16.03 - Damian 02.2010 г. 9:28.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.502.325 [GMT 2:00]

Running from: d:\documents and settings\Damian\Desktop\Tool.exe

Command switches used :: d:\documents and settings\Damian\Desktop\CFScript.txt.txt

.

((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))

.

2010-02-17 18:49 . 2010-02-17 18:49 -------- d-----w- d:\program files\Trend Micro

2010-02-16 17:51 . 2010-02-16 17:51 -------- d-----w- d:\documents and settings\Damian\Local Settings\Application Data\Threat Expert

2010-02-15 20:25 . 2009-11-10 08:26 767952 ----a-w- d:\windows\BDTSupport.dll

2010-02-15 20:25 . 2009-11-10 08:28 149456 ----a-w- d:\windows\SGDetectionTool.dll

2010-02-15 20:25 . 2009-11-10 08:28 1640400 ----a-w- d:\windows\PCTBDCore.dll

2010-02-15 20:25 . 2009-10-27 23:36 1152444 ----a-w- d:\windows\UDB.zip

2010-02-15 20:25 . 2008-11-26 10:08 131 ----a-w- d:\windows\IDB.zip

2010-02-15 20:25 . 2009-11-10 08:28 165840 ----a-w- d:\windows\PCTBDRes.dll

2010-02-15 20:19 . 2009-10-30 09:11 233136 ----a-w- d:\windows\system32\drivers\pctgntdi.sys

2010-02-15 20:18 . 2009-11-09 09:20 207792 ----a-w- d:\windows\system32\drivers\PCTCore.sys

2010-02-15 20:18 . 2009-10-06 14:31 87784 ----a-w- d:\windows\system32\drivers\PCTAppEvent.sys

2010-02-15 20:17 . 2009-09-03 07:45 70408 ----a-w- d:\windows\system32\drivers\pctplsg.sys

2010-02-15 20:17 . 2010-02-17 21:17 -------- d-----w- d:\program files\Spyware Doctor

2010-02-15 20:17 . 2010-02-15 20:25 -------- d-----w- d:\program files\Common Files\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\Damian\Application Data\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\All Users\Application Data\PC Tools

2010-02-15 20:16 . 2010-02-18 05:44 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP

2010-02-15 20:02 . 2010-02-15 20:02 -------- d-----w- d:\documents and settings\All Users\Application Data\Alwil Software

2010-02-15 19:52 . 2010-02-15 19:52 -------- d-----w- d:\documents and settings\Damian\Application Data\Malwarebytes

2010-02-15 19:37 . 2010-02-15 19:37 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Adobe

2010-02-15 18:32 . 2010-02-15 18:32 -------- d-----w- d:\documents and settings\Administrator\Application Data\Malwarebytes

2010-02-15 18:32 . 2010-01-07 14:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys

2010-02-15 18:25 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Microsoft

2010-02-15 18:25 . 2010-02-15 18:25 -------- d-----w- d:\documents and settings\Administrator

2010-02-15 15:21 . 2010-02-15 15:21 52224 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-02-15 15:21 . 2010-02-15 15:21 117760 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\SUPERAntiSpyware

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard

2010-02-15 15:06 . 2010-02-15 15:06 43520 ----a-w- d:\program files\lookCitesIpsum.exe

2010-02-08 06:13 . 2010-02-08 06:13 -------- d-----w- d:\program files\XLS Converter

2010-02-07 15:34 . 2010-02-18 07:02 -------- d-----w- d:\documents and settings\Damian\Application Data\MxBoost

2010-02-07 15:34 . 2010-02-11 17:56 -------- d-----w- d:\program files\Maxthon2

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-15 20:20 . 2009-10-05 18:10 -------- d-----w- d:\documents and settings\Damian\Application Data\uTorrent

2010-02-15 20:02 . 2009-04-12 11:56 -------- d-----w- d:\program files\Alwil Software

2010-02-15 18:32 . 2010-02-15 18:31 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware

2010-02-15 18:31 . 2010-02-15 18:31 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-15 18:31 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Application Data\MxBoost

2010-02-15 18:26 . 2010-02-15 18:26 -------- d-----w- d:\documents and settings\Administrator\Application Data\Avant Profiles

2010-02-10 18:53 . 2009-10-05 16:53 -------- d-----w- d:\program files\Avant Browser

2010-02-07 15:50 . 2009-11-09 19:18 -------- d-----w- d:\program files\TVAnts

2010-01-14 04:29 . 2009-04-12 12:12 21072 ----a-w- d:\documents and settings\Damian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-07 14:07 . 2010-02-15 18:31 19160 ----a-w- d:\windows\system32\drivers\mbam.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-18_05.44.06 )))))))))))))))))))))))))))))))))))))))))

.

- 2001-08-23 14:00 . 2010-02-17 20:35 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 05:48 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 05:48 311938 d:\windows\system32\perfh009.dat

- 2001-08-23 14:00 . 2010-02-17 20:35 311938 d:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=d:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-02-27 14:10 35696 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- d:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

2005-12-21 12:02 53248 ------w- d:\program files\Realtek\InstallShield\AzMixerSel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 00:56 15360 ------w- d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

2006-03-23 09:13 77824 ----a-w- d:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

2006-03-23 09:17 118784 ----a-w- d:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

2006-03-23 09:17 94208 ----a-w- d:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

2004-08-03 22:32 208952 ----a-w- d:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-03 22:06 1667584 ------w- d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 07:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2006-06-28 11:54 16248320 ----a-w- d:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

2006-05-16 15:04 2879488 ----a-w- d:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

2010-01-05 05:56 2002160 ----a-w- d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2006-03-03 10:07 761946 ----a-w- d:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\uTorrent\\uTorrent.exe"=

"d:\\Program Files\\TVAnts\\Tvants.exe"=

R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [15.2.2010 г. 22:18 207792]

R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [05.1.2010 г. 07:56 9968]

R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.1.2010 г. 07:56 74480]

R2 Browser Defender Update Service;Browser Defender Update Service;d:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [15.2.2010 г. 22:25 112592]

S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [15.2.2010 г. 20:32 38224]

S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [05.1.2010 г. 07:56 7408]

S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [15.2.2010 г. 22:17 359624]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=15709&l=dis

IE: Send to &Bluetooth Device... - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

Trusted Zone: buy-security-essentials.com

Trusted Zone: download-soft-package.com

Trusted Zone: download-software-package.com

Trusted Zone: get-key-se10.com

Trusted Zone: is-software-download.com

Trusted Zone: buy-security-essentials.com

Trusted Zone: get-key-se10.com

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-18 10:14

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

@DACL=(02 0000)

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

@DACL=(02 0000)

"NoChange"="1"

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

@DACL=(02 0000)

"Installed"="1"

@=""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(884)

d:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(2588)

d:\windows\system32\shdoclc.dll

.

------------------------ Other Running Processes ------------------------

.

d:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

d:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2010-02-18 10:15:52 - machine was rebooted

ComboFix-quarantined-files.txt 2010-02-18 08:15

ComboFix2.txt 2010-02-18 05:46

Pre-Run: 30 968 496 128 bytes free

Post-Run: 31 149 238 272 bytes free

- - End Of File - - DF6197D16733D68F27C2BED25B2CAE25

Toва е лог файлът. Опитах се да деинсталирам адоуба, но ми дава грешка към края на процеса. Не успях да я махна.

Скриптът Ви също не се е активирал. Обърнете внимание на файла Ви, той е с име: CFScript.txt.txt , а трябва да е CFScript.txt . Повторете процедурата!

  • Автор

ComboFix 10-02-16.03 - Damian 02.2010 г. 10:24:31.3.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.502.271 [GMT 2:00]

Running from: d:\documents and settings\Damian\Desktop\Tool.exe

Command switches used :: d:\documents and settings\Damian\Desktop\CFScript.txt

.

((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))

.

2010-02-17 18:49 . 2010-02-17 18:49 -------- d-----w- d:\program files\Trend Micro

2010-02-16 17:51 . 2010-02-16 17:51 -------- d-----w- d:\documents and settings\Damian\Local Settings\Application Data\Threat Expert

2010-02-15 20:25 . 2009-11-10 08:26 767952 ----a-w- d:\windows\BDTSupport.dll

2010-02-15 20:25 . 2009-11-10 08:28 149456 ----a-w- d:\windows\SGDetectionTool.dll

2010-02-15 20:25 . 2009-11-10 08:28 1640400 ----a-w- d:\windows\PCTBDCore.dll

2010-02-15 20:25 . 2009-10-27 23:36 1152444 ----a-w- d:\windows\UDB.zip

2010-02-15 20:25 . 2008-11-26 10:08 131 ----a-w- d:\windows\IDB.zip

2010-02-15 20:25 . 2009-11-10 08:28 165840 ----a-w- d:\windows\PCTBDRes.dll

2010-02-15 20:19 . 2009-10-30 09:11 233136 ----a-w- d:\windows\system32\drivers\pctgntdi.sys

2010-02-15 20:18 . 2009-11-09 09:20 207792 ----a-w- d:\windows\system32\drivers\PCTCore.sys

2010-02-15 20:18 . 2009-10-06 14:31 87784 ----a-w- d:\windows\system32\drivers\PCTAppEvent.sys

2010-02-15 20:17 . 2009-09-03 07:45 70408 ----a-w- d:\windows\system32\drivers\pctplsg.sys

2010-02-15 20:17 . 2010-02-17 21:17 -------- d-----w- d:\program files\Spyware Doctor

2010-02-15 20:17 . 2010-02-15 20:25 -------- d-----w- d:\program files\Common Files\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\Damian\Application Data\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\All Users\Application Data\PC Tools

2010-02-15 20:16 . 2010-02-18 08:14 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP

2010-02-15 20:02 . 2010-02-15 20:02 -------- d-----w- d:\documents and settings\All Users\Application Data\Alwil Software

2010-02-15 19:52 . 2010-02-15 19:52 -------- d-----w- d:\documents and settings\Damian\Application Data\Malwarebytes

2010-02-15 19:37 . 2010-02-15 19:37 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Adobe

2010-02-15 18:32 . 2010-02-15 18:32 -------- d-----w- d:\documents and settings\Administrator\Application Data\Malwarebytes

2010-02-15 18:32 . 2010-01-07 14:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys

2010-02-15 18:25 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Microsoft

2010-02-15 18:25 . 2010-02-15 18:25 -------- d-----w- d:\documents and settings\Administrator

2010-02-15 15:21 . 2010-02-15 15:21 52224 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-02-15 15:21 . 2010-02-15 15:21 117760 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\SUPERAntiSpyware

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard

2010-02-15 15:06 . 2010-02-15 15:06 43520 ----a-w- d:\program files\lookCitesIpsum.exe

2010-02-08 06:13 . 2010-02-08 06:13 -------- d-----w- d:\program files\XLS Converter

2010-02-07 15:34 . 2010-02-18 08:16 -------- d-----w- d:\documents and settings\Damian\Application Data\MxBoost

2010-02-07 15:34 . 2010-02-11 17:56 -------- d-----w- d:\program files\Maxthon2

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-15 20:20 . 2009-10-05 18:10 -------- d-----w- d:\documents and settings\Damian\Application Data\uTorrent

2010-02-15 20:02 . 2009-04-12 11:56 -------- d-----w- d:\program files\Alwil Software

2010-02-15 18:32 . 2010-02-15 18:31 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware

2010-02-15 18:31 . 2010-02-15 18:31 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-15 18:31 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Application Data\MxBoost

2010-02-15 18:26 . 2010-02-15 18:26 -------- d-----w- d:\documents and settings\Administrator\Application Data\Avant Profiles

2010-02-10 18:53 . 2009-10-05 16:53 -------- d-----w- d:\program files\Avant Browser

2010-02-07 15:50 . 2009-11-09 19:18 -------- d-----w- d:\program files\TVAnts

2010-01-14 04:29 . 2009-04-12 12:12 21072 ----a-w- d:\documents and settings\Damian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-07 14:07 . 2010-02-15 18:31 19160 ----a-w- d:\windows\system32\drivers\mbam.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-18_05.44.06 )))))))))))))))))))))))))))))))))))))))))

.

- 2001-08-23 14:00 . 2010-02-17 20:35 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 08:18 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 08:18 311938 d:\windows\system32\perfh009.dat

- 2001-08-23 14:00 . 2010-02-17 20:35 311938 d:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=d:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-02-27 14:10 35696 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- d:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

2005-12-21 12:02 53248 ------w- d:\program files\Realtek\InstallShield\AzMixerSel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 00:56 15360 ------w- d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

2006-03-23 09:13 77824 ----a-w- d:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

2006-03-23 09:17 118784 ----a-w- d:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

2006-03-23 09:17 94208 ----a-w- d:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

2004-08-03 22:32 208952 ----a-w- d:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-03 22:06 1667584 ------w- d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 07:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2006-06-28 11:54 16248320 ----a-w- d:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

2006-05-16 15:04 2879488 ----a-w- d:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

2010-01-05 05:56 2002160 ----a-w- d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2006-03-03 10:07 761946 ----a-w- d:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\uTorrent\\uTorrent.exe"=

"d:\\Program Files\\TVAnts\\Tvants.exe"=

R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [15.2.2010 г. 22:18 207792]

R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [05.1.2010 г. 07:56 9968]

R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.1.2010 г. 07:56 74480]

R2 Browser Defender Update Service;Browser Defender Update Service;d:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [15.2.2010 г. 22:25 112592]

S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [15.2.2010 г. 20:32 38224]

S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [05.1.2010 г. 07:56 7408]

S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [15.2.2010 г. 22:17 359624]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=15709&l=dis

IE: Send to &Bluetooth Device... - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

Trusted Zone: buy-security-essentials.com

Trusted Zone: download-soft-package.com

Trusted Zone: download-software-package.com

Trusted Zone: get-key-se10.com

Trusted Zone: is-software-download.com

Trusted Zone: buy-security-essentials.com

Trusted Zone: get-key-se10.com

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-18 10:30

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

@DACL=(02 0000)

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

@DACL=(02 0000)

"NoChange"="1"

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

@DACL=(02 0000)

"Installed"="1"

@=""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(888)

d:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(3380)

d:\windows\system32\shdoclc.dll

.

------------------------ Other Running Processes ------------------------

.

d:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

d:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2010-02-18 10:32:05 - machine was rebooted

ComboFix-quarantined-files.txt 2010-02-18 08:32

ComboFix2.txt 2010-02-18 08:15

ComboFix3.txt 2010-02-18 05:46

Pre-Run: 31 166 395 392 bytes free

Post-Run: 31 144 059 904 bytes free

- - End Of File - - 2F8AA4789223A1D5898518F17B9E7715

  • Автор

ComboFix 10-02-16.03 - Damian 02.2010 г. 11:18:21.4.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1251.359.1033.18.502.274 [GMT 2:00]

Running from: d:\documents and settings\Damian\Desktop\Tool.exe

Command switches used :: d:\documents and settings\Damian\Desktop\CFScript.txt

.

((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))

.

2010-02-17 18:49 . 2010-02-17 18:49 -------- d-----w- d:\program files\Trend Micro

2010-02-16 17:51 . 2010-02-16 17:51 -------- d-----w- d:\documents and settings\Damian\Local Settings\Application Data\Threat Expert

2010-02-15 20:25 . 2009-11-10 08:26 767952 ----a-w- d:\windows\BDTSupport.dll

2010-02-15 20:25 . 2009-11-10 08:28 149456 ----a-w- d:\windows\SGDetectionTool.dll

2010-02-15 20:25 . 2009-11-10 08:28 1640400 ----a-w- d:\windows\PCTBDCore.dll

2010-02-15 20:25 . 2009-10-27 23:36 1152444 ----a-w- d:\windows\UDB.zip

2010-02-15 20:25 . 2008-11-26 10:08 131 ----a-w- d:\windows\IDB.zip

2010-02-15 20:25 . 2009-11-10 08:28 165840 ----a-w- d:\windows\PCTBDRes.dll

2010-02-15 20:19 . 2009-10-30 09:11 233136 ----a-w- d:\windows\system32\drivers\pctgntdi.sys

2010-02-15 20:18 . 2009-11-09 09:20 207792 ----a-w- d:\windows\system32\drivers\PCTCore.sys

2010-02-15 20:18 . 2009-10-06 14:31 87784 ----a-w- d:\windows\system32\drivers\PCTAppEvent.sys

2010-02-15 20:17 . 2009-09-03 07:45 70408 ----a-w- d:\windows\system32\drivers\pctplsg.sys

2010-02-15 20:17 . 2010-02-17 21:17 -------- d-----w- d:\program files\Spyware Doctor

2010-02-15 20:17 . 2010-02-15 20:25 -------- d-----w- d:\program files\Common Files\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\Damian\Application Data\PC Tools

2010-02-15 20:17 . 2010-02-15 20:17 -------- d-----w- d:\documents and settings\All Users\Application Data\PC Tools

2010-02-15 20:16 . 2010-02-18 08:30 -------- d---a-w- d:\documents and settings\All Users\Application Data\TEMP

2010-02-15 20:02 . 2010-02-15 20:02 -------- d-----w- d:\documents and settings\All Users\Application Data\Alwil Software

2010-02-15 19:52 . 2010-02-15 19:52 -------- d-----w- d:\documents and settings\Damian\Application Data\Malwarebytes

2010-02-15 19:37 . 2010-02-15 19:37 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Adobe

2010-02-15 18:32 . 2010-02-15 18:32 -------- d-----w- d:\documents and settings\Administrator\Application Data\Malwarebytes

2010-02-15 18:32 . 2010-01-07 14:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys

2010-02-15 18:25 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Local Settings\Application Data\Microsoft

2010-02-15 18:25 . 2010-02-15 18:25 -------- d-----w- d:\documents and settings\Administrator

2010-02-15 15:21 . 2010-02-15 15:21 52224 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll

2010-02-15 15:21 . 2010-02-15 15:21 117760 ----a-w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\SUPERAntiSpyware

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\documents and settings\Damian\Application Data\SUPERAntiSpyware.com

2010-02-15 15:20 . 2010-02-15 15:20 -------- d-----w- d:\program files\Common Files\Wise Installation Wizard

2010-02-15 15:06 . 2010-02-15 15:06 43520 ----a-w- d:\program files\lookCitesIpsum.exe

2010-02-08 06:13 . 2010-02-08 06:13 -------- d-----w- d:\program files\XLS Converter

2010-02-07 15:34 . 2010-02-18 08:32 -------- d-----w- d:\documents and settings\Damian\Application Data\MxBoost

2010-02-07 15:34 . 2010-02-11 17:56 -------- d-----w- d:\program files\Maxthon2

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-02-15 20:20 . 2009-10-05 18:10 -------- d-----w- d:\documents and settings\Damian\Application Data\uTorrent

2010-02-15 20:02 . 2009-04-12 11:56 -------- d-----w- d:\program files\Alwil Software

2010-02-15 18:32 . 2010-02-15 18:31 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware

2010-02-15 18:31 . 2010-02-15 18:31 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-15 18:31 . 2010-02-15 18:30 -------- d-----w- d:\documents and settings\Administrator\Application Data\MxBoost

2010-02-15 18:26 . 2010-02-15 18:26 -------- d-----w- d:\documents and settings\Administrator\Application Data\Avant Profiles

2010-02-10 18:53 . 2009-10-05 16:53 -------- d-----w- d:\program files\Avant Browser

2010-02-07 15:50 . 2009-11-09 19:18 -------- d-----w- d:\program files\TVAnts

2010-01-14 04:29 . 2009-04-12 12:12 21072 ----a-w- d:\documents and settings\Damian\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-01-07 14:07 . 2010-02-15 18:31 19160 ----a-w- d:\windows\system32\drivers\mbam.sys

.

((((((((((((((((((((((((((((( SnapShot@2010-02-18_05.44.06 )))))))))))))))))))))))))))))))))))))))))

.

- 2001-08-23 14:00 . 2010-02-17 20:35 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 08:34 40326 d:\windows\system32\perfc009.dat

+ 2001-08-23 14:00 . 2010-02-18 08:34 311938 d:\windows\system32\perfh009.dat

- 2001-08-23 14:00 . 2010-02-17 20:35 311938 d:\windows\system32\perfh009.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- d:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk

backup=d:\windows\pss\Bluetooth.lnkCommon Startup

[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]

path=d:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk

backup=d:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2009-02-27 14:10 35696 ----a-w- d:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]

2005-05-03 15:43 69632 ----a-w- d:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]

2005-12-21 12:02 53248 ------w- d:\program files\Realtek\InstallShield\AzMixerSel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]

2004-08-04 00:56 15360 ------w- d:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]

2006-03-23 09:13 77824 ----a-w- d:\windows\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]

2006-03-23 09:17 118784 ----a-w- d:\windows\system32\igfxpers.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]

2006-03-23 09:17 94208 ----a-w- d:\windows\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]

2004-08-03 22:32 208952 ----a-w- d:\windows\ime\IMJP8_1\imjpmig.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

2004-08-03 22:06 1667584 ------w- d:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]

2001-07-09 07:50 155648 ----a-w- d:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]

2004-08-03 22:32 455168 ----a-w- d:\windows\system32\IME\TINTLGNT\TINTSETP.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]

2006-06-28 11:54 16248320 ----a-w- d:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]

2006-05-16 15:04 2879488 ----a-w- d:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]

2010-01-05 05:56 2002160 ----a-w- d:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]

2006-03-03 10:07 761946 ----a-w- d:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\Program Files\\uTorrent\\uTorrent.exe"=

"d:\\Program Files\\TVAnts\\Tvants.exe"=

R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [15.2.2010 г. 22:18 207792]

R1 SASDIFSV;SASDIFSV;d:\program files\SUPERAntiSpyware\sasdifsv.sys [05.1.2010 г. 07:56 9968]

R1 SASKUTIL;SASKUTIL;d:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05.1.2010 г. 07:56 74480]

R2 Browser Defender Update Service;Browser Defender Update Service;d:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [15.2.2010 г. 22:25 112592]

S3 MBAMSwissArmy;MBAMSwissArmy;d:\windows\system32\drivers\mbamswissarmy.sys [15.2.2010 г. 20:32 38224]

S3 SASENUM;SASENUM;d:\program files\SUPERAntiSpyware\SASENUM.SYS [05.1.2010 г. 07:56 7408]

S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [15.2.2010 г. 22:17 359624]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=15709&l=dis

IE: Send to &Bluetooth Device... - d:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

Trusted Zone: buy-security-essentials.com

Trusted Zone: download-soft-package.com

Trusted Zone: download-software-package.com

Trusted Zone: get-key-se10.com

Trusted Zone: is-software-download.com

Trusted Zone: buy-security-essentials.com

Trusted Zone: get-key-se10.com

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-02-18 11:24

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]

@DACL=(02 0000)

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]

@DACL=(02 0000)

"NoChange"="1"

"Installed"="1"

@=""

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]

@DACL=(02 0000)

"Installed"="1"

@=""

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(884)

d:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(552)

d:\windows\system32\shdoclc.dll

.

------------------------ Other Running Processes ------------------------

.

d:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

d:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Completion time: 2010-02-18 11:26:09 - machine was rebooted

ComboFix-quarantined-files.txt 2010-02-18 09:26

ComboFix2.txt 2010-02-18 08:32

ComboFix3.txt 2010-02-18 08:15

ComboFix4.txt 2010-02-18 05:46

Pre-Run: 31 217 357 824 bytes free

Post-Run: 31 203 568 640 bytes free

- - End Of File - - CD9719013596BBA2E420F24F66082555

Стъпка 1:

Моля, отворете HijackThis, и изберете Do a system scan only.

Сложете отметки на следните редове:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ask.com/?o=15709&l=dis

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?o=15709&l=dis

O15 - Trusted Zone: http://*.buy-security-essentials.com

O15 - Trusted Zone: http://*.download-soft-package.com

O15 - Trusted Zone: http://*.download-software-package.com

O15 - Trusted Zone: http://*.get-key-se10.com

O15 - Trusted Zone: http://*.is-software-download.com

O15 - Trusted Zone: http://*.buy-security-essentials.com (HKLM)

O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)

След това, затворете всички отворени прозорци, освен този на HiJackThis, и изберете Fix checked.

Стъпка 2:

Обновете MalwareBytes' Anti-Malware и направете бързо сканиране. Накрая публикувайте резултата.

  • Автор

Malwarebytes' Anti-Malware 1.44

Database version: 3758

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

18.2.2010 г. 22:43:09

mbam-log-2010-02-18 (22-43-04).txt

Scan type: Quick Scan

Objects scanned: 115229

Time elapsed: 5 minute(s), 50 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 2

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-61we-kkx5-457qwe23218} (Trojan.Agent) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\SE2010 (Rogue.Securityessentials2010) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

D:\Program Files\lookCitesIpsum.exe (Trojan.FakeAlert) -> No action taken.

D:\Documents and Settings\Damian\Application Data\Microsoft\Internet Explorer\Quick Launch\Security essentials 2010.lnk (Rogue.SecurityEssentials2010) -> No action taken.

  • Автор

Съжалявам, изтрих обектите след като прочетох мнението Ви. Лошото е, че ми се спи и от несъобразителност натиснах рестарт без да запазя лог файла. Преди малко направих още един quick scan и не намери нищо.

  • Автор

Aми досадният тапет изчезна. Приложенията се отварят нормално. Видимо системата функционира нормално.

Значи можем да считаме проблема за решен? Хубаво е само да изтеглите и инсталирате някоя антивирусна и за всеки случай да направите сканиране с нея.

  • Автор

Значи можем да считаме проблема за решен? Хубаво е само да изтеглите и инсталирате някоя антивирусна и за всеки случай да направите сканиране с нея.

Toчно това исках да попитам. Коя антивирусна препоръчвате. Само да не е аваст. Благодаря за голямата помощ!

Защо да не е Avast? Вие мисля, че сте използвали версия 4, а сега вече има и версия 5, която е сериозно подобрена. Иначе варианти много: ESET NOD32 Antivirus, Microsoft Security Essentials, Avira AntiVir и прочие.

Регистрирайте се или влезете в профила си за да коментирате

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.