Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Sality и други вируси [РЕШЕН]

Featured Replies

Следвайте следните стъпки за работа с ComboFix:

1. Изтеглете ComboFix от следния мирър: от BleepingComputer.

След изтегляне на файла го запишете (бутон Save -> Save as) ComboFix на вашия десктоп, снимка:

2exprgh.jpg

След като изтеглите ComboFix на десктопа, иконката на програмата би трябвало да изглежда така:

29eqjuq.jpg

2. Затворете всички работещи приложения или отворени прозорци. Прекратете временно работата на антивирусната програма и на други програми за сигурност, ако има такива. За целта може да прегледате информацията от този линк: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs.

3. Преименувайте ComboFix.exe на ff2.exe

4. Стартирайте с двоен клик ff2.exe. За целта използвайте YES, за да се съгласите с условията за използване на програмата. Важно: след като се стартира ComboFix не бива да се движи мишката или да се кликва върху отворения прозорец на програмата. Просто търпеливо оставете ComboFix да си свърши работата (20-30 минути), без да използвате компютъра за други цели.

5. След като приключи сканирането на регистрите (Windows Registry) ComboFix ще провери дали има инсталирана Windows Recovery Console.

*Ако Windows Recovery Console е инсталирана, ComboFix ще продължи работата си.

*Ако Windows Recovery Console не е инсталирана, ще е необходимо да използвате YES за инсталация на Windows Recovery Console, виж снимката:

33wr6us.jpg

След инсталация на Windows Recovery Console потвърдете с YES, за да продължите напред. Снимка:

m9lvnk.jpg

6. ComboFix ще спре временно Интернет връзката, но след като приключи работата на програмата тази връзка ще бъде възстановена автоматично. ComboFix ще сканира за проблеми и за заразени файлове, като това може да отнеме известно време. Моля да бъдете търпеливи. Ако има проблем с Интернет връзката, моля да прочетете това: Manually restoring the Internet connection section.

Забележка: При проблеми с ComboFix копирайте (Copy) и поставете (Paste) съдържанието на C:\BUG.txt в следващия си коментар.

7. Когато работата на ComboFix приключи, ще се появи текстов документ (log) в Notepad, виж снимката:

157m978.jpg

Копирайте (Copy) и поставете (Paste) съдържанието на лога в следващия си коментар или го прикачете към коментара си.

  • Автор

ComboFix 10-03-29.04 - Plamen 03.2010 г. 22:09:28.4.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.261 [GMT 3:00]

Running from: c:\documents and settings\Plamen\Desktop\ff2.exe

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

AV: Eset NOD32 antivirus system 2.50 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\windows\wpe pro.INI

.

((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-31 )))))))))))))))))))))))))))))))

.

2010-03-31 12:12 . 2010-03-31 12:12 -------- d-----w- c:\documents and settings\Plamen\Application Data\GRETECH

2010-03-31 12:10 . 2010-03-31 12:10 -------- d-----w- c:\program files\GRETECH

2010-03-30 19:27 . 2010-03-30 19:27 -------- d-----w- c:\program files\ESET

2010-03-29 19:05 . 2010-03-29 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software

2010-03-29 18:59 . 2010-03-29 18:59 -------- d-----w- c:\program files\Uninstall Tool

2010-03-29 18:15 . 2010-03-29 18:15 -------- d-----w- c:\program files\MSECache

2010-03-28 09:55 . 2010-03-28 09:55 -------- d-----w- C:\_OTL

2010-03-27 17:57 . 2010-03-27 17:57 -------- d-----w- c:\documents and settings\Plamen\DoctorWeb

2010-03-27 08:12 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-03-27 08:12 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-03-27 08:11 . 2010-03-27 08:11 -------- d-----w- c:\program files\CCleaner

2010-03-27 07:22 . 2010-03-27 08:05 -------- d-----w- C:\HijackThis

2010-03-23 20:27 . 2010-03-23 20:27 152856 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2010-03-22 09:47 . 2010-03-28 14:41 -------- d-----w- c:\documents and settings\Plamen\Application Data\QuickScan

2010-03-19 15:43 . 2010-03-19 15:43 -------- d-----w- c:\documents and settings\Plamen\Application Data\MusicIP

2010-03-18 17:22 . 2010-03-18 17:22 -------- d-----w- c:\windows\system32\wbem\Repository

2010-03-18 17:19 . 2010-03-18 17:19 0 ----a-w- c:\windows\ativpsrm.bin

2010-03-18 17:15 . 2009-04-28 05:08 887724 ----a-w- c:\windows\system32\ativva6x.dat

2010-03-18 17:14 . 2009-04-28 05:08 3107788 ----a-w- c:\windows\system32\ativva5x.dat

2010-03-16 14:34 . 2010-03-16 14:34 -------- d-----w- c:\documents and settings\Plamen\Local Settings\Application Data\Help

2010-03-14 09:07 . 2010-03-14 09:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Panda Security

2010-03-14 09:07 . 2010-03-14 09:07 -------- d-----w- c:\program files\Panda USB Vaccine

2010-03-11 10:56 . 2010-03-11 10:56 -------- d-sh--w- c:\documents and settings\Stoqnovi\IETldCache

2010-03-10 04:58 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe

2010-03-06 05:10 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2010-03-05 09:24 . 2010-03-05 09:24 -------- d-----w- c:\documents and settings\Yavorcho\Local Settings\Application Data\Adobe

2010-03-05 09:22 . 2010-03-05 09:22 -------- d-sh--w- c:\documents and settings\Yavorcho\IETldCache

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-03-31 19:15 . 2009-09-16 05:01 -------- d-----w- c:\program files\Common Files\Akamai

2010-03-31 19:06 . 2009-09-14 14:15 -------- d-----w- c:\documents and settings\Plamen\Application Data\Skype

2010-03-31 12:25 . 2009-12-26 14:46 -------- d-----w- c:\documents and settings\Plamen\Application Data\uTorrent

2010-03-29 11:46 . 2009-11-13 20:58 -------- d-----w- c:\program files\Sandboxie

2010-03-29 11:45 . 2009-05-17 15:16 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-03-27 08:12 . 2010-02-11 11:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-03-23 16:37 . 2009-10-04 07:42 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet

2010-03-22 06:04 . 2009-05-17 15:02 -------- d-----w- c:\program files\Windows Media Connect 2

2010-03-22 06:04 . 2009-09-15 00:55 -------- d-----w- c:\program files\ViOrb

2010-03-22 06:04 . 2009-09-15 00:55 -------- d-----w- c:\program files\ViGlance

2010-03-22 06:03 . 2009-09-15 00:56 -------- d-----w- c:\program files\Thoosje Vista Sidebar

2010-03-22 06:03 . 2010-02-19 10:02 -------- d-----w- c:\program files\TeamSpeak 3 Client

2010-03-22 06:03 . 2009-08-26 06:55 -------- d-----w- c:\program files\Realtek AC97

2010-03-22 06:01 . 2009-12-25 18:27 -------- d-----w- c:\program files\Media Player Classic

2010-03-22 06:01 . 2009-06-04 11:59 -------- d-----w- c:\program files\K-Lite Codec Pack

2010-03-22 05:59 . 2009-10-09 05:31 -------- d-----w- c:\program files\Elecard MPEG2 Decoder Package 2.0

2010-03-22 05:59 . 2009-05-21 12:04 -------- d-----w- c:\program files\Common Files\snp2std

2010-03-22 05:55 . 2009-10-04 07:37 -------- d-----w- c:\program files\Bonjour

2010-03-22 05:55 . 2009-05-17 15:16 -------- d-----w- c:\program files\AvRack

2010-03-22 05:52 . 2009-07-01 12:05 -------- d-----w- c:\program files\ABBYY FineReader 5.0 Sprint

2010-03-22 05:49 . 2009-05-24 05:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro 3

2010-03-15 18:24 . 2009-09-15 00:50 -------- d-----w- c:\program files\Vista Drive Status

2010-03-14 18:42 . 2010-03-14 17:42 26032 ----a-w- c:\windows\system32\drivers\WIEH.002

2010-03-14 18:42 . 2010-03-14 17:58 48726 ----a-w- c:\windows\system32\drivers\WIEH.005

2010-03-14 18:30 . 2010-03-14 18:30 166248 ----a-w- c:\windows\system32\drivers\WIEH.009

2010-03-13 05:04 . 2009-05-17 15:24 46864 ----a-w- c:\documents and settings\Stoqnovi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-03-09 11:24 . 2010-01-30 16:14 153184 ----a-w- c:\windows\system32\aswBoot.exe

2010-03-09 11:12 . 2010-01-30 16:14 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2010-03-09 11:12 . 2010-01-30 16:14 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys

2010-03-09 11:09 . 2010-01-30 16:14 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2010-03-09 11:08 . 2010-01-30 16:14 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2010-03-09 11:08 . 2010-01-30 16:14 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys

2010-03-09 11:08 . 2010-01-30 16:14 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2010-03-09 11:08 . 2010-01-30 16:14 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2010-03-08 10:25 . 2010-02-24 12:33 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-03-05 09:23 . 2009-09-10 20:56 46864 ----a-w- c:\documents and settings\Yavorcho\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-03-02 09:28 . 2009-07-22 07:46 86979 -c--a-w- c:\windows\War3Unin.dat

2010-02-26 20:37 . 2010-02-26 16:24 69 ----a-w- c:\documents and settings\Plamen\jagex_runescape_preferences2.dat

2010-02-26 20:36 . 2010-02-26 16:16 41 ----a-w- c:\documents and settings\Plamen\jagex_runescape_preferences.dat

2010-02-26 16:14 . 2010-02-26 16:14 -------- d-----w- c:\program files\Common Files\Java

2010-02-26 16:14 . 2010-02-26 16:14 348160 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\msvcr71.dll

2010-02-26 16:14 . 2010-02-26 16:14 503808 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\msvcp71.dll

2010-02-26 16:14 . 2010-02-26 16:14 499712 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\jmc.dll

2010-02-26 16:13 . 2010-02-26 16:13 61440 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-20bf0fa7-n\decora-sse.dll

2010-02-26 16:13 . 2010-02-26 16:13 12800 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-20bf0fa7-n\decora-d3d.dll

2010-02-26 16:13 . 2010-02-26 16:13 411368 ----a-w- c:\windows\system32\deploytk.dll

2010-02-26 16:13 . 2010-02-26 16:13 -------- d-----w- c:\program files\Java

2010-02-23 21:42 . 2010-02-23 21:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Innovative Solutions

2010-02-21 19:05 . 2010-02-19 10:06 -------- d-----w- c:\documents and settings\Plamen\Application Data\TS3Client

2010-02-19 19:34 . 2009-09-14 18:38 -------- d-----w- c:\documents and settings\Plamen\Application Data\TeamViewer

2010-02-13 08:53 . 2009-11-11 18:27 -------- d-----w- c:\program files\Microsoft Silverlight

2010-02-13 08:09 . 2010-02-13 08:09 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2

2010-02-12 20:04 . 2009-09-11 20:16 46864 ----a-w- c:\documents and settings\Plamen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-12 19:49 . 2009-05-17 15:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2010-02-12 06:01 . 2009-11-11 18:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-11 18:53 . 2010-01-30 16:14 38848 ----a-w- c:\windows\system32\avastSS.scr

2010-02-11 14:01 . 2009-06-09 11:54 -------- d-----w- c:\program files\ICQ6.5

2010-02-11 11:39 . 2010-02-11 11:39 -------- d-----w- c:\documents and settings\Plamen\Application Data\Malwarebytes

2010-02-11 11:39 . 2010-02-11 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-11 10:53 . 2009-12-26 14:47 -------- d-----w- c:\program files\uTorrent

2010-02-01 09:41 . 2010-01-31 17:02 -------- d-----w- c:\documents and settings\Plamen\Application Data\MSNInstaller

2010-01-31 06:55 . 2009-09-15 14:13 -------- d-----w- c:\documents and settings\Plamen\Application Data\ICQ

.

------- Sigcheck -------

[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys

[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys

[7] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\dllcache\tcpip.sys

[-] 2008-06-20 . A29E1209F925A0E9B330E11DA5FC7BAB . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys

[7] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\ERDNT\cache\tcpip.sys

[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\$NtUninstallKB951748$\tcpip.sys

[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\tcpip.sys

[7] 2008-04-13 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\tcpip.sys

[-] 2007-07-22 . E6B15BCC470953E600EF7ADED3CAB142 . 360704 . . [5.1.2600.3002] . . c:\windows\$NtUninstallKB951748_0$\tcpip.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-02-10 319280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Plamen\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-3-22 0]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - d:\programs\FT\Flex2K.exe [2009-5-18 130048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

@="SecurityDevices"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"DriverMax"="c:\program files\Innovative Solutions\DriverMax\devices.exe" -agent

"DriverMax_RESTART"="c:\program files\Innovative Solutions\DriverMax\devices.exe" -RESTART

"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe"

"uTorrent"="c:\program files\uTorrent\uTorrent.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\ICQ6.5\\ICQ.exe"=

"d:\\Games\\World of Warcraft\\Launcher.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Plamen\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Documents and Settings\\Plamen\\Local Settings\\Apps\\2.0\\NGC4YMBX.JAO\\8R8YC5JP.1ZA\\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\\CurseClient.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

"8344:TCP"= 8344:TCP:*:Disabled:BitComet 8344 TCP

"8344:UDP"= 8344:UDP:*:Disabled:BitComet 8344 UDP

"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015

"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016

"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

"3294:TCP"= 3294:TCP:Akamai NetSession Interface

"5000:UDP"= 5000:UDP:Akamai NetSession Interface

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

"AllowOutboundPacketTooBig"= 1 (0x1)

"AllowOutboundDestinationUnreachable"= 1 (0x1)

"AllowOutboundSourceQuench"= 1 (0x1)

"AllowRedirect"= 1 (0x1)

"AllowInboundRouterRequest"= 1 (0x1)

"AllowOutboundTimeExceeded"= 1 (0x1)

"AllowOutboundParameterProblem"= 1 (0x1)

"AllowInboundTimestampRequest"= 1 (0x1)

"AllowInboundMaskRequest"= 1 (0x1)

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30.1.2010 і. 19:14 162640]

R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [04.8.2004 і. 02:56 14336]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.1.2010 і. 19:14 19024]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp --> c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp [?]

S3 LLRING0;LLRING0;\??\d:\games\mumaya\MuGuard\llck1.sys --> d:\games\mumaya\MuGuard\llck1.sys [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

Akamai REG_MULTI_SZ Akamai

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=0&l=dir

mWindow Title = Microsoft Internet Explorer

IE: &Download All with FlashGet

IE: &Download with FlashGet

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {65D8D449-C7D5-44DA-A400-64E953CE448E} = 88.87.0.2,88.87.10.2

TCP: {71C3DE41-451E-4471-9F06-2AFCDBAAF0C0} = 88.87.0.2 88.87.10.2

FF - ProfilePath - c:\documents and settings\Plamen\Application Data\Mozilla\Firefox\Profiles\xhzoy185.default\

FF - prefs.js: browser.startup.homepage - hxxp://muonline.telnet.bg/

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

.

- - - - ORPHANS REMOVED - - - -

SafeBoot-sglfb.sys

SafeBoot-tga.sys

SafeBoot-volmgr.sys

SafeBoot-volmgrx.sys

SafeBoot-wd.sys

SafeBoot-AppInfo

SafeBoot-KeyIso

SafeBoot-NTDS

SafeBoot-ProfSvc

SafeBoot-sacsvr

SafeBoot-TabletInputService

SafeBoot-TBS

SafeBoot-TrustedInstaller

SafeBoot-WinDefend

AddRemove-Adobe AIR - c:\program files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe

AddRemove-Aleo Flash Intro Banner Maker_is1 - d:\programs\Flash Intro and Banner Maker\unins000.exe

AddRemove-All ATI Software - c:\program files\ATI Technologies\UninstallAll\AtiCimUn.exe

AddRemove-DivXG400 - c:\windows\IPUI_DivXG400.exe

AddRemove-Elecard MPEG2 Decoder Package - c:\program files\Elecard MPEG2 Decoder Package 2.0\Uninstall.exe

AddRemove-HijackThis - c:\hijackthis\HijackThis.exe

AddRemove-KLiteCodecPack_is1 - c:\program files\K-Lite Codec Pack\unins000.exe

AddRemove-M953297 - c:\windows\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe

AddRemove-Media Player Classic - c:\program files\Media Player Classic\uninstall.exe

AddRemove-ViGlance - c:\program files\ViGlance\KillMe.exe

AddRemove-World of Warcraft - c:\program files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe

AddRemove-{60DE4033-9503-48D1-A483-7846BD217CA9} - c:\program files\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-03-31 22:15

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1229272821-1085031214-682003330-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2C856886-A75F-FF60-4E60-5F380E83474E}*]

"jadmhpcdbejooiajeppn"=hex:62,61,6d,62,00,00

"iadlllhifokangnhll"=hex:6b,61,65,62,66,6d,6f,64,6d,6b,67,6a,63,6d,6a,67,66,6d,

6a,70,6f,64,00,00

"jadmhpcdbejooiajepln"=hex:62,61,68,62,00,00

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(720)

c:\windows\system32\Ati2evxx.dll

.

Completion time: 2010-03-31 22:18:20

ComboFix-quarantined-files.txt 2010-03-31 19:17

Pre-Run: 3 220 193 280 bytes free

Post-Run: 3 205 140 480 bytes free

- - End Of File - - 9680BA67C2C80C65821BD427F49A4D5D

Сега отворете notepad.exe и с copy/paste въведете следната информация:

KILLALL::

SecCenter::

{E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

Fcopy::

c:\windows\ServicePackFiles\i386\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

c:\windows\ServicePackFiles\i386\tcpip.sys | c:\windows\$NtUninstallKB951748_0$\tcpip.sys

RegNull::

[HKEY_USERS\S-1-5-21-1229272821-1085031214-682003330-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2C856886-A75F-FF60-4E60-5F380E83474E}*]

Запазете файла с име CFScript и го провлачете и пуснете в Combofix, както е показано на снимката:

cfscript10uc2.gif

Забележка: По време на сканиране от страна на ComboFix не стартирайте никакви други приложения, не натискайте клавиши от клавиатурата и не местете мишката !

Публикувайте лог файла, който ще се създаде след рестарта на компютъра в следващия си коментар.

  • Автор

ComboFix 10-03-29.04 - Plamen 03.2010 г. 22:54:41.5.1 - x86

Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.511.179 [GMT 3:00]

Running from: c:\documents and settings\Plamen\Desktop\ff2.exe

Command switches used :: c:\documents and settings\Plamen\Desktop\CFScript.txt

AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

AV: Eset NOD32 antivirus system 2.50 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\tcpip.sys --> c:\windows\system32\drivers\tcpip.sys

c:\windows\ServicePackFiles\i386\tcpip.sys --> c:\windows\$NtUninstallKB951748_0$\tcpip.sys

.

((((((((((((((((((((((((( Files Created from 2010-03-01 to 2010-04-01 )))))))))))))))))))))))))))))))

.

2010-03-31 12:12 . 2010-03-31 12:12 -------- d-----w- c:\documents and settings\Plamen\Application Data\GRETECH

2010-03-31 12:10 . 2010-03-31 12:10 -------- d-----w- c:\program files\GRETECH

2010-03-30 19:27 . 2010-03-30 19:27 -------- d-----w- c:\program files\ESET

2010-03-29 19:05 . 2010-03-29 19:05 -------- d-----w- c:\documents and settings\All Users\Application Data\CrystalIdea Software

2010-03-29 18:59 . 2010-03-29 18:59 -------- d-----w- c:\program files\Uninstall Tool

2010-03-29 18:15 . 2010-03-29 18:15 -------- d-----w- c:\program files\MSECache

2010-03-28 09:55 . 2010-03-28 09:55 -------- d-----w- C:\_OTL

2010-03-27 17:57 . 2010-03-27 17:57 -------- d-----w- c:\documents and settings\Plamen\DoctorWeb

2010-03-27 08:12 . 2010-01-07 14:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-03-27 08:12 . 2010-01-07 14:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-03-27 08:11 . 2010-03-27 08:11 -------- d-----w- c:\program files\CCleaner

2010-03-27 07:22 . 2010-03-27 08:05 -------- d-----w- C:\HijackThis

2010-03-23 20:27 . 2010-03-23 20:27 152856 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2010-03-22 09:47 . 2010-03-28 14:41 -------- d-----w- c:\documents and settings\Plamen\Application Data\QuickScan

2010-03-19 15:43 . 2010-03-19 15:43 -------- d-----w- c:\documents and settings\Plamen\Application Data\MusicIP

2010-03-18 17:22 . 2010-03-18 17:22 -------- d-----w- c:\windows\system32\wbem\Repository

2010-03-18 17:19 . 2010-03-18 17:19 0 ----a-w- c:\windows\ativpsrm.bin

2010-03-18 17:15 . 2009-04-28 05:08 887724 ----a-w- c:\windows\system32\ativva6x.dat

2010-03-18 17:14 . 2009-04-28 05:08 3107788 ----a-w- c:\windows\system32\ativva5x.dat

2010-03-16 14:34 . 2010-03-16 14:34 -------- d-----w- c:\documents and settings\Plamen\Local Settings\Application Data\Help

2010-03-14 09:07 . 2010-03-14 09:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Panda Security

2010-03-14 09:07 . 2010-03-14 09:07 -------- d-----w- c:\program files\Panda USB Vaccine

2010-03-11 10:56 . 2010-03-11 10:56 -------- d-sh--w- c:\documents and settings\Stoqnovi\IETldCache

2010-03-10 04:58 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe

2010-03-06 05:10 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2010-03-05 09:24 . 2010-03-05 09:24 -------- d-----w- c:\documents and settings\Yavorcho\Local Settings\Application Data\Adobe

2010-03-05 09:22 . 2010-03-05 09:22 -------- d-sh--w- c:\documents and settings\Yavorcho\IETldCache

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2010-04-01 04:34 . 2009-12-26 14:46 -------- d-----w- c:\documents and settings\Plamen\Application Data\uTorrent

2010-04-01 04:32 . 2009-09-16 05:01 -------- d-----w- c:\program files\Common Files\Akamai

2010-03-31 19:42 . 2009-09-14 14:15 -------- d-----w- c:\documents and settings\Plamen\Application Data\Skype

2010-03-29 11:46 . 2009-11-13 20:58 -------- d-----w- c:\program files\Sandboxie

2010-03-29 11:45 . 2009-05-17 15:16 -------- d--h--w- c:\program files\InstallShield Installation Information

2010-03-27 08:12 . 2010-02-11 11:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-03-23 16:37 . 2009-10-04 07:42 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet

2010-03-22 06:04 . 2009-05-17 15:02 -------- d-----w- c:\program files\Windows Media Connect 2

2010-03-22 06:04 . 2009-09-15 00:55 -------- d-----w- c:\program files\ViOrb

2010-03-22 06:04 . 2009-09-15 00:55 -------- d-----w- c:\program files\ViGlance

2010-03-22 06:03 . 2009-09-15 00:56 -------- d-----w- c:\program files\Thoosje Vista Sidebar

2010-03-22 06:03 . 2010-02-19 10:02 -------- d-----w- c:\program files\TeamSpeak 3 Client

2010-03-22 06:03 . 2009-08-26 06:55 -------- d-----w- c:\program files\Realtek AC97

2010-03-22 06:01 . 2009-12-25 18:27 -------- d-----w- c:\program files\Media Player Classic

2010-03-22 06:01 . 2009-06-04 11:59 -------- d-----w- c:\program files\K-Lite Codec Pack

2010-03-22 05:59 . 2009-10-09 05:31 -------- d-----w- c:\program files\Elecard MPEG2 Decoder Package 2.0

2010-03-22 05:59 . 2009-05-21 12:04 -------- d-----w- c:\program files\Common Files\snp2std

2010-03-22 05:55 . 2009-10-04 07:37 -------- d-----w- c:\program files\Bonjour

2010-03-22 05:55 . 2009-05-17 15:16 -------- d-----w- c:\program files\AvRack

2010-03-22 05:52 . 2009-07-01 12:05 -------- d-----w- c:\program files\ABBYY FineReader 5.0 Sprint

2010-03-22 05:49 . 2009-05-24 05:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro 3

2010-03-15 18:24 . 2009-09-15 00:50 -------- d-----w- c:\program files\Vista Drive Status

2010-03-14 18:42 . 2010-03-14 17:42 26032 ----a-w- c:\windows\system32\drivers\WIEH.002

2010-03-14 18:42 . 2010-03-14 17:58 48726 ----a-w- c:\windows\system32\drivers\WIEH.005

2010-03-14 18:30 . 2010-03-14 18:30 166248 ----a-w- c:\windows\system32\drivers\WIEH.009

2010-03-13 05:04 . 2009-05-17 15:24 46864 ----a-w- c:\documents and settings\Stoqnovi\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-03-09 11:24 . 2010-01-30 16:14 153184 ----a-w- c:\windows\system32\aswBoot.exe

2010-03-09 11:12 . 2010-01-30 16:14 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2010-03-09 11:12 . 2010-01-30 16:14 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys

2010-03-09 11:09 . 2010-01-30 16:14 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2010-03-09 11:08 . 2010-01-30 16:14 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2010-03-09 11:08 . 2010-01-30 16:14 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys

2010-03-09 11:08 . 2010-01-30 16:14 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2010-03-09 11:08 . 2010-01-30 16:14 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2010-03-08 10:25 . 2010-02-24 12:33 664 ----a-w- c:\windows\system32\d3d9caps.dat

2010-03-05 09:23 . 2009-09-10 20:56 46864 ----a-w- c:\documents and settings\Yavorcho\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-03-02 09:28 . 2009-07-22 07:46 86979 -c--a-w- c:\windows\War3Unin.dat

2010-02-26 20:37 . 2010-02-26 16:24 69 ----a-w- c:\documents and settings\Plamen\jagex_runescape_preferences2.dat

2010-02-26 20:36 . 2010-02-26 16:16 41 ----a-w- c:\documents and settings\Plamen\jagex_runescape_preferences.dat

2010-02-26 16:14 . 2010-02-26 16:14 -------- d-----w- c:\program files\Common Files\Java

2010-02-26 16:14 . 2010-02-26 16:14 348160 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\msvcr71.dll

2010-02-26 16:14 . 2010-02-26 16:14 503808 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\msvcp71.dll

2010-02-26 16:14 . 2010-02-26 16:14 499712 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4cc317f3-n\jmc.dll

2010-02-26 16:13 . 2010-02-26 16:13 61440 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-20bf0fa7-n\decora-sse.dll

2010-02-26 16:13 . 2010-02-26 16:13 12800 ----a-w- c:\documents and settings\Plamen\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-20bf0fa7-n\decora-d3d.dll

2010-02-26 16:13 . 2010-02-26 16:13 411368 ----a-w- c:\windows\system32\deploytk.dll

2010-02-26 16:13 . 2010-02-26 16:13 -------- d-----w- c:\program files\Java

2010-02-23 21:42 . 2010-02-23 21:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Innovative Solutions

2010-02-21 19:05 . 2010-02-19 10:06 -------- d-----w- c:\documents and settings\Plamen\Application Data\TS3Client

2010-02-19 19:34 . 2009-09-14 18:38 -------- d-----w- c:\documents and settings\Plamen\Application Data\TeamViewer

2010-02-13 08:53 . 2009-11-11 18:27 -------- d-----w- c:\program files\Microsoft Silverlight

2010-02-13 08:09 . 2010-02-13 08:09 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2

2010-02-12 20:04 . 2009-09-11 20:16 46864 ----a-w- c:\documents and settings\Plamen\Local Settings\Application Data\GDIPFONTCACHEV1.DAT

2010-02-12 19:49 . 2009-05-17 15:05 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2010-02-12 06:01 . 2009-11-11 18:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help

2010-02-11 18:53 . 2010-01-30 16:14 38848 ----a-w- c:\windows\system32\avastSS.scr

2010-02-11 14:01 . 2009-06-09 11:54 -------- d-----w- c:\program files\ICQ6.5

2010-02-11 11:39 . 2010-02-11 11:39 -------- d-----w- c:\documents and settings\Plamen\Application Data\Malwarebytes

2010-02-11 11:39 . 2010-02-11 11:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2010-02-11 10:53 . 2009-12-26 14:47 -------- d-----w- c:\program files\uTorrent

2010-02-01 09:41 . 2010-01-31 17:02 -------- d-----w- c:\documents and settings\Plamen\Application Data\MSNInstaller

2010-01-31 06:55 . 2009-09-15 14:13 -------- d-----w- c:\documents and settings\Plamen\Application Data\ICQ

.

((((((((((((((((((((((((((((( SnapShot@2010-03-31_19.15.26 )))))))))))))))))))))))))))))))))))))))))

.

+ 2010-03-31 20:01 . 2010-03-31 20:01 16384 c:\windows\Temp\Perflib_Perfdata_5ec.dat

+ 2010-04-01 04:32 . 2010-04-01 04:32 16384 c:\windows\Temp\Perflib_Perfdata_5e8.dat

+ 2010-03-31 20:01 . 2010-03-31 20:01 16384 c:\windows\Temp\Perflib_Perfdata_57c.dat

- 2010-03-30 04:18 . 2010-03-30 04:18 16384 c:\windows\Temp\Perflib_Perfdata_57c.dat

+ 2010-04-01 04:32 . 2010-04-01 04:32 16384 c:\windows\Temp\Perflib_Perfdata_578.dat

+ 2007-07-22 11:16 . 2008-04-13 22:50 361344 c:\windows\system32\dllcache\tcpip.sys

+ 2010-02-12 06:00 . 2008-04-13 22:50 361344 c:\windows\$NtUninstallKB951748_0$\tcpip.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-02-10 319280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]

"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-21 35760]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\Plamen\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-3-22 0]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

FlexType 2K.lnk - d:\programs\FT\Flex2K.exe [2009-5-18 130048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]

"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]

@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]

@="IEEE 1394 Bus host controllers"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]

@="SBP2 IEEE 1394 Devices"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]

@="SecurityDevices"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"DriverMax"="c:\program files\Innovative Solutions\DriverMax\devices.exe" -agent

"DriverMax_RESTART"="c:\program files\Innovative Solutions\DriverMax\devices.exe" -RESTART

"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe"

"uTorrent"="c:\program files\uTorrent\uTorrent.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\ICQ6.5\\ICQ.exe"=

"d:\\Games\\World of Warcraft\\Launcher.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Documents and Settings\\Plamen\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Documents and Settings\\Plamen\\Local Settings\\Apps\\2.0\\NGC4YMBX.JAO\\8R8YC5JP.1ZA\\curs..tion_eee711038731a406_0004.0000_152ef8e82e8f5a48\\CurseClient.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

"8344:TCP"= 8344:TCP:*:Disabled:BitComet 8344 TCP

"8344:UDP"= 8344:UDP:*:Disabled:BitComet 8344 UDP

"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015

"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016

"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

"AllowOutboundPacketTooBig"= 1 (0x1)

"AllowOutboundDestinationUnreachable"= 1 (0x1)

"AllowOutboundSourceQuench"= 1 (0x1)

"AllowRedirect"= 1 (0x1)

"AllowInboundRouterRequest"= 1 (0x1)

"AllowOutboundTimeExceeded"= 1 (0x1)

"AllowOutboundParameterProblem"= 1 (0x1)

"AllowInboundTimestampRequest"= 1 (0x1)

"AllowInboundMaskRequest"= 1 (0x1)

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30.1.2010 і. 19:14 162640]

R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [04.8.2004 і. 02:56 14336]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30.1.2010 і. 19:14 19024]

S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp --> c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp [?]

S3 LLRING0;LLRING0;\??\d:\games\mumaya\MuGuard\llck1.sys --> d:\games\mumaya\MuGuard\llck1.sys [?]

S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

Akamai REG_MULTI_SZ Akamai

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.ask.com/?o=0&l=dir

mWindow Title = Microsoft Internet Explorer

uInternet Settings,ProxyOverride = *.local

IE: &Download All with FlashGet

IE: &Download with FlashGet

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

TCP: {65D8D449-C7D5-44DA-A400-64E953CE448E} = 88.87.0.2,88.87.10.2

TCP: {71C3DE41-451E-4471-9F06-2AFCDBAAF0C0} = 88.87.0.2 88.87.10.2

FF - ProfilePath - c:\documents and settings\Plamen\Application Data\Mozilla\Firefox\Profiles\xhzoy185.default\

FF - prefs.js: browser.startup.homepage - hxxp://muonline.telnet.bg/

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-04-01 07:34

Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]

"ImagePath"="\??\c:\docume~1\Plamen\LOCALS~1\Temp\WCS6E.tmp"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]

"ImagePath"="c:\windows\system32\GameMon.des -service"

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(720)

c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(2548)

c:\windows\system32\WININET.dll

c:\windows\system32\newdll.dll

c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\windows\system32\wpdshserviceobj.dll

c:\windows\system32\portabledevicetypes.dll

c:\windows\system32\portabledeviceapi.dll

.

------------------------ Other Running Processes ------------------------

.

c:\windows\system32\Ati2evxx.exe

c:\program files\Alwil Software\Avast5\AvastSvc.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\Ati2evxx.exe

c:\windows\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe

.

**************************************************************************

.

Completion time: 2010-04-01 07:38:22 - machine was rebooted

ComboFix-quarantined-files.txt 2010-04-01 04:38

ComboFix2.txt 2010-03-31 19:18

Pre-Run: 3 213 332 480 bytes free

Post-Run: 3 173 269 504 bytes free

- - End Of File - - CF277AFBE5CC48CDB2D4E4A09F36D190

Дотук добре. Ето какво следва:

Стъпка 1

Трябва да се махнат някои остатъци от ESET NOD32. Ето един начин:

  • Start -> Run -> пишете wbemtest -> OK.
  • Изберете Connect и напишете root\SecurityCenter -> натиснете Connect -> изберете Query -> въведете командата SELECT * FROM AntivirusProduct и натиснете Apply
  • Проверете списъка за стената на NOD32 и го изтрийте.

Стъпка 2

Деинсталирайте Combofix. Ето как: Start -> Run -> въведете Combofix /Uninstall -> (има празно място между Combofix и /Uninstall) -> Enter => това ще стартира и ще деинсталира Combofix, ще изтрие и файловете, асоциирани с този инструмент, както и папката C:\Qoobox - карантината на Combofix.

Стъпка 3

Деинсталирайте OTL. Ето как: стартирайте OTL.exe още веднъж и натиснете бутона CleanUp!

35hfp21.jpg

Стъпка 4

Изтеглете и инсталирайте Service Pack 3 за Windows XP.

  • Автор

Благодаря ви много. Само имам няколко въпроса.

1. Как да защитя си системата си оптимално?

2. Как да предотвратя отново появяването?

3. Ако можете да ми препоръчате комплект от програми с които редовно да сканирам.

  • Автор

Така готов съм. Чух от 1 приятел че той си направил Гоуст копие на твърдите дискове и всяка вечер възтановявал към него като изнасял данните си на собствен сървър. Това възможно ли е да предотврати поява и разпостранение на вирус ?

Сега следва една проверка с MBAM. Съгласно Стъпка 3 от тази тема.

P.S. Съществуват невероятно много начини за защита от загуба на данни, било то с програми, които са в добавка на Windows XP SP3 (Third Party) или без. Най-простото е да се огледа добре Windows XP и да се използват по-пълноценно инструментите, които предлага.

  • Автор

Ако може да ми кажете вие до колко часа ще стоите буден за да знам дали да чакам лога :)

  • Автор

Malwarebytes' Anti-Malware 1.44

Database version: 3920

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

02.4.2010 г. 06:01:23

mbam-log-2010-04-02 (06-01-23).txt

Scan type: Full Scan (C:\|D:\|)

Objects scanned: 241978

Time elapsed: 1 hour(s), 19 minute(s), 36 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Много добре! Сега остава да споделите как се държи Windows, има ли проблеми с приложенията, как е Интернет връзката.

P.S. Препоръчвам да използвате безплатната версия на MBAM, като проверявате периодично. Също така може да използвате CCleaner за периодично почистване, JavaRA за махане на стари версии на Java, както и да обновявате операционната система и инсталираните програми. Препоръчително е да инсталирате в бъдеще някоя защитна стена, но първо огледайте форума. Има достатъчно информация.

  • Автор

Здравейте. За сега компютъра се държи доста добре. Ако може да ми препоръчате защитна стена която не товари до толкова много компютъра, както и ако може да ми кажете с коя програма да си правя бекъпи на твърдите дискове и вечер да го възтановявам.

Здравейте. За сега компютъра се държи доста добре. Ако може да ми препоръчате защитна стена която не товари до толкова много компютъра, както и ако може да ми кажете с коя програма да си правя бекъпи на твърдите дискове и вечер да го възтановявам.

Кажи поне какъв ти е процесорът и с колко RAM разполагаш, че това ''да не товари много'' е много относително.:rolleyes:

Добре, в такъв случай ще добавя в заглавието на темата, че случаят е приключен (РЕШЕН).

В бъдеще използвайте антивирусни програми, защитни стени или други програми за сигурност само с валиден лиценз, в никакъв случай пачнати, кракнати или с фалшив лиценз. Във форума има достатъчно промоции за платени програми, както и информация за безплатни приложения за сигурност. Използвайте Skype по този начин, за да намалите възможността за зараза.

Засега може да комбинирате някоя защитна стена с Avast, ако сте свикнали и харесвате програмата. PC Tools Firewall Plus може би се ще комбинира добре с Avast, ето свежа справка от форумите на avast.

Препоръчвам в бъдеще, ако сте се решили да останете с Windows XP да направите чиста инсталация (с триене на дялове и създаване, после бърз формат и инсталация) и да не използвате FlexType. Има далеч по-лесни и безплатни варианти за "кирилизация" и фонетика, например този.

Ако може да ми препоръчате защитна стена която не товари до толкова много компютъра, както и ако може да ми кажете с коя програма да си правя бекъпи на твърдите дискове и вечер да го възтановявам.

Коя защитна стена използвате и защо?

Засега темата се затваря. nexusbg, ако имате желание да пишете в нея, напишете ми ЛС и аз ще я отворя. Във форума има доста теми за защита на Windows, за кирилизация и т.н.

Успех!

Гост
Тази тема е заключена за нови отговори.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.