Премини към съдържанието
Форумът в приложение

По-лесно сърфиране. Научи повече.

Kaldata.com - Форуми

Приложение на форума на цял екран с push известия, значки и други.

За да инсталирате това приложение на iOS и iPadOS
  1. Докоснете Иконата за споделяне в Safari
  2. Превъртете менюто и докоснете Добавяне към началния екран.
  3. Докоснете Добавяне в горния десен ъгъл.
За да инсталирате това приложение на Android
  1. Докоснете менюто с 3 точки (⋮) в горния десен ъгъл на браузъра.
  2. Докоснете Добавяне към началния екран или Инсталиране на приложение.
  3. Потвърдете, като докоснете Инсталиране.

Добре дошли!

Добре дошли в нашите форуми, пълни с полезна информация. Имате проблем с компютъра или телефона си? Публикувайте нова тема и ще намерите решение на всичките си проблеми. Общувайте свободно и открийте безброй нови приятели.

Моля, регистрирайте се за да публикувате тема и да получите пълен достъп до всички функции.

 

Поразии след conficker

Featured Replies

Супер...!Сега започни по инструкциите в пост 25.....!:)

  • Отговори 76
  • Прегледи 8,7k
  • Създадено
  • Последен отговор
  • Автор

Да попитам само информативно, от този изкоренихме ли гадинката и ако да, дали пак има шанс да се зарази? Изпълнението на пост #24 няма да е толкова лесно, защото има рестрикции, VLAN-ове и други все хубави неща, но започвам да работя по въпроса да ги сканирам така мрежово. Поздрави!

Да попитам само информативно, от този изкоренихме ли гадинката и ако да, дали пак има шанс да се зарази?

Ако дадете един лог DDS ще ви кажа...!Но мисля че с още едно пълно сканиране с Malwarebytes' Anti-Malware или Microsoft Malicious Software Removal Tool нещата ще си дойдат на мястото...за тази машина.

  • Автор

DDS (Ver_2011-09-30.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by Administrator at 12:47:29 on 2012-06-22
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.511.206 [GMT 3:00]
.
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:Program FilesAVAST SoftwareAvastAvastSvc.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
C:WINDOWSSystem32alg.exe
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSExplorer.EXE
C:Program FilesAdobeAcrobat 7.0DistillrAcrotray.exe
C:Program FilesAVAST SoftwareAvastavastUI.exe
C:WINDOWSsystem32VNICMon.exe
C:Program FilesAdobeAcrobat 7.0DistillrAcroDist.exe
C:Program FilesAdobeAcrobat 7.0Acrobatacrobat_sl.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSsystem32svchost.exe -k DcomLaunch
C:WINDOWSsystem32svchost.exe -k rpcss
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = hxxp://192.168.0.9/
uProxyServer = 192.168.0.4:3128
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:program filesadobeacrobat 7.0activexAcroIEHelper.dll
BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
mRun: [Acrobat Assistant 7.0] "c:program filesadobeacrobat 7.0distillrAcrotray.exe"
mRun: [Synchronization Manager] c:windowssystem32mobsync.exe /logon
mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui
mRun: [NIC Monitor] VNICMon.exe
dRun: [CTFMON.EXE] c:windowssystem32ctfmon.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobea~1.lnk - c:windowsinstaller{ac76ba86-1033-0000-7760-000000000002}SC_Acrobat.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~1.lnk - c:program filesmicrosoft officeofficeOSA9.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-WindowsSystem: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Convert link target to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1173263183406
TCP: Interfaces{712FAC7E-D530-4E5E-A378-68A1E239E603} : NameServer = 192.168.0.158
TCP: Interfaces{7F8696AA-D5F3-447A-94DD-707987820422} : NameServer = 192.168.0.158
.
============= SERVICES / DRIVERS ===============
.
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:windowssystem32driverssi3112r.sys [2004-6-9 97873]
R0 SiWinAcc;SiWinAcc;c:windowssystem32driversSiWinAcc.sys [2004-6-9 10240]
R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-2-10 435032]
R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-2-10 314456]
R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-2-10 20568]
R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-2-10 44768]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2011-9-8 22344]
R4 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2011-10-28 654408]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Услуга на Google Актуализация (gupdate);c:program filesgoogleupdateGoogleUpdate.exe [2011-11-21 136176]
S3 gupdatem;Услуга на Google Актуализация (gupdatem);c:program filesgoogleupdateGoogleUpdate.exe [2011-11-21 136176]
S3 VNICPKT5;VNICPKT5 Protocol Driver;c:windowssystem32VNICPKT5.sys [2012-2-24 16066]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-06-22 09:44:59 -------- d-----w- c:documents and settingsadministratorapplication dataMalwarebytes
2012-06-22 09:06:24 2380 ----a-w- C:8.reg
2012-06-22 09:06:24 2208 ----a-w- C:9.reg
2012-06-22 09:06:24 2198 ----a-w- C:5.reg
2012-06-22 09:06:24 1902 ----a-w- C:6.reg
2012-06-22 09:06:24 1898 ----a-w- C:7.reg
2012-06-22 09:06:23 2168 ----a-w- C:3.reg
2012-06-22 09:06:23 2158 ----a-w- C:2.reg
2012-06-22 09:06:23 2146 ----a-w- C:1.reg
2012-06-22 09:06:23 1896 ----a-w- C:4.reg
2012-06-22 09:06:22 2644 ----a-w- C:avexport.bat
2012-06-19 06:41:20 -------- d-s---w- C:ComboFix
2012-06-18 11:49:39 333952 -c----w- c:windowssystem32dllcachesrv.sys
2012-06-18 11:49:25 337408 -c----w- c:windowssystem32dllcachenetapi32.dll
2012-06-18 11:49:03 -------- d--h--w- c:windows$hf_mig$
2012-06-18 11:49:01 455296 -c----w- c:windowssystem32dllcachemrxsmb.sys
2012-06-18 11:03:29 -------- d-sha-r- C:cmdcons
2012-06-18 09:51:37 98816 ----a-w- c:windowssed.exe
2012-06-18 09:51:37 256000 ----a-w- c:windowsPEV.exe
2012-06-18 09:51:37 208896 ----a-w- c:windowsMBR.exe
2012-06-04 14:08:08 -------- d-----w- c:program filesPaintStar
2012-06-04 14:07:57 -------- d-----w- C:paintstar
2012-05-29 11:45:37 -------- d-----w- c:documents and settingsall usersapplication dataDAEMON Tools Lite
.
==================== Find3M  ====================
.
2012-04-04 12:56:40 22344 ----a-w- c:windowssystem32driversmbam.sys
.
============= FINISH: 12:47:51.70 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-09-30.01)
.
Microsoft Windows XP Professional
Boot Device: DeviceHarddiskVolume1
Install Date: 11/18/2006 5:33:12 PM
System Uptime: 6/22/2012 12:42:32 PM (0 hours ago)
.
Motherboard: http://www.abit.com.tw/ |  | AN7 (nVidia-nForce2)
Processor: AMD Athlon(tm) XP | Socket A | 2088/166mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 15 GiB total, 0.924 GiB free.
D: is FIXED (NTFS) - 60 GiB total, 53.048 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP20: 3/21/2012 9:58:20 AM - System Checkpoint
RP21: 3/26/2012 9:38:39 AM - System Checkpoint
RP22: 4/2/2012 8:45:44 AM - System Checkpoint
RP23: 4/3/2012 10:41:16 AM - System Checkpoint
RP24: 4/6/2012 2:20:20 PM - System Checkpoint
RP25: 4/23/2012 9:54:06 AM - System Checkpoint
RP26: 4/24/2012 10:14:46 AM - System Checkpoint
RP27: 5/8/2012 11:25:03 AM - System Checkpoint
RP28: 5/10/2012 10:14:50 AM - System Checkpoint
RP29: 5/15/2012 9:17:10 AM - System Checkpoint
RP30: 5/16/2012 9:23:59 AM - System Checkpoint
RP31: 5/23/2012 8:34:25 AM - System Checkpoint
RP32: 5/28/2012 10:36:36 AM - System Checkpoint
RP33: 5/31/2012 9:25:25 AM - System Checkpoint
RP34: 6/1/2012 12:19:35 PM - System Checkpoint
RP35: 6/6/2012 9:27:42 AM - System Checkpoint
RP36: 6/12/2012 9:56:55 AM - System Checkpoint
RP37: 6/18/2012 12:49:42 PM - combo_fix
RP38: 6/18/2012 2:49:12 PM - Installed Windows XP KB957097.
RP39: 6/18/2012 2:49:34 PM - Installed Windows XP KB958644.
RP40: 6/18/2012 2:49:46 PM - Installed Windows XP KB958687.
RP41: 6/18/2012 2:50:13 PM - Installed Windows XP KB957097.
RP42: 6/18/2012 2:50:25 PM - Installed Windows XP KB958644.
RP43: 6/18/2012 2:50:39 PM - Installed Windows XP KB958687.
RP44: 6/18/2012 2:53:36 PM - Installed Microsoft Fix it 50471
RP45: 6/22/2012 12:26:56 PM - System Checkpoint
.
==== Installed Programs ======================
.
МаксИнфо Про 2.3
Adobe Acrobat 7.0 Professional
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Stock Photos 1.0
avast! Free Antivirus
Data Access Objects (DAO) 3.5
Google Земя
Google Chrome
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2484832)
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2498911)
Hotfix for Windows XP (KB954550-v5)
Malwarebytes Anti-Malware, версия 1.61.0.1400
MapInfo ODBC Support
MapInfo Professional 10.5
MapInfo Professional 11.0
MapInfo Professional 5.0
MapInfo Professional 7.5 SCP
MapInfo Professional 9.0
MapperG for MapInfo Pro
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Access database engine 2010 (English)
Microsoft Office 2000 Professional
Microsoft Office Access database engine 2007 (English)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
MSXML 4.0 SP2 (KB927978)
MSXML 6.0 Parser (KB933579)
NICSET
NVIDIA Drivers
OLE DB Service Provider
OpenOffice.org 2.0
PaintStar 2.70
SA Dictionary 2004 Datacenter
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Setup1
SetupAddresses
SpTTpack «Remove» DataMap FontPack
Surfer 8 Demo
Total Commander (Remove or Repair)
TrueCrypt
Vertical Mapper 3.0
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Imaging Component
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
6/18/2012 5:13:24 PM, error: Service Control Manager [7034]  - The MBAMService service terminated unexpectedly.  It has done this 1 time(s).
6/18/2012 5:13:21 PM, error: Service Control Manager [7034]  - The Print Spooler service terminated unexpectedly.  It has done this 1 time(s).
6/18/2012 5:13:21 PM, error: Service Control Manager [7034]  - The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).
6/18/2012 1:58:52 PM, error: NETLOGON [5719]  - No Domain Controller is available for domain DMEUROPE due to the following:  There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
6/15/2012 10:54:45 AM, error: Service Control Manager [7026]  - The following boot-start or system-start driver(s) failed to load:  atapi PCIIde
6/15/2012 10:54:45 AM, error: Service Control Manager [7023]  - The Windows Helper service terminated with the following error:  The specified module could not be found.
6/15/2012 10:54:45 AM, error: Service Control Manager [7023]  - The Shell Helper service terminated with the following error:  The specified module could not be found.
6/15/2012 10:54:45 AM, error: Service Control Manager [7023]  - The Server Boot service terminated with the following error:  The specified module could not be found.
6/15/2012 10:54:45 AM, error: Service Control Manager [7023]  - The Security Shell service terminated with the following error:  The specified module could not be found.
6/15/2012 10:54:45 AM, error: Service Control Manager [7023]  - The Network Monitor service terminated with the following error:  The specified module could not be found.
6/15/2012 10:53:28 AM, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Update Monitor service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Update Config service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Time Helper service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Task Support service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Task Microsoft service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Support Boot service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Shell Task service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Server Update service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Server Center service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Security Boot service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The pzivqo service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Manager Support service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Helper Time service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Helper Installer service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Driver Universal service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Config Image service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Center Microsoft service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The brboha service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Boot Task service terminated with the following error:  The specified module could not be found.
6/15/2012 10:38:46 AM, error: Service Control Manager [7023]  - The Boot Server service terminated with the following error:  The specified module could not be found.
.
==== End Of File ===========================

Добре изглежда....!Тези файлове:

2012-06-22 09:06:24 2380 ----a-w- C:8.reg
2012-06-22 09:06:24 2208 ----a-w- C:9.reg
2012-06-22 09:06:24 2198 ----a-w- C:5.reg
2012-06-22 09:06:24 1902 ----a-w- C:6.reg
2012-06-22 09:06:24 1898 ----a-w- C:7.reg
2012-06-22 09:06:23 2168 ----a-w- C:3.reg
2012-06-22 09:06:23 2158 ----a-w- C:2.reg
2012-06-22 09:06:23 2146 ----a-w- C:1.reg
2012-06-22 09:06:23 1896 ----a-w- C:4.reg

..предполагам са от някоя програма...За сега изчакваме резултат от мрежовото сканиране..После ще ти дам един инструмент - мрежов скенер за проверка за наличие на Conficker в цялата ти налична мрежа..! :)

  • Автор

За reg файловете ти пратих ЛС. Успях да сканирам един компютър през мрежата, но нещо не дава логове?

Ето го въпросния лог:

Ok Loading BitDefender Engines
State 0
Sleeping 3 seconds...
Found so far : 0x0 files/regs
Searching for Downadup file ....
   - System folder
   - Temporary folder
   - Program Files
   - Application Data
Found so far : 0x0 files/regs
No Traces of Downadup Worm were found
Ok Loading BitDefender Engines
State 0
Sleeping 3 seconds...
Found so far : 0x0 files/regs
Searching for Downadup file ....
   - System folder
   - Temporary folder
   - Program Files
   - Application Data
Found so far : 0x0 files/regs
No Traces of Downadup Worm were found

Поздрави!

Редактирано от Limitless (преглед на промените)

  • Автор

Това е от една, конкретно с тази която се занимавахме. Сега почнах и останалите. А има ли опция да ги изтегля автоматично, защото лог файла се генерира на C: на компютъра?

Това е от една, конкретно с тази която се занимавахме.....

Нормално да е чист...ние го оправихме него ръчно....! ;)

  • Автор

Ако може да споделиш другия инструмент, за conficker, защото този твърди, че компютрите са чисти и с тези ограничения по мрежата ни, ми създава малко допълнителни главоболия. Поздрави!

....и с тези ограничения по мрежата ни, ми създава малко допълнителни главоболия.

Да..да ги премахнем...щом имате инсталирани кръпките и фиксовете,няма опастност за разпространение на червея..!

Отворете и настройките на мрежовата карта и този път сложете отметката пред File and Printer Sharing for Microsoft Networks и потвърдете с ОК.

Публикувано изображение

Освен това:

Изтеглете файла Conficker_registry_fix_1.rar и го разархивирайте на десктопа.

Стартирайте файла conficker-fix.reg и се съгласете с всички предупреждения.С този фикс ще премахнем ограниченията по мрежата.

  • 2 седмици по-късно...
  • Автор

Интересно, сканирах цялата мрежа с конфикер скенера и нищо не откри... Съжалявам, нямах възможност последните 2 седмици да пиша. Шерването не може да се спре, необходимо е. Ще трябва всеки един по един да се изчисти... Поздрави!

Интересно, сканирах цялата мрежа с конфикер скенера и нищо не откри...

Ще трябва всеки един по един да се изчисти...

Поздрави!

Подгответе контролни дневници с програмата DDS за всички машини ....!

  • 2 седмици по-късно...
  • Автор

Здравей, последната седмица имах много работа и не можех да обърна внимание на проблема с вирусите. Прикачвам лог на 2рата машина от ComboFix и DDS. Ако може да кажеш как е и евентуални предписания. Благодаря предварително!

ComboFix:

ComboFix 12-07-13.02 - Administrator 07.2012 ?.  17:34:37.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.511.21 [GMT 3:00]
Running from: c:documents and settingsAdministratorDesktopBorba s virusiComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *Disabled* {EDC10449-64D1-46c7-A59A-EC20D662F26D}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:documents and settingsNatalN.DATAMAPWINDOWS
c:documents and settingswizardWINDOWS
c:program filesDaemonTools_WhenUSave_Installer
c:program filesDaemonTools_WhenUSave_Installervvsn.cfg
c:windowspkunzip.pif
c:windowspkzip.pif
c:windowssystem32dllcachedlimport.exe
.
.
(((((((((((((((((((((((((   Files Created from 2012-06-13 to 2012-07-13  )))))))))))))))))))))))))))))))
.
.
2012-07-09 08:39 . 2008-12-11 10:57 333952 -c----w- c:windowssystem32dllcachesrv.sys
2012-07-09 08:39 . 2008-10-15 16:34 337408 -c----w- c:windowssystem32dllcachenetapi32.dll
2012-07-09 08:38 . 2008-10-24 11:21 455296 -c----w- c:windowssystem32dllcachemrxsmb.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-31 14:12 . 2012-02-22 07:11 26739584 ----a-w- c:program filesAdbeRdr910_en_US.exe
2011-12-17 05:04 . 2012-03-20 08:42 121816 ----a-w- c:program filesmozilla firefoxcomponentsbrowsercomps.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionexplorershelliconoverlayidentifiers00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOTCLSID{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:program filesAVAST SoftwareAvastashShell.dll
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"SoundMAXPnP"="c:program filesAnalog DevicesCoresmax4pnp.exe" [2006-07-20 847872]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2006-02-13 7557120]
"nwiz"="nwiz.exe" [2006-02-13 1519616]
"NvMediaCenter"="c:windowssystem32NvMcTray.dll" [2006-02-13 86016]
"Synchronization Manager"="c:windowssystem32mobsync.exe" [2008-04-14 143360]
"Acrobat Assistant 7.0"="c:program filesAdobeAcrobat 7.0DistillrAcrotray.exe" [2004-12-14 483328]
"Malwarebytes' Anti-Malware"="c:program filesMalwarebytes' Anti-Malwarembamgui.exe" [2011-12-24 460872]
"avast"="c:program filesAVAST SoftwareAvastavastUI.exe" [2011-11-28 3744552]
"Adobe Reader Speed Launcher"="c:program filesAdobeReader 9.0ReaderReader_sl.exe" [2009-02-27 35696]
.
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
.
c:documents and settingsnataln.DMEUROPEStart MenuProgramsStartup
OpenOffice.org 2.0.lnk - c:program filesOpenOffice.org 2.0programquickstart.exe [2006-1-25 61440]
.
c:documents and settingsRoniDStart MenuProgramsStartup
OpenOffice.org 2.0.lnk - c:program filesOpenOffice.org 2.0programquickstart.exe [2006-1-25 61440]
.
c:documents and settingsCvetiBStart MenuProgramsStartup
OpenOffice.org 2.0.lnk - c:program filesOpenOffice.org 2.0programquickstart.exe [2006-1-25 61440]
.
c:documents and settingsAll UsersStart MenuProgramsStartup
Adobe Acrobat Speed Launcher.lnk - c:windowsInstaller{AC76BA86-1033-0000-7760-000000000002}SC_Acrobat.exe [2006-11-7 25214]
Adobe Gamma.lnk - c:program filesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe [2005-3-16 113664]
Microsoft Office.lnk - c:program filesMicrosoft OfficeOfficeOSA9.EXE [1999-2-17 65588]
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversiongroup policystateS-1-5-21-606747145-2111687655-839522115-1162ScriptsLogon00]
"Script"=BORALogon.bat.txt
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversiongroup policystateS-1-5-21-606747145-2111687655-839522115-1164ScriptsLogon00]
"Script"=BORALogon.bat.txt
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversiongroup policystateS-1-5-21-606747145-2111687655-839522115-1167ScriptsLogon00]
"Script"=BORALogon.bat.txt
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversiongroup policystateS-1-5-21-606747145-2111687655-839522115-1168ScriptsLogon00]
"Script"=BORALogon.bat.txt
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%system32sessmgr.exe"=
"c:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binApache.exe"=
"%windir%Network Diagnosticxpnetdiag.exe"=
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"4081:TCP"= 4081:TCP:dqwlmys
.
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileIcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
"AllowInboundTimestampRequest"= 1 (0x1)
"AllowInboundMaskRequest"= 1 (0x1)
"AllowInboundRouterRequest"= 1 (0x1)
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundParameterProblem"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
"AllowOutboundPacketTooBig"= 1 (0x1)
.
R0 sptd;sptd;c:windowssystem32driverssptd.sys [11/3/2006 11:51 AM 611064]
R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2/6/2012 5:25 PM 435032]
R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2/6/2012 5:25 PM 314456]
R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2/6/2012 5:25 PM 20568]
R2 MBAMService;MBAMService;c:program filesMalwarebytes' Anti-Malwarembamservice.exe [10/28/2011 1:21 PM 652872]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [9/8/2011 2:01 PM 20464]
S2 ayctovpm;Manager Driver;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 cucirdx;Security Server;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 gjqnvtmmd;Task Windows;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 gnrpual;Boot Monitor;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 jcmqzgjat;Driver Update;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 jogjg;Boot Helper;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 jqxheo;Update Network;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 ltgkjjzxv;Monitor Config;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 mbmdmxolx;Installer Network;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 owelordo;Monitor Server;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
S2 rlhnvu;System Center;c:windowssystem32svchost.exe -k netsvcs [2/28/2006 3:00 PM 14336]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 192.168.0.4:3128
IE: Convert link target to Adobe PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:program filesAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll/AcroIEAppend.html
TCP: DhcpNameServer = 192.168.51.1
FF - ProfilePath - c:documents and settingsAdministratorApplication DataMozillaFirefoxProfilesed37fp1i.default
FF - prefs.js: network.proxy.ftp - 192.168.0.4
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - 192.168.0.4
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 192.168.0.4
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 192.168.0.4
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-DaemonTools_WhenUSave_Installer - c:program filesDaemonTools_WhenUSave_InstallerDaemonTools_WhenUSave_Installer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-13 17:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesayctovpm]
"ServiceDll"="c:program filesMovie Makerjbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicescucirdx]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesgjqnvtmmd]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesgnrpual]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesjcmqzgjat]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesjogjg]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesjqxheo]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesltgkjjzxv]
"ServiceDll"="c:program filesInternet Explorerjbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesmbmdmxolx]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesowelordo]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
[HKEY_LOCAL_MACHINESystemControlSet001Servicesrlhnvu]
"ServiceDll"="c:windowssystem32jbmrrkm.dll.old"
.
Completion time: 2012-07-13  17:54:32
ComboFix-quarantined-files.txt  2012-07-13 14:54
.
Pre-Run: 30 609 367 040 bytes free
Post-Run: 33 516 367 872 bytes free
.
- - End Of File - - AB5DCD67F9E05EAFF9912F89CF3E8FFC

DDS:

DDS (Ver_2011-09-30.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by Administrator at 17:55:10 on 2012-07-13
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.511.138 [GMT 3:00]
.
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *Disabled*
.
============== Running Processes ================
.
C:Program FilesAVAST SoftwareAvastAvastSvc.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSATKKBService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:Program FilesAnalog DevicesCoresmax4pnp.exe
C:Program FilesAnalog DevicesSoundMAXSmax4.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
C:Program FilesAdobeAcrobat 7.0DistillrAcrotray.exe
C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe
C:Program FilesAVAST SoftwareAvastavastUI.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32nvsvc32.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
C:WINDOWSSystem32alg.exe
C:WINDOWSexplorer.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSsystem32svchost.exe -k DcomLaunch
C:WINDOWSsystem32svchost.exe -k rpcss
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uProxyServer = 192.168.0.4:3128
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:program filesadobeacrobat 7.0activexAcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
mRun: [SoundMAXPnP] c:program filesanalog devicescoresmax4pnp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:windowssystem32NvMcTray.dll,NvTaskbarInit
mRun: [Synchronization Manager] c:windowssystem32mobsync.exe /logon
mRun: [Acrobat Assistant 7.0] "c:program filesadobeacrobat 7.0distillrAcrotray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:program filesmalwarebytes' anti-malwarembamgui.exe" /starttray
mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"
dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobea~1.lnk - c:windowsinstaller{ac76ba86-1033-0000-7760-000000000002}SC_Acrobat.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobeg~1.lnk - c:program filescommon filesadobecalibrationAdobe Gamma Loader.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~1.lnk - c:program filesmicrosoft officeofficeOSA9.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-WindowsSystem: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Convert link target to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
TCP: NameServer = 192.168.51.1
TCP: Interfaces{FC275C34-1B87-44EB-A65B-8F68A7DAD17A} : DHCPNameServer = 192.168.51.1
.
================= FIREFOX ===================
.
FF - ProfilePath - c:documents and settingsadministratorapplication datamozillafirefoxprofilesed37fp1i.default
FF - prefs.js: network.proxy.ftp - 192.168.0.4
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - 192.168.0.4
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 192.168.0.4
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 192.168.0.4
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-2-6 435032]
R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-2-6 314456]
R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-2-6 20568]
R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-2-6 44768]
R2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2011-10-28 652872]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2011-9-8 20464]
S2 ayctovpm;Manager Driver;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S2 cucirdx;Security Server;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 gjqnvtmmd;Task Windows;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 gnrpual;Boot Monitor;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 jcmqzgjat;Driver Update;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 jogjg;Boot Helper;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 jqxheo;Update Network;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 ltgkjjzxv;Monitor Config;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 mbmdmxolx;Installer Network;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 owelordo;Monitor Server;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S2 rlhnvu;System Center;c:windowssystem32svchost.exe -k netsvcs [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-07-13 11:00:43 -------- d-sha-r- C:cmdcons
2012-07-09 09:45:26 98816 ----a-w- c:windowssed.exe
2012-07-09 09:45:26 256000 ----a-w- c:windowsPEV.exe
2012-07-09 09:45:26 208896 ----a-w- c:windowsMBR.exe
2012-07-09 08:39:26 333952 -c----w- c:windowssystem32dllcachesrv.sys
2012-07-09 08:39:09 337408 -c----w- c:windowssystem32dllcachenetapi32.dll
2012-07-09 08:38:43 455296 -c----w- c:windowssystem32dllcachemrxsmb.sys
.
==================== Find3M  ====================
.
2011-10-31 14:12:00 26739584 ----a-w- c:program filesAdbeRdr910_en_US.exe
.
============= FINISH: 17:55:30,92 ===============

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-09-30.01)
.
Microsoft Windows XP Professional
Boot Device: DeviceHarddiskVolume1
Install Date: 10/27/2006 10:08:55 AM
System Uptime: 7/13/2012 5:18:01 PM (0 hours ago)
.
Motherboard: ASUSTeK Computer INC. |  | M2N
Processor: AMD Athlon(tm) 64 Processor 3000+ | CPU 1 | 1808/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 60 GiB total, 31.243 GiB free.
D: is FIXED (NTFS) - 406 GiB total, 347.502 GiB free.
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP74: 4/12/2012 1:32:53 PM - System Checkpoint
RP75: 4/16/2012 2:19:58 PM - System Checkpoint
RP76: 4/24/2012 9:40:17 AM - System Checkpoint
RP77: 5/4/2012 9:59:28 AM - System Checkpoint
RP78: 5/7/2012 2:58:49 PM - System Checkpoint
RP79: 6/4/2012 11:38:52 AM - System Checkpoint
RP80: 6/10/2012 4:15:05 PM - System Checkpoint
RP81: 6/15/2012 12:00:30 PM - System Checkpoint
RP82: 6/18/2012 11:48:33 AM - System Checkpoint
RP83: 7/2/2012 6:04:43 PM - System Checkpoint
RP84: 7/4/2012 2:23:14 PM - System Checkpoint
RP85: 7/6/2012 12:31:34 PM - System Checkpoint
RP86: 7/9/2012 10:07:50 AM - System Checkpoint
RP87: 7/9/2012 11:35:48 AM - conficker
RP88: 7/9/2012 11:38:58 AM - Installed Windows XP KB957097.
RP89: 7/9/2012 11:39:19 AM - Installed Windows XP KB958644.
RP90: 7/9/2012 11:39:36 AM - Installed Windows XP KB958687.
RP91: 7/9/2012 11:39:54 AM - Installed Windows XP KB957097.
RP92: 7/9/2012 11:40:06 AM - Installed Windows XP KB958644.
RP93: 7/9/2012 11:40:18 AM - Installed Windows XP KB958687.
RP94: 7/9/2012 11:45:48 AM - Installed Microsoft Fix it 50471
RP95: 7/10/2012 11:51:10 AM - System Checkpoint
RP96: 7/11/2012 1:51:02 PM - System Checkpoint
RP97: 7/13/2012 1:56:14 PM - ComboFix created restore point
.
==== Installed Programs ======================
.
???????? ??? 2.3
Adobe Acrobat 7.0 Professional
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge 1.0
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color Common Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Common File Installer
Adobe Creative Suite 2
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Fonts All
Adobe Help Center 1.0
Adobe Help Viewer CS3
Adobe Illustrator CS2
Adobe Illustrator CS2 Tryout
Adobe Illustrator CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS2
Adobe Reader 9.1
Adobe Setup
Adobe Stock Photos 1.0
Adobe Stock Photos CS3
Adobe SVG Viewer 3.0
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
ASUS Enhanced Display Driver
ASUS nVIDIA Driver
avast! Free Antivirus
Bulgarian Keyboards XP by G. Atanasov
Data Access Objects (DAO) 3.5
Google ????
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2484832)
Hotfix for Microsoft .NET Framework 4 Client Profile (KB2498911)
Hotfix for Windows XP (KB942288-v3)
Hotfix for Windows XP (KB954550-v5)
Malwarebytes Anti-Malware, ?????? 1.60.0.1800
MapInfo ODBC Support
MapInfo Professional 10.5
MapInfo Professional 11.0
MapInfo Professional 5.0
MapInfo Professional 7.5 SCP
MapInfo Professional 9.0
MapperG for MapInfo Pro
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Access database engine 2010 (English)
Microsoft Office 2000 Disc 2
Microsoft Office 2000 Professional
Microsoft Office Access database engine 2007 (English)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
Mozilla Firefox 9.0 (x86 bg)
MSXML 6.0 Parser (KB933579)
NVIDIA Drivers
NVIDIA ForceWare Network Access Manager
OLE DB Service Provider
OpenOffice.org 2.0
PDF Settings
SA Dictionary 2004 Datacenter
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
SoundMAX
SpTTpack «Remove» DataMap FontPack
Suite Specific
Surfer 8 Demo
Total Commander (Remove or Repair)
TrueCrypt
WebFldrs XP
Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
Windows Imaging Component
Windows XP Service Pack 3
WinRAR archiver
XML Paper Specification Shared Components Pack 1.0
.
==== Event Viewer Messages From Past Week ========
.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Update Network service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Task Windows service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The System Center service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Security Server service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Monitor Server service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Monitor Config service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Manager Driver service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Installer Network service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Driver Update service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Boot Monitor service terminated with the following error:  The specified module could not be found.
7/9/2012 9:54:49 AM, error: Service Control Manager [7023]  - The Boot Helper service terminated with the following error:  The specified module could not be found.
7/9/2012 12:42:51 PM, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'.  It has stopped monitoring the volume.
7/13/2012 2:30:30 PM, error: NETLOGON [5719]  - No Domain Controller is available for domain DMEUROPE due to the following:  There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
7/13/2012 1:57:27 PM, error: Dhcp [1002]  - The IP address lease 192.168.0.107 for the Network Card with network address 0018F346D2BE has been denied by the DHCP server 192.168.51.1 (The DHCP Server sent a DHCPNACK message).
.
==== End Of File ===========================

Така не се работи...! :mad:

Копирайте текста в карето на notepad и го запазвате с име CFScript.txt на десктопа си:

KILLALL::

File::
c:program filesMovie Makerjbmrrkm.dll.old

NetSvc::
ayctovpm
cucirdx
gjqnvtmmd
gnrpual
jcmqzgjat
jogjg
jqxheo
ltgkjjzxv
mbmdmxolx
owelordo
rlhnvu

Registry::
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"4081:TCP"=-

След съхранението преместете CFScript.txt на иконата на ComboFix.exe

Публикувано изображение

Генерирания рапорт прикачете в следващия си пост..!

  • Автор

Да, проксито е познато. Понеделник ще кача резултатите. Весел уикенд. Поздрави!

  • Автор

Здравейте, Отново ComboFix забива и не стига дори до stages... 3 пъти го пусках със скрипта, не съм бутал компютъра, след пускането му.

  • Автор

Да пробвам ли с Avenger със следния код:

Drivers to delete:
ayctovpm
cucirdx
gjqnvtmmd
gnrpual
jcmqzgjat
jogjg
jqxheo
ltgkjjzxv
mbmdmxolx
owelordo
rlhnvu

?

Някой може ли да помогне :(

Естествено...до сега кой ти помага..?Но това че се появявате изключително рядко ..е проблем...!

..

Изчакай малко ....

Моля, изтеглете The Avenger и го разархивирайте на десктопа. Стартирайте avenger.exe, копирайте следния текст и го поставете в текстовото поле на програмата:

Files to delete:
c:\program files\Movie Maker\jbmrrkm.dll.old

Drivers to delete:
ayctovpm
cucirdx
gjqnvtmmd
gnrpual
jcmqzgjat
jogjg
jqxheo
ltgkjjzxv
mbmdmxolx
owelordo
rlhnvu

Уверете се, че Scan for rootkits и Automatically disable any rootkits found имат отметки.

След това изберете Execute и при въпрос от страна на програмата, кликнете върху Yes, при което компютъра ще се рестартира. След рестартта копирайте и поставете съдържанието на лог файла от програмата, намиращ се в C:\avenger.txt в следващия си коментар в тази тема.

  • Автор

Окей, утре ще кача лога(днес не е работен ден), мерси предварително!

  • Автор

Ето разултат от Avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform:  Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!

Error:  file "c:program filesMovie Makerjbmrrkm.dll.old" not found!
Deletion of file "c:program filesMovie Makerjbmrrkm.dll.old" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
  --> the object does not exist
Driver "ayctovpm" deleted successfully.
Driver "cucirdx" deleted successfully.
Driver "gjqnvtmmd" deleted successfully.
Driver "gnrpual" deleted successfully.
Driver "jcmqzgjat" deleted successfully.
Driver "jogjg" deleted successfully.
Driver "jqxheo" deleted successfully.
Driver "ltgkjjzxv" deleted successfully.
Driver "mbmdmxolx" deleted successfully.
Driver "owelordo" deleted successfully.
Driver "rlhnvu" deleted successfully.
Completed script processing.
*******************
Finished!  Terminate.

DDS след Agenger:

DDS (Ver_2011-09-30.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by Administrator at 9:13:13 on 2012-07-23
Microsoft Windows XP Professional  5.1.2600.3.1251.359.1033.18.511.31 [GMT 3:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ActiveArmor Firewall *Disabled*
.
============== Running Processes ================
.
C:Program FilesAVAST SoftwareAvastAvastSvc.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSATKKBService.exe
C:Program FilesBonjourmDNSResponder.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:Program FilesMalwarebytes' Anti-Malwarembamservice.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerApache GroupApache2binapache.exe
C:WINDOWSExplorer.EXE
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcLog.exe
C:WINDOWSsystem32nvsvc32.exe
C:Program FilesNVIDIA CorporationNetworkAccessManagerbinnSvcIp.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSSystem32alg.exe
C:Program FilesAnalog DevicesCoresmax4pnp.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:Program FilesAdobeAcrobat 7.0DistillrAcrotray.exe
C:Program FilesMalwarebytes' Anti-Malwarembamgui.exe
C:Program FilesAVAST SoftwareAvastavastUI.exe
C:Program FilesAdobeReader 9.0ReaderReader_sl.exe
C:Program FilesAdobeAcrobat 7.0Acrobatacrobat_sl.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:WINDOWSsystem32msiexec.exe
C:Program FilesMalwarebytes' Anti-Malwarembam.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSsystem32svchost.exe -k DcomLaunch
C:WINDOWSsystem32svchost.exe -k rpcss
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uProxyServer = 192.168.0.4:3128
BHO: AcroIEHlprObj Class: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:program filesadobeacrobat 7.0activexAcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:program filescommon filesadobeacrobatactivexAcroIEHelperShim.dll
BHO: AcroIEToolbarHelper Class: {AE7CD045-E861-484f-8273-0445EE161910} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll
mRun: [SoundMAXPnP] c:program filesanalog devicescoresmax4pnp.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:windowssystem32NvMcTray.dll,NvTaskbarInit
mRun: [Synchronization Manager] c:windowssystem32mobsync.exe /logon
mRun: [Acrobat Assistant 7.0] "c:program filesadobeacrobat 7.0distillrAcrotray.exe"
mRun: [Malwarebytes' Anti-Malware] "c:program filesmalwarebytes' anti-malwarembamgui.exe" /starttray
mRun: [avast] "c:program filesavast softwareavastavastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:program filesadobereader 9.0readerReader_sl.exe"
dRun: [CTFMON.EXE] c:windowssystem32CTFMON.EXE
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobea~1.lnk - c:windowsinstaller{ac76ba86-1033-0000-7760-000000000002}SC_Acrobat.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupadobeg~1.lnk - c:program filescommon filesadobecalibrationAdobe Gamma Loader.exe
StartupFolder: c:docume~1alluse~1startm~1programsstartupmicros~1.lnk - c:program filesmicrosoft officeofficeOSA9.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-WindowsSystem: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: Convert link target to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:program filesadobeacrobat 7.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%Network Diagnosticxpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
TCP: Interfaces{FC275C34-1B87-44EB-A65B-8F68A7DAD17A} : NameServer = 192.168.0.158
.
================= FIREFOX ===================
.
FF - ProfilePath - c:documents and settingsadministratorapplication datamozillafirefoxprofilesed37fp1i.default
FF - prefs.js: network.proxy.ftp - 192.168.0.4
FF - prefs.js: network.proxy.ftp_port - 3128
FF - prefs.js: network.proxy.http - 192.168.0.4
FF - prefs.js: network.proxy.http_port - 3128
FF - prefs.js: network.proxy.socks - 192.168.0.4
FF - prefs.js: network.proxy.socks_port - 3128
FF - prefs.js: network.proxy.ssl - 192.168.0.4
FF - prefs.js: network.proxy.ssl_port - 3128
FF - prefs.js: network.proxy.type - 1
FF - plugin: c:program filesgooglegoogle earthpluginnpgeplugin.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:windowssystem32driversaswSnx.sys [2012-2-6 435032]
R1 aswSP;aswSP;c:windowssystem32driversaswSP.sys [2012-2-6 314456]
R2 aswFsBlk;aswFsBlk;c:windowssystem32driversaswFsBlk.sys [2012-2-6 20568]
R2 avast! Antivirus;avast! Antivirus;c:program filesavast softwareavastAvastSvc.exe [2012-2-6 44768]
R2 MBAMService;MBAMService;c:program filesmalwarebytes' anti-malwarembamservice.exe [2011-10-28 652872]
R3 MBAMProtector;MBAMProtector;c:windowssystem32driversmbam.sys [2011-9-8 20464]
R3 MBAMSwissArmy;MBAMSwissArmy;c:windowssystem32driversmbamswissarmy.sys [2012-7-23 40776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:windowsmicrosoft.netframeworkv4.0.30319mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:windowsmicrosoft.netframeworkv4.0.30319wpfWPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-07-23 06:11:22 40776 ----a-w- c:windowssystem32driversmbamswissarmy.sys
2012-07-20 15:02:53 -------- d-s---w- C:ComboFix
2012-07-13 11:00:43 -------- d-sha-r- C:cmdcons
2012-07-09 09:45:26 98816 ----a-w- c:windowssed.exe
2012-07-09 09:45:26 256000 ----a-w- c:windowsPEV.exe
2012-07-09 09:45:26 208896 ----a-w- c:windowsMBR.exe
2012-07-09 08:39:26 333952 -c----w- c:windowssystem32dllcachesrv.sys
2012-07-09 08:39:09 337408 -c----w- c:windowssystem32dllcachenetapi32.dll
2012-07-09 08:38:43 455296 -c----w- c:windowssystem32dllcachemrxsmb.sys
.
==================== Find3M  ====================
.
2011-10-31 14:12:00 26739584 ----a-w- c:program filesAdbeRdr910_en_US.exe
.
============= FINISH:  9:15:39,70 ===============

Сега ще подготвя DDS дневник и за останалите машини.

Поздрави!

Архивирана тема

Темата е твърде стара и е архивирана. Не можете да добавяте нови отговори в нея, но винаги можете да публикувате нова тема, в която да продължи дискусията. Регистрирайте се или влезте във вашия профил за да публикувате нова тема.

Разглеждащи това в момента 0

  • Няма регистрирани потребители разглеждащи тази страница.

Дарение

  • Подкрепи съществуването на форума - направи дарение
    32%
    Дарени 315 € от нужните 1 000 €

Бюлетин

Получавайте известие, когато има важна промяна или новина свързана с форума.

Профил

Навигация

Търсене

Търсене

Конфигуриране на push известия в браузъра

Chrome (Android)
  1. Докоснете иконата на катинар до адресната лента.
  2. Докоснете Разрешения → Известия.
  3. Променете предпочитанията си.
Chrome (Desktop)
  1. Кликнете върху иконата на катинар в адресната лента.
  2. Изберете Настройки на сайта.
  3. Намерете Известия и коригирайте предпочитанията си.