B-boy/StyLe/ Публикувано Февруари 17, 2009 Report Share Публикувано Февруари 17, 2009 Отвори Notepad и въведи: Killall:: File:: c:\windows\system32\81.scr c:\windows\system32\80.scr c:\windows\system32\15.scr c:\windows\system32\32.scr c:\windows\system32\66.scr c:\windows\wciactrl.exe c:\windows\system32\12.scr c:\windows\system32\62.scr c:\windows\system32\01.scr c:\windows\system32\31.scr c:\windows\wciactrl.exe.vir c:\windows\system32\txsocm32.dll c:\windows\system32\frnscli32.dll c:\windows\system32\84.scr c:\windows\system32\06.scr c:\windows\system32\41.scr c:\windows\system32\38.scr c:\windows\system32\68.scr Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Intel Physical Address Aventis 1.3"=- [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "Intel Physical Address Aventis 1.3"=- [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\WINDOWS\\System32\\68.scr"=- "c:\\WINDOWS\\System32\\38.scr"=- "c:\\WINDOWS\\System32\\41.scr"=- "c:\\WINDOWS\\System32\\06.scr"=- [-HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Intel Physical Address Aventis 1.3] Запази файла с име CFScript и го провлачи в иконата на ComboFix. Публикувай новия лог в следващия си пост. Цитирай Link to comment Сподели другаде More sharing options...
MeGa Публикувано Февруари 17, 2009 Author Report Share Публикувано Февруари 17, 2009 ComboFix 09-02-15.01 - Ivaylo 2009-02-17 17:58:38.2 - NTFSx86Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.511.219 [GMT 2:00]Running from: c:\documents and settings\Ivaylo\Desktop\ComboFix.exeCommand switches used :: c:\documents and settings\Ivaylo\Desktop\CFScript.txtAV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated)AV: Norton AntiVirus *On-access scanning enabled* (Updated) * Created a new restore point * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! FILE ::c:\windows\system32\01.scrc:\windows\system32\06.scrc:\windows\system32\12.scrc:\windows\system32\15.scrc:\windows\system32\31.scrc:\windows\system32\32.scrc:\windows\system32\38.scrc:\windows\system32\41.scrc:\windows\system32\62.scrc:\windows\system32\66.scrc:\windows\system32\68.scrc:\windows\system32\80.scrc:\windows\system32\81.scrc:\windows\system32\84.scrc:\windows\system32\frnscli32.dllc:\windows\system32\txsocm32.dllc:\windows\wciactrl.exec:\windows\wciactrl.exe.vir. ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))). c:\windows\system32\01.scrc:\windows\system32\12.scrc:\windows\system32\15.scrc:\windows\system32\31.scrc:\windows\system32\32.scrc:\windows\system32\62.scrc:\windows\system32\66.scrc:\windows\system32\68.scrc:\windows\system32\80.scrc:\windows\system32\81.scrc:\windows\system32\84.scrc:\windows\system32\frnscli32.dllc:\windows\system32\txsocm32.dllc:\windows\wciactrl.exec:\windows\wciactrl.exe.vir .((((((((((((((((((((((((( Files Created from 2009-01-17 to 2009-02-17 ))))))))))))))))))))))))))))))). 2009-02-17 17:55 . 2009-02-17 17:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Symantec2009-02-17 17:48 . 2009-02-17 17:48 <DIR> d-------- c:\program files\Symantec2009-02-17 17:48 . 2009-02-17 17:56 <DIR> d-------- c:\program files\Common Files\Symantec Shared2009-02-17 17:48 . 2009-02-17 17:48 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS2009-02-17 17:48 . 2009-02-17 17:48 60,808 --a------ c:\windows\system32\S32EVNT1.DLL2009-02-17 17:48 . 2009-02-17 17:48 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys2009-02-17 17:48 . 2009-02-17 17:48 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT2009-02-17 17:48 . 2009-02-17 17:48 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF2009-02-17 17:47 . 2009-02-17 17:47 <DIR> d-------- c:\windows\system32\drivers\NAV2009-02-17 17:47 . 2009-02-17 17:47 <DIR> d-------- c:\program files\Windows Sidebar2009-02-17 17:47 . 2009-02-17 17:48 <DIR> d-------- c:\program files\Norton AntiVirus2009-02-17 17:47 . 2009-02-17 17:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\Norton2009-02-17 17:46 . 2009-02-17 17:46 <DIR> d-------- c:\program files\NortonInstaller2009-02-17 17:46 . 2009-02-17 17:46 <DIR> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller2009-02-17 15:58 . 2009-02-17 15:58 65,664 --a------ c:\windows\system32\04.scr2009-02-16 22:39 . 2009-02-16 22:40 250 --a------ c:\windows\gmer.ini2009-02-16 20:34 . 2009-02-17 17:48 3 --a------ c:\windows\switch.inf2009-02-15 23:45 . 2009-02-15 23:45 <DIR> d-------- c:\program files\SUPERAntiSpyware2009-02-15 23:45 . 2009-02-15 23:45 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard2009-02-15 23:45 . 2009-02-15 23:45 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\SUPERAntiSpyware.com2009-02-15 23:45 . 2009-02-15 23:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com2009-02-15 19:19 . 2008-11-06 02:03 <DIR> d-------- C:\SDFix2009-02-15 19:13 . 2009-02-15 19:13 410,984 --a------ c:\windows\system32\deploytk.dll2009-02-15 19:13 . 2009-02-15 19:13 73,728 --a------ c:\windows\system32\javacpl.cpl2009-02-15 18:31 . 2009-02-15 18:33 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware2009-02-15 18:31 . 2009-02-15 18:31 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\Malwarebytes2009-02-15 18:31 . 2009-02-15 18:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes2009-02-15 18:31 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys2009-02-15 18:31 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys2009-02-15 18:08 . 2009-02-15 18:08 <DIR> d-------- c:\program files\CCleaner2009-02-15 17:37 . 2009-02-15 17:37 <DIR> d-------- c:\program files\Trend Micro2009-02-14 22:10 . 2009-02-16 15:29 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP2009-02-14 22:09 . 2009-02-14 22:10 <DIR> d-------- c:\program files\Trojan Remover2009-02-14 22:09 . 2009-02-14 22:09 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\Simply Super Software2009-02-14 22:09 . 2009-02-14 22:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software2009-02-14 22:09 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll2009-02-14 22:09 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll2009-02-14 22:09 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll2009-02-14 22:09 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll2009-02-14 22:09 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll2009-02-14 13:34 . 2009-02-14 13:34 <DIR> d-------- c:\program files\Webteh2009-02-14 13:34 . 2009-02-14 13:35 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\BSplayer Pro2009-02-13 23:05 . 2009-02-13 23:05 <DIR> d-------- c:\windows\system32\Lang2009-02-13 23:05 . 2009-02-13 23:05 146,650 --a------ c:\windows\system32\BuzzingBee.wav2009-02-13 23:05 . 2009-02-13 23:05 125,690 --a------ c:\windows\system32\LoopyMusic.wav2009-02-13 21:15 . 2009-02-17 17:44 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\uTorrent2009-02-13 20:54 . 2009-02-13 20:54 <DIR> d-------- c:\program files\foobar20002009-02-13 20:54 . 2009-02-16 17:04 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\foobar20002009-02-13 20:46 . 2009-02-13 20:46 <DIR> d-------- c:\windows\nview2009-02-13 20:46 . 2008-05-16 14:01 446,464 --a------ c:\windows\system32\nvudisp.exe2009-02-13 20:46 . 2009-02-17 18:02 186,097 --a------ c:\windows\system32\nvapps.xml2009-02-13 20:46 . 2008-05-16 14:01 18,070 --a------ c:\windows\system32\nvdisp.nvu2009-02-13 20:45 . 2009-02-13 20:45 <DIR> d-------- C:\NVIDIA2009-02-13 20:45 . 2008-05-16 11:48 446,464 --a------ c:\windows\system32\NVUNINST.EXE2009-02-13 20:43 . 2009-02-13 20:43 <DIR> d-------- c:\program files\Common Files\Skype2009-02-13 20:34 . 2009-02-13 20:34 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.12009-02-13 20:30 . 2009-02-13 20:30 <DIR> d-------- c:\program files\Common Files\Adobe AIR2009-02-13 20:30 . 2009-02-13 20:30 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\vlc2009-02-13 20:29 . 2009-02-13 20:30 <DIR> d-------- c:\program files\Common Files\Adobe2009-02-13 20:28 . 2009-02-13 20:28 <DIR> d-------- c:\program files\VideoLAN2009-02-13 20:16 . 2004-08-04 01:56 221,184 --a------ c:\windows\system32\wmpns.dll2009-02-13 20:13 . 2009-02-13 20:13 <DIR> d-------- c:\windows\system32\LogFiles2009-02-13 20:13 . 2009-02-13 20:14 <DIR> d-------- c:\windows\system32\drivers\UMDF2009-02-13 20:13 . 2006-09-25 17:58 23,856 --a------ c:\windows\system32\spupdsvc.exe2009-02-13 20:07 . 2009-02-13 20:07 <DIR> d-------- c:\windows\Sun2009-02-13 20:02 . 2009-02-13 20:42 <DIR> d-------- c:\program files\NOS2009-02-13 20:02 . 2009-02-13 20:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS2009-02-13 19:54 . 2009-02-17 16:07 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\skypePM2009-02-13 19:54 . 2009-02-13 19:54 56 --ah----- c:\windows\system32\ezsidmv.dat2009-02-13 19:53 . 2009-02-17 17:30 <DIR> d-------- c:\documents and settings\Ivaylo\Application Data\Skype2009-02-13 19:52 . 2009-02-13 20:43 <DIR> dr------- c:\program files\Skype2009-02-13 19:52 . 2009-02-13 20:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype2009-02-13 19:45 . 2009-02-13 19:45 0 --a------ c:\windows\nsreg.dat2009-02-13 19:03 . 2001-08-17 15:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys2009-02-13 19:02 . 2008-05-16 14:01 6,557,408 --a------ c:\windows\system32\drivers\nv4_mini.sys2009-02-13 19:02 . 2008-05-16 14:01 6,557,408 --a--c--- c:\windows\system32\dllcache\nv4_mini.sys2009-02-13 19:02 . 2008-05-16 14:01 6,108,928 --a------ c:\windows\system32\nv4_disp.dll2009-02-13 19:02 . 2003-03-04 05:56 145,408 -ra------ c:\windows\system32\drivers\e100b325.sys2009-02-13 19:02 . 2003-03-04 05:56 145,408 --a--c--- c:\windows\system32\dllcache\e100b325.sys2009-02-13 19:02 . 2004-08-04 00:59 57,472 --a------ c:\windows\system32\drivers\redbook.sys2009-02-13 19:02 . 2004-08-04 00:31 20,992 --a------ c:\windows\system32\drivers\RTL8139.sys2009-02-13 19:02 . 2004-08-04 01:08 10,624 --a------ c:\windows\system32\drivers\gameenum.sys2009-02-13 19:01 . 2004-08-04 02:56 74,240 --a------ c:\windows\system32\usbui.dll2009-02-13 19:01 . 2004-08-04 01:07 42,368 --a------ c:\windows\system32\drivers\AGP440.SYS2009-02-13 19:01 . 2004-08-04 00:59 5,504 --a------ c:\windows\system32\drivers\intelide.sys2009-02-13 19:00 . 2009-02-13 17:12 <DIR> dr------- c:\documents and settings\All Users\Documents .(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-02-15 17:13 --------- d-----w c:\program files\Java2009-02-15 16:37 --------- d-----w c:\program files\ESET2009-02-13 18:15 --------- d-----w c:\program files\Windows Media Connect 22009-02-13 18:13 --------- d-----w c:\program files\Common Files\InstallShield2009-02-13 16:48 --------- d-----w c:\program files\K-Lite Codec Pack2009-02-13 16:47 --------- d-----w c:\program files\Gaberoff Koral2009-02-13 16:39 --------- d-----w c:\program files\SA Dictionary 2005 T22009-02-13 16:27 --------- d-----w c:\program files\AnMing2009-02-13 16:24 --------- d-----w c:\program files\SkyCode2009-02-13 16:22 --------- d-----w c:\program files\Common Files\Java2009-02-13 16:19 --------- d-----w c:\program files\Microsoft ActiveSync2009-02-13 16:16 --------- d--h--w c:\program files\InstallShield Installation Information2009-02-13 16:16 --------- d-----w c:\program files\A4-Tech2009-02-13 16:16 --------- d-----w c:\documents and settings\Ivaylo\Application Data\InstallShield2009-02-13 15:58 --------- d-----w c:\program files\Realtek Sound Manager2009-02-13 15:58 --------- d-----w c:\program files\AvRack2009-02-13 15:54 512,096 ----a-w c:\windows\system32\drivers\amon.sys2009-02-13 15:54 299,392 ----a-w c:\windows\system32\imon.dll2009-02-13 15:54 15,424 ----a-w c:\windows\system32\drivers\nod32drv.sys2009-02-13 15:17 --------- d-----w c:\program files\microsoft frontpage. ((((((((((((((((((((((((((((( SnapShot@2009-02-17_15.56.36.60 ))))))))))))))))))))))))))))))))))))))))).+ 2009-02-17 15:48:30 255,536 ----a-w c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys+ 2009-02-17 15:48:30 362,544 ----a-w c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys+ 2009-02-17 15:48:31 306,736 ----a-w c:\windows\system32\drivers\NAV\1002000.007\srtsp.sys+ 2009-02-17 15:48:31 43,696 ----a-w c:\windows\system32\drivers\NAV\1002000.007\srtspx.sys+ 2009-02-17 15:48:32 12,976 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symdns.sys+ 2009-02-17 15:48:32 309,296 ----a-w c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys+ 2009-02-17 15:48:32 89,904 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symfw.sys+ 2009-02-17 15:48:32 34,608 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symids.sys+ 2009-02-17 15:48:32 37,424 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symndis.sys+ 2009-02-17 15:48:32 40,496 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symndisv.sys+ 2009-02-17 15:48:32 24,624 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symredrv.sys+ 2009-02-17 15:48:32 198,192 ----a-w c:\windows\system32\drivers\NAV\1002000.007\symtdi.sys+ 2009-02-17 16:02:48 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6c0.dat.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-15 136600] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="d:\\Games\\cs\\59579088499187464721.exe"="d:\\µTorrent\\uTorrent.exe"="d:\\Games\\cs\\88479782745917389057.exe"="d:\\Games\\cs\\80250369886764936677.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1002000.007\SymEFA.sys [2009-02-17 309296]R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1002000.007\BHDrvx86.sys [2009-02-17 255536]R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1002000.007\cchpx86.sys [2009-02-17 362544]R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20080826.006\IDSxpx86.sys [2009-02-17 274808]R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-02-13 15424]R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe [2009-02-17 115560]R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-02-17 99376]R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408] --- Other Services/Drivers In Memory --- *NewlyCreated* - ERASERUTILREBOOTDRV..------- Supplementary Scan -------.LSP: c:\windows\system32\imon.dllFF - ProfilePath - c:\documents and settings\Ivaylo\Application Data\Mozilla\Firefox\Profiles\s2jq9cda.default\FF - prefs.js: browser.startup.homepage - free.haskovo.netFF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll. ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-02-17 18:02:59Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.2.0.7\diMaster.dll\" /prefetch:1".--------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(972)c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'lsass.exe'(1028)c:\windows\system32\imon.dll.------------------------ Other Running Processes ------------------------.c:\program files\Java\jre6\bin\jqs.exec:\program files\ESET\nod32krn.exec:\windows\system32\nvsvc32.exec:\windows\system32\wscntfy.exe.**************************************************************************.Completion time: 2009-02-17 18:04:48 - machine was rebootedComboFix-quarantined-files.txt 2009-02-17 16:04:43ComboFix2.txt 2009-02-17 13:57:09 Pre-Run: 15,048,769,536 bytes freePost-Run: 15,045,763,072 bytes free 252 инсталирах Norton AntiVirus 2009 16.2.0.7, сега ще сканирам. Цитирай Link to comment Сподели другаде More sharing options...
MeGa Публикувано Февруари 17, 2009 Author Report Share Публикувано Февруари 17, 2009 Norton-a намери доста проблеми и ги оправи.Тrojan remover-a не засича нищо вече.Бях пробвал 2 антивирусни на ESЕТ едната от които беше най-новата им и нищо не направиха, вече няма да ползвам антивирусни на ESET.Сега мисля че всичко е наред.Мерси за помощта. Цитирай Link to comment Сподели другаде More sharing options...
Препоръчан пост
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.