Stránka 1 z 1

Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 13:40
od kuba11
Hoj, mam menší problém :) Nejde mi otevřít Disk C, když ho chci otevřít tak mi to vyhodí tuhle hlášku:
Obrázek

Projel jsem to Anti-Malware a tady je log


Malwarebytes' Anti-Malware 1.33
Verze databáze: 1654
Windows 5.1.2600 Service Pack 2

6.2.2009 13:23:32
mbam-log-2009-02-06 (13-23-24).txt

Typ skenu: Rychlý sken
Objektu skenováno: 51108
Uplynulý cas: 5 minute(s), 57 second(s)

Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 11
Infikované složky: 0
Infikované soubory: 1

Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)

Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)

Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované položky dat registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> No action taken.

Infikované složky:
(Žádné zákerné položky nebyly zjišteny)

Infikované soubory:
C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> No action taken.


Jinak tady je ještě výpis z HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:01:37, on 6.2.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
C:\Program Files\QIP\qip.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Documents and Settings\HP\Plocha\RapgetRS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 SPIRun.dll,RunDLLEntry
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [OEXPRESS] C:\Documents and Settings\All Users\Data aplikací\LangSoft\OETRN.EXE
O4 - HKCU\..\Run: [QIP2005] C:\Program Files\QIP\qip.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Výřezy obrazovky a spuštění aplikace OneNote 2007.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe (file missing)
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{B65CBAF5-4469-406A-9EAD-0016E84A25AD}: NameServer = 85.255.112.39,85.255.112.40
O17 - HKLM\System\CCS\Services\Tcpip\..\{EF6613FE-9322-441D-9732-1E6AF072EF77}: NameServer = 85.255.112.39,85.255.112.40
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.112.39,85.255.112.40
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/HP/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.jpg

--
End of file - 7820 bytes


Díkes všem za pomoc :bigups:

/odstraněny kódy.memphisto

Re: Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 17:55
od mts_rcs
staci si pozriet sekciu viry....atď a sekcia tajemna slozka recycler..................aj ja som mal ten isty problem prakticky on este trva vyriesisl som akurat otvaranie disku

Re: Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 18:18
od kuba11
Jinak tady je ještě výpis z Fixwareout

Username "HP" - 06.02.2009 18:09:11 [Fixwareout edited 9/01/2007]

~~~~~ Prerun check

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
"nameserver"="85.255.112.39,85.255.112.40 " <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{B65CBAF5-4469-406A-9EAD-0016E84A25AD}
"nameserver"="85.255.112.39,85.255.112.40" <Value cleared.
HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{EF6613FE-9322-441D-9732-1E6AF072EF77}
"nameserver"="85.255.112.39,85.255.112.40" <Value cleared.

Mezipaměť překládání DNS byla úspěšně vyprázdněna.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"SetRefresh"="C:\\Program Files\\Compaq\\SetRefresh\\SetRefresh.exe"
"P17Helper"="Rundll32 SPIRun.dll,RunDLLEntry"
"VolPanel"="\"C:\\Program Files\\Creative\\Sound Blaster X-Fi\\Volume Panel\\VolPanlu.exe\" /r"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
"egui"="\"C:\\Program Files\\ESET\\ESET NOD32 Antivirus\\egui.exe\" /hide /waitservice"
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
"Lexmark X1100 Series"="\"C:\\Program Files\\Lexmark X1100 Series\\lxbkbmgr.exe\""
"PWRISOVM.EXE"="C:\\Program Files\\PowerISO\\PWRISOVM.EXE"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre6\\bin\\jusched.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun"
"OEXPRESS"="C:\\Documents and Settings\\All Users\\Data aplikací\\LangSoft\\OETRN.EXE"
"WEBTRAN"=""
"QIP2005"="C:\\Program Files\\QIP\\qip.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
....
Hosts file was reset, If you use a custom hosts file please replace it...
~~~~~ End report ~~~~~

Re: Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 19:29
od jaro3
. Takže spusť znovu MbAM a dej Scan
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Show Results
- ujistit se že máš zatrhnuté všechny vypsané nálezy a klikni na tlačítko Remove Selected
- když skončí odstraňování tak se ti zobrazí log, tak ho sem dej.
- pak zvol v programu OK a pak program ukonči přes Exit

Můžeš sem pak vložit log z MbAM.
Poté:
Vypni rez. ochranu u NOD32.
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah

Re: Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 20:20
od kuba11
No tak jsem to projel Anti-Malware a pak tim Combofixem a ten mi pravděpodobně vymazal i něco co je důležitýho pro spuštění internetu, ptž ten potom vůbec nešel, takže jsem musel vrátit pc o několik dní zpátky.

Jinak tady jsou ty logy:

Combofix

ComboFix 09-02-06.01 - HP 2009-02-06 19:58:12.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.446.165 [GMT 1:00]
Running from: c:\documents and settings\HP\Plocha\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning enabled* (Updated)
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\docume~1\HP\LOCALS~1\Temp\tmp1.tmp
c:\docume~1\HP\LOCALS~1\Temp\tmp2.tmp
c:\recycler\S-8-9-26-100000566-100010773-100027040-4999.com
c:\windows\system32\drivers\gaopdxkwbapuiq.sys
c:\windows\system32\drivers\gaopdxlhhbmqey.sys
c:\windows\system32\drivers\gaopdxmkqcbbst.sys
c:\windows\system32\drivers\gaopdxornrefay.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxrwqomupw.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys


((((((((((((((((((((((((( Files Created from 2009-01-06 to 2009-02-06 )))))))))))))))))))))))))))))))
.

2009-02-06 18:08 . 2009-02-06 18:13 <DIR> d-------- C:\fixwareout
2009-02-06 13:15 . 2009-02-06 13:15 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-06 13:15 . <DIR> c:\documents and settings\HP\Data aplikací\Malwarebytes
2009-02-06 13:15 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-06 13:15 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-06 13:09 . 2009-02-06 13:09 <DIR> d-------- c:\program files\Trend Micro
2009-02-06 09:36 . 2009-02-06 09:36 <DIR> d-------- c:\program files\EA SPORTS
2009-02-05 23:17 . 2009-02-05 23:17 0 --a------ c:\windows\system32\budda
2009-02-05 23:09 . 2009-02-05 23:09 <DIR> d-------- C:\Programme
2009-02-05 17:45 . 2009-02-05 17:45 <DIR> d-------- c:\program files\VS Revo Group
2009-02-02 23:04 . 2009-02-02 23:04 <DIR> d-------- c:\program files\Mediostream
2009-02-02 23:04 . 2009-02-02 23:04 <DIR> d-------- c:\program files\Common Files\Mediostream
2009-02-02 23:04 . 2007-05-30 10:32 1,700,352 --a------ c:\windows\system32\gdiplus.dll
2009-02-02 23:04 . 2005-05-13 14:12 1,060,864 -ra------ c:\windows\system32\mfc71.dll
2009-02-02 23:04 . 2005-05-13 14:12 1,047,552 -ra------ c:\windows\system32\mfc71u.dll
2009-02-02 23:04 . 2006-12-28 21:18 122,512 --a------ c:\windows\system32\bgsvcgen.exe
2009-02-02 23:04 . 2006-12-28 21:18 56,976 --a------ c:\windows\system32\GenSvcInst.exe
2009-02-02 21:17 . 2009-02-02 21:18 <DIR> d-------- c:\program files\SuperDVD Video Editor
2009-01-28 15:23 . 2009-01-28 15:23 <DIR> d-------- c:\program files\Fox
2009-01-20 19:50 . <DIR> c:\documents and settings\HP\Data aplikací\U3
2009-01-19 20:30 . 2009-01-19 20:30 39 --a------ c:\windows\PBUpdate.ini
2009-01-17 16:03 . 2009-01-17 16:06 73,886 ---h----- C:\treeinfo.wc
2009-01-14 14:59 . 2006-08-21 10:14 128,896 --------- c:\windows\system32\dllcache\fltmgr.sys
2009-01-14 14:59 . 2006-08-21 10:14 23,040 --------- c:\windows\system32\dllcache\fltmc.exe
2009-01-14 14:59 . 2006-08-21 13:27 16,896 --------- c:\windows\system32\dllcache\fltlib.dll
2009-01-12 11:25 . 2009-01-13 19:00 <DIR> d-------- c:\windows\A3W_DATA
2009-01-12 11:24 . 2009-01-13 18:50 38,119 --a------ c:\windows\Run32A50.mch
2009-01-12 11:24 . 2009-01-13 18:50 73 --a------ c:\windows\CONTEXT.INI
2009-01-12 11:17 . 2009-01-13 18:48 <DIR> d-------- c:\windows\A5W_DATA
2009-01-12 11:17 . 2009-01-13 18:48 35 --a------ c:\windows\A5W.INI
2009-01-10 17:10 . 2004-08-17 15:49 159,232 --a------ c:\windows\system32\ptpusd.dll
2009-01-10 17:10 . 2001-10-24 12:25 5,632 --a------ c:\windows\system32\ptpusb.dll
2009-01-09 22:14 . 2009-01-09 22:14 479,298 --a------ c:\windows\system32\wbocx.ocx
2009-01-09 22:14 . 2009-01-09 22:14 172,032 --a------ c:\windows\system32\AniGIF.ocx
2009-01-09 22:14 . 2009-01-09 22:14 50,688 --a------ c:\windows\system32\wbhelp2.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 12:49 --------- d-----w c:\documents and settings\HP\Data aplikací\dvdcss
2009-02-05 17:04 --------- d-----w c:\documents and settings\HP\Data aplikací\LimeWire
2009-02-05 17:03 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-01 10:07 --------- d-----w c:\program files\Hamachi
2009-01-28 14:36 21,840 ----atw c:\windows\system32\SIntfNT.dll
2009-01-28 14:36 17,212 ----atw c:\windows\system32\SIntf32.dll
2009-01-28 14:36 12,067 ----atw c:\windows\system32\SIntf16.dll
2009-01-26 17:02 --------- d-s---w c:\documents and settings\HP\Data aplikací\Microsoft
2009-01-22 19:10 --------- d-----w c:\documents and settings\HP\Data aplikací\temp
2009-01-13 18:24 --------- d-----w c:\program files\Lexmark X1100 Series
2009-01-13 13:05 --------- d-----w c:\program files\7-Zip
2009-01-08 13:45 --------- d-----w c:\program files\The KMPlayer
2009-01-04 13:45 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-04 13:45 --------- d-----w c:\program files\Java
2008-12-30 22:07 --------- d--h--r c:\documents and settings\HP\Data aplikací\SecuROM
2008-12-23 21:17 --------- d-----w c:\documents and settings\HP\Data aplikací\Sports Interactive
2008-12-23 21:01 --------- d--h--w c:\program files\Zero G Registry
2008-12-22 22:08 --------- d-----w c:\program files\PowerISO
2008-12-22 18:48 --------- d-----w c:\program files\MagicISO
2008-12-22 16:27 --------- d-----w c:\documents and settings\HP\Data aplikací\Canneverbe_Limited
2008-12-21 14:31 61,440 ----a-w c:\windows\diabswun.exe
2008-12-15 19:24 --------- d-----w c:\program files\QIP
2008-12-15 17:20 --------- d-----w c:\documents and settings\HP\Data aplikací\Hamachi
2008-12-12 18:36 --------- d-----w c:\program files\Parallel Port Joystick
2008-12-12 17:36 3,081,216 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 11:57 333,184 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 11:57 333,184 ------w c:\windows\system32\dllcache\srv.sys
2008-12-09 18:28 25,280 ----a-w c:\windows\system32\drivers\hamachi.sys
2008-12-09 15:25 --------- d-----w c:\program files\QIP Infium
2008-12-09 14:54 --------- d-----w c:\documents and settings\HP\Data aplikací\ICQ
2008-12-08 14:28 --------- d-----w c:\program files\ABBYY FineReader 6.0
2008-12-08 14:27 --------- d-----w c:\program files\FaxTools
2008-12-06 17:51 --------- d-----w c:\program files\Reference Assemblies
2008-12-06 17:51 --------- d-----w c:\program files\MSBuild
2008-12-06 17:45 --------- d-----w c:\program files\MSXML 6.0
2008-11-19 18:39 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-19 18:39 22,328 ----a-w c:\documents and settings\HP\Data aplikací\PnkBstrK.sys
2008-11-19 18:39 103,736 ----a-w c:\windows\system32\PnkBstrB.exe
2008-11-16 14:11 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-10 18:48 737,280 ----a-w c:\windows\iun6002.exe
2008-11-10 18:39 413,696 ----a-w c:\windows\system32\wrap_oal.dll
2008-11-10 18:39 102,400 ----a-w c:\windows\system32\OpenAL32.dll
2008-11-07 17:32 2,109,440 ------w c:\windows\system32\dllcache\WMVCore.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-10-14 863688]

[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{32099AAC-C132-4136-9E9A-4E364A424E17}"= "c:\program files\DAEMON Tools Toolbar\DTToolbar.dll" [2008-10-14 863688]

[HKEY_CLASSES_ROOT\clsid\{32099aac-c132-4136-9e9a-4e364a424e17}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj.1]
[HKEY_CLASSES_ROOT\TypeLib\{3E288F79-03E4-4983-A48E-0D879B51FF19}]
[HKEY_CLASSES_ROOT\DTToolbar.ToolBandObj]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-17 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"QIP2005"="c:\program files\QIP\qip.exe" [2008-12-09 3259392]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-17 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-08 339968]
"SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-28 122880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-07-01 1447168]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"Lexmark X1100 Series"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-04 136600]
"P17Helper"="SPIRun.dll" [2006-07-03 c:\windows\system32\SPIRUN.DLL]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]

c:\documents and settings\HP\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Věýezy obrazovky a spuçtŘnˇ aplikace OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Infium]
--a------ 2008-10-14 19:10 4888576 c:\program files\QIP Infium\infium.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Documents and Settings\\HP\\Plocha\\Games\\PES 2009\\Pro Evolution Soccer 2009\\program files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\HP\\Plocha\\Games\\pes2009.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Documents and Settings\\HP\\Plocha\\Games\\Age of Empires 2\\Age of Empires II\\age2_x1.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys [2006-07-05 63352]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-07-01 34312]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
R2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [2004-08-17 14336]
R3 PPJoyBus;Parallel Port Joystick Bus device driver;c:\windows\system32\drivers\PPJoyBus.sys [2004-01-23 13952]
R3 PPortJoystick;Parallel Port Joystick device driver;c:\windows\system32\drivers\PPortJoy.sys [2004-01-23 28800]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-08-04 69120]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77597142-e704-11dd-a53b-0013d38c3133}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-OEXPRESS - c:\documents and settings\All Users\Data aplikací\LangSoft\OETRN.EXE
HKCU-Run-WEBTRAN - (no file)
MSConfigStartUp-BearShare - c:\program files\BearShare\BearShare.exe
MSConfigStartUp-DownloadAccelerator - c:\program files\DAP\DAP.EXE
MSConfigStartUp-ICQ - c:\program files\ICQ6.5\ICQ.exe
MSConfigStartUp-ICQ Lite - c:\program files\ICQLite\ICQLite.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com/cz/
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath -

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-06 20:00:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
P17Helper = Rundll32 SPIRun.dll,RunDLLEntry?

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-3096542944-285476498-1053739513-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e1,8a,c5,b1,b7,94,4c,a1,f0,7a,9f,7e,e4,28,c5,ef,04,67,6b,7c,b7,7a,26,
5a,66,33,d5,5a,44,2c,6b,66,95,c3,b0,bc,5c,10,f9,29,56,c1,02,0c,4c,3d,d1,2a,\
"??"=hex:55,58,9d,8d,70,e2,a9,ac,91,49,59,32,7b,52,2a,39

[HKEY_USERS\S-1-5-21-3096542944-285476498-1053739513-1006\Software\SecuROM\License information*]
"datasecu"=hex:f8,57,75,ae,90,23,a3,61,dd,f9,aa,af,48,b9,5d,c8,1e,b3,df,8b,9f,
4e,24,81,e4,cb,49,19,23,72,be,f0,fe,45,94,fb,14,fc,cb,d7,41,25,35,1a,1f,b7,\
"rkeysecu"=hex:00,c8,5b,12,0d,68,61,87,53,e2,4b,fd,90,8f,60,b2
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-02-06 20:01:29
ComboFix-quarantined-files.txt 2009-02-06 19:01:27

Pre-Run: 8,785,858,560
Post-Run: 9,228,709,888

218 --- E O F --- 2009-01-15 14:20:19






MBAM log

Malwarebytes' Anti-Malware 1.33
Verze databáze: 1654
Windows 5.1.2600 Service Pack 2

6.2.2009 19:50:29
mbam-log-2009-02-06 (19-50-29).txt

Typ skenu: Rychlý sken
Objektu skenováno: 50893
Uplynulý cas: 3 minute(s), 47 second(s)

Infikované procesy pameti: 0
Infikované pametové moduly: 0
Infikované klíce registru: 0
Infikované hodnoty registru: 0
Infikované položky dat registru: 11
Infikované složky: 0
Infikované soubory: 1

Infikované procesy pameti:
(Žádné zákerné položky nebyly zjišteny)

Infikované pametové moduly:
(Žádné zákerné položky nebyly zjišteny)

Infikované klíce registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované hodnoty registru:
(Žádné zákerné položky nebyly zjišteny)

Infikované položky dat registru:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\DhcpNameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{b65cbaf5-4469-406a-9ead-0016e84a25ad}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ef6613fe-9322-441d-9732-1e6af072ef77}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.39,85.255.112.40 -> Quarantined and deleted successfully.

Infikované složky:
(Žádné zákerné položky nebyly zjišteny)

Infikované soubory:
C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> Quarantined and deleted successfully.

Re: Nejde otevřít Disk C... pls help

Napsal: 06 úno 2009 21:19
od jaro3
Ten Combofix jsi dělal až po vrácení o několik dní zpátky?
Odinstaluj: DAEMON Tools Toolbar
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

File::
c:\windows\iun6002.exe

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Toto otestuj na Virustotal
c:\windows\system32\budda
Vlož sem pak odkaz výsledku.

Re: Nejde otevřít Disk C... pls help

Napsal: 07 úno 2009 18:34
od wasaw
To samé sem měl i já..byl to Rootkit RECYCLER..Udělej to podle postupu a pc bude zase svěží viewtopic.php?f=47&t=36428