AUTOLOGER - Pomoc
Napsal: 20 pro 2019 01:07
Zdravicko.
Reknu to ve zkratce. Reset WIn nepomohl, clean instal taky ne,secure erase disk v biosu taky ne. Porad dookola seru se s tim uz snad tyden.
Jedina pomoc bude snad KillDisk, ale pokud by se na to nekdo podival a vedel co s tim...
A otazka - Prenesl se vir na jine devices na networku ? Jsem na spolecne wifine s hovno zabezpecenim, neustale nas nekdo napada ale bohuzel landlord nechce zmenit heslo [ktere je fakt stupidni] a o lepsim routeru nechce ani slyset.
Mam Placeny AW Bit defender, malware, original windows, atd. Vsechny placene programy bohuzel hlasi ze je vse v poradku. Ja si myslim ze v poradku nic neni. Jsem na wifine s dalsima 6ti lidma. Kazdy mi tvrdi ze nikdo z nas vir nema a ze podnikat nejake kroky je zbytecne. Myslim si, ze dle NET statusu je vir/malware na drive X:\ networku, a proto ho maji i ostatni. Take dle odesilanych dat si myslim, ze nekdo nam proste krade nase osobni info.
Pridavam LOG z GMEru - je to pouze quick scan, mohu pridat i full scan ale je dost obsahly.
Omlouvam se za diakritiku. Ziju v USA.
Dekuji.
GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2019-12-19 15:35:08
Windows 6.2.9200 x64
Running: g732ut3z.exe
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\MSBDD_ACR0603TA1AA0038541_20_07E3_33_1002_731F_0000002F_00000000_0^41FA3D732F842EAA3B5B4C5284826835@Timestamp 0xB4 0x38 0xB8 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\hivelist@\REGISTRY\MACHINE\DRIVERS \Device\HarddiskVolume4\Windows\System32\config\DRIVERS?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 812
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute autocheck autochk *?aswBoot.exe /A:"*STARTUP" /A:"*" /L:"1033" /heur:100 /RA:fix /pup /archives /IA:0 /KBD:3 /dir:"C:\Program Files\AVAST Software\Avast"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????????????ex???????V???????????????4?malwarebytes_assistant.exe????????????????????????mbam.exe??????????????????????0?MBAMInstallerService.exe????????????????????????MbamPt.exe????410??17018-1001-12192019151035688-UsrClass.dat????? ?????????????????????????????????????C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup?ysX?? ????????????????????????????????????????????????8???????????????????????????????t????????????????????s????? ?????????????????????r??????????????????487-??? ??????????????????????????????T?:?????????????????????????ex????6?????????????????system32\drivers\aswSP.sys?vers\aswSP.sys????????????m?????ee?????6?????????????FSFilter Security Enhancer?xe????????????????????????????P???????e??? ??????????????????????????????V?;??????????????????????????????????e??tT??NDIS????????????????????w.????8???????????h?????system32\drivers\aswStm.sys?ers\aswStm.sys??????tcpip????????????????2?????eat??aswStm?s.d???? ??????u??? ???????????????????????????????????e??? ??????????????????????????????8?<????
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 6228309
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 2095501923
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 13
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 584462723
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 19771
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 19595
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID 544ee1f4-c012-4749-af36-479952c
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@SystemRoot \Device\HarddiskVolume4\WINDOWS
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@BootCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767910590152573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913430462573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913506252573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913563432573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913581562573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913601872573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767932801092573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767967390002573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767969983592573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767974755462573@SetupOperations ?????U??????????????as??????t.??????????????????????????????ex???????V???????????????4?malwarebytes_assistant.exe????????????????????????mbam.exe??????????????????????0?MBAMInstallerService.exe????????????????????????MbamPt.exe????410??17018-1001-12192019151035688-UsrClass.dat????? ?????????????????????????????????????C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup?ysX?? ????????????????????????????????????????????????8???????????????????????????????t????????????????????s????? ?????????????????????r??????????????????487-??? ??????????????????????????????T?:?????????????????????????ex????6?????????????????system32\drivers\aswSP.sys?vers\aswSP.sys????????????m?????ee?????6?????????????FSFilter Security Enhancer?xe????????????????????????????P???????e??? ??????????????????????????????V?;??????????????????????????????????e??tT??NDIS????????????????????w.????8???????????h?????system32\drivers\aswStm.sys?ers\aswStm.sys??????tcpip????????????????2?????eat??aswStm?s.d???? ??????u??? ?????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679427942104@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428006208@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428056209@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428081207@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-18@SequenceNumber 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3538239455-103221015-4105317018-1001@SequenceNumber 10
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-90-0-1@SequenceNumber 5
Reg HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon@RefCount 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 459
Reg HKLM\SYSTEM\CurrentControlSet\Services\srvnet\Parameters@MajorSequence 11
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Group Early-Launch
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@ImagePath system32\drivers\wd\WdBoot.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@ImagePath system32\drivers\wd\WdFilter.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend
Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo@4107911F-E1B6-9E44-AE3E-7BEB0B32418B 1?60??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\CloudCacheInvalidator@4107911f-e1b6-9e44-ae3e-7beb0b32418b { "DatabaseInstanceId" : 41939, "Sequence" : 1305, "activityStoreId" : "4107911F-E1B6-9E44-AE3E-7BEB0B32418B", "filter" : { "isReadFilter" : 0, "originFilterKey" : 0, "stateFilterKey" : 0, "userActionStateFilter" : 0 } }
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@C:\Users\Kuba\Downloads\g732ut3z.exe 2
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@Microsoft.Windows.Explorer 1
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Samsung\Samsung Magician\SamsungMagician.exe 5
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\TrayButtonClicked@NotificationCenterButton 3
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications@TimestampWhenSeen 0xCD 0xB1 0x2B 0x5C ...
---- EOF - GMER 2.2 ----
Reknu to ve zkratce. Reset WIn nepomohl, clean instal taky ne,secure erase disk v biosu taky ne. Porad dookola seru se s tim uz snad tyden.
Jedina pomoc bude snad KillDisk, ale pokud by se na to nekdo podival a vedel co s tim...
A otazka - Prenesl se vir na jine devices na networku ? Jsem na spolecne wifine s hovno zabezpecenim, neustale nas nekdo napada ale bohuzel landlord nechce zmenit heslo [ktere je fakt stupidni] a o lepsim routeru nechce ani slyset.
Mam Placeny AW Bit defender, malware, original windows, atd. Vsechny placene programy bohuzel hlasi ze je vse v poradku. Ja si myslim ze v poradku nic neni. Jsem na wifine s dalsima 6ti lidma. Kazdy mi tvrdi ze nikdo z nas vir nema a ze podnikat nejake kroky je zbytecne. Myslim si, ze dle NET statusu je vir/malware na drive X:\ networku, a proto ho maji i ostatni. Take dle odesilanych dat si myslim, ze nekdo nam proste krade nase osobni info.
Pridavam LOG z GMEru - je to pouze quick scan, mohu pridat i full scan ale je dost obsahly.
Omlouvam se za diakritiku. Ziju v USA.
Dekuji.
GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2019-12-19 15:35:08
Windows 6.2.9200 x64
Running: g732ut3z.exe
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Configuration\MSBDD_ACR0603TA1AA0038541_20_07E3_33_1002_731F_0000002F_00000000_0^41FA3D732F842EAA3B5B4C5284826835@Timestamp 0xB4 0x38 0xB8 0x82 ...
Reg HKLM\SYSTEM\CurrentControlSet\Control\hivelist@\REGISTRY\MACHINE\DRIVERS \Device\HarddiskVolume4\Windows\System32\config\DRIVERS?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Lsa@LsaPid 812
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute autocheck autochk *?aswBoot.exe /A:"*STARTUP" /A:"*" /L:"1033" /heur:100 /RA:fix /pup /archives /IA:0 /KBD:3 /dir:"C:\Program Files\AVAST Software\Avast"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ????????????ex???????V???????????????4?malwarebytes_assistant.exe????????????????????????mbam.exe??????????????????????0?MBAMInstallerService.exe????????????????????????MbamPt.exe????410??17018-1001-12192019151035688-UsrClass.dat????? ?????????????????????????????????????C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup?ysX?? ????????????????????????????????????????????????8???????????????????????????????t????????????????????s????? ?????????????????????r??????????????????487-??? ??????????????????????????????T?:?????????????????????????ex????6?????????????????system32\drivers\aswSP.sys?vers\aswSP.sys????????????m?????ee?????6?????????????FSFilter Security Enhancer?xe????????????????????????????P???????e??? ??????????????????????????????V?;??????????????????????????????????e??tT??NDIS????????????????????w.????8???????????h?????system32\drivers\aswStm.sys?ers\aswStm.sys??????tcpip????????????????2?????eat??aswStm?s.d???? ??????u??? ???????????????????????????????????e??? ??????????????????????????????8?<????
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Executive@UuidSequenceNumber 6228309
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\RNG@RNGAuxiliarySeed 2095501923
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BootId 13
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters@BaseTime 584462723
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@POSTTime 19771
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power@FwPOSTTime 19595
Reg HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server@InstanceID 544ee1f4-c012-4749-af36-479952c
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger@Start 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog@FileCounter 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@SystemRoot \Device\HarddiskVolume4\WINDOWS
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters@BootCounter 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767910590152573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913430462573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913506252573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913563432573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913581562573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767913601872573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767932801092573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767967390002573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767969983592573@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Instup_15767974755462573@SetupOperations ?????U??????????????as??????t.??????????????????????????????ex???????V???????????????4?malwarebytes_assistant.exe????????????????????????mbam.exe??????????????????????0?MBAMInstallerService.exe????????????????????????MbamPt.exe????410??17018-1001-12192019151035688-UsrClass.dat????? ?????????????????????????????????????C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup?ysX?? ????????????????????????????????????????????????8???????????????????????????????t????????????????????s????? ?????????????????????r??????????????????487-??? ??????????????????????????????T?:?????????????????????????ex????6?????????????????system32\drivers\aswSP.sys?vers\aswSP.sys????????????m?????ee?????6?????????????FSFilter Security Enhancer?xe????????????????????????????P???????e??? ??????????????????????????????V?;??????????????????????????????????e??tT??NDIS????????????????????w.????8???????????h?????system32\drivers\aswStm.sys?ers\aswStm.sys??????tcpip????????????????2?????eat??aswStm?s.d???? ??????u??? ?????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679427942104@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428006208@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428056209@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\aswRvrt\Parameters\Uupdate_157679428081207@ Package
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-18@SequenceNumber 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-21-3538239455-103221015-4105317018-1001@SequenceNumber 10
Reg HKLM\SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\S-1-5-90-0-1@SequenceNumber 5
Reg HKLM\SYSTEM\CurrentControlSet\Services\MBAMChameleon@RefCount 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 459
Reg HKLM\SYSTEM\CurrentControlSet\Services\srvnet\Parameters@MajorSequence 11
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Group Early-Launch
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@ImagePath system32\drivers\wd\WdBoot.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdBoot
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@ImagePath system32\drivers\wd\WdFilter.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WdFilter
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\WinDefend
Reg HKLM\SYSTEM\CurrentControlSet\Services\Winmgmt\Parameters@ServiceDllUnloadOnStop 0
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ActivityDataModel\ReaderRevisionInfo@4107911F-E1B6-9E44-AE3E-7BEB0B32418B 1?60??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\CloudStore\Store\DefaultAccount\CloudCacheInvalidator@4107911f-e1b6-9e44-ae3e-7beb0b32418b { "DatabaseInstanceId" : 41939, "Sequence" : 1305, "activityStoreId" : "4107911F-E1B6-9E44-AE3E-7BEB0B32418B", "filter" : { "isReadFilter" : 0, "originFilterKey" : 0, "stateFilterKey" : 0, "userActionStateFilter" : 0 } }
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@C:\Users\Kuba\Downloads\g732ut3z.exe 2
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@Microsoft.Windows.Explorer 1
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\AppSwitched@{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Samsung\Samsung Magician\SamsungMagician.exe 5
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage\TrayButtonClicked@NotificationCenterButton 3
Reg HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Notifications@TimestampWhenSeen 0xCD 0xB1 0x2B 0x5C ...
---- EOF - GMER 2.2 ----