Prosim o kontrolu LOGU Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 28 pro 2009 16:00

Az ked mi na pracovnom PC virus vyradil systemovy HDD :crazy: , zacal som sa vaznejsie zaujimat o SW... Prosim o kontrolu logu mojho zalozneho Pc - nerad by som prisiel i jeho data. Prikladam vypis scanu MWAV a HJT log. Vopred dik. P.S: pravidelne pouzivam AVAST a Spyboot, ale evidentne je to malo... Vopred dakujem.

MWAV-vypis
Objekt "Conducent FlexPak Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Adware.FindNavi Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Spyware.NetScreenWatch Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "HotBar Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Trust Fighter Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Trust Fighter Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Trust Fighter Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Objekt "Trust Fighter Spyware/Adware" nalezen v souborovém systému! Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" odkazuje na neplatný objekt "C:\Program Files\HP\Digital Imaging\Smart Web Printing\". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" odkazuje na neplatný objekt "C:\Program Files\HP\Digital Imaging\HP Photosmart C4500 series\". Provedené akce: Ponecháno, neodstraněno!.
Záznam "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" odkazuje na neplatný objekt "C:\Program Files\HP\Digital Imaging\hp Photosmart C4500 series\help\". Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\WINDOWS\Install.exe je infikovaný virem Adware.Generic.59500 (DB) !! Provedené akce: Ponecháno, neodstraněno!.
Soubor C:\WINDOWS\Install.exe je infikovaný virem Adware.Generic.59500 (DB) !! Provedené akce: Ponecháno, neodstraněno!.

HJT-log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:47:47, on 28. 12. 2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gAutoPan.exe
C:\Genius\ioCentre\gAutoScroll.exe
C:\Genius\ioCentre\gZoom.exe
C:\Genius\ioCentre\gMGlass.exe
C:\Genius\ioCentre\gIMMgm.exe
C:\Genius\ioCentre\gKbStatus.exe
C:\Genius\ioCentre\gDeskMgm.exe
C:\Genius\ioCentre\gTaskSwitch.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\svchost.exe
G:\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ioCentre] C:\Genius\ioCentre\gTaskBar.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: FuzzyPWM Application.LNK = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1} (NOXLATE) -
O16 - DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} (CSOBEnroll Class) - https://ib24.csob.sk/Comp/CSOBEnroll.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 2002392687
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Ovládací prvek AcDcToday) -
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (Prvek AcPreview) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5CC0DEFE-EBC2-462C-80E8-31E723E680FC}: NameServer = 208.67.220.220,208.67.222.222
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 5734 bytes

Reklama
pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 28 pro 2009 22:26

Ahoj.

1) Otestuj subor(y) na >>VIRUSTOTALe<<:

Kód: Vybrat vše

C:\WINDOWS\Install.exe

Ak vypise, ze subor uz bol testovany, daj ho otestovat znovu. Vysledok posli ako LINK.


2) Stiahni CKScanner na plochu. Spust program dvojklikom na ikonu. Otvori sa okno, v nom klik na "Search For Files". Zacne scan, po jeho skonceni klikni na "Save List To File" -> "OK". Na ploche by sa mal objavit subor s nazvom CKFiles.txt, jeho obsah mi sem skopiruj.


3) Stiahni DDS. Uloz na plochu, ukonci vsetky spustene programy a spust ho. Po skonceni scanu sa otvoria vysledky v 2 oknach - DDS.txt a Attach.txt. Obsah oboch by som rad videl.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 29 pro 2009 11:26

Dik - posielam pozadovane subory....

Soubor Install.exe přijatý 2009.12.29 10:04:32 (UTC)
Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.43 2009.12.29 Riskware.AdWare.Win32.Casino.q!IK
AhnLab-V3 5.0.0.2 2009.12.28 -
AntiVir 7.9.1.122 2009.12.29 GAME/Casino.Gen
Antiy-AVL 2.0.3.7 2009.12.29 -
Authentium 5.2.0.5 2009.12.29 W32/Adware.AP
Avast 4.8.1351.0 2009.12.27 -
AVG 8.5.0.430 2009.12.28 Generic.KLT
BitDefender 7.2 2009.12.29 Adware.Generic.59500
CAT-QuickHeal 10.00 2009.12.29 -
ClamAV 0.94.1 2009.12.29 Adware.Casino-3
Comodo 3399 2009.12.29 ApplicUnwnt.Win32.Adware.CasOnline.8
DrWeb 5.0.1.12222 2009.12.29 Adware.Casino
eSafe 7.0.17.0 2009.12.28 -
eTrust-Vet 35.1.7203 2009.12.29 Win32/CasOnline!Adware
F-Prot 4.5.1.85 2009.12.28 W32/Adware.AP
F-Secure 9.0.15370.0 2009.12.29 Adware.Generic.59500
Fortinet 4.0.14.0 2009.12.29 Adware/Casino
GData 19 2009.12.29 Adware.Generic.59500
Ikarus T3.1.1.79.0 2009.12.29 not-a-virus:AdWare.Win32.Casino.q
Jiangmin 13.0.900 2009.12.29 Adware/Ncast.e
K7AntiVirus 7.10.932 2009.12.28 Non-Virus:AdWare.Win32.Casino.q
Kaspersky 7.0.0.125 2009.12.29 -
McAfee 5845 2009.12.28 potentially unwanted program CasOnline
McAfee+Artemis 5845 2009.12.28 potentially unwanted program CasOnline
McAfee-GW-Edition 6.8.5 2009.12.29 Heuristic.LooksLike.Win32.CasOnline.H
Microsoft 1.5302 2009.12.29 -
NOD32 4723 2009.12.28 -
Norman 6.04.03 2009.12.28 W32/Casino.AB
nProtect 2009.1.8.0 2009.12.29 -
Panda 10.0.2.2 2009.12.15 Adware/888Bar
PCTools 7.0.3.5 2009.12.29 Adware.Casino.N
Prevx 3.0 2009.12.29 Low Risk Adware
Rising 22.28.01.03 2009.12.29 -
Sophos 4.49.0 2009.12.29 Casino-On-Net downloader
Sunbelt 3.2.1858.2 2009.12.29 Trojan.Agent
Symantec 1.4.4.12 2009.12.29 -
TheHacker 6.5.0.3.117 2009.12.29 -
TrendMicro 9.120.0.1004 2009.12.29 -
VBA32 3.12.12.1 2009.12.28 -
ViRobot 2009.12.29.2114 2009.12.29 -
VirusBuster 5.0.21.0 2009.12.28 Adware.Agent.JOSX

Rozšiřující informace
File size: 166680 bytes
MD5...: 0972eddd484b43168f879a75ae7e6fb4
SHA1..: ddbc006670e3cb8e045f7a669867795153ed0a5c
SHA256: 6de8b18779decf77d1c257bc0b20c364403238513f5a51db7911a02abbda0512
ssdeep: 3072:7+R0hajiERTWntMGQhGzRRlKOogPbtL5wbNhYJWfln5lwrlXnN:7J2yR0Qb<br>tLONhtlCl9<br>
PEiD..: -
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x13bff<br>timedatestamp.....: 0x43c614a4 (Thu Jan 12 08:34:44 2006)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x1b9d4 0x1c000 6.33 57a5ff17a55be38db514dca8f5e969a2<br>.rdata 0x1d000 0x1c20 0x2000 4.96 918883116a59907003ab7f252f2f614e<br>.data 0x1f000 0x3122c 0x5000 2.91 e0542c994b283c37f252af1ea2a51b81<br>.rsrc 0x51000 0xec0 0x1000 4.93 dd07dc988312c9df2fae84641e74b801<br><br>( 8 imports ) <br>&gt; WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>&gt; VERSION.dll: GetFileVersionInfoSizeA, VerQueryValueA, GetFileVersionInfoA<br>&gt; KERNEL32.dll: ReleaseMutex, GetPrivateProfileIntA, CreateThread, LeaveCriticalSection, EnterCriticalSection, TerminateThread, GetModuleFileNameA, GetTempPathA, GetModuleHandleA, GetCurrentDirectoryA, lstrlenA, GetLastError, WaitForMultipleObjects, DeleteFileA, InitializeCriticalSection, DeleteCriticalSection, WriteFile, CopyFileA, GetUserDefaultLangID, GlobalFree, GlobalSize, GlobalUnlock, GlobalLock, GlobalAlloc, LocalFree, LocalAlloc, SetConsoleCtrlHandler, SetStdHandle, FlushFileBuffers, CompareStringA, CompareStringW, SetEnvironmentVariableA, GlobalMemoryStatus, GetVersion, GetVersionExA, CreateMutexA, CloseHandle, CreateEventA, WinExec, GetTickCount, GetPrivateProfileStringA, WaitForSingleObject, SetEvent, MulDiv, CreateFileA, LoadLibraryA, ReadFile, SetFilePointer, GetFileSize, IsBadWritePtr, HeapCreate, HeapDestroy, VirtualFree, GetProcAddress, HeapSize, GetEnvironmentVariableA, TerminateProcess, VirtualAlloc, UnhandledExceptionFilter, GetCurrentProcess, GetOEMCP, GetACP, GetCPInfo, RemoveDirectoryA, CreateDirectoryA, ExitProcess, GetCommandLineA, GetStartupInfoA, HeapFree, HeapAlloc, GetStringTypeW, GetSystemTime, GetTimeZoneInformation, GetLocalTime, FreeEnvironmentStringsA, FreeEnvironmentStringsW, RtlUnwind, GetEnvironmentStrings, GetEnvironmentStringsW, WideCharToMultiByte, GetStdHandle, GetFileType, SetHandleCount, IsBadReadPtr, IsBadCodePtr, SetUnhandledExceptionFilter, LCMapStringA, LCMapStringW, MultiByteToWideChar, GetStringTypeA, HeapReAlloc<br>&gt; USER32.dll: LoadIconA, DialogBoxParamA, TranslateAcceleratorA, TranslateMessage, DispatchMessageA, LoadCursorA, MessageBoxA, GetClassInfoExA, SetForegroundWindow, EndPaint, FindWindowA, SetFocus, ReleaseDC, FillRect, GetClientRect, ScreenToClient, GetDC, CreateWindowExA, ShowWindow, GetWindowRect, SetWindowTextA, IntersectRect, IsRectEmpty, PtInRect, UnionRect, SendDlgItemMessageA, DrawTextA, InvalidateRect, UpdateWindow, SetDlgItemTextA, KillTimer, SetTimer, EnumDisplaySettingsA, ChangeDisplaySettingsA, GetSystemMetrics, GetMessageA, MessageBoxIndirectA, EndDialog, DestroyWindow, PostQuitMessage, GetDlgItem, EnableWindow, RegisterClassExA, DefWindowProcA, LoadAcceleratorsA, PostMessageA, SendMessageA, IsWindow<br>&gt; GDI32.dll: CreateSolidBrush, CreateCompatibleDC, SelectObject, CreateCompatibleBitmap, GetDeviceCaps, GetObjectA, CreateFontIndirectA, SetMapMode, SetTextColor, SetBkColor, GetBkColor, DeleteDC, SetBkMode, CreateBitmap, CreateDIBitmap, DeleteObject, BitBlt<br>&gt; ADVAPI32.dll: RegCloseKey, RegSetValueExA, RegCreateKeyExA, RegOpenKeyExA, RegQueryValueExA<br>&gt; SHELL32.dll: ShellExecuteExA<br>&gt; ole32.dll: CoCreateGuid<br><br>( 0 exports ) <br>
RDS...: NSRL Reference Data Set<br>-
pdfid.: -
trid..: Win64 Executable Generic (59.6%)<br>Win32 Executable MS Visual C++ (generic) (26.2%)<br>Win32 Executable Generic (5.9%)<br>Win32 Dynamic Link Library (generic) (5.2%)<br>Generic Win/DOS Executable (1.3%)
&lt;a href='http://info.prevx.com/aboutprogramtext.asp?PX5=1CF4239B1896CD0C8B6502E99EAC710038E21EAF' target='_blank'&gt;http://info.prevx.com/aboutprogramtext.asp?PX5=1CF4239B1896CD0C8B6502E99EAC710038E21EAF&lt;/a&gt;
ThreatExpert info: &lt;a href='http://www.threatexpert.com/report.aspx?md5=0972eddd484b43168f879a75ae7e6fb4' target='_blank'&gt;http://www.threatexpert.com/report.aspx?md5=0972eddd484b43168f879a75ae7e6fb4&lt;/a&gt;
sigcheck:<br>publisher....: Random-Logic<br>copyright....: Copyright (c) 2004<br>product......: Random-Logic Installer<br>description..: Installer<br>original name: Installer.exe<br>internal name: Installer<br>file version.: 3.5.0.6<br>comments.....: <br>signers......: -<br>signing date.: -<br>verified.....: Unsigned<br>

CKScanner - Additional Security Risks - These are not necessarily bad
c:\program files\bitcomet\torrents\crysis.cracks+key-saved.torrent
c:\program files\bitcomet\torrents\mass.effect.crackfix+key-saved.torrent
scanner sequence 3.LB.11
----- EOF -----


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Systém Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 27.12.2009 22:40:47
System Uptime: 29.12.2009 10:52:36 (1 hours ago)

Motherboard: MICRO-STAR INC. | | MS-6580
Processor: Intel(R) Pentium(R) 4 CPU 2.80GHz | FC-478 | 2800/133mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 49 GiB total, 27,218 GiB free.
F: is FIXED (NTFS) - 78 GiB total, 22,78 GiB free.
G: is FIXED (NTFS) - 22 GiB total, 21,021 GiB free.
H: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Ralink Turbo Wireless LAN Card
Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_25611814&REV_00\4&1A671D0C&0&18F0
Manufacturer: Ralink Technology, Inc.
Name: Ralink Turbo Wireless LAN Card #4
PNP Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_25611814&REV_00\4&1A671D0C&0&18F0
Service: RT61

Class GUID: {4D36E96A-E325-11CE-BFC1-08002BE10318}
Description: Sekundární kanál IDE
Device ID: PCIIDE\IDECHANNEL\4&EDAF9CF&0&1
Manufacturer: (Standardní řadiče IDE ATA/ATAPI)
Name: Sekundární kanál IDE
PNP Device ID: PCIIDE\IDECHANNEL\4&EDAF9CF&0&1
Service: idechndr

==== System Restore Points ===================

RP1: 27.12.2009 22:56:48 - Kontrolní bod systému
RP2: 27.12.2009 23:10:45 - Nainstalováno Windows XP Service Pack 3.

==== Installed Programs ======================


32 Bit HP CIO Components Installer
Acronis Disk Director Suite
Adobe Acrobat 6.0 Professional
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
AIM
AnswerWorks Runtime
AutoCAD 2008 - Český
AutoCAD LT 2000i česká verze
Autodesk DWF Viewer 7
avast! Antivirus
BitComet 0.60
BS.Player FREE
BSPlayer
BufferChm
C4580
C4580_Help
Cards_Calendar_OrderGift_DoMorePlugout
Codec Pack - All In 1 6.0.3.0
Comfy KB-16M
Core Center
Destination Component
DeviceDiscovery
DocProc
DocProcQFolder
eSupportQFolder
Freelancer
Gaming Mouse
GPBaseService
HijackThis 2.0.2
HP Imaging Device Functions 11.0
HP Photosmart C4500 All-In-One Driver Software 11.0 Rel .4
HP Photosmart Essential 2.5
HP Photosmart Essential 3.0
HP Smart Web Printing
HP Solution Center 11.0
HP Update
HPPhotoSmartPhotobookWebPack1
HPProductAssistant
Intel Application Accelerator
ioCentre
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Language Pack - CSY
Microsoft AutoRoute Express Europa 2000
Microsoft Game Studios Common Redistributables Pack 1
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft XML Parser
Mozilla Firefox (3.0.16)
MSXML 6.0 Parser
Nero 6 Ultra Edition
Nero 6.6.0.18 a Nero vision express 3.1.0.21 Cz
Network
Norton PartitionMagic
Norton PartitionMagic 8.0
NVIDIA Drivers
OCR Software by I.R.I.S. 11.0
PanoStandAlone
PowerISO
PS_AIO_04_C4580_ProductContext
PS_AIO_04_C4580_Software
PS_AIO_04_C4580_Software_Min
PSSWCORE
Ralink Wireless LAN Card
Realtek AC'97 Audio
Realtek High Definition Audio Driver
Registry Mechanic 6.0
Scan
SmartWebPrinting
SolutionCenter
Spybot - Search & Destroy
Status
The KMPlayer (remove only)
Toolbox
TrayApp
TuneUp Utilities 2008
UnloadSupport
VBA (2627.01)
VideoToolkit01
WebFldrs XP
WebReg
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WingMan Software
WinRAR archivátor
X3 Reunion v2.5
X3 Terran Conflict v2.5
Zoner Photo Studio 8

==== End Of File ===========================


DDS (Ver_09-12-01.01) - NTFSx86
Run by user at 11:15:46,53 on ut 29. 12. 2009
Internet Explorer: 6.0.2900.5512
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.649 [GMT 1:00]

AV: avast! antivirus 4.8.1368 [VPS 091227-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Genius\ioCentre\gTaskBar.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Genius\ioCentre\gMouseTask.exe
C:\Genius\ioCentre\gKbdTask.exe
C:\Genius\ioCentre\gAutoPan.exe
C:\Genius\ioCentre\gAutoScroll.exe
C:\Genius\ioCentre\gZoom.exe
C:\Genius\ioCentre\gMGlass.exe
C:\Genius\ioCentre\gIMMgm.exe
C:\Genius\ioCentre\gKbStatus.exe
C:\Genius\ioCentre\gDeskMgm.exe
C:\Genius\ioCentre\gTaskSwitch.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Documents and Settings\user\Plocha\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.sk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [ioCentre] c:\genius\iocentre\gTaskBar.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [OSSelectorReinstall] c:\program files\common files\acronis\acronis disk director\oss_reinstall.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\user\nabdka~1\programy\posput~1\fuzzyp~1.lnk - c:\program files\msi\core center\CoreCenter.exe
StartupFolder: c:\docume~1\alluse~1\nabdka~1\programy\posput~1\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: csob.sk\ib24
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1}
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://ib24.csob.sk/Comp/CSOBEnroll.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupda ... 2002392687
DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/sh ... wflash.cab
DPF: {F281A59C-7B65-11D3-8617-0010830243BD}
TCP: {5CC0DEFE-EBC2-462C-80E8-31E723E680FC} = 208.67.220.220,208.67.222.222
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\user\dataap~1\mozilla\firefox\profiles\rta72c9p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - BS_Player Customized Web Search
FF - prefs.js: browser.startup.homepage - www.google.sk

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.XMLHttpRequest.channel", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("security.checkloaduri", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("bidi.characterset", 1);
c:\program files\mozilla firefox\defaults\pref\channel-prefs.js - pref("app.update.channel", "release");
c:\program files\mozilla firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");

============= SERVICES / DRIVERS ===============

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [2009-1-17 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [2009-1-17 5248]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-6 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-1-17 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-1-17 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-1-17 138680]
R3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\drivers\gMouPS2.sys [2009-2-28 17408]
R3 PCAlertDriver;PCAlertDriver;c:\program files\msi\core center\NTGLM7X.sys [2009-1-15 28160]
R3 PSched;Plánovač paketů technologie QoS;c:\windows\system32\drivers\psched.sys [2004-8-3 69120]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-1-17 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-1-17 352920]

=============== Created Last 30 ================

2009-12-28 18:00:22 844 ------w- c:\windows\hpomdl30.dat
2009-12-28 18:00:22 166422 ----a-w- c:\windows\hpoins30.dat
2009-12-28 17:19:10 974848 ----a-w- c:\windows\system32\hpost_p01a.dll
2009-12-28 17:19:10 729088 ----a-w- c:\windows\system32\hposwia_p01a.dll
2009-12-28 17:19:10 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2009-12-28 17:19:10 309760 ----a-w- c:\windows\system32\difxapi.dll
2009-12-28 17:19:10 303104 ----a-w- c:\windows\system32\hposc_p01a.dll
2009-12-28 12:17:37 0 d---a-w- c:\windows\rundll16.exe
2009-12-28 12:17:37 0 d---a-w- c:\windows\logo1_.exe
2009-12-27 22:13:49 0 d-----w- c:\windows\ServicePackFiles
2009-12-27 22:13:29 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-12-27 22:10:37 19569 ----a-w- c:\windows\003338_.tmp
2009-12-27 21:39:59 23040 -c--a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2009-12-27 21:38:59 13463552 -c--a-w- c:\windows\system32\dllcache\hwxjpn.dll
2009-12-27 21:37:58 95232 -c--a-w- c:\windows\system32\dllcache\certmap.ocx
2009-12-27 21:36:27 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2009-12-27 21:36:20 749 ---ha-r- c:\windows\WindowsShell.Manifest
2009-12-27 21:36:20 749 ---ha-r- c:\windows\system32\wuaucpl.cpl.manifest
2009-12-27 21:36:20 749 ---ha-r- c:\windows\system32\sapi.cpl.manifest
2009-12-27 21:36:20 749 ---ha-r- c:\windows\system32\nwc.cpl.manifest
2009-12-27 21:36:20 749 ---ha-r- c:\windows\system32\ncpa.cpl.manifest
2009-12-27 21:36:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-12-27 21:35:54 162304 ----a-w- c:\windows\system32\wuaucpl.cpl
2009-12-27 21:35:00 0 d-----w- c:\windows\system32\wbem\Repository
2009-12-27 21:30:42 0 d-----w- c:\windows\system32\ReinstallBackups
2009-12-27 19:34:47 25065 ----a-w- c:\windows\system32\wmpscheme.xml
2009-12-27 19:34:44 299552 ----a-w- c:\windows\WMSysPrx.prx
2009-12-27 19:24:34 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-27 19:24:32 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2009-12-27 19:21:09 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-12-27 19:21:00 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2009-12-27 19:20:58 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-12-27 17:41:08 0 d-----w- c:\program files\Trend Micro
2009-12-27 13:50:02 0 d---a-w- c:\windows\VDLL.DLL
2009-12-27 13:50:02 0 d---a-w- c:\windows\system32\runouce.exe
2009-12-27 13:50:02 0 d---a-w- c:\windows\RUNDL132.EXE
2009-12-27 13:50:02 0 d---a-w- c:\windows\logo_1.exe
2009-12-27 13:49:18 54 ----a-w- c:\windows\Lic.xxx
2009-12-27 13:48:50 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-12-27 13:48:49 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-12-27 13:48:47 522 ----a-w- c:\windows\system32\Microsoft.VC80.CRT.manifest
2009-12-27 13:48:47 34048 ----a-w- c:\windows\system32\eEmpty.exe
2009-12-27 13:48:45 147968 ----a-w- c:\windows\R.COM
2009-12-27 13:48:45 137216 ----a-w- c:\windows\system32\TASKMGR.COM
2009-12-27 13:48:45 137216 ----a-w- c:\windows\system32\T.COM
2009-12-27 13:48:44 147968 ----a-w- c:\windows\REGEDIT.COM
2009-12-27 13:48:42 0 d-----w- c:\program files\common files\MicroWorld
2009-12-27 13:48:40 0 d-----w- c:\docume~1\alluse~1\dataap~1\MicroWorld
2009-12-13 12:41:45 0 d-----w- c:\program files\common files\HP
2009-12-13 12:41:16 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-12-13 12:39:16 316286 ----a-w- c:\windows\setupapi.old
2009-12-12 14:23:54 588148 ----a-w- c:\windows\hpoins30.dat.temp
2009-12-12 14:23:53 844 ----a-w- c:\windows\hpomdl30.dat.temp
2009-12-12 14:22:48 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-12-12 14:22:05 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-12-12 14:21:42 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-06 18:27:00 0 d-----w- c:\program files\EGOSOFT
2009-12-06 13:10:13 0 d-----w- c:\program files\Rapget

==================== Find3M ====================

2009-12-29 09:57:19 87168 ----a-w- c:\windows\system32\perfc005.dat
2009-12-29 09:57:19 432736 ----a-w- c:\windows\system32\perfh005.dat
2009-12-27 21:34:43 22900 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-17 18:41:22 796672 ----a-w- c:\windows\GPInstall.exe

============= FINISH: 11:16:06,79 ===============

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 29 pro 2009 13:14

1) Stiahni ComboFix, najlepsie na plochu. Vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall. Spust program cez ucet s administratorskymi pravami a postupuj podla instrukcii. Cely sken bude trvat cca 10 minut. Pocas neho moze byt PC restartovane. Log, ktory ComboFix vytvori, najdes na adrese "C:\ComboFix.txt".
Ten vloz sem.

Pozor: Kym ComboFix nevytvori log, na nic neklikat, nic nestlacat !!


2) Stiahni GMER, rozbal ho na plochu a spust. Program automaticky zacne scan (po jeho skonceni vloz log c. 1) - pokial pri scanovani nieco najde (=vyskoci nejake upozornenie), klik na "NO" a nastavis program podla obrazku:
Obrázek
Klik na "Scan". Po scane klik na "Save" a log c. 2 vloz sem.

Ak nic nenajde (=nevyskoci nic), zaskrtaj vpravo vsetko a spusti scan. Po jeho ukonceni klik na "Copy" a vloz log c. 2.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 29 pro 2009 20:50

Prikladam pozadovane logy...

LOG c. 1:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-29 19:59:32
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\pxtdqpoc.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEB3196B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEB319574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEB319A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEB31914C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEB31964E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEB31908C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEB3190F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEB31976E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEB31972E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEB3198AE]

Code \??\C:\DOCUME~1\user\LOCALS~1\Temp\catchme.sys pIofCallDriver

---- Kernel code sections - GMER 1.0.15 ----

.sfreloc˙˙˙˙sfsync03unknown last section [0xF75DB000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xF75DB000, 0xA20, 0x40000040]
? C:\DOCUME~1\user\LOCALS~1\Temp\catchme.sys Systém nemůže nalézt uvedený soubor. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP0T0L0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\IdeChnDr \Device\Ide\IdeChnDr0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----

LOG c. 2:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-29 20:47:15
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\user\LOCALS~1\Temp\pxtdqpoc.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEB3196B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xEB319574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEB319A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEB31914C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xEB31964E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEB31908C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEB3190F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEB31976E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEB31972E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEB3198AE]

Code \??\C:\DOCUME~1\user\LOCALS~1\Temp\catchme.sys pIofCallDriver

---- Kernel code sections - GMER 1.0.15 ----

.sfreloc˙˙˙˙sfsync03unknown last section [0xF75DB000, 0xA20, 0x40000040] C:\WINDOWS\system32\drivers\sfsync03.sys unknown last section [0xF75DB000, 0xA20, 0x40000040]
? C:\DOCUME~1\user\LOCALS~1\Temp\catchme.sys Systém nemůže nalézt uvedený soubor. !
? C:\WINDOWS\system32\Drivers\PROCEXP113.SYS Systém nemůže nalézt uvedený soubor. !

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003D0002
IAT C:\WINDOWS\system32\services.exe[800] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003D0000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\IdeChnDr \Device\Ide\IdeDeviceP0T0L0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \Driver\IdeChnDr \Device\Ide\IdeChnDr0 sfsync03.sys (StarForce Protection Synchronization Driver/Protection Technology)

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- EOF - GMER 1.0.15 ----

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 30 pro 2009 11:07

Miesto 3 roznych logov (2x GMER, 1x CF) tu vidim len dva rovnake logy z GMERu... :blink:
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 30 pro 2009 14:16

Sorry, ComboFix som zabudol prvykrat prilozit. Ale GMER je urobeny podla navodu. Prvy LOG je urobeny po instalacii GMER (nevypisal mi ziadne chybove hlasenie) a druhy LOG je scan s oznacenim vsetkych poloziek. Takze teraz prikladam len CF-log. GMER logy su zaslane zo vcera - ak treba urobit zmeny v nastaveni scanu, urobim nove - ale isiel som podla navodu...

ComboFix 09-12-28.06 - user . 12. 2009 17:12:55.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.703 [GMT 1:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091229-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\install.exe
c:\windows\regedit.com
c:\windows\system32\ieuinit.inf
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((( Soubory vytvořené od 2009-11-28 do 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-28 18:02 . 2009-12-28 18:02 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-28 18:00 . 2009-12-28 18:09 166422 ----a-w- c:\windows\hpoins30.dat
2009-12-28 18:00 . 2008-06-18 06:22 844 ------w- c:\windows\hpomdl30.dat
2009-12-28 17:19 . 2008-04-16 04:05 974848 ----a-w- c:\windows\system32\hpost_p01a.dll
2009-12-28 17:19 . 2008-04-16 04:05 729088 ----a-w- c:\windows\system32\hposwia_p01a.dll
2009-12-28 17:19 . 2008-04-16 04:05 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2009-12-28 17:19 . 2008-04-16 04:05 309760 ----a-w- c:\windows\system32\difxapi.dll
2009-12-28 17:19 . 2008-02-28 10:08 303104 ----a-w- c:\windows\system32\hposc_p01a.dll
2009-12-28 12:17 . 2009-12-28 12:17 -------- d---a-w- c:\windows\rundll16.exe
2009-12-28 12:17 . 2009-12-28 12:17 -------- d---a-w- c:\windows\logo1_.exe
2009-12-27 22:13 . 2008-04-14 07:52 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-12-27 21:39 . 2001-10-25 14:00 14848 -c--a-w- c:\windows\system32\dllcache\register.exe
2009-12-27 21:38 . 2008-04-14 07:46 13463552 -c--a-w- c:\windows\system32\dllcache\hwxjpn.dll
2009-12-27 21:36 . 2001-10-25 14:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-12-27 21:35 . 2009-12-27 21:35 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-27 21:15 . 2001-10-25 14:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-12-27 21:15 . 2001-10-25 14:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-12-27 21:15 . 2001-10-25 14:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-12-27 21:15 . 2001-10-25 14:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-12-27 19:27 . 2008-04-14 07:52 131584 ----a-w- c:\windows\system32\sndrec32.exe
2009-12-27 19:24 . 2008-04-13 23:15 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-27 19:24 . 2008-04-13 23:15 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2009-12-27 19:21 . 2008-04-14 06:44 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-12-27 19:21 . 2008-04-14 07:53 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2009-12-27 19:20 . 2008-04-13 23:02 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-12-27 19:19 . 2008-04-13 23:24 11264 ----a-w- c:\windows\system32\drivers\irenum.sys
2009-12-27 19:19 . 2008-04-14 07:53 146944 ----a-w- c:\windows\system\winspool.drv
2009-12-27 19:19 . 2008-04-14 07:52 75264 ----a-w- c:\windows\system32\storprop.dll
2009-12-27 17:41 . 2009-12-27 17:41 -------- d-----w- c:\program files\Trend Micro
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\VDLL.DLL
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\system32\runouce.exe
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\logo_1.exe
2009-12-27 13:48 . 2009-12-27 13:48 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-12-27 13:48 . 2009-12-27 13:48 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-12-27 13:48 . 2009-12-27 13:48 34048 ----a-w- c:\windows\system32\eEmpty.exe
2009-12-27 13:48 . 2008-04-14 06:52 137216 ----a-w- c:\windows\system32\T.COM
2009-12-27 13:48 . 2008-04-14 06:52 147968 ----a-w- c:\windows\R.COM
2009-12-27 13:48 . 2009-12-27 13:48 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-12-13 12:41 . 2009-12-13 12:41 -------- d-----w- c:\program files\Common Files\HP
2009-12-13 12:41 . 2008-04-16 04:05 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-12-12 14:22 . 2008-04-16 04:05 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-12-12 14:22 . 2008-04-16 04:05 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-12-12 14:21 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-06 18:27 . 2009-12-06 18:47 -------- d-----w- c:\program files\EGOSOFT
2009-12-06 13:10 . 2009-12-06 13:10 -------- d-----w- c:\program files\Rapget

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 16:13 . 2001-10-25 14:00 88044 ----a-w- c:\windows\system32\perfc005.dat
2009-12-29 16:13 . 2001-10-25 14:00 434542 ----a-w- c:\windows\system32\perfh005.dat
2009-12-29 09:51 . 2009-06-21 08:40 -------- d-----w- c:\program files\HP
2009-12-28 10:34 . 2009-01-24 14:26 -------- d-----w- c:\program files\Common Files\Acronis
2009-12-27 22:35 . 2009-04-10 19:33 -------- d-----w- c:\program files\Google
2009-12-27 22:18 . 2009-12-27 19:30 86665 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-27 22:18 . 2009-01-15 14:09 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-27 21:34 . 2009-01-15 14:07 22900 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-27 20:10 . 2009-01-15 20:58 -------- d-----w- c:\program files\MSI
2009-12-27 19:32 . 2009-12-27 19:30 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-11 22:17 . 2009-01-15 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-24 23:54 . 2009-01-17 18:28 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-01-17 18:29 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-01-17 18:29 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-01-17 18:45 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-01-17 18:45 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-01-17 18:29 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-01-17 18:29 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-01-17 18:29 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-01-17 18:28 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2009-11-17 18:41 . 2009-11-17 18:41 796672 ----a-w- c:\windows\GPInstall.exe
2009-10-24 17:14 . 2009-10-24 17:14 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-12-17 61440]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
"OSSelectorReinstall"="c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2007-02-22 2209224]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\user\Nabˇdka Start\Programy\Po spuçtŘnˇ\
FuzzyPWM Application.LNK - c:\program files\MSI\Core Center\CoreCenter.exe [2009-1-15 932864]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-14 07:51 625664 ----a-w- c:\windows\system32\catsrvut.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"SW20"=c:\windows\system32\sw20.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"SW24"=c:\windows\system32\sw24.exe
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"CHotKey"=mHotkey.exe
"mouseElf"=c:\progra~1\GAMING~1\MouseElf.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\Freelancer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [17.1.2009 20:15 5248]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 16:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [17.1.2009 19:45 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.1.2009 19:45 20560]
R3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\drivers\gMouPS2.sys [28.2.2009 13:42 17408]
S0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [17.1.2009 20:15 160640]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: csob.sk\ib24
TCP: {5CC0DEFE-EBC2-462C-80E8-31E723E680FC} = 208.67.220.220,208.67.222.222
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1}
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://ib24.csob.sk/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\documents and settings\user\Data aplikací\Mozilla\Firefox\Profiles\rta72c9p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - BS_Player Customized Web Search
FF - prefs.js: browser.startup.homepage - www.google.sk

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 17:16
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
Celkový čas: 2009-12-29 17:19:07
ComboFix-quarantined-files.txt 2009-12-29 16:19

Před spuštěním: Volných bajtů: 29 100 924 928
Po spuštění: Volných bajtů: 29 354 545 152

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 75B215C58F1B8D02ECFC6EB1894C63BF

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 30 pro 2009 15:55

Stiahni a spust AVPTool. Vypracuj log podla navodu a vloz ho.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 30 pro 2009 18:44

Pripajam AVP log
Autoscan: completed 13 minutes ago (events: 2, objects: 307393, time: 01:43:09)
30. 12. 2009 16:43:13 Task started
30. 12. 2009 18:26:22 Task completed

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 30 pro 2009 23:35

OK, tak teda sprav toto:

Presun ikonu CF na plochu, vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall a otvor poznamkovy blok. Donho skopiruj:

Kód: Vybrat vše

KillAll::
File::
C:\WINDOWS\Install.exe

FixCSet::

Uloz na plochu ako CFScript.txt a mysou pretiahni nad ikonou CF.

Obrázek

Program script spracuje a spravi novy log.


Pozor: Ak po aplikacii skriptu nenabehne Windows, restartuj PC, stlac F8 a zvol Poslednu znamu funkcnu konfiguraciu.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Bubo3
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod Bubo3 » 31 pro 2009 10:36

Prikladam CF log po zrealizovani CFScrip.txt:

ComboFix 09-12-30.01 - user . 12. 2009 10:18:54.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.1023.721 [GMT 1:00]
Spuštěný z: c:\documents and settings\user\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\user\Plocha\CFScript.txt.txt
AV: avast! antivirus 4.8.1368 [VPS 091230-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
"c:\windows\Install.exe"
.

((((((((((((((((((((((((( Soubory vytvořené od 2009-11-28 do 2009-12-31 )))))))))))))))))))))))))))))))
.

2009-12-30 15:08 . 2009-12-30 15:09 -------- d-----w- c:\windows\system32\NtmsData
2009-12-28 18:02 . 2009-12-28 18:02 -------- d-----w- c:\program files\Hewlett-Packard
2009-12-28 18:00 . 2009-12-28 18:09 166422 ----a-w- c:\windows\hpoins30.dat
2009-12-28 18:00 . 2008-06-18 06:22 844 ------w- c:\windows\hpomdl30.dat
2009-12-28 17:19 . 2008-04-16 04:05 974848 ----a-w- c:\windows\system32\hpost_p01a.dll
2009-12-28 17:19 . 2008-04-16 04:05 729088 ----a-w- c:\windows\system32\hposwia_p01a.dll
2009-12-28 17:19 . 2008-04-16 04:05 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2009-12-28 17:19 . 2008-04-16 04:05 309760 ----a-w- c:\windows\system32\difxapi.dll
2009-12-28 17:19 . 2008-02-28 10:08 303104 ----a-w- c:\windows\system32\hposc_p01a.dll
2009-12-28 12:17 . 2009-12-28 12:17 -------- d---a-w- c:\windows\rundll16.exe
2009-12-28 12:17 . 2009-12-28 12:17 -------- d---a-w- c:\windows\logo1_.exe
2009-12-27 22:13 . 2008-04-14 07:52 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2009-12-27 21:39 . 2001-10-25 14:00 14848 -c--a-w- c:\windows\system32\dllcache\register.exe
2009-12-27 21:38 . 2008-04-14 07:46 13463552 -c--a-w- c:\windows\system32\dllcache\hwxjpn.dll
2009-12-27 21:36 . 2001-10-25 14:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-12-27 21:35 . 2009-12-27 21:35 -------- d-----w- c:\windows\system32\wbem\Repository
2009-12-27 21:15 . 2001-10-25 14:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-12-27 21:15 . 2001-10-25 14:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-12-27 21:15 . 2001-10-25 14:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-12-27 21:15 . 2001-10-25 14:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-12-27 19:27 . 2008-04-14 07:52 131584 ----a-w- c:\windows\system32\sndrec32.exe
2009-12-27 19:24 . 2008-04-13 23:15 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2009-12-27 19:24 . 2008-04-13 23:15 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2009-12-27 19:21 . 2008-04-14 06:44 58496 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-12-27 19:21 . 2008-04-14 07:53 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2009-12-27 19:20 . 2008-04-13 23:02 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2009-12-27 19:19 . 2008-04-13 23:24 11264 ----a-w- c:\windows\system32\drivers\irenum.sys
2009-12-27 19:19 . 2008-04-14 07:53 146944 ----a-w- c:\windows\system\winspool.drv
2009-12-27 19:19 . 2008-04-14 07:52 75264 ----a-w- c:\windows\system32\storprop.dll
2009-12-27 17:41 . 2009-12-27 17:41 -------- d-----w- c:\program files\Trend Micro
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\VDLL.DLL
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\system32\runouce.exe
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-12-27 13:50 . 2009-12-27 13:50 -------- d---a-w- c:\windows\logo_1.exe
2009-12-27 13:48 . 2009-12-27 13:48 632064 ----a-w- c:\windows\system32\msvcr80.dll
2009-12-27 13:48 . 2009-12-27 13:48 554240 ----a-w- c:\windows\system32\msvcp80.dll
2009-12-27 13:48 . 2009-12-27 13:48 34048 ----a-w- c:\windows\system32\eEmpty.exe
2009-12-27 13:48 . 2008-04-14 06:52 137216 ----a-w- c:\windows\system32\T.COM
2009-12-27 13:48 . 2008-04-14 06:52 147968 ----a-w- c:\windows\R.COM
2009-12-27 13:48 . 2009-12-27 13:48 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-12-13 12:41 . 2009-12-13 12:41 -------- d-----w- c:\program files\Common Files\HP
2009-12-13 12:41 . 2008-04-16 04:05 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-12-12 14:22 . 2008-04-16 04:05 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-12-12 14:22 . 2008-04-16 04:05 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-12-12 14:21 . 2008-04-13 23:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-06 18:27 . 2009-12-06 18:47 -------- d-----w- c:\program files\EGOSOFT
2009-12-06 13:10 . 2009-12-06 13:10 -------- d-----w- c:\program files\Rapget

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 09:09 . 2001-10-25 14:00 90380 ----a-w- c:\windows\system32\perfc005.dat
2009-12-31 09:09 . 2001-10-25 14:00 439358 ----a-w- c:\windows\system32\perfh005.dat
2009-12-29 09:51 . 2009-06-21 08:40 -------- d-----w- c:\program files\HP
2009-12-28 10:34 . 2009-01-24 14:26 -------- d-----w- c:\program files\Common Files\Acronis
2009-12-27 22:35 . 2009-04-10 19:33 -------- d-----w- c:\program files\Google
2009-12-27 22:18 . 2009-12-27 19:30 86665 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-27 22:18 . 2009-01-15 14:09 2740 ----a-w- c:\windows\pchealth\helpctr\PackageStore\SkuStore.bin
2009-12-27 21:34 . 2009-01-15 14:07 22900 ----a-w- c:\windows\system32\emptyregdb.dat
2009-12-27 20:10 . 2009-01-15 20:58 -------- d-----w- c:\program files\MSI
2009-12-27 19:32 . 2009-12-27 19:30 8972 ----a-w- c:\windows\pchealth\helpctr\Config\Cntstore.bin
2009-12-11 22:17 . 2009-01-15 14:19 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-24 23:54 . 2009-01-17 18:28 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-01-17 18:29 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-01-17 18:29 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-01-17 18:45 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-01-17 18:45 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-01-17 18:29 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-01-17 18:29 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-01-17 18:29 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-01-17 18:28 97480 ----a-w- c:\windows\system32\AVASTSS.scr
2009-11-17 18:41 . 2009-11-17 18:41 796672 ----a-w- c:\windows\GPInstall.exe
2009-10-24 17:14 . 2009-10-24 17:14 21275 ----a-w- c:\windows\system32\drivers\AegisP.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-12-29_16.17.00 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-31 09:24 . 2009-12-31 09:24 16384 c:\windows\Temp\Perflib_Perfdata_5d4.dat
+ 2009-12-31 09:05 . 2009-12-31 09:05 16384 c:\windows\Temp\Perflib_Perfdata_5cc.dat
+ 2001-10-25 14:00 . 2009-12-31 09:09 34488 c:\windows\system32\perfc009.dat
- 2001-10-25 14:00 . 2009-12-29 16:13 34488 c:\windows\system32\perfc009.dat
+ 2001-10-25 14:00 . 2009-12-31 09:09 292614 c:\windows\system32\perfh009.dat
- 2001-10-25 14:00 . 2009-12-29 16:13 292614 c:\windows\system32\perfh009.dat
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-12-17 61440]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 577536]
"OSSelectorReinstall"="c:\program files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe" [2007-02-22 2209224]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-25 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\user\Nabˇdka Start\Programy\Po spuçtŘnˇ\
FuzzyPWM Application.LNK - c:\program files\MSI\Core Center\CoreCenter.exe [2009-1-15 932864]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2008-04-14 07:51 625664 ----a-w- c:\windows\system32\catsrvut.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"SoundMan"=SOUNDMAN.EXE
"SW20"=c:\windows\system32\sw20.exe
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=nwiz.exe /install
"SW24"=c:\windows\system32\sw24.exe
"CHotKey"=mHotkey.exe
"mouseElf"=c:\progra~1\GAMING~1\MouseElf.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Freelancer\\EXE\\Freelancer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"427:UDP"= 427:UDP:SLP_Port(427)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [17.1.2009 20:15 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [17.1.2009 20:15 5248]
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [6.12.2005 16:11 35328]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [17.1.2009 19:45 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [17.1.2009 19:45 20560]
R3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\drivers\gMouPS2.sys [28.2.2009 13:42 17408]

--- Ostatní služby/ovladače v paměti ---

*NewlyCreated* - RUSHTOPDEVICE
*Deregistered* - RushTopDevice

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HPService REG_MULTI_SZ HPSLPSVC
.
Obsah adresáře 'Naplánované úlohy'

2009-01-17 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 12:49]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.sk/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: csob.sk\ib24
TCP: {5CC0DEFE-EBC2-462C-80E8-31E723E680FC} = 208.67.220.220,208.67.222.222
DPF: {1F831FA2-42FC-11D4-95A6-0080AD30DCE1}
DPF: {461A37E7-17B3-40E3-B6BB-7CAEC732C9E4} - hxxps://ib24.csob.sk/Comp/CSOBEnroll.dll
FF - ProfilePath - c:\documents and settings\user\Data aplikací\Mozilla\Firefox\Profiles\rta72c9p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.as ... ource=3&q=
FF - prefs.js: browser.search.selectedEngine - BS_Player Customized Web Search
FF - prefs.js: browser.startup.homepage - www.google.sk

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".sk");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-31 10:25
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'explorer.exe'(892)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\SOUNDMAN.EXE
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Celkový čas: 2009-12-31 10:27:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-12-31 09:27
ComboFix2.txt 2009-12-29 16:19

Před spuštěním: Volných bajtů: 30 851 645 440
Po spuštění: Volných bajtů: 30 817 091 584

Current=1 Default=1 Failed=0 LastKnownGood=5 Sets=1,2,3,5
- - End Of File - - DF58204E766DE2A5482920E2BC9030A4

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Prosim o kontrolu LOGU

Příspěvekod pitimir » 31 pro 2009 17:06

1) Docistime to:

  • Odinstaluj Combofix:
    Start -> Spustit -> (napis) combofix /uninstall

  • Pouzi T-Cleaner (ak by ho antivirus hlasil ako smejda, nic sa netreba bat, ide len o paranoju AV programu).
  • Pouzi TFC (spust program a klikni na "Start". Pozor, PC moze byt restartovane).


2) Vloz log z HJT.

V pripade nezrovnalosti sa >>tu<< nachadza navod.
Nemam rad amaterizmus...

A adresat odkazu to vie :)


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 80 hostů