Stránka 1 z 1

WIN32.Agent - pada system

Napsal: 17 lis 2006 08:37
od mravcek
.. problemy take se spoustenim PC... :o(

Logfile of HijackThis v1.99.1
Scan saved at 8:14:35, on 17.11.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Spy Sniper\SpySniper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\marek\LOCALS~1\Temp\Rar$EX00.828\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.quick.cz/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Acrobate Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Picasa Media Detector] D:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [SpySniper] "C:\Program Files\Spy Sniper\SpySniper.exe" OSStarting
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{9EF325B9-4BA2-4FCB-8A83-6CDD7BECE051}: NameServer = 192.168.1.1
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - D:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe



Dekuji

Napsal: 17 lis 2006 09:03
od Guivan5
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000

tušim že tohle je ono, ale nejsem si moc jistej. ještě sem dej log z MWAVu (mám ho v podpisu)

Napsal: 17 lis 2006 10:27
od mijaja
V první řadě odinstaluj Spy Sniper. To není antispyware ale spyware. Jen se tváří, jako dobrý program. V linku Důležité... mám osvědčené programy proti spywaru.

V Taskmanageru (CTRL+ALT+DEL - záložka Procesy - tlačítko Ukončit proces) zastav procesy:
C:\Program Files\Spy Sniper
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

Až to budeš mít, spusť znovu HijackThis a zaškrtni v něm okénka před řádky:

O4 - HKLM\..\Run: [SpySniper] "C:\Program Files\Spy Sniper\SpySniper.exe" OSStarting
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"

Potom se musíš vynasnažit, aby nezůstalo na disku nic od toho šmejda SpySnipera - všechno vymaž.

Kde se ti hlásí ten WIN32.Agent? Kdo ho našel a ve kterém souboru? Ten upravený log MWAVu o kterém ti psal Guivan5 by se k tomu nalezení hodil.

Napsal: 17 lis 2006 10:43
od mravcek
WIN32.Agent.bbq mi nasel tusim Avast. Bylo to v temporary souborech .. vyskakovalo mi to nekolikrat stale sem to dal do truhly. Ted je na chvili od toho klid ale PC pada a nekdy jsou strasne problemy s jeho zapnutim...
MWAV bezi pak zaslu vysledky.

Zatim dik...

MWAV nic.. ??

Napsal: 17 lis 2006 10:58
od mravcek
ri Nov 17 10:32:42 2006 => Total Objects Scanned: 54962
Fri Nov 17 10:32:42 2006 => Total Critical Objects: 0
Fri Nov 17 10:32:42 2006 => Total Disinfected Objects: 0
Fri Nov 17 10:32:42 2006 => Total Objects Renamed: 0
Fri Nov 17 10:32:42 2006 => Total Deleted Objects: 0
Fri Nov 17 10:32:42 2006 => Total Errors: 28
Fri Nov 17 10:32:42 2006 => Time Elapsed: 00:33:13
Fri Nov 17 10:32:42 2006 => Virus Database Date: 11/10/2006
Fri Nov 17 10:32:42 2006 => Virus Database Count: 239678

Fri Nov 17 10:32:42 2006 => Scan Completed.

Jo byl to AVAST a soubor Soft Nagra+ 1.22.exe v C:\DOCUME..\marek\LOCALS.\TEMP\AAWTMP\C97593\....

Napsal: 17 lis 2006 11:23
od fredik
Log z mwav je v pořádku. Když mrkneš tak mijaja má v podpisu odkaz na Ccleaner, tak si ho stáhni a pročisti si s ním komp.