Dobrý den,
avast mi neustále hlásí infekci BV: Malware-gen v souboru a.bat. Nejde s tím nic dšlat. Zkusil jsem různé programy na odstranwění spyware a adware (Ad aware, Spybot, Spyware Terminator...) nic mi nepomohlo. Program buď nenašel nic, nebo našel, ale po restartu e problém objevil znovu.
Momentálně nejspíš kvůli tomu nejde prohlížet stránky na webu. Explorer se spustí, ale objeví se jen Stránku nelze zobrazit. ICq normálně funguje. Posílám na kontrolu log z hijack this. Předem díéky za pomoc.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:31:56, on 14.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\msNTNSslog.exe
C:\WINDOWS\msSsyslog.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\WINDOWS\system32\msnmanegers.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.seznam.cz
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~2\toolbaru.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~2\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet Helper - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.5.19.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Seznam Lištička - {B71B15CE-3093-459C-B764-AEB2486F2273} - C:\Program Files\Seznam\Listicka\Toolbar.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~2\toolbaru.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [Windows Serviece Agents] yafridcqz.exe
O4 - HKLM\..\RunServices: [Windows Serviece Agents] yafridcqz.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -trayboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [hotefix] msnmanegers.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [hotefix] msnmanegers.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Přelož do češtiny - res://C:\Program Files\Seznam\Listicka\Toolbar.dll/5034
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Hledej v &Seznamu - res://C:\Program Files\Seznam\Listicka\Toolbar.dll/5033
O8 - Extra context menu item: Hledej v Seznam &Fulltextu - res://C:\Program Files\Seznam\Listicka\Toolbar.dll/5035
O8 - Extra context menu item: Stáhnout odkaz s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Stáhnout všechna videa s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Stáhnout všechny odkazy s použitím BitCometu - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O9 - Extra button: Přeložit - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Internetový překladač... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{20C7BB40-E383-4D71-A9A5-AC08D689DED3}: NameServer = 212.80.64.118,85.93.160.118
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: jqvm465hmygebkpp6 - Unknown owner - C:\WINDOWS\system32\lcss.exe (file missing)
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Windows Name Server Management Services (Windows Name System Server) - Unknown owner - C:\WINDOWS\msNTNSslog.exe
O23 - Service: Windows Server Management Services (Windows System Server) - Unknown owner - C:\WINDOWS\msSsyslog.exe
--
End of file - 11124 bytes
BV: Malware-gen v souboru a.bat
- gyga
- Level 4
- Příspěvky: 1011
- Registrován: únor 08
- Bydliště: Kutná Hora - Malešov
- Pohlaví:
- Stav:
Offline
Re: BV: Malware-gen v souboru a.bat
Vítej na fóru.
Zkusil jsi to odstranit v nouzovém režimu? S výpisem si musíš počkat někoho lepšího
Zkusil jsi to odstranit v nouzovém režimu? S výpisem si musíš počkat někoho lepšího

Lenovo Thinkpad Edge 15
Re: BV: Malware-gen v souboru a.bat
jj, zkoušel jsem to. Buhužel bez úspěchu, po restartu se vždycky objeví znova
- Pic
- Moderátor
-
Guru Level 13
- Příspěvky: 23292
- Registrován: září 06
- Bydliště: Východní Čechy
- Pohlaví:
- Stav:
Offline
Re: BV: Malware-gen v souboru a.bat
Na soubor bat se můžeš podívat třeba v poznámkovém bloku, nebo přímo v Total Commanderu, je to textový soubor (klávesa F3) a tak se mrknout co spouští.
Přečti si pravidla tohoto fóra! Přečetl jsi si nejprve manuál? Piš tak, abychom Ti rozuměli! Na SZ neodpovídám na požadavky řešení Vašich problémů s PC!
Nic není dokonalé, ani člověk!
Nic není dokonalé, ani člověk!
Re: BV: Malware-gen v souboru a.bat
Ukázalo se tohle. Mám z toho něco smazat?
@echo off
net stop "Security Center"
net stop winvnc4
del c:\a.bat
@echo off
net stop "Security Center"
net stop winvnc4
del c:\a.bat
- Owner
- Master Level 8.5
- Příspěvky: 7260
- Registrován: červenec 07
- Bydliště: Třinec
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: BV: Malware-gen v souboru a.bat
hmm..... jestli to funguje ,tak to je teda dobrý script 

Fallout fan | HJT | MWAV | CCleaner | Provozuji Minecraft server Minecore.cz | Osobní blog
Notebook: Thinkpad X200s - 12", Core2Duo L9300, 9cell, 240GB SSD, 5GB DDR3
PC: AMD Phenom II X6 1055T, 12GB DDR3, AMD 6870, 500GB Seagate 7200.12
Notebook: Thinkpad X200s - 12", Core2Duo L9300, 9cell, 240GB SSD, 5GB DDR3
PC: AMD Phenom II X6 1055T, 12GB DDR3, AMD 6870, 500GB Seagate 7200.12
Re: BV: Malware-gen v souboru a.bat
tohle je jeden z a.bat přesunutých do truhly (jeden z tech ktery nahodou sly), jinej a.bat mi windowsovsky vyhledavani nenaslo...
Owner: moc diky za radu
, neco lepsiho nemas?
Owner: moc diky za radu

- Argoneus
- Level 3.5
- Příspěvky: 939
- Registrován: prosinec 07
- Bydliště: Praha
- Pohlaví:
- Stav:
Offline
- Kontakt:
Re: BV: Malware-gen v souboru a.bat
dej Start Spustit a napiš services.msc, a zakaž službu Windows Serviece Agents, pak restartuj počítač a vlož nový log, a řekni jestli problém stále trvá
teď koukám ještě tam straší hotefix, doporučil bych ti combofix, ale fredik by mě zabil
//používej tlačítko upravit a nedávej za sebe zbytečně nové příspěvky
....
fredik
teď koukám ještě tam straší hotefix, doporučil bych ti combofix, ale fredik by mě zabil
//používej tlačítko upravit a nedávej za sebe zbytečně nové příspěvky


fredik
CPU: AMD Athlon 64 X2 5000+ EE @ 2,6 Ghz GPU: Sapphire HD 3850 512MB, PCI-E
Zákl. deska: Gigabyte GA-M52L-S3 - nForce 520 RAM: A-DATA 2x1GB DDR2 PC800 Extreme Edition
HDD: Samsung Spin Point F1 HD322HJ 320GB Zdroj: Seasonic SS-500ET-T3 500W
Case: THERMALTAKE VG1000BNS Wing RS100 Black
Zákl. deska: Gigabyte GA-M52L-S3 - nForce 520 RAM: A-DATA 2x1GB DDR2 PC800 Extreme Edition
HDD: Samsung Spin Point F1 HD322HJ 320GB Zdroj: Seasonic SS-500ET-T3 500W
Case: THERMALTAKE VG1000BNS Wing RS100 Black
- fredik
- člen Security týmu
-
Master Level 7
- Příspěvky: 4680
- Registrován: červenec 06
- Pohlaví:
- Stav:
Offline
Re: BV: Malware-gen v souboru a.bat
Stáhni si SDFix
- Spusť ho a rozbalí se ti na disk kde je nainstalovaný Windows (typicky to je C:\SDfix)
- Pak restartuj PC do nouzového režimu (zvol možnost: Stav nouze, ne Stav nouze s práci v síti)
- Otevři adresář kde je vybalený SDFix a spusť soubor RunThis.bat tím spustíš program.
* Pak stiskni klávesu Y a pak Enter pro zahájení čistícího procesu.
* Pro dokončení kontroly budeš vyzván ke stisknoutí libovolné klávesy a počítač se restartuje.
* Při nabíhání operačního systému se program spustí znovu a dokončí čistící proces. Až se objeví Finish, budeš muset po vyzvání stisknout libovolnou klávesu, tim se ukončí program a zobrazí se ti ikony na ploše
- Když se skončí načítání ikon na ploše, otevře se ti na obrazovce log z SDFix a zároveň ho uloží do adresáře kde je rozbalený SDFix jako soubor Report.txt
Pak sem zkopíruj jeho obsah
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Před použitím vypni rez. ochranu u SpyBota:
- spusť Spybot - Search & Destroy
- nahoře v menu zvol: Režim => Pro pokročilé
- objeví se ti varovné okno kde zvol Ano
- okno programu se ti přepne do pokročilého zobrazení a tam zvol: Nástroje => Rezidentní
- tam zruš zatržení pokud bude u položky: Rezidentní program "TeaTimer" (Ochrana ...)

- zavři program
Restartuj PC.
Po té si stáhni ResetTeaTimer.bat a ulož si ho na disku.
- spusť ho a po vyzvání zmáčkni libovolnou klávesu
- po proběhnutí a výzvě opět zmáčkni libovolnou klávesu a program se zavře.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Pak si stáhni ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Vlož sem pak logy z:
- SDFix
- ComboFix
- Spusť ho a rozbalí se ti na disk kde je nainstalovaný Windows (typicky to je C:\SDfix)
- Pak restartuj PC do nouzového režimu (zvol možnost: Stav nouze, ne Stav nouze s práci v síti)
- Otevři adresář kde je vybalený SDFix a spusť soubor RunThis.bat tím spustíš program.
* Pak stiskni klávesu Y a pak Enter pro zahájení čistícího procesu.
* Pro dokončení kontroly budeš vyzván ke stisknoutí libovolné klávesy a počítač se restartuje.
* Při nabíhání operačního systému se program spustí znovu a dokončí čistící proces. Až se objeví Finish, budeš muset po vyzvání stisknout libovolnou klávesu, tim se ukončí program a zobrazí se ti ikony na ploše
- Když se skončí načítání ikon na ploše, otevře se ti na obrazovce log z SDFix a zároveň ho uloží do adresáře kde je rozbalený SDFix jako soubor Report.txt
Pak sem zkopíruj jeho obsah
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Před použitím vypni rez. ochranu u SpyBota:
- spusť Spybot - Search & Destroy
- nahoře v menu zvol: Režim => Pro pokročilé
- objeví se ti varovné okno kde zvol Ano
- okno programu se ti přepne do pokročilého zobrazení a tam zvol: Nástroje => Rezidentní
- tam zruš zatržení pokud bude u položky: Rezidentní program "TeaTimer" (Ochrana ...)
- zavři program
Restartuj PC.
Po té si stáhni ResetTeaTimer.bat a ulož si ho na disku.
- spusť ho a po vyzvání zmáčkni libovolnou klávesu
- po proběhnutí a výzvě opět zmáčkni libovolnou klávesu a program se zavře.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Pak si stáhni ComboFix (by sUBs) a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Vlož sem pak logy z:
- SDFix
- ComboFix
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Re: BV: Malware-gen v souboru a.bat
Tady jsou ty dva logy....
ComboFix 08-04-18.3 - Maša 2008-04-20 15:48:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.436 [GMT 2:00]
Running from: C:\Documents and Settings\Maša\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
G:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-20 15:30 . 2008-04-20 15:30 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-20 15:23 . 2008-04-20 15:45 <DIR> d-------- C:\SDFix
2008-04-18 10:11 . 2008-04-18 16:45 16,896 --a------ C:\bluezm.exe
2008-04-18 10:01 . 2008-04-18 10:01 102,435 --a------ C:\WINDOWS\system32\msvcrt2.dll
2008-04-16 17:20 . 2008-04-16 17:20 <DIR> d-------- C:\Documents and Settings\Maša\Data aplikací\Oxford
2008-04-16 17:19 . 2008-04-16 17:19 <DIR> d-------- C:\Program Files\TEXTware
2008-04-16 17:17 . 2008-04-16 17:17 <DIR> d-------- C:\Program Files\Oxford
2008-04-15 18:02 . 2008-04-17 18:45 13,824 --a------ C:\ploaderedr.exe
2008-04-15 16:21 . 2008-04-15 16:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-04-15 16:20 . 2006-06-16 11:12 <DIR> d-------- C:\Documents and Settings\Administrator\Šablony
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-04-15 16:20 . 2008-04-15 16:20 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-15 16:20 . 2008-04-20 15:48 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-14 20:31 . 2008-04-14 20:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 19:25 . 2006-09-05 18:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-14 19:09 . 2008-04-14 19:09 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-14 18:38 . 2008-04-14 18:38 0 --a------ C:\23990098.$$$
2008-04-14 18:28 . 2004-08-17 15:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-04-14 17:29 . 2008-04-17 18:14 13,824 -r-hs---- C:\WINDOWS\msNTNSslog.exe
2008-04-13 17:42 . 2008-04-13 17:42 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-12 17:37 . 2008-04-12 17:37 <DIR> d-------- C:\VundoFix Backups
2008-04-09 17:33 . 2008-04-09 17:33 13,824 -r-hs---- C:\WINDOWS\msSsyslog.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-04-09 16:21 . 2008-04-14 18:29 50 --a------ C:\WINDOWS\Lic.xxx
2008-04-09 16:20 . 2004-08-17 15:49 147,968 --a------ C:\WINDOWS\R.COM
2008-04-09 16:10 . 2008-04-09 16:10 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-09 15:53 . 2008-04-09 15:53 <DIR> d-------- C:\Program Files\CCleaner
2008-04-09 15:49 . 2008-04-09 15:50 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Lavasoft
2008-04-08 20:38 . 2008-04-08 20:38 130 --a------ C:\WINDOWS\wininit.ini
2008-04-08 19:17 . 2008-04-08 19:14 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-08 19:17 . 2008-04-08 19:17 2,550 --a------ C:\WINDOWS\unins000.dat
2008-04-08 19:02 . 2008-04-08 19:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-08 19:02 . 2008-04-14 18:47 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2008-04-06 19:01 . 2008-04-06 19:01 <DIR> d-------- C:\Program Files\uTorrent
2008-04-06 19:01 . 2008-04-06 19:03 <DIR> d-------- C:\Documents and Settings\Maša\Data aplikací\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 13:17 --------- d-----w C:\Program Files\Lx_cats
2008-04-20 09:11 --------- d-----w C:\Program Files\ICQToolbar
2008-04-17 13:17 --------- d-----w C:\Program Files\ICQ6
2008-04-13 16:05 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Yahoo! Companion
2008-04-09 14:43 --------- d-----w C:\Documents and Settings\Maša\Data aplikací\ICQ Toolbar
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-09 09:54 --------- d-----w C:\Program Files\Lexmark 2300 Series
2008-03-06 10:34 --------- d-----w C:\Program Files\ICQLite
2008-03-06 10:24 --------- d-----w C:\Documents and Settings\Maša\Data aplikací\ICQ
2008-03-02 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:05 660,480 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-26 13:38 737,280 ----a-w C:\WINDOWS\iun6002.exe
2006-02-02 15:08 914 ----a-w C:\Program Files\INSTALL.LOG
2005-12-21 13:13 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(2).DAT
2005-12-17 10:52 237,568 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(3).DAT
2007-06-13 13:23 222,515 --sh--r C:\WINDOWS\system32\yafridcqz.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-23 00:43 413775]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 11:43 68856]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-19 16:59 1449984]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 08:07 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 14:05 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 15:36 299008]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"WireLessMouse "="C:\Program Files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 15:54 503808]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 23:45 253952]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 19:48 73728]
"wcmdmgr"="C:\WINDOWS\wt\updater\wcmdmgrl.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-09 23:12:54 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 08:05:26 29696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-08-27 09:27:17 106560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Documents and Settings\\Maša\\Dokumenty\\eMule\\emule.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16316:TCP"= 16316:TCP:BitComet 16316 TCP
"16316:UDP"= 16316:UDP:BitComet 16316 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys [2002-04-15 13:18]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Windows Name System Server;Windows Name Server Management Services;"C:\WINDOWS\msNTNSslog.exe" [2008-04-17 18:14]
R2 Windows System Server;Windows Server Management Services;"C:\WINDOWS\msSsyslog.exe" [2008-04-09 17:33]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S2 jqvm465hmygebkpp6;jqvm465hmygebkpp6;"C:\WINDOWS\system32\lcss.exe" []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-11 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-10 07:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 08:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-11 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-12 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-23 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-07 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-08 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\W62qCIr8.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 15:50:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-04-20 15:53:43
ComboFix-quarantined-files.txt 2008-04-20 13:52:39
Adresářů: 17, Volných bajtů: 8,837,451,776
Adresářů: 19, Volných bajtů: 8,854,790,144
208 --- E O F --- 2008-04-10 06:35:58
SDFix: Version 1.173
Run by Maça on ne 20.04.2008 at 15:34
Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe - Deleted
C:\WINDOWS\hosts - Deleted
C:\WINDOWS\system32\drivers\hosts - Deleted
C:\WINDOWS\system32\SysMgr.exe - Deleted
C:\WINDOWS\system32\SysMgr.exe - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 15:40:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\\Program Files\\GPRSpeed Plus\\GPRSpeed Plus Client\\GPRSpeed_c.exe"="C:\\Program Files\\GPRSpeed Plus\\GPRSpeed Plus Client\\GPRSpeed_c.exe:*:Enabled:NettGain1100_C"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Enabled:Connection Manager"
"C:\\Program Files\\ICQ\\Icq.exe"="C:\\Program Files\\ICQ\\Icq.exe:*:Enabled:ICQ"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Psygnosis\\Rollcage\\Direct3D\\Rollcage.exe"="C:\\Program Files\\Psygnosis\\Rollcage\\Direct3D\\Rollcage.exe:*:Enabled:Rollcage Main Game Executable"
"C:\\Documents and Settings\\Maça\\Dokumenty\\eMule\\emule.exe"="C:\\Documents and Settings\\Maça\\Dokumenty\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Thu 17 Apr 2008 13,824 ..SHR --- "C:\WINDOWS\msNTNSslog.exe"
Wed 9 Apr 2008 13,824 ..SHR --- "C:\WINDOWS\msSsyslog.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 13 Jun 2007 222,515 ..SHR --- "C:\WINDOWS\system32\yafridcqz.exe"
Thu 15 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Fri 12 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
Finished!
ComboFix 08-04-18.3 - Maša 2008-04-20 15:48:55.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.1.1029.18.436 [GMT 2:00]
Running from: C:\Documents and Settings\Maša\Plocha\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Maša\Data aplikací\ShoppingReport\cs\res1\WhiteList.dbs
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
G:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-03-20 to 2008-04-20 )))))))))))))))))))))))))))))))
.
2008-04-20 15:30 . 2008-04-20 15:30 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-20 15:23 . 2008-04-20 15:45 <DIR> d-------- C:\SDFix
2008-04-18 10:11 . 2008-04-18 16:45 16,896 --a------ C:\bluezm.exe
2008-04-18 10:01 . 2008-04-18 10:01 102,435 --a------ C:\WINDOWS\system32\msvcrt2.dll
2008-04-16 17:20 . 2008-04-16 17:20 <DIR> d-------- C:\Documents and Settings\Maša\Data aplikací\Oxford
2008-04-16 17:19 . 2008-04-16 17:19 <DIR> d-------- C:\Program Files\TEXTware
2008-04-16 17:17 . 2008-04-16 17:17 <DIR> d-------- C:\Program Files\Oxford
2008-04-15 18:02 . 2008-04-17 18:45 13,824 --a------ C:\ploaderedr.exe
2008-04-15 16:21 . 2008-04-15 16:21 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Plocha
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní tiskárny
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d--h----- C:\Documents and Settings\Administrator\Okolní síť
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Oblíbené položky
2008-04-15 16:20 . 2006-06-16 11:12 <DIR> d-------- C:\Documents and Settings\Administrator\Šablony
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> dr------- C:\Documents and Settings\Administrator\Nabídka Start
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> d-------- C:\Documents and Settings\Administrator\Dokumenty
2008-04-15 16:20 . 2005-12-17 13:11 <DIR> dr-h----- C:\Documents and Settings\Administrator\Data aplikací
2008-04-15 16:20 . 2008-04-15 16:20 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-15 16:20 . 2008-04-20 15:48 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-14 20:31 . 2008-04-14 20:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 19:25 . 2006-09-05 18:03 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-14 19:09 . 2008-04-14 19:09 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-14 18:38 . 2008-04-14 18:38 0 --a------ C:\23990098.$$$
2008-04-14 18:28 . 2004-08-17 15:49 137,216 --a------ C:\WINDOWS\system32\T.COM
2008-04-14 17:29 . 2008-04-17 18:14 13,824 -r-hs---- C:\WINDOWS\msNTNSslog.exe
2008-04-13 17:42 . 2008-04-13 17:42 <DIR> d-------- C:\Program Files\Yahoo!
2008-04-12 17:37 . 2008-04-12 17:37 <DIR> d-------- C:\VundoFix Backups
2008-04-09 17:33 . 2008-04-09 17:33 13,824 -r-hs---- C:\WINDOWS\msSsyslog.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\zts2.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\rundll16.exe
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\rundl132.dll
2008-04-09 16:28 . 2008-04-09 16:28 <DIR> d-a------ C:\WINDOWS\logo1_.exe
2008-04-09 16:21 . 2008-04-14 18:29 50 --a------ C:\WINDOWS\Lic.xxx
2008-04-09 16:20 . 2004-08-17 15:49 147,968 --a------ C:\WINDOWS\R.COM
2008-04-09 16:10 . 2008-04-09 16:10 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-09 15:53 . 2008-04-09 15:53 <DIR> d-------- C:\Program Files\CCleaner
2008-04-09 15:49 . 2008-04-09 15:50 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Lavasoft
2008-04-08 20:38 . 2008-04-08 20:38 130 --a------ C:\WINDOWS\wininit.ini
2008-04-08 19:17 . 2008-04-08 19:14 691,545 --a------ C:\WINDOWS\unins000.exe
2008-04-08 19:17 . 2008-04-08 19:17 2,550 --a------ C:\WINDOWS\unins000.dat
2008-04-08 19:02 . 2008-04-08 19:35 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-08 19:02 . 2008-04-14 18:47 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Spybot - Search & Destroy
2008-04-06 19:01 . 2008-04-06 19:01 <DIR> d-------- C:\Program Files\uTorrent
2008-04-06 19:01 . 2008-04-06 19:03 <DIR> d-------- C:\Documents and Settings\Maša\Data aplikací\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 13:17 --------- d-----w C:\Program Files\Lx_cats
2008-04-20 09:11 --------- d-----w C:\Program Files\ICQToolbar
2008-04-17 13:17 --------- d-----w C:\Program Files\ICQ6
2008-04-13 16:05 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Data aplikací\Yahoo! Companion
2008-04-09 14:43 --------- d-----w C:\Documents and Settings\Maša\Data aplikací\ICQ Toolbar
2008-03-20 08:09 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-09 09:54 --------- d-----w C:\Program Files\Lexmark 2300 Series
2008-03-06 10:34 --------- d-----w C:\Program Files\ICQLite
2008-03-06 10:24 --------- d-----w C:\Documents and Settings\Maša\Data aplikací\ICQ
2008-03-02 11:33 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:38 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-16 09:05 660,480 ----a-w C:\WINDOWS\system32\wininet.dll
2008-01-26 13:38 737,280 ----a-w C:\WINDOWS\iun6002.exe
2006-02-02 15:08 914 ----a-w C:\Program Files\INSTALL.LOG
2005-12-21 13:13 262,144 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(2).DAT
2005-12-17 10:52 237,568 ----a-w C:\WINDOWS\system32\config\systemprofile\NTUSER(3).DAT
2007-06-13 13:23 222,515 --sh--r C:\WINDOWS\system32\yafridcqz.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 15:49 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-23 00:43 413775]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 11:43 68856]
"PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-19 16:59 1449984]
"Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 08:07 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 14:05 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 15:36 299008]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"WireLessMouse "="C:\Program Files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 15:54 503808]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 23:45 253952]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 19:48 73728]
"wcmdmgr"="C:\WINDOWS\wt\updater\wcmdmgrl.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-09 23:12:54 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 08:05:26 29696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-08-27 09:27:17 106560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Documents and Settings\\Maša\\Dokumenty\\eMule\\emule.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16316:TCP"= 16316:TCP:BitComet 16316 TCP
"16316:UDP"= 16316:UDP:BitComet 16316 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys [2002-04-15 13:18]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Windows Name System Server;Windows Name Server Management Services;"C:\WINDOWS\msNTNSslog.exe" [2008-04-17 18:14]
R2 Windows System Server;Windows Server Management Services;"C:\WINDOWS\msSsyslog.exe" [2008-04-09 17:33]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
S2 jqvm465hmygebkpp6;jqvm465hmygebkpp6;"C:\WINDOWS\system32\lcss.exe" []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-11 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-10 07:00:00 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 08:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-20 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-11 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-18 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-12 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-03 10:41:17 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2007-07-23 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-07 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\W62qCIr8.exe
"2008-04-08 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\W62qCIr8.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 15:50:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCGCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-04-20 15:53:43
ComboFix-quarantined-files.txt 2008-04-20 13:52:39
Adresářů: 17, Volných bajtů: 8,837,451,776
Adresářů: 19, Volných bajtů: 8,854,790,144
208 --- E O F --- 2008-04-10 06:35:58
SDFix: Version 1.173
Run by Maça on ne 20.04.2008 at 15:34
Microsoft Windows XP [Verze 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
Checking Files :
Trojan Files Found:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe - Deleted
C:\WINDOWS\hosts - Deleted
C:\WINDOWS\system32\drivers\hosts - Deleted
C:\WINDOWS\system32\SysMgr.exe - Deleted
C:\WINDOWS\system32\SysMgr.exe - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-20 15:40:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Control Panel\Cursors\Schemes]
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?"="C:\WINDOWS\cursors\arrow_r.cur,C:\WINDOWS\cursors\help_r.cur,C:\WINDOWS\cursors\wait_r.cur,C:\WINDOWS\cursors\busy_r.cur,C:\WINDOWS\cursors\cross_r.cur,C:\WINDOWS\cursors\beam_r.cur,C:\WINDOWS\cursors\pen_r.cur,C:\WINDOWS\cursors\no_r.cur,C:\WINDOWS\cursors\size4_r.cur,C:\WINDOWS\cursors\size3_r.cur,C:\WINDOWS\cursors\size2_r.cur,C:\WINDOWS\cursors\size1_r.cur,C:\WINDOWS\cursors\move_r.cur,C:\WINDOWS\cursors\up_r.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?v?e?l?k?é?)?"="C:\WINDOWS\cursors\arrow_rm.cur,C:\WINDOWS\cursors\help_rm.cur,C:\WINDOWS\cursors\wait_rm.cur,C:\WINDOWS\cursors\busy_rm.cur,C:\WINDOWS\cursors\cross_rm.cur,C:\WINDOWS\cursors\beam_rm.cur,C:\WINDOWS\cursors\pen_rm.cur,C:\WINDOWS\cursors\no_rm.cur,C:\WINDOWS\cursors\size4_rm.cur,C:\WINDOWS\cursors\size3_rm.cur,C:\WINDOWS\cursors\size2_rm.cur,C:\WINDOWS\cursors\size1_rm.cur,C:\WINDOWS\cursors\move_rm.cur,C:\WINDOWS\cursors\up_rm.cur"
"\f\1e?r?n?é? ?u?k?a?z?a?t?e?l?e? ?(?n?e?j?v?\e\1t?a\1í?)?"="C:\WINDOWS\cursors\arrow_rl.cur,C:\WINDOWS\cursors\help_rl.cur,C:\WINDOWS\cursors\wait_rl.cur,C:\WINDOWS\cursors\busy_rl.cur,C:\WINDOWS\cursors\cross_rl.cur,C:\WINDOWS\cursors\beam_rl.cur,C:\WINDOWS\cursors\pen_rl.cur,C:\WINDOWS\cursors\no_rl.cur,C:\WINDOWS\cursors\size4_rl.cur,C:\WINDOWS\cursors\size3_rl.cur,C:\WINDOWS\cursors\size2_rl.cur,C:\WINDOWS\cursors\size1_rl.cur,C:\WINDOWS\cursors\move_rl.cur,C:\WINDOWS\cursors\up_rl.cur"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\\Program Files\\GPRSpeed Plus\\GPRSpeed Plus Client\\GPRSpeed_c.exe"="C:\\Program Files\\GPRSpeed Plus\\GPRSpeed Plus Client\\GPRSpeed_c.exe:*:Enabled:NettGain1100_C"
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"="C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE:*:Enabled:Connection Manager"
"C:\\Program Files\\ICQ\\Icq.exe"="C:\\Program Files\\ICQ\\Icq.exe:*:Enabled:ICQ"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Psygnosis\\Rollcage\\Direct3D\\Rollcage.exe"="C:\\Program Files\\Psygnosis\\Rollcage\\Direct3D\\Rollcage.exe:*:Enabled:Rollcage Main Game Executable"
"C:\\Documents and Settings\\Maça\\Dokumenty\\eMule\\emule.exe"="C:\\Documents and Settings\\Maça\\Dokumenty\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite"
"C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:uTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes :
Thu 17 Apr 2008 13,824 ..SHR --- "C:\WINDOWS\msNTNSslog.exe"
Wed 9 Apr 2008 13,824 ..SHR --- "C:\WINDOWS\msSsyslog.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 13 Jun 2007 222,515 ..SHR --- "C:\WINDOWS\system32\yafridcqz.exe"
Thu 15 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Fri 12 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
Finished!
- fredik
- člen Security týmu
-
Master Level 7
- Příspěvky: 4680
- Registrován: červenec 06
- Pohlaví:
- Stav:
Offline
Re: BV: Malware-gen v souboru a.bat
Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok)
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
+
Na ploše se ti vytvoří soubor Submit(Datum+Čas).zip, vlož ho jako přílohu ke svému dalšímu příspěvku.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE
Kód: Vybrat vše
Driver::
jqvm465hmygebkpp6
File::
C:\bluezm.exe
C:\ploaderedr.exe
C:\WINDOWS\system32\yafridcqz.exe
C:\WINDOWS\system32\W62qCIr8.exe
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At10.job
C:\WINDOWS\Tasks\At11.job
C:\WINDOWS\Tasks\At12.job
C:\WINDOWS\Tasks\At13.job
C:\WINDOWS\Tasks\At14.job
C:\WINDOWS\Tasks\At15.job
C:\WINDOWS\Tasks\At16.job
C:\WINDOWS\Tasks\At17.job
C:\WINDOWS\Tasks\At18.job
C:\WINDOWS\Tasks\At19.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At20.job
C:\WINDOWS\Tasks\At21.job
C:\WINDOWS\Tasks\At22.job
C:\WINDOWS\Tasks\At23.job
C:\WINDOWS\Tasks\At24.job
C:\WINDOWS\Tasks\At3.job
C:\WINDOWS\Tasks\At4.job
C:\WINDOWS\Tasks\At5.job
C:\WINDOWS\Tasks\At6.job
C:\WINDOWS\Tasks\At7.job
C:\WINDOWS\Tasks\At8.job
C:\WINDOWS\Tasks\At9.job
Suspect::
C:\WINDOWS\system32\msvcrt2.dll
C:\WINDOWS\msNTNSslog.exe
C:\WINDOWS\msSsyslog.exe
Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť

- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
+
Na ploše se ti vytvoří soubor Submit(Datum+Čas).zip, vlož ho jako přílohu ke svému dalšímu příspěvku.
It may take a while to get a response, because the "HJT Team" are very busy. Please, be patient, these people are volunteers. They will help you out, as soon as possible.
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Pokud máte nějaký problém, tak mi neposílejte SZ/PM zprávy s logy a dejte je do fóra. Na tyto SZ není možno odpovědět
Re: BV: Malware-gen v souboru a.bat
Nechal jsem projet pocitac combofixem a vyběhl log, jenže se nevytvořil ten soubor submit. Tak jsem postup zopakoval, bohužel se soubor submit zase nevytvořil a navíc se mi ztratil ten původní log. Takže vkládám až te¨n druhej, i když mám takovej pocit, že to bude k ničemu. Co dělat dál?
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 08:07 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 14:05 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 15:36 299008]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"WireLessMouse "="C:\Program Files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 15:54 503808]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 23:45 253952]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 19:48 73728]
"wcmdmgr"="C:\WINDOWS\wt\updater\wcmdmgrl.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-09 23:12:54 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 08:05:26 29696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-08-27 09:27:17 106560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16316:TCP"= 16316:TCP:BitComet 16316 TCP
"16316:UDP"= 16316:UDP:BitComet 16316 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys [2002-04-15 13:18]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Windows Name System Server;Windows Name Server Management Services;"C:\WINDOWS\msNTNSslog.exe" [2008-04-17 18:14]
R2 Windows System Server;Windows Server Management Services;"C:\WINDOWS\msSsyslog.exe" [2008-04-09 17:33]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-21 20:21:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-21 20:23:34
ComboFix-quarantined-files.txt 2008-04-21 18:23:28
ComboFix2.txt 2008-04-21 18:10:32
ComboFix3.txt 2008-04-20 13:53:44
Adresářů: 17, Volných bajtů: 8,623,013,888
Adresářů: 18, Volných bajtů: 8,613,289,984
180 --- E O F --- 2008-04-10 06:35:58
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lxcgmon.exe"="C:\Program Files\Lexmark 2300 Series\lxcgmon.exe" [2005-07-21 08:07 200704]
"EzPrint"="C:\Program Files\Lexmark 2300 Series\ezprint.exe" [2005-08-01 14:05 94208]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2005-07-12 15:36 299008]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 00:46 57344]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [2006-06-15 13:36 229376]
"WireLessMouse "="C:\Program Files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 15:54 503808]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 23:45 253952]
"LXCGCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll" [2005-07-20 19:48 73728]
"wcmdmgr"="C:\WINDOWS\wt\updater\wcmdmgrl.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-17 15:49 15360]
C:\Documents and Settings\All Users.WINDOWS\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-02-09 23:12:54 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 08:05:26 29696]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2006-08-27 09:27:17 106560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMGR.EXE"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"C:\\Program Files\\ICQ6\\ICQ.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16316:TCP"= 16316:TCP:BitComet 16316 TCP
"16316:UDP"= 16316:UDP:BitComet 16316 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys [2002-04-15 13:18]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Windows Name System Server;Windows Name Server Management Services;"C:\WINDOWS\msNTNSslog.exe" [2008-04-17 18:14]
R2 Windows System Server;Windows Server Management Services;"C:\WINDOWS\msSsyslog.exe" [2008-04-09 17:33]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-03 23:04]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612}]
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-21 20:21:54
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-21 20:23:34
ComboFix-quarantined-files.txt 2008-04-21 18:23:28
ComboFix2.txt 2008-04-21 18:10:32
ComboFix3.txt 2008-04-20 13:53:44
Adresářů: 17, Volných bajtů: 8,623,013,888
Adresářů: 18, Volných bajtů: 8,613,289,984
180 --- E O F --- 2008-04-10 06:35:58
Zpět na “Viry, antiviry, firewally…”
Kdo je online
Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 5 hostů