Avast hlásí podezřelá zpráva Vyřešeno

Sekce věnovaná virům a jiným škodlivým kódům, rovněž ale nástrojům, kterým se lze proti nim bránit…

Moderátoři: Mods_senior, Security team

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod pitimir » 18 pro 2009 15:33

Nie, aj tak by ti to neslo :)

Stiahni GMER, rozbal ho na plochu a spust. Program automaticky zacne scan (po jeho skonceni vloz log c. 1) - pokial pri scanovani nieco najde (=vyskoci nejake upozornenie), klik na "NO" a vpravo zafajknes vsetky polozky OKREM:
  • Sections
  • IAT/EAT
  • Registry
  • nesystemovych diskov a particii (system je zvycajne na "C:\" - takze nezaskrtnute nechas "D:\", "E:\"...atd.)
  • Show All
Klik na "Scan". Po scane klik na "Save" a log c. 2 vloz sem.

Ak nic nenajde (=nevyskoci nic), zaskrtaj vpravo vsetko a spusti scan. Po jeho ukonceni klik na "Copy" a vloz log c. 2.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

Reklama
tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 18 pro 2009 18:18

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-18 18:14:24
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\kwlyrpob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF1B106B8] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF1B10574] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF1B10A52] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF1B1014C] <-- ROOTKIT !!!
SSDT sptd.sys ZwEnumerateKey [0xF73CEC7E] <-- ROOTKIT !!!
SSDT sptd.sys ZwEnumerateValueKey [0xF73CEFF6] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF1B1064E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF1B1008C] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF1B100F0] <-- ROOTKIT !!!
SSDT sptd.sys ZwQueryKey [0xF73CF0C0] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF1B1076E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF1B1072E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF1B108AE] <-- ROOTKIT !!!
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xF1BF40B0] <-- ROOTKIT !!!

---- Kernel code sections - GMER 1.0.15 ----

? C:\WINDOWS\system32\drivers\sptd.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
? C:\WINDOWS\System32\Drivers\SPTD4717.SYS Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
.pak2 C:\WINDOWS\system32\drivers\okpfkoo.sys entry point in ".pak2" section [0xF72C848A]
? C:\WINDOWS\system32\drivers\okpfkoo.sys Zařízení připojené k systému nefunguje.
.sfreloc˙˙˙˙sfsync04unknown last section [0xF725B000, 0xBB6, 0x40000040] C:\WINDOWS\system32\drivers\sfsync04.sys unknown last section [0xF725B000, 0xBB6, 0x40000040]
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF443F360, 0x34CDBF, 0xE8000020]
.text vaxscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 F434E4D0 16 Bytes [BF, FA, 5B, B1, 2F, 62, 36, ...]
.text vaxscsi.sys!A0DB34FC6FE35D429A28ADDE5467D4D7 + 11 F434E4E1 31 Bytes [D0, 34, F4, 4D, 71, CE, 08, ...]
? C:\WINDOWS\System32\Drivers\vaxscsi.sys Proces nemá přístup k souboru, neboť jej právě využívá jiný proces.
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xBA66D300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF7862300, 0x1B7E, 0xE8000020]

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F73CAA32] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F73CAB6E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F73CAAF6] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F73CB6CC] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F73CB5A2] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73ECC82] sptd.sys

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\Explorer.EXE[576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [011A2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [011A2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [011A2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[576] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [011A2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\services.exe[916] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003C0002
IAT C:\WINDOWS\system32\services.exe[916] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003C0000
IAT C:\Program Files\Messenger\msmsgs.exe[1752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00E82E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00E82C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00E82C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1752] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00E82C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX10.406\gmer.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX10.406\gmer.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX10.406\gmer.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00802C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX10.406\gmer.exe[2860] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3544] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01162E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3544] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01162C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3544] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01162C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Mozilla Firefox\firefox.exe[3544] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01162C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 8695C260

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Fastfat \FatCdrom 8652B648

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\DefragFS \Device\RaxcoPerfectDisk 8676A550
Device \Driver\dmio \Device\DmControl\DmIoDaemon 869990E8
Device \Driver\dmio \Device\DmControl\DmConfig 869990E8
Device \Driver\dmio \Device\DmControl\DmPnP 869990E8
Device \Driver\dmio \Device\DmControl\DmInfo 869990E8

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Ftdisk \Device\HarddiskVolume1 8699A3D0
Device \Driver\Cdrom \Device\CdRom0 86743B30
Device \FileSystem\Rdbss \Device\FsWrap 86452568
Device \Driver\Cdrom \Device\CdRom1 86743B30
Device \Driver\atapi \Device\Ide\IdePort0 [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdePort0 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort1 [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdePort1 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort2 [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdePort2 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort3 [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdePort3 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [F71F82F0] atapi.sys[unknown section] {MOV EAX, 0x86999dd0; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73df442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\NetBT \Device\NetBt_Wins_Export 865B99C8
Device \Driver\NetBT \Device\NetbiosSmb 865B99C8
Device \Driver\00000043 \Device\0000004e sptd.sys

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Disk \Device\Harddisk0\DR0 86999C78
Device \Driver\NetBT \Device\NetBT_Tcpip_{1729162C-88F5-477B-94AD-74A90113003E} 865B99C8

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 864250E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 864250E8
Device \FileSystem\Npfs \Device\NamedPipe 866570E8
Device \Driver\Ftdisk \Device\FtControl 8699A3D0
Device \FileSystem\Msfs \Device\Mailslot 8642A0E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C1CADE68-F7FC-4140-9001-397CC3D62CA8} 865B99C8
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 865B80E8
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 865B80E8
Device \Driver\vaxscsi \Device\Scsi\vaxscsi1Port4Path0Target0Lun0 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \FileSystem\Fastfat \Fat 8652B648

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

Device \FileSystem\Cdfs \Cdfs 864C00E8

---- Services - GMER 1.0.15 ----

Service (*** hidden *** ) [BOOT] okpfkoo <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Group Boot Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 672453486
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 1878647101
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 885561682
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0x63 0xFF 0xFD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x21 0x41 0x33 0xA1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x15 0x3E 0x09 0x27 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Start 0
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0x63 0xFF 0xFD ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x21 0x41 0x33 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x15 0x3E 0x09 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

---- EOF - GMER 1.0.15 ----

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod pitimir » 18 pro 2009 21:19

Pekny kusok :)

1) Stiahni Avenger. Spust ho a suhlas s podmienkami atd.
Do bieleho pola v strede programu vloz skript:

Kód: Vybrat vše

Files to delete:
C:\WINDOWS\System32\drivers\okpfkoo.sys

Driver to delete:
okpfkoo

Stlac "Execute" -> "Yes". Restart a vloz log.


2) Stiahni Defogger. Spust, klik na "Disable" -> "OK". V mieste spustenia by sa mal zjavit log, ten sem vloz.


3) Znova prescanuj PC GMERom, nech vieme ci sme toho rootkita odstranili.
Nemam rad amaterizmus...

A adresat odkazu to vie :)

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 18 pro 2009 23:06

tak tady je ten log z avengeru

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: could not open file "C:\WINDOWS\System32\drivers\okpfkoo.sys"
Deletion of file "C:\WINDOWS\System32\drivers\okpfkoo.sys" failed!
Status: 0xc0000001 (STATUS_UNSUCCESSFUL)


Error: file "Driver to delete:" not found!
Deletion of file "Driver to delete:" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "okpfkoo" not found!
Deletion of file "okpfkoo" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 18 pro 2009 23:12

defogger

defogger_disable by jpshortstuff (28.11.09.2)
Log created at 23:11 on 18/12/2009 (Admin)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...
Unable to read okpfkoo.sys
SPTD -> Already disabled


-=E.O.F=-

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 18 pro 2009 23:16

tak zatim dekuju :)
necham pres noc scanovat ten GMER a zejtra sem dam log.

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 19 pro 2009 10:01

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-19 10:00:54
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Admin\LOCALS~1\Temp\kwlyrpob.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xF1B8C6B8] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xF1B8C574] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xF1B8CA52] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xF1B8C14C] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xF1B8C64E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xF1B8C08C] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xF1B8C0F0] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xF1B8C76E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xF1B8C72E] <-- ROOTKIT !!!
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xF1B8C8AE] <-- ROOTKIT !!!
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xF1C480B0] <-- ROOTKIT !!!

---- Kernel code sections - GMER 1.0.15 ----

.pak2 C:\WINDOWS\system32\drivers\okpfkoo.sys entry point in ".pak2" section [0xF73F248A]
? C:\WINDOWS\system32\drivers\okpfkoo.sys Zařízení připojené k systému nefunguje.
.sfreloc˙˙˙˙sfsync04unknown last section [0xF7385000, 0xBB6, 0x40000040] C:\WINDOWS\system32\drivers\sfsync04.sys unknown last section [0xF7385000, 0xBB6, 0x40000040]
PAGE Ntfs.sys F7266C55 4 Bytes CALL 867CE011
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF4431360, 0x34CDBF, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xBA58F300, 0x3ACC8, 0xE8000020]
.text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xF7934300, 0x1B7E, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\Explorer.EXE[316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01C92E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01C92C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01C92C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[316] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01C92C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 003C0002
IAT C:\WINDOWS\system32\services.exe[832] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 003C0000
IAT C:\Program Files\Messenger\msmsgs.exe[1548] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00EB2E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1548] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00EB2C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1548] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00EB2C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\Messenger\msmsgs.exe[1548] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00EB2C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.297\gmer.exe[2300] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00802E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.297\gmer.exe[2300] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00802C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.297\gmer.exe[2300] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00802C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\DOCUME~1\Admin\LOCALS~1\Temp\Rar$EX00.297\gmer.exe[2300] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00802C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\WinRAR\WinRAR.exe[3380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00E02E70] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\WinRAR\WinRAR.exe[3380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00E02C30] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\WinRAR\WinRAR.exe[3380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00E02C50] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)
IAT C:\Program Files\WinRAR\WinRAR.exe[3380] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00E02C40] C:\Program Files\Common Files\Logitech\LVMVFM\LVPrcInj.dll (Logitech Helper Library./Logitech Inc.)

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 867875C0

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\atapi \Device\Ide\IdePort0 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort1 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort2 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdePort3 sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e sfsync04.sys (SF FrontLine Synchronization Driver/Protection Technology (StarForce))

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Services - GMER 1.0.15 ----

Service (*** hidden *** ) [BOOT] okpfkoo <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Start 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\okpfkoo@Group Boot Bus Extender
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0x63 0xFF 0xFD ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x21 0x41 0x33 0xA1 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x15 0x3E 0x09 0x27 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Start 0
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\okpfkoo@Group Boot Bus Extender
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xAB 0x63 0xFF 0xFD ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x21 0x41 0x33 0xA1 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x15 0x3E 0x09 0x27 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0xD4 0xC3 0x97 0x02 ...

---- EOF - GMER 1.0.15 ----

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod pitimir » 19 pro 2009 11:16

Pardon, chyba v skripte :blush:
Takze este raz skript pre Avenger:

Kód: Vybrat vše

Files to delete:
C:\WINDOWS\System32\drivers\okpfkoo.sys

Drivers to delete:
okpfkoo


A uvidime, ci s nim Avenger pohne :)
Nemam rad amaterizmus...

A adresat odkazu to vie :)

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 19 pro 2009 11:31

zkoušel sem to 2x a žádnej log se mi tam neukázal :(

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod pitimir » 19 pro 2009 12:23

Tak inak :)
Stiahni KittyFix, najlepsie na plochu. Vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall. Spust program cez ucet s administratorskymi pravami a postupuj podla instrukcii. Cely sken bude trvat cca 10 minut. Pocas neho moze byt PC restartovane. Log, ktory KittyFix vytvori, najdes na adrese "C:\KittyFix.txt".
Ten vloz sem.

Pozor: Kym KittyFix nevytvori log, na nic neklikat, nic nestlacat !!
Nemam rad amaterizmus...

A adresat odkazu to vie :)

tomas06
nováček
Příspěvky: 24
Registrován: prosinec 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod tomas06 » 19 pro 2009 12:52

ComboFix 09-12-18.02 - Admin 19.12.2009 12:37:18.1.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.2.1250.420.1029.18.1023.595 [GMT 1:00]
Spuštěný z: c:\documents and settings\Admin\Plocha\KittyFix.exe
AV: avast! antivirus 4.8.1368 [VPS 091218-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\cleanup.exe
c:\program files\Cheat Engine\dbk32.sys
c:\windows\msettings.ini
c:\windows\regedit.com
c:\windows\rising129.exe
c:\windows\rising245.exe
c:\windows\rising249.exe
c:\windows\rising268.exe
c:\windows\rising299.exe
c:\windows\rising442.exe
c:\windows\rising453.exe
c:\windows\rising456.exe
c:\windows\rising474.exe
c:\windows\rising498.exe
c:\windows\rising547.exe
c:\windows\rising616.exe
c:\windows\rising620.exe
c:\windows\rising676.exe
c:\windows\rising749.exe
c:\windows\rising986.exe
c:\windows\system32\2844480763.dat
c:\windows\system32\dn100de410.dat
c:\windows\system32\ieuinit.inf
c:\windows\system32\Packet.dll
c:\windows\system32\taskmgr.com

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DOMAINSERVICE
-------\Legacy_QANDR
-------\Legacy_WINDOWSREMOTE


((((((((((((((((((((((((( Soubory vytvořené od 2009-11-19 do 2009-12-19 )))))))))))))))))))))))))))))))
.

2009-12-19 10:20 . 2009-12-19 10:25 0 ----a-w- C:\backup.reg
2009-12-19 10:20 . 2009-12-19 10:25 574 ----a-w- C:\cleanup.bat
2009-12-19 10:20 . 2009-12-19 10:25 135168 ----a-w- C:\zip.exe
2009-12-18 20:06 . 2009-12-19 10:16 -------- d-----w- c:\program files\Warlords Battlecry III
2009-12-18 14:30 . 2009-12-18 14:30 -------- d-----w- c:\program files\AskBardis
2009-12-18 14:25 . 2009-12-18 14:25 -------- d-----w- C:\_OTL
2009-12-18 10:10 . 2009-12-18 10:10 -------- d-----w- c:\program files\Enlight
2009-12-18 10:07 . 2009-12-18 10:07 -------- d-----w- c:\program files\Alcohol Soft
2009-12-18 10:03 . 2009-12-18 10:03 96256 ----a-w- c:\windows\system32\drivers\sptd4717.sys
2009-12-18 10:03 . 2009-12-18 10:03 642560 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-16 19:39 . 2009-12-16 19:39 -------- d---a-w- c:\windows\VDLL.DLL
2009-12-16 19:39 . 2009-12-16 19:39 -------- d---a-w- c:\windows\system32\runouce.exe
2009-12-16 19:39 . 2009-12-16 19:39 -------- d---a-w- c:\windows\RUNDL132.EXE
2009-12-16 19:39 . 2009-12-16 19:39 -------- d---a-w- c:\windows\logo_1.exe
2009-12-16 19:16 . 2009-12-16 19:16 34048 ----a-w- c:\windows\system32\eEmpty.exe
2009-12-16 19:16 . 2004-08-17 13:49 147968 ----a-w- c:\windows\R.COM
2009-12-16 19:16 . 2004-08-17 13:49 137216 ----a-w- c:\windows\system32\T.COM
2009-12-16 19:16 . 2009-12-16 19:16 -------- d-----w- c:\program files\Common Files\MicroWorld
2009-12-15 20:35 . 2009-12-16 14:15 -------- d-----w- c:\program files\RegScrubXP
2009-12-15 20:33 . 2009-12-15 20:47 -------- d-----w- c:\program files\RegCleaner
2009-12-15 13:20 . 2009-12-15 13:20 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-15 13:17 . 2009-12-15 13:19 -------- d-----w- c:\program files\CPU Speed Pro
2009-12-15 12:35 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-15 12:35 . 2009-12-15 12:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-15 12:35 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-13 16:14 . 2009-12-13 18:49 -------- d-----w- c:\program files\Alcohol 120
2009-12-06 13:32 . 2009-12-10 15:15 -------- d-----w- c:\program files\Giants
2009-11-29 15:33 . 2009-11-29 15:33 -------- d-----w- c:\program files\Eidos
2009-11-27 15:03 . 2009-12-11 17:29 -------- d-----w- c:\program files\DivX

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-19 11:40 . 2009-11-02 18:53 -------- d-----w- c:\program files\Cheat Engine
2009-12-19 11:33 . 2009-04-03 14:38 -------- d-----w- c:\program files\BitComet
2009-12-18 10:10 . 2007-06-21 01:04 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-18 10:07 . 2007-06-20 20:27 223128 ----a-w- c:\windows\system32\drivers\vaxscsi.sys
2009-12-16 14:22 . 2009-08-13 14:31 -------- d-----w- c:\program files\ATMA V
2009-12-15 13:20 . 2007-08-06 20:17 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-13 15:33 . 2007-06-20 20:26 721904 ----a-w- c:\windows\system32\drivers\sptd.sys.83724678
2009-12-11 18:27 . 2007-09-29 13:15 -------- d-----w- c:\program files\Google
2009-12-06 13:48 . 2007-06-26 15:36 -------- d-----w- c:\program files\Mplayer
2009-11-24 23:54 . 2007-06-20 20:18 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2007-06-20 20:18 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2007-06-20 20:18 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-03-31 16:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-03-31 16:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2007-06-20 20:18 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2007-06-20 20:18 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2007-06-20 20:18 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2007-09-07 20:45 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-20 11:16 . 2008-10-25 16:21 -------- d-----w- c:\program files\Winamp3
2009-10-25 17:25 . 2009-10-25 17:22 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-25 07:50 . 2001-10-25 14:00 74606 ----a-w- c:\windows\system32\perfc005.dat
2009-10-25 07:50 . 2001-10-25 14:00 402000 ----a-w- c:\windows\system32\perfh005.dat
2009-10-24 10:03 . 2009-10-14 14:01 -------- d-----w- c:\program files\Battle for Wesnoth 1.7.6
2009-10-20 15:25 . 2008-03-26 14:37 -------- d-----w- c:\program files\Strategy First
2008-08-17 21:08 . 2008-08-17 21:08 774144 ----a-w- c:\program files\RngInterstitial.dll
2009-07-15 10:20 . 2009-06-21 10:55 952 --sha-w- c:\windows\system32\KGyGaAvL.sys
.

------- Sigcheck -------

[-] 2007-10-30 . ECF02439FD31BBD0DBC2EC05600CF08A . 360064 . . [5.1.2600.3244] . . c:\windows\system32\dllcache\tcpip.sys
[-] 2007-10-30 . ECF02439FD31BBD0DBC2EC05600CF08A . 360064 . . [5.1.2600.3244] . . c:\windows\system32\drivers\tcpip.sys
[7] 2007-10-30 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244] . . c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2004-08-03 . 9F4B36614A0FC234525BA224957DE55C . 359040 . . [5.1.2600.2180] . . c:\windows\$NtUninstallKB941644$\tcpip.sys
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-23 2001648]
"BitComet"="c:\program files\BitComet\BitComet.exe" [2009-03-09 2564408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"nwiz"="nwiz.exe" [2008-12-03 1630208]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-03 13672448]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-17 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 1241088]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 13:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 20:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2005-08-12 12:43 45056 ----a-w- c:\program files\ATI Technologies\ATI.ACE\CLI.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2007-05-16 07:27 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitComet]
2009-03-09 09:32 2564408 ----a-w- c:\program files\BitComet\BitComet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-05-11 21:12 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2006-09-10 19:56 218032 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2006-09-10 19:56 86960 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2004-10-13 16:24 1694208 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 09:50 155648 ----a-r- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 13:57 153136 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-12-03 07:39 13672448 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-12-03 07:39 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
2007-06-18 14:10 271360 ----a-w- c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-28 21:37 413696 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 15:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\EA SPORTS\\FIFA 08\\FIFA08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17137:TCP"= 17137:TCP:BitComet 17137 TCP
"17137:UDP"= 17137:UDP:BitComet 17137 UDP
"8480:TCP"= 8480:TCP:BitComet 8480 TCP
"8480:UDP"= 8480:UDP:BitComet 8480 UDP
"24670:TCP"= 24670:TCP:BitComet 24670 TCP
"24670:UDP"= 24670:UDP:BitComet 24670 UDP
"22450:TCP"= 22450:TCP:BitComet 22450 TCP
"22450:UDP"= 22450:UDP:BitComet 22450 UDP

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [31.3.2008 17:07 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [23.11.2009 8:43 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [23.11.2009 8:43 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [31.3.2008 17:07 20560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [23.11.2009 8:43 7408]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [20.6.2007 21:27 223128]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [18.12.2009 11:03 642560]
.
------- Doplňkový sken -------
.
uStart Page = hxxp://seznam.cz/
mLocal Page =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Clean Traces - c:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - c:\program files\DAP\dapextie.htm
IE: Download &all with DAP - c:\program files\DAP\dapextie2.htm
IE: E&xportovat do aplikace Microsoft Office Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Stáhnout odkaz s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: Stáhnout všechna videa s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Stáhnout všechny odkazy s použitím BitCometu - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Eurotran XP\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Eurotran XP\etnxp.dll
FF - ProfilePath - c:\documents and settings\Admin\Data aplikací\Mozilla\Firefox\Profiles\8eeswhdp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.sweetim.com/search.asp?src=2&q=
FF - prefs.js: browser.search.selectedEngine - Seznam
FF - prefs.js: browser.startup.homepage - seznam.cz
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll

---- NASTAVENÍ FIREFOXU ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

MSConfigStartUp-BitTorrent - c:\program files\BitTorrent\bittorrent.exe
MSConfigStartUp-Google Update - c:\documents and settings\Admin\Local Settings\Data aplikací\Google\Update\GoogleUpdate.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-LogitechQuickCamRibbon - c:\program files\Logitech\QuickCam10\QuickCam10.exe
MSConfigStartUp-LogitechSetup - d:\setup\Setup.exe
MSConfigStartUp-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-WinampAgent - c:\program files\Winamp3\winampa.exe
AddRemove-Heroes of Might and Magic II - c:\ostatni\Heroes2\DeIsL1.isu
AddRemove-Warlords Battlecry - c:\program files\SSI\Warlords Battlecry\Uninst.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-19 12:43
Windows 5.1.2600 Service Pack 2 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************
.
--------------------- Knihovny navázané na běžící procesy ---------------------

- - - - - - - > 'winlogon.exe'(780)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(7424)
c:\program files\Common Files\Logitech\LVMVFM\LVPrcInj.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
c:\windows\RTHDCPL.EXE
c:\ostatni\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Celkový čas: 2009-12-19 12:47:51 - počítač byl restartován
ComboFix-quarantined-files.txt 2009-12-19 11:47

Před spuštěním: Volných bajtů: 27 011 080 192
Po spuštění: Volných bajtů: 26 880 352 256

WindowsXP-KB310994-SP2-Pro-BootDisk-CSY.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - BB0C8D5DCE1D135DB5F447E5E95398ED

pitimir
Level 3.5
Level 3.5
Příspěvky: 850
Registrován: srpen 09
Pohlaví: Muž
Stav:
Offline

Re: Avast hlásí podezřelá zpráva

Příspěvekod pitimir » 19 pro 2009 15:43

Aby som ti objasnil situaciu: KittyFix=beta verzia ComboFixu, povodny CF je stiahnuty z obehu kvoli problemom s novym smejdom. Ja mam sablony napisane pre ComboFix a nechce sa mi ich prepisovat na KittyFix. Preto ta prosim, aby si chapal, ze vsade, kde je napisane "ComboFix", myslim KittyFix. Snad som to napisal jasne :)


Presun ikonu CF na plochu, vypni vsetky otvorene aplikacie, ako aj rezidenty antiviru, antispywaru a firewall a otvor poznamkovy blok. Donho skopiruj:

Kód: Vybrat vše

KillAll::
FCopy::
c:\windows\$NtUninstallKB941644$\tcpip.sys | c:\windows\system32\dllcache\tcpip.sys
c:\windows\$NtUninstallKB941644$\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

FileLook::
C:\zip.exe

Folder::
c:\program files\AskBardis

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"=dword:00000001

Uloz na plochu ako CFScript.txt a mysou pretiahni nad ikonou CF.

Obrázek

Program script spracuje a spravi novy log.


Pozor: Ak po aplikacii skriptu nenabehne Windows, restartuj PC, stlac F8 a zvol Poslednu znamu funkcnu konfiguraciu.
Nemam rad amaterizmus...

A adresat odkazu to vie :)


Zpět na “Viry, antiviry, firewally…”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 2 hosti