Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Win32: Rootkit-gen

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
X.E.R.X.E.S.
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 23 úno 2010 15:28

Win32: Rootkit-gen

#1 Příspěvek od X.E.R.X.E.S. »

Nazdárek,

vypadá to, že mám co dočinění s rootkitem. Krátká anamnéza: nejdříve windows po spuštění hlásil chyby v Nvidia driverech (NvCpl.dll, NvStartup), nešlo mi ani aktualizovat virovou databázi Avastu (hlásila server problem), začaly problémy s přehráváním videí na internetu (Youtube, např.) - nejprve jsem zkoušel použít jiné browsery (Safari, Chrome), nezměnilo se vůbec nic, vypadalo to, že ani jeden z mnou používaných browserů není schopen downloadovat žádný soubor bez potíží (download byl pomalý, musel jsem jej několikrát přerušit a zase spustit, stáhnuté soubory hlásily poškození). Zkoušel jsem pročistit PC Ccleanerem, Advanced Systemcare, Registryboosterem. Po reinstalaci driverů vymizely problémy s nimi, ale zdá se, že rootkit si vždy najde jiný program, kterému škodit. Reinstaloval jsem i Avast, po spuštění jakéhokoli programu Avast hlásil (nyní už nehlásí) pokus o napadení programu rootkitem. Našel také trojany v procesech. Několikrát jsem hloubkově prošel systém Avastem, vždy našel viry, přesunul je do karantény, ale problémy přetrvávají.

Log z RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Ing. Jiří Ťápal at 2010-02-23 15:23:43
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 5 GB (14%) free of 38 GB
Total RAM: 447 MB (34% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:24:43, on 23.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Ing. Jiří Ťápal\Plocha\RootkitRevealer.exe
C:\DOCUME~1\ING~1.JIP\LOCALS~1\Temp\RXB.exe
C:\Documents and Settings\Ing. Jiří Ťápal\Plocha\RSIT.exe
C:\Program Files\trend micro\Ing. Jiří Ťápal.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.qip.ru
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.qip.ru
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = start.qip.ru
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.qip.ru/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.karneval.cz:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
R3 - URLSearchHook: QIPBHO Class - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: QIPBHO - {A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE} - C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [UniblueRegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Eurotran XP - {230D1201-7607-4CF6-A11F-9E4BF0A333E0} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra button: (no name) - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra 'Tools' menuitem: Eurotran XP... - {2C73F784-D2DE-4422-B070-2E3332FE5744} - C:\Program Files\Eurotran XP\etnxp.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: QIP Infium - {1EF681F7-A04B-4D6D-9012-A307CCA55610} - C:\Program Files\QIP Infium\infium.exe (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: winmm.dll
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: RXB - Sysinternals - www.sysinternals.com - C:\DOCUME~1\ING~1.JIP\LOCALS~1\Temp\RXB.exe

--
End of file - 8274 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\SmartDefrag.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
QIPBHO Class - C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll [2009-10-05 150768]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - []
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2006-02-14 1191424]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"nwiz"=nwiz.exe /install []
"Easy-PrintToolBox"=C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE [2004-01-14 409600]
"gcasServ"=C:\Program Files\Microsoft AntiSpyware\gcasServ.exe [2005-11-15 473928]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]
"avast5"=C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe [2010-02-11 2756488]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-10-22 86016]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"UniblueRegistryBooster"=C:\Program Files\Uniblue\RegistryBooster\launcher.exe [2010-02-15 60208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe [2009-06-30 2329224]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\MSMSGS.EXE [2008-04-14 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2006-10-22 7700480]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2005-03-12 98304]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="winmm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{9EF34FF2-3396-4527-9D27-04C8C1C67806}"=C:\Program Files\Microsoft AntiSpyware\shellextension.dll [2005-11-15 101080]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Hamachi2Svc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoResolveSearch"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Starcraft\starcraft.exe"="C:\Program Files\Starcraft\starcraft.exe:*:Enabled:Starcraft"
"C:\Games\Shadow of Death\Heroes3.exe"="C:\Games\Shadow of Death\Heroes3.exe:*:Enabled:Heroes of Might and Magic® III"
"C:\WINDOWS\system32\dplaysvr.exe"="C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"C:\Games\LieroXtreme\LieroX.exe"="C:\Games\LieroXtreme\LieroX.exe:*:Enabled:LieroX"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\WINDOWS\system32\dpvsetup.exe"="C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\WINDOWS\system32\rundll32.exe"="C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App"
"C:\totalcmd\TOTALCMD.EXE"="C:\totalcmd\TOTALCMD.EXE:*:Enabled:Total Commander 32 bit international version, file manager replacement for Windows"
"C:\Program Files\Real\RealPlayer\realplay.exe"="C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer"
"C:\Games\Wesnoth 1.2.1\wesnothd.exe"="C:\Games\Wesnoth 1.2.1\wesnothd.exe:*:Enabled:wesnothd"
"K:\Unreal Tournament\System\UnrealTournament.exe"="K:\Unreal Tournament\System\UnrealTournament.exe:*:Enabled:UnrealTournament"
"C:\Program Files\QIP\qip.exe"="C:\Program Files\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"K:\Age_of_Empires_II\age2_x1.exe"="K:\Age_of_Empires_II\age2_x1.exe:*:Enabled:Age of Empires II Expansion"
"K:\C & C Tiberian Sun\game.exe"="K:\C & C Tiberian Sun\game.exe:*:Enabled:Main executable for Tiberian Sun"
"C:\Games\Shadow of Death\h3wog.exe"="C:\Games\Shadow of Death\h3wog.exe:*:Enabled:Heroes of Might and Magic® III"
"K:\magic\Magic\Manalink.exe"="K:\magic\Magic\Manalink.exe:*:Enabled:manalink"
"C:\Program Files\Java\jre1.5.0_04\bin\javaw.exe"="C:\Program Files\Java\jre1.5.0_04\bin\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"K:\Heroes of Might and Magic III Complete\h3wog.exe"="K:\Heroes of Might and Magic III Complete\h3wog.exe:*:Enabled:Heroes of Might and Magic® III"
"K:\Trackmania\TmForever.exe"="K:\Trackmania\TmForever.exe:*:Enabled:TmForever"
"C:\Documents and Settings\Ing. Jiří Ťápal\Dokumenty\QIP\qip.exe"="C:\Documents and Settings\Ing. Jiří Ťápal\Dokumenty\QIP\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"K:\miTorrent\uTorrent.exe"="K:\miTorrent\uTorrent.exe:*:Enabled:µTorrent"
"K:\Typing of the Dead\Tod_e.exe"="K:\Typing of the Dead\Tod_e.exe:*:Enabled:Tod_e"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

======List of files/folders created in the last 1 months======

2010-02-23 15:23:50 ----D---- C:\Program Files\trend micro
2010-02-23 15:23:43 ----D---- C:\rsit
2010-02-23 15:15:56 ----A---- C:\WINDOWS\system32\RootkitReveal.txt
2010-02-22 21:59:35 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-02-21 14:22:37 ----D---- C:\Program Files\Sophos
2010-02-21 13:46:45 ----D---- C:\Program Files\Alwil Software
2010-02-21 13:46:30 ----D---- C:\Documents and Settings\All Users\Data aplikací\Alwil Software
2010-02-20 14:09:59 ----D---- C:\WINDOWS\pss
2010-02-20 12:49:33 ----D---- C:\Program Files\Uniblue
2010-02-20 12:21:42 ----D---- C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\Uniblue
2010-02-18 23:25:51 ----D---- C:\Program Files\Opera
2010-01-30 13:22:12 ----D---- C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\dvdcss
2010-01-25 14:00:55 ----A---- C:\WINDOWS\7THLEVEL.INI

======List of files/folders modified in the last 1 months======

2010-02-23 15:24:06 ----D---- C:\WINDOWS\Prefetch
2010-02-23 15:23:50 ----AD---- C:\Program Files
2010-02-23 15:16:45 ----D---- C:\Jarre
2010-02-23 15:15:56 ----D---- C:\WINDOWS\system32
2010-02-23 14:42:08 ----D---- C:\WINDOWS\system32\drivers
2010-02-23 14:35:43 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-23 14:35:00 ----D---- C:\WINDOWS\Temp
2010-02-23 14:21:53 ----D---- C:\Program Files\Microsoft AntiSpyware
2010-02-23 02:21:55 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-22 22:51:16 ----D---- C:\WINDOWS
2010-02-22 22:48:52 ----D---- C:\WINDOWS\nview
2010-02-22 22:47:36 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-22 22:47:34 ----HD---- C:\WINDOWS\inf
2010-02-22 22:47:34 ----D---- C:\WINDOWS\Help
2010-02-22 22:42:55 ----D---- C:\WINDOWS\system32\ReinstallBackups
2010-02-22 22:00:18 ----SHD---- C:\WINDOWS\Installer
2010-02-22 21:59:39 ----D---- C:\Program Files\Common Files\Adobe
2010-02-22 21:58:17 ----D---- C:\Program Files\Adobe
2010-02-22 12:14:59 ----D---- C:\Documents and Settings
2010-02-21 15:00:53 ----D---- C:\Program Files\iPhox
2010-02-21 15:00:20 ----D---- C:\Program Files\eMedia Codec
2010-02-21 13:47:14 ----D---- C:\WINDOWS\WinSxS
2010-02-21 13:47:12 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-21 13:44:22 ----ASH---- C:\boot.ini
2010-02-21 13:44:22 ----A---- C:\WINDOWS\win.ini
2010-02-21 13:44:22 ----A---- C:\WINDOWS\system.ini
2010-02-20 13:27:24 ----D---- C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\uTorrent
2010-02-20 12:52:12 ----D---- C:\WINDOWS\system32\config
2010-02-19 01:39:35 ----D---- C:\Program Files\Mozilla Firefox
2010-02-18 23:13:22 ----D---- C:\Program Files\zOpera
2010-02-18 22:27:15 ----D---- C:\Add-on's
2010-02-18 22:09:00 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft
2010-02-11 19:53:36 ----A---- C:\WINDOWS\system32\aswBoot.exe
2010-02-03 17:10:13 ----D---- C:\Documents and Settings\Ing. Jiří Ťápal\Data aplikací\vlc

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2010-02-11 28880]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2010-02-11 162512]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2010-02-11 46672]
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\System32\mbmiodrvr.sys []
R1 P3;Ovladač procesoru Intel PentiumIII; C:\WINDOWS\System32\DRIVERS\p3.sys [2008-04-14 46592]
R1 SAVRKBootTasks;Boot Tasks Driver; \??\C:\WINDOWS\system32\SAVRKBootTasks.sys []
R1 WS2IFSL;Podpůrné prostředí zprostředkovatele služeb Windows Socket 2.0 bez podpory IFS; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-10-25 12032]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\drivers\aswFsBlk.sys [2010-02-11 19024]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2010-02-11 100432]
R2 Fallback;Fallback; C:\WINDOWS\System32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\System32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\System32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;Služba NWLink pro rozhraní NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2001-10-25 63232]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2001-10-25 55936]
R2 SoftFax;SoftFax; C:\WINDOWS\System32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 SpeakerPhone;SpeakerPhone; C:\WINDOWS\System32\DRIVERS\HSF_SPKP.sys [2001-08-17 73279]
R2 Tones;Tones; C:\WINDOWS\System32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\System32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 ac97intc;Služba instalace zvukového ovladače Intel(r) (WDM); C:\WINDOWS\system32\drivers\ac97intc.sys [2001-08-17 96256]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2010-02-11 23376]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2009-09-23 26176]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-10-22 3994624]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-01-18 80512]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 09e7bnc1;09e7bnc1; \??\C:\DOCUME~1\ING~1.JIP\LOCALS~1\Temp\qrl15L []
S3 basic2;basic2; C:\WINDOWS\System32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2005-11-17 223128]
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
S3 hsf_msft;hsf_msft; C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\10.tmp []
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 nm;Ovladač programu Sledování sítě; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-13 40320]
S3 PnkBstrK;PnkBstrK; \??\C:\WINDOWS\system32\drivers\PnkBstrK.sys []
S3 Rksample;Rksample; C:\WINDOWS\System32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SE2Bbus;Sony Ericsson Device 043 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE2Bbus.sys [2006-05-01 61600]
S3 SE2Bmdfl;Sony Ericsson Device 043 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE2Bmdfl.sys [2006-05-01 9360]
S3 SE2Bmdm;Sony Ericsson Device 043 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE2Bmdm.sys [2006-05-01 97184]
S3 SE2Bmgmt;Sony Ericsson Device 043 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE2Bmgmt.sys [2006-05-01 88688]
S3 se2Bnd5;Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (NDIS); C:\WINDOWS\system32\DRIVERS\se2Bnd5.sys [2006-05-01 18704]
S3 SE2Bobex;Sony Ericsson Device 043 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE2Bobex.sys [2006-05-01 86560]
S3 se2Bunic;Sony Ericsson Device 043 USB Ethernet Emulation SEMC43 (WDM); C:\WINDOWS\system32\DRIVERS\se2Bunic.sys [2006-05-01 90800]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [2009-10-29 1074568]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2001-02-23 270336]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-10-22 159810]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2007-11-14 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2007-12-16 107832]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2010-02-11 40384]
R3 RXB;RXB; C:\DOCUME~1\ING~1.JIP\LOCALS~1\Temp\RXB.exe [2010-02-23 383872]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S4 aswUpdSv;avast! iAVS4 Control Service; K:\Utility a updaty\Avast\aswUpdSv.exe []

-----------------EOF-----------------

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32: Rootkit-gen

#2 Příspěvek od Caroprd111 »

Zdravím :)

Na logu se pracuje, prosím o strpení.
Obrázek

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32: Rootkit-gen

#3 Příspěvek od Caroprd111 »

Obrázek Stáhněte a uložte, nejlépe na plochu http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Obrázek Vypněte všechny rezidentní bezpečnostní programy - firewally, antiviry, antispywary

Obrázek Spusťte aplikaci pod účtem s oprávněním Administrátora (Správce), ihned po startu se zobrází stránka s licenčnímy podmínkami, pokračujte stisknutím tlačítka "Ano"

Obrázek Dále postupujte dle pokynů, během scanu nespouštějte jiné aplikace a neklikejte do zobrazujícího se okna :!:

Obrázek Scan by měl trvat okolo 5 - 10 minut, po dokončení Combofix zobrazí log C:\ComboFix.txt , který sem vložte.

Obrázek Během skenování může být počítač restartován.
Obrázek

X.E.R.X.E.S.
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 23 úno 2010 15:28

Re: Win32: Rootkit-gen

#4 Příspěvek od X.E.R.X.E.S. »

Tak jo, provedl jsem podle příkazů, zde je log: :)

ComboFix 10-02-22.07 - Ing. Jiří Ťápal 23.02.2010 17:37:50.2.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.242 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ing. Jiří Ťápal\Plocha\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\documents and settings\Ing. Jiří Ťápal\Local Settings\Temp\qpkvrto.old
c:\program files\INSTALL.LOG
c:\windows\system32\ieuinit.inf
c:\windows\system32\SIntf16.dll

.
((((((((((((((((((((((((( Soubory vytvořené od 2010-01-23 do 2010-02-23 )))))))))))))))))))))))))))))))
.

2010-02-23 14:23 . 2010-02-23 14:24 -------- d-----w- c:\program files\trend micro
2010-02-23 14:23 . 2010-02-23 14:24 -------- d-----w- C:\rsit
2010-02-23 14:16 . 2010-02-23 14:16 -------- d-----r- c:\documents and settings\LocalService\Dokumenty
2010-02-22 20:43 . 2009-06-18 11:55 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2010-02-21 13:22 . 2010-02-21 13:22 -------- d-----w- c:\program files\Sophos
2010-02-21 12:46 . 2010-02-21 12:46 -------- d-----w- c:\program files\Alwil Software
2010-02-20 11:49 . 2010-02-20 11:49 -------- d-----w- c:\program files\Uniblue
2010-02-18 22:26 . 2010-02-18 22:26 -------- d-----w- c:\documents and settings\ING~2.JIP\Data aplikac?
2010-02-18 22:26 . 2010-02-18 22:26 -------- d-----w- c:\documents and settings\Ing. Ji?? ??pal
2010-02-18 22:25 . 2010-02-18 22:26 -------- d-----w- c:\program files\Opera

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 16:32 . 2006-01-29 15:15 -------- d-----w- c:\program files\Microsoft AntiSpyware
2010-02-22 20:59 . 2004-10-16 16:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-21 14:00 . 2006-02-26 18:53 -------- d-----w- c:\program files\iPhox
2010-02-21 14:00 . 2006-01-28 22:09 -------- d-----w- c:\program files\eMedia Codec
2010-02-18 22:13 . 2004-11-11 21:37 -------- d-----w- c:\program files\zOpera
2010-02-11 18:53 . 2009-07-08 23:32 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-11 18:53 . 2009-07-08 23:31 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-11 18:42 . 2009-07-08 23:32 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-11 18:42 . 2009-07-08 23:32 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-11 18:39 . 2009-07-08 23:32 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-11 18:38 . 2009-07-08 23:32 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-11 18:38 . 2009-07-08 23:32 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-11 18:38 . 2009-07-08 23:32 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-11 18:38 . 2009-07-08 23:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2006-07-23 09:30 . 2006-07-20 13:35 7170259 ----a-w- c:\program files\Xerxes.dat
2006-07-12 13:14 . 2006-07-12 13:14 1905565 ----a-w- c:\program files\miranda-v05a60w.zip
2006-07-09 22:38 . 2006-07-12 13:14 414286 ----a-w- c:\program files\miranda32.exe
2006-07-09 21:55 . 2006-07-12 13:14 566044 ----a-w- c:\program files\ChangeLog.txt
2006-06-25 22:43 . 2006-07-12 13:14 40960 ----a-w- c:\program files\dbtool.exe
2005-09-25 14:02 . 2006-02-10 16:39 204875 ----a-w- c:\program files\icq.dll
2004-12-01 14:15 . 2006-03-28 18:18 3767005 ----a-w- c:\program files\mp_uo_adlerstein.pk3
2004-08-31 23:43 . 2006-03-28 18:18 6099736 ----a-w- c:\program files\mp_bazolles_final.pk3
2004-03-18 14:55 . 2006-03-28 18:18 5226372 ----a-w- c:\program files\mp_subharbor.pk3
2007-10-05 17:52 . 2006-03-02 21:06 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-10-05 17:52 . 2006-03-02 21:06 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-10-05 17:34 . 2009-11-06 10:52 118000 ----a-w- c:\program files\mozilla firefox\components\qippipe.dll
2007-10-05 17:52 . 2006-03-02 21:06 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-06-01 18:00 . 2008-06-01 17:42 66936 --sha-w- c:\windows\dlinfo_0.drv
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}"= "c:\documents and settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll" [2009-10-05 150768]

[HKEY_CLASSES_ROOT\clsid\{a55f9c95-2bb1-4ea2-bc77-dfaab78832ce}]
[HKEY_CLASSES_ROOT\qipbar.QIPBHO.1]
[HKEY_CLASSES_ROOT\qipbar.QIPBHO]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
2009-10-05 17:34 150768 ----a-w- c:\documents and settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"UniblueRegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-02-15 60208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2009-06-30 08:55 2329224 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 09:50 155648 ----a-r- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 11:22 7700480 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-03-12 19:58 98304 ----a-w- c:\program files\QuickTime\qttask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Starcraft\\starcraft.exe"=
"c:\\Games\\Shadow of Death\\Heroes3.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Games\\LieroXtreme\\LieroX.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Games\\Wesnoth 1.2.1\\wesnothd.exe"=
"k:\\Unreal Tournament\\System\\UnrealTournament.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"k:\\Age_of_Empires_II\\age2_x1.exe"=
"k:\\C & C Tiberian Sun\\game.exe"=
"c:\\Games\\Shadow of Death\\h3wog.exe"=
"c:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"k:\\Heroes of Might and Magic III Complete\\h3wog.exe"=
"k:\\Trackmania\\TmForever.exe"=
"c:\\Documents and Settings\\Ing. Jiří Ťápal\\Dokumenty\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"k:\\miTorrent\\uTorrent.exe"=
"k:\\Typing of the Dead\\Tod_e.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16.9.2004 19:42 5248]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.7.2009 0:32 162512]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [22.2.2010 21:43 18816]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.7.2009 0:32 19024]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.11.2005 16:03 664064]
S0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16.9.2004 19:42 141184]
S3 09e7bnc1;09e7bnc1;\??\c:\docume~1\ING~1.JIP\LOCALS~1\Temp\qrl15L --> c:\docume~1\ING~1.JIP\LOCALS~1\Temp\qrl15L [?]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\10.tmp --> c:\windows\system32\10.tmp [?]
.
Obsah adresáře 'Naplánované úlohy'

2010-02-21 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-03-04 17:15]
.
.
------- Doplňkový sken -------
.
uStart Page = start.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = about:blank
uInternet Settings,ProxyServer = proxy.karneval.cz:3128
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Eurotran XP\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Eurotran XP\etnxp.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -

AddRemove-Beyond Wolfenstein II Special Edition - c:\games\Wolf2\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 17:45
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\09e7bnc1]
"ImagePath"="\??\c:\docume~1\ING~1.JIP\LOCALS~1\Temp\qrl15L"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\10.tmp"
.
Celkový čas: 2010-02-23 17:50:57
ComboFix-quarantined-files.txt 2010-02-23 16:50

Před spuštěním: 6 116 483 072
Po spuštění: 6 083 514 368

- - End Of File - - 32EEB8BD63F7256BD524472EA3842921

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32: Rootkit-gen

#5 Příspěvek od Caroprd111 »

Obrázek Pokud nemáte, přesuňte Combofix na plochu
  • otevřete si Poznámkový blok a zkopírujte do něj text z bílého okénka.

Kód: Vybrat vše

Driver::
09e7bnc1
MEMSWEEP2

File::
c:\docume~1\ING~1.JIP\LOCALS~1\Temp\qrl15L 
c:\windows\system32\10.tmp 
  • uložte Vámi vytvořený TXT soubor jako CFScript.txt na plochu
  • po uložení uchopte vámi vytvořený skript levým myšítkem a přesuňte ho nad ikonu Combofixu, kde ho upustíte:
    Obrázek
  • po aplikaci na Vás vypadne další log,vložte ho sem
Může se stát, že po aplikaci skriptu a restartu Windows nenaběhnou, v tom případě znovu restartujte a přitom mačkejte F8, pak zvolte Poslední známou funkční konfiguraci
Obrázek

X.E.R.X.E.S.
Návštěvník
Návštěvník
Příspěvky: 3
Registrován: 23 úno 2010 15:28

Re: Win32: Rootkit-gen

#6 Příspěvek od X.E.R.X.E.S. »

Tak, zde je další log, zatím to vypadá, že je všechno v pořádku :-)

ComboFix 10-02-22.07 - Ing. Jiří Ťápal 23.02.2010 18:14:31.3.1 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.447.150 [GMT 1:00]
Spuštěný z: c:\documents and settings\Ing. Jiří Ťápal\Plocha\ComboFix.exe
Použité ovládací přepínače :: c:\documents and settings\Ing. Jiří Ťápal\Plocha\CFScript.txt
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

FILE ::
"c:\docume~1\ING~1.JIP\LOCALS~1\Temp\qrl15L"
"c:\windows\system32\10.tmp"
.

((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_MEMSWEEP2
-------\Service_09e7bnc1
-------\Service_MEMSWEEP2


((((((((((((((((((((((((( Soubory vytvořené od 2010-01-23 do 2010-02-23 )))))))))))))))))))))))))))))))
.

2010-02-23 14:23 . 2010-02-23 14:24 -------- d-----w- c:\program files\trend micro
2010-02-23 14:23 . 2010-02-23 14:24 -------- d-----w- C:\rsit
2010-02-23 14:16 . 2010-02-23 14:16 -------- d-----r- c:\documents and settings\LocalService\Dokumenty
2010-02-22 20:43 . 2009-06-18 11:55 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2010-02-21 13:22 . 2010-02-21 13:22 -------- d-----w- c:\program files\Sophos
2010-02-21 12:46 . 2010-02-21 12:46 -------- d-----w- c:\program files\Alwil Software
2010-02-20 11:49 . 2010-02-20 11:49 -------- d-----w- c:\program files\Uniblue
2010-02-18 22:26 . 2010-02-18 22:26 -------- d-----w- c:\documents and settings\ING~2.JIP\Data aplikac?
2010-02-18 22:26 . 2010-02-18 22:26 -------- d-----w- c:\documents and settings\Ing. Ji?? ??pal
2010-02-18 22:25 . 2010-02-18 22:26 -------- d-----w- c:\program files\Opera

.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 17:50 . 2006-01-29 15:15 -------- d-----w- c:\program files\Microsoft AntiSpyware
2010-02-22 20:59 . 2004-10-16 16:28 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-21 14:00 . 2006-02-26 18:53 -------- d-----w- c:\program files\iPhox
2010-02-21 14:00 . 2006-01-28 22:09 -------- d-----w- c:\program files\eMedia Codec
2010-02-18 22:13 . 2004-11-11 21:37 -------- d-----w- c:\program files\zOpera
2010-02-11 18:53 . 2009-07-08 23:32 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-02-11 18:53 . 2009-07-08 23:31 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-02-11 18:42 . 2009-07-08 23:32 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-02-11 18:42 . 2009-07-08 23:32 162512 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-02-11 18:39 . 2009-07-08 23:32 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-02-11 18:38 . 2009-07-08 23:32 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-02-11 18:38 . 2009-07-08 23:32 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-02-11 18:38 . 2009-07-08 23:32 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-02-11 18:38 . 2009-07-08 23:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2006-07-23 09:30 . 2006-07-20 13:35 7170259 ----a-w- c:\program files\Xerxes.dat
2006-07-12 13:14 . 2006-07-12 13:14 1905565 ----a-w- c:\program files\miranda-v05a60w.zip
2006-07-09 22:38 . 2006-07-12 13:14 414286 ----a-w- c:\program files\miranda32.exe
2006-07-09 21:55 . 2006-07-12 13:14 566044 ----a-w- c:\program files\ChangeLog.txt
2006-06-25 22:43 . 2006-07-12 13:14 40960 ----a-w- c:\program files\dbtool.exe
2005-09-25 14:02 . 2006-02-10 16:39 204875 ----a-w- c:\program files\icq.dll
2004-12-01 14:15 . 2006-03-28 18:18 3767005 ----a-w- c:\program files\mp_uo_adlerstein.pk3
2004-08-31 23:43 . 2006-03-28 18:18 6099736 ----a-w- c:\program files\mp_bazolles_final.pk3
2004-03-18 14:55 . 2006-03-28 18:18 5226372 ----a-w- c:\program files\mp_subharbor.pk3
2007-10-05 17:52 . 2006-03-02 21:06 61038 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2007-10-05 17:52 . 2006-03-02 21:06 49256 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-10-05 17:34 . 2009-11-06 10:52 118000 ----a-w- c:\program files\mozilla firefox\components\qippipe.dll
2007-10-05 17:52 . 2006-03-02 21:06 166000 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2008-06-01 18:00 . 2008-06-01 17:42 66936 --sha-w- c:\windows\dlinfo_0.drv
.

(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}"= "c:\documents and settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll" [2009-10-05 150768]

[HKEY_CLASSES_ROOT\clsid\{a55f9c95-2bb1-4ea2-bc77-dfaab78832ce}]
[HKEY_CLASSES_ROOT\qipbar.QIPBHO.1]
[HKEY_CLASSES_ROOT\qipbar.QIPBHO]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A55F9C95-2BB1-4EA2-BC77-DFAAB78832CE}]
2009-10-05 17:34 150768 ----a-w- c:\documents and settings\Ing. Jiří Ťápal\Data aplikací\Microsoft\Internet Explorer\qipsearchbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"gcasServ"="c:\program files\Microsoft AntiSpyware\gcasServ.exe" [2005-11-15 473928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-02-11 2756488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Nabˇdka Start\Programy\Po spuçtŘnˇ\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2009-06-30 08:55 2329224 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 06:52 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
2001-07-09 09:50 155648 ----a-r- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 11:22 7700480 ----a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-03-12 19:58 98304 ----a-w- c:\program files\QuickTime\qttask.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Starcraft\\starcraft.exe"=
"c:\\Games\\Shadow of Death\\Heroes3.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Games\\LieroXtreme\\LieroX.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Games\\Wesnoth 1.2.1\\wesnothd.exe"=
"k:\\Unreal Tournament\\System\\UnrealTournament.exe"=
"c:\\Program Files\\QIP\\qip.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"k:\\Age_of_Empires_II\\age2_x1.exe"=
"k:\\C & C Tiberian Sun\\game.exe"=
"c:\\Games\\Shadow of Death\\h3wog.exe"=
"c:\\Program Files\\Java\\jre1.5.0_04\\bin\\javaw.exe"=
"k:\\Heroes of Might and Magic III Complete\\h3wog.exe"=
"k:\\Trackmania\\TmForever.exe"=
"c:\\Documents and Settings\\Ing. Jiří Ťápal\\Dokumenty\\QIP\\qip.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"k:\\miTorrent\\uTorrent.exe"=
"k:\\Typing of the Dead\\Tod_e.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 xmasbus;xmasbus;c:\windows\system32\drivers\xmasbus.sys [16.9.2004 19:42 141184]
R0 xmasscsi;xmasscsi;c:\windows\system32\drivers\xmasscsi.sys [16.9.2004 19:42 5248]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9.7.2009 0:32 162512]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [22.2.2010 21:43 18816]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9.7.2009 0:32 19024]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17.11.2005 16:03 664064]
.
.
------- Doplňkový sken -------
.
uStart Page = start.qip.ru
uDefault_Search_URL = hxxp://search.qip.ru
mStart Page = about:blank
uInternet Settings,ProxyServer = proxy.karneval.cz:3128
uSearchAssistant = hxxp://search.qip.ru/ie
uSearchURL,(Default) = Root: HKCU; Subkey: Software\Microsoft\Internet Explorer\SearchUrl; ValueType: string; ValueName: '; ValueData: '; Flags: createvalueifdoesntexist noerror; Tasks: AddSearchQip
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {{230D1201-7607-4CF6-A11F-9E4BF0A333E0} - {0DB13731-CEFD-43CF-A8FD-B61DCBC4D5B8} - c:\program files\Eurotran XP\etnxp.dll
IE: {{2C73F784-D2DE-4422-B070-2E3332FE5744} - {0320AC26-52C8-4316-B2C4-24BB6FA73C9A} - c:\program files\Eurotran XP\etnxp.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 18:50
Windows 5.1.2600 Service Pack 3 NTFS

skenování skrytých procesů ...

skenování skrytých položek 'Po spuštění' ...

skenování skrytých souborů ...

sken byl úspešně dokončen
skryté soubory: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8406AF00]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf752df28
\Driver\ACPI -> ACPI.sys @ 0xf747dcb8
\Driver\atapi -> atapi.sys @ 0xf740f852
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056c1d6
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0598
ParseProcedure -> ntoskrnl.exe @ 0x8056c1d6
NDIS: Realtek RTL8139/810x Family Fast Ethernet NIC -> SendCompleteHandler -> NDIS.sys @ 0xf72ecbd4
PacketIndicateHandler -> NDIS.sys @ 0xf72f8a21
SendHandler -> NDIS.sys @ 0xf72ecd44
user & kernel MBR OK

**************************************************************************
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft AntiSpyware\gcasDtServ.exe
.
**************************************************************************
.
Celkový čas: 2010-02-23 18:57:31 - počítač byl restartován
ComboFix-quarantined-files.txt 2010-02-23 17:57
ComboFix2.txt 2010-02-23 16:50

Před spuštěním: 6 107 586 560
Po spuštění: 6 013 169 664

- - End Of File - - 81B32FF30120135CCF216312E91ABDEE

Uživatelský avatar
Caroprd111
VIP
VIP
Příspěvky: 13492
Registrován: 22 bře 2009 20:48
Bydliště: Třebíč
Kontaktovat uživatele:

Re: Win32: Rootkit-gen

#7 Příspěvek od Caroprd111 »

Obrázek

Odpovědět