Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

PRosím o kontrolu logu po návštěve Win32: Virtob

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

PRosím o kontrolu logu po návštěve Win32: Virtob

#1 Příspěvek od BFU »

Dobrý den,

dnes ráno jsem chtěl projet svůj notebook pomoci Secunie PSI. Při jejím spouštěn které zlobilo jsem jí musel pouštět asi 3x a potvrdil jsem možná Comodu spuštění o jedné akce víc než jsem chtěl ( :oops: ). Každopádně se následně ozval Avast 4.8 detekující Win32:Virtob v zálozních souborech na disku D hluboko v podložkách obsahujících drivery k mému pc (staré asi tak 3 měsíce, tenkrát jsem je myslím testoval a ok). Soubory jsem nepotřeboval, takže následovalo smazaní Avastem několika nahlášených souborů a sken celé složky. Smazáno bylo antivirem ještě asi 10 souborů. Poté jsem preventivně smazal přes ctrl &del celou složku a vysypal koš. Měl jsem ejště zapnuté zálohování systému přes body obnovy, to jsem vypnul (ale ještě nerestartoval) a projel pc celé Avastem. Nic nenašel. Stejně tak ani Dr Web CureIT a AVG Virut Removal Tool (http://www.hm2k.com/posts/win32-virtob-virut-removal).

Celé PC jsem tedy ještě nerestartoval a bojím se aby nebyl po resetu nazpět. NA jednom routeru jsou navím další dvě PC, je tahle mrška nakažlivá v rámci sítě? Zatím jsem žádné problémy nepozoroval... Jedno pc vidí Avasta jako OK, druhé ještě sjíždí. Prodeju je pak ještě preventivně oba AVG Virut removalem, ok?

Posílám loga, mrknete mi na to prosím lidé dobří? Jsem Vám zauzlován :)

PS: Jestli by to bylo lepší, není až takový problém udělat radši reinstal, ale na druhou stranu jestli ej to ok, ušetří mi to práci...

RSIT za jeden měsíc:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2010-02-26 14:28:11
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 12 GB (59%) free of 21 GB
Total RAM: 446 MB (22% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:21, on 26.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\WINDOWS\system32\sistray.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Documents and Settings\Admin\Plocha\drweb-cureit.exe
C:\DOCUME~1\Admin\LOCALS~1\Temp\RarSFX0\2zr2ew.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Admin\Plocha\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\Program Files\Opera\program\plugins\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{64123F00-3CE1-4784-991E-E393F395E610}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C744B0A-FE5E-4D21-8773-6F9C3CA9181F}: NameServer = 156.154.70.25,156.154.71.25
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: wlcrdplauncher - C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 7277 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-23 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-23 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY []
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2004-10-08 88363]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-10-08 98394]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-10-08 688218]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-01-11 1800464]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-02-23 77824]
"SiSPower"=SiSPower.dll,ModeAgent []
"SiS Windows KeyHook"=C:\WINDOWS\system32\keyhook.exe [2005-03-04 32768]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-11 3037696]
"MoeMonitor.exe"=C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe [2010-01-14 1315152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"=C:\Program Files\Opera\program\plugins\NPSWF32_FlashUtil.exe [2009-10-28 257440]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe

C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění
Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlcrdplauncher]
C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll [2010-01-14 21840]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"

======List of files/folders created in the last 1 months======

2010-02-26 14:17:57 ----D---- C:\Program Files\trend micro
2010-02-26 14:17:37 ----D---- C:\rsit
2010-02-15 21:29:34 ----D---- C:\Program Files\The KMPlayer
2010-02-15 21:18:40 ----D---- C:\Documents and Settings\Admin\Data aplikací\Media Player Classic
2010-02-10 16:59:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 16:59:52 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 16:59:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 16:59:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 16:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 16:59:21 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 16:58:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 16:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 16:57:52 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-03 23:25:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-02-01 19:39:02 ----D---- C:\Program Files\CCleaner
2010-02-01 19:37:44 ----D---- C:\Program Files\Microsoft Bootvis

======List of files/folders modified in the last 1 months======

2010-02-26 14:18:46 ----D---- C:\WINDOWS\Prefetch
2010-02-26 14:17:57 ----RD---- C:\Program Files
2010-02-26 14:11:34 ----D---- C:\WINDOWS\Temp
2010-02-26 11:11:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-02-26 08:52:39 ----SHD---- C:\System Volume Information
2010-02-26 08:52:39 ----D---- C:\WINDOWS\system32\Restore
2010-02-26 08:11:36 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-26 08:06:16 ----D---- C:\WINDOWS
2010-02-22 21:57:06 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-17 00:11:30 ----D---- C:\Program Files\CDBurnerXP
2010-02-16 23:35:23 ----D---- C:\WINDOWS\system32\drivers
2010-02-15 21:28:27 ----D---- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
2010-02-15 21:28:26 ----D---- C:\Program Files\Spyware Terminator
2010-02-13 09:10:17 ----D---- C:\WINDOWS\system32
2010-02-10 17:00:03 ----HD---- C:\WINDOWS\inf
2010-02-10 16:59:58 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-10 16:59:56 ----A---- C:\WINDOWS\imsins.BAK
2010-02-10 16:59:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-10 16:59:15 ----SHD---- C:\WINDOWS\Installer
2010-02-10 16:59:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-02-07 11:29:45 ----RSD---- C:\WINDOWS\Fonts
2010-02-07 11:29:34 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-07 11:28:53 ----D---- C:\Program Files\Microsoft Works
2010-02-07 11:25:23 ----N---- C:\WINDOWS\win.ini
2010-02-07 11:25:23 ----D---- C:\Program Files\Common Files\System
2010-01-29 16:01:17 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-08-11 39424]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-01-11 133064]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-01-11 25160]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2005-02-25 13312]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-01-11 17801]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-10-08 1270540]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-02-24 2311680]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 BCM43XX;Broadcom 802.11 ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2004-12-22 369024]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 RDPDISPM;RDPDISPM; C:\WINDOWS\system32\DRIVERS\rdpdispm.sys [2010-01-14 9040]
R3 RDPVDD;RDPVDD; C:\WINDOWS\system32\DRIVERS\rdpvmp.sys [2010-01-14 19408]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2005-03-02 240640]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\sisnic.sys [2004-08-03 32768]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-10-08 185824]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
R4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\System32\DRIVERS\sr.sys [2008-04-14 73344]
S3 ao1jtxmx;ao1jtxmx; C:\WINDOWS\system32\drivers\ao1jtxmx.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-01-11 723632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-01-23 153376]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-09-06 71096]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-01-11 488960]
R2 wlcrasvc;Live Mesh Remote Desktop; C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe [2010-01-14 44880]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\wltrysvc.exe [2004-12-22 65536]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#2 Příspěvek od motji »

Hezké odpoledne :)
Log vypadá v pořádku.
Můžete proskenovat počítač AVPtoolem :)

:arrow: Stahněte z mého podpisu AVPTOOl http://www.viry.cz/forum/viewtopic.php?f=29&t=58179

-Podle návodu nainstalujte a proveďte sken
-co najde nechejte léčit, mazat
-sken může trvat několik hodin
-vložte zde log z výsledky
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#3 Příspěvek od BFU »

Děkuji za rady, jdu na to. V mezičase jsem ještě projel PC MWAWem a tohle je výsledek:

Soubor C:\Documents and Settings\Admin\Plocha\rmvirut.exe je infikovaný virem Generic.HorstBased.060B6EE8 (DB) !! Provedené akce: Ponecháno, neodstraněno!

** Scanning may fail! File Locked [SUSPICIOUS]: C:\WINDOWS\system32\Drivers\sptd.sys (????)

Soubor C:\Documents and Settings\Admin\Plocha\rmvirut.exe je infikovaný virem Generic.HorstBased.060B6EE8 (DB) !! Provedené akce: Ponecháno, neodstraněno!.

Soubor C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Temp\ZAP468.tmp\System.Web.Extensions.dll je infikovaný virem Exe.Corrupted !! Provedené akce: Ponecháno, neodstraněno!.

...rmvirut je předpokládám planý poplach u antimalware software. Tomu suspicious locked file nerozumím :). Zkoušel jsem najít ten poslední jmenovaný, ale žádné "NativeImages..." atd. ve složce Windows\assembly není, ani když mám nastavené zobrazování skrytých a systémových souborů.

Jdu na AVPTOOL, log pak přihodím. Myslíte že může u téhle potvory hrozit to, že se stihla rozšířit po síti na ostatní pc, které mám doma? Zatím nic nehlásí, ale bojím bojím :)

Díky za Vaši pomco a čas!

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#4 Příspěvek od motji »

To co našel mwaw, je v pořádku.
** Scanning may fail! File Locked [SUSPICIOUS]: C:\WINDOWS\system32\Drivers\sptd.sys ( - to je driver patřící k virtuální jednotce, takže bude pravděpodobně také v pořádku

Pokud se virut nerozběhl na Vašem počítači, je dost nepravděpodobné, aby se rozšířil po síti.

Avast Vám ty soubory hlásil hned po povolení akce v Comodu nebo později? Mohla to být také falešná detekce Avastu. Pokud webcureit, mwaw a ted ani Avptool nic nenašli, pc bude čistý :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#5 Příspěvek od BFU »

Tak log je tu...

Autoscan: completed 3 minutes ago (events: 7, objects: 173662, time: 01:38:23)
26.2.2010 19:21:53 Task started
26.2.2010 19:36:29 Detected: http://www.viruslist.com/en/advisories/38547 C:\Program Files\Opera\program\plugins\NPSWF32.dll
26.2.2010 19:54:57 Detected: http://www.viruslist.com/en/advisories/38547 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
26.2.2010 20:35:49 Detected: http://www.viruslist.com/en/advisories/38547 C:\Program Files\Opera\program\plugins\NPSWF32.dll
26.2.2010 20:48:54 Detected: http://www.viruslist.com/en/advisories/38547 C:\Program Files\Opera\program\plugins\NPSWF32.dll
26.2.2010 20:58:26 Detected: http://www.viruslist.com/en/advisories/38547 C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
26.2.2010 21:00:19 Task completed

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#6 Příspěvek od motji »

Mazal jste už něco?
Můžete poslední dva soubory otestovat na www.virustotal.com?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#7 Příspěvek od BFU »

motji píše:To co našel mwaw, je v pořádku.
** Scanning may fail! File Locked [SUSPICIOUS]: C:\WINDOWS\system32\Drivers\sptd.sys ( - to je driver patřící k virtuální jednotce, takže bude pravděpodobně také v pořádku

Pokud se virut nerozběhl na Vašem počítači, je dost nepravděpodobné, aby se rozšířil po síti.

Avast Vám ty soubory hlásil hned po povolení akce v Comodu nebo později? Mohla to být také falešná detekce Avastu. Pokud webcureit, mwaw a ted ani Avptool nic nenašli, pc bude čistý :)
Doufám, že se nerozběhl. Jak jsem psal v prvním postu. Avast zahlásil nějdřív sám od sebe asi tři poplachy. Všechny soubory jsem ho nechal rovnou smazat. Pak se při mnou spuštěném skenu složky, ve které k tomu došlo objevilo ještě asi šest podobných hlášení.

Časová osa byla spuštění Secunia PSI, několik vyskočivších upozornění a povolení v Comodu a zhruba ve chvíli kdy začala Secunie pracovat začal Avast hlásit. Nejsem si jistý jestli byla závada v povolení, ale popravdě jsem si pořádně nepřečetl jestli se spouští jeden ze souborů od PSI a vím že ted to chtělo o jedno-dvě potvrzení víc, než minule. Co mě zaráží, že se soubory se hodně dlouho nepracovalo, byly zahrabané na Dčku a rozhodně jsem je nespouštěl.

Falešná detekce to asi nebude, protože ještě než jsem v Avastu vybral smazání prohnal jsem první hlášený soubor přes virustotal.com a detekovalo ho 41 ze 42 programů.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#8 Příspěvek od motji »

A nevíte jaký vir antiviry detekovali? jen ten vitrool, nebo padli i jiné názvy?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#9 Příspěvek od BFU »

motji píše:A nevíte jaký vir antiviry detekovali? jen ten vitrool, nebo padli i jiné názvy?
Co si pamatuju, tak se docela shodovali. Někteří dle Avastu tvrdili Win32:Virtob jiní myslím "Virut". Plus změť ne moc říkajících "Win 32 cosi". Celkově mi ale přišlo že se celkem shodovali.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#10 Příspěvek od BFU »

motji píše:Mazal jste už něco?
Můžete poslední dva soubory otestovat na http://www.virustotal.com?
Nemazal, raději čekám na instrukce. Jinak na tyhle dva soubory upozornuje i Secunia s tím že jsou neaktuální a doporučuje mi stažení flashe.

Tak výsledku souborů jsou tu, čerstvé a nově otestované:

Soubor NPSWF32.dll přijatý 2010.02.26 20:22:53 (UTC)
Současný stav: Dokončeno
Výsledek: 0/42 (0%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.02.26 -
AhnLab-V3 5.0.0.2 2010.02.26 -
AntiVir 8.2.1.176 2010.02.26 -
Antiy-AVL 2.0.3.7 2010.02.26 -
Authentium 5.2.0.5 2010.02.26 -
Avast 4.8.1351.0 2010.02.26 -
Avast5 5.0.332.0 2010.02.26 -
AVG 9.0.0.730 2010.02.26 -
BitDefender 7.2 2010.02.26 -
CAT-QuickHeal 10.00 2010.02.26 -
ClamAV 0.96.0.0-git 2010.02.26 -
Comodo 4075 2010.02.26 -
DrWeb 5.0.1.12222 2010.02.26 -
eSafe 7.0.17.0 2010.02.25 -
eTrust-Vet 35.2.7331 2010.02.26 -
F-Prot 4.5.1.85 2010.02.26 -
F-Secure 9.0.15370.0 2010.02.26 -
Fortinet 4.0.14.0 2010.02.26 -
GData 19 2010.02.26 -
Ikarus T3.1.1.80.0 2010.02.26 -
Jiangmin 13.0.900 2010.02.25 -
K7AntiVirus 7.10.984 2010.02.26 -
Kaspersky 7.0.0.125 2010.02.26 -
McAfee 5903 2010.02.25 -
McAfee+Artemis 5903 2010.02.25 -
McAfee-GW-Edition 6.8.5 2010.02.26 -
Microsoft 1.5502 2010.02.26 -
NOD32 4899 2010.02.26 -
Norman 6.04.08 2010.02.26 -
nProtect 2009.1.8.0 2010.02.26 -
Panda 10.0.2.2 2010.02.26 -
PCTools 7.0.3.5 2010.02.26 -
Prevx 3.0 2010.02.26 -
Rising 22.36.04.04 2010.02.26 -
Sophos 4.50.0 2010.02.26 -
Sunbelt 5700 2010.02.26 -
Symantec 20091.2.0.41 2010.02.26 -
TheHacker 6.5.1.6.212 2010.02.26 -
TrendMicro 9.120.0.1004 2010.02.26 -
VBA32 3.12.12.2 2010.02.26 -
ViRobot 2010.2.26.2204 2010.02.26 -
VirusBuster 5.0.27.0 2010.02.26 -
Rozšiřující informace
File size: 3885984 bytes
MD5...: 6291009ff02c67c1957194c798e0fdce
SHA1..: 798b845729986dceff783392f512e5c37000a4e5
SHA256: c012fbe8fd5aa7ba27ecb003c97c74357a4bbaf5d45838f312690e3b2e648fe8
ssdeep: 49152:VSsARioZHxcuJNK3rGGmNxrXbiKlNrdSbskDYgQAVwwuIycPmQcYyOmBuF
g8WSrR:VSBFHxcuormz/SbsXimQclIWmeMx
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x2e7bc0
timedatestamp.....: 0x4ae7bd0e (Wed Oct 28 03:39:58 2009)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2f2407 0x2f2600 6.80 6815cf0afa5ff4eddc6b1146f209dd2f
.rdata 0x2f4000 0x800fe 0x80200 6.51 5d6c34bf3242c86f86acaca9befec344
.data 0x375000 0xf88fc 0x1ac00 6.29 d43e30749d413e2adbb07ea172d5cd87
.rodata 0x46e000 0x5e0 0x600 5.43 66ff6171c9347427d2b9c712bd6823f5
.rsrc 0x46f000 0xe408 0xe600 4.34 abbf58ba694945d3a3c449fb3dc27f08
.reloc 0x47e000 0x17082 0x17200 6.07 5488f2f766759b3048a1c2cd73b41de5

( 16 imports )
> VERSION.dll: GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
> WINMM.dll: waveOutGetPosition, waveInOpen, waveInPrepareHeader, waveInAddBuffer, waveInStart, waveOutOpen, timeGetTime, waveInGetDevCapsA, waveOutGetDevCapsA, waveInGetNumDevs, waveInStop, waveInReset, waveInUnprepareHeader, waveInClose, waveOutUnprepareHeader, waveOutPrepareHeader, waveOutWrite, waveOutClose, waveOutReset, timeGetDevCaps, timeEndPeriod, timeBeginPeriod, timeKillEvent, timeSetEvent, waveOutGetNumDevs
> WININET.dll: InternetCloseHandle, HttpQueryInfoA, InternetOpenA, InternetConnectA, HttpOpenRequestA, HttpSendRequestA, InternetReadFile
> CRYPT32.dll: CryptGetMessageCertificates, CertCreateCertificateContext, CertFindCertificateInStore, CertVerifySubjectCertificateContext, CertFreeCertificateContext, CertCloseStore, CryptVerifyMessageSignature
> RPCRT4.dll: RpcStringFreeA, UuidToStringA
> OLEAUT32.dll: -, -, -, -, -, -, -
> urlmon.dll: CopyStgMedium
> KERNEL32.dll: OpenFile, LockResource, LoadResource, SizeofResource, FindResourceA, GetModuleHandleA, DeleteFileA, WriteFile, CreateFileA, GetTempFileNameA, GetCurrentDirectoryA, CreateDirectoryA, GetEnvironmentVariableA, GlobalFree, WideCharToMultiByte, QueryPerformanceCounter, QueryPerformanceFrequency, SetThreadPriority, WaitForSingleObject, SetWaitableTimer, CreateThread, CreateWaitableTimerA, GetProcessTimes, GetCurrentProcess, GlobalUnlock, GlobalLock, GetCurrentProcessId, GlobalSize, GlobalAlloc, FreeLibrary, GetSystemInfo, GetSystemDefaultLangID, MoveFileA, GetFileAttributesA, GetUserDefaultLangID, _lwrite, SetFilePointer, ReadFile, GetFileSize, FindResourceExA, FindResourceExW, GetFileAttributesW, SetUnhandledExceptionFilter, GetTempPathA, FindClose, FindNextFileA, FindFirstFileA, InterlockedIncrement, InterlockedDecrement, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, CreateMutexA, CreateFileW, GetSystemDirectoryA, ExpandEnvironmentStringsA, ExpandEnvironmentStringsW, GetFileAttributesExA, SetCurrentDirectoryA, RemoveDirectoryA, SetFilePointerEx, GetFileSizeEx, CreateProcessA, UnmapViewOfFile, ReleaseMutex, MapViewOfFile, CreateFileMappingA, TerminateThread, lstrcpyA, IsDBCSLeadByteEx, UnhandledExceptionFilter, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, TerminateProcess, _lclose, FreeResource, GetModuleFileNameA, lstrlenA, RaiseException, lstrlenW, FlushInstructionCache, LCMapStringW, LCMapStringA, GetTickCount, GetCurrentThreadId, GetLocaleInfoA, SetErrorMode, GetLastError, GetVersionExA, LoadLibraryA, GetProcAddress, GetCurrentThread, SetThreadAffinityMask, VirtualQuery, IsDBCSLeadByte, GetACP, GetCPInfo, MultiByteToWideChar, ResetEvent, CreateEventA, CloseHandle, WaitForMultipleObjects, SetEvent, InterlockedExchange, InterlockedCompareExchange, Sleep, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, IsDebuggerPresent, RtlUnwind, GetCommandLineA, GetModuleHandleW, ReleaseSemaphore, CreateSemaphoreA, VirtualProtect, VirtualFree, VirtualAlloc, HeapFree, GetProcessHeap, HeapAlloc, VirtualProtectEx, HeapReAlloc, HeapCreate, HeapDestroy, ExitProcess, GetOEMCP, IsValidCodePage, HeapSize, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, GetStringTypeA, GetStringTypeW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers, ExitThread
> USER32.dll: DialogBoxIndirectParamW, DialogBoxIndirectParamA, EndDialog, GetDesktopWindow, LoadIconA, GetDlgItem, SetWindowTextA, GetMenuItemCount, InsertMenuItemW, GetSystemMetrics, GetClipboardFormatNameA, RegisterClipboardFormatA, GetCapture, SystemParametersInfoA, ScreenToClient, GetMenuItemID, DeleteMenu, InsertMenuItemA, GetMenuItemInfoA, TrackPopupMenu, ReleaseCapture, SetCapture, GetCursorPos, WindowFromPoint, GetParent, CreateWindowExA, GetWindowRect, SetWindowPos, ShowWindow, DestroyWindow, RedrawWindow, SendNotifyMessageA, SetWindowLongA, KillTimer, MapVirtualKeyA, GetClientRect, MessageBoxA, DefWindowProcA, RegisterClassA, PostMessageA, GetFocus, GetTopWindow, LoadStringA, LoadMenuA, GetSubMenu, DestroyMenu, InvalidateRect, LoadCursorA, SetCursor, GetKeyState, BeginPaint, EndPaint, EnableMenuItem, CheckMenuItem, EnumDisplaySettingsA, SetFocus, GetWindowInfo, CopyRect, SendInput, GetKeyboardLayout, FillRect, DialogBoxParamA, DialogBoxParamW, GetForegroundWindow, SendMessageA, WaitForInputIdle, GetDC, ReleaseDC, ClientToScreen, GetMonitorInfoA, OffsetRect, SetRect, MonitorFromWindow, GetDoubleClickTime, IsWindow, GetWindowThreadProcessId, GetWindowLongA, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, GetClipboardData, IsClipboardFormatAvailable, SetTimer, UnregisterClassA
> GDI32.dll: BitBlt, SelectObject, RealizePalette, SelectPalette, ExtTextOutA, SetBkColor, CreateSolidBrush, GetDeviceCaps, SetStretchBltMode, GetStretchBltMode, GetClipBox, GetSystemPaletteEntries, Rectangle, GetStockObject, StretchDIBits, LPtoDP, CreateCompatibleBitmap, GetDIBits, DeleteObject, CreateDIBSection, GetObjectA, GetPixel, StretchBlt, DeleteDC, CreateCompatibleDC, CreateDCA, CreateFontIndirectA, GetTextMetricsA, EnumFontFamiliesA, SetBkMode, SetTextAlign, IntersectClipRect, SelectClipRgn, ExtTextOutW, SetTextColor, GetClipRgn, CreateRectRgn, GetTextAlign, GetBkMode, GetTextColor, GetBkColor, CreateFontIndirectW, SetWorldTransform, SetGraphicsMode, GetWorldTransform, SetTextCharacterExtra, CreatePen, DPtoLP, GetTextExtentPoint32W, GetCurrentObject, GetTextExtentPoint32A, CreatePalette, StartDocA, EndDoc, StrokePath, ExtCreatePen, FillPath, GdiFlush, RestoreDC, SelectClipPath, StartPage, PolyBezierTo, EndPage, SetPolyFillMode, SaveDC, BeginPath, EndPath, MoveToEx, GetFontData, GetICMProfileA, EnumFontFamiliesExW, LineTo
> COMDLG32.dll: CommDlgExtendedError, GetSaveFileNameA, PrintDlgA, GetOpenFileNameA
> ADVAPI32.dll: RegDeleteValueA, RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegCreateKeyA, RegSetValueExA, RegCloseKey
> SHELL32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHAppBarMessage, SHBrowseForFolderA
> ole32.dll: CreateBindCtx, ReleaseStgMedium, OleUninitialize, CoInitialize, OleGetClipboard, OleFlushClipboard, OleInitialize, CoUninitialize, CoTaskMemAlloc, CoCreateInstance, CoTaskMemFree, OleIsCurrentClipboard, OleSetClipboard
> mscms.dll: OpenColorProfileA, CloseColorProfile, TranslateBitmapBits, DeleteColorTransform, CreateColorTransformW
> WS2_32.dll: WSACreateEvent, WSAEventSelect, WSAEnumNetworkEvents, -, -, -, WSAAddressToStringA, -, -, WSACloseEvent, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, WSASocketA, -, -, WSAIoctl, -, -, -

( 64 exports )
DllRegisterServer, DllUnregisterServer, FlashPlayer_10_0_42_34_FlashPlayer, Flash_DisableLocalSecurity, Flash_EnforceLocalSecurity, Java_ShockwaveFlash_CurrentFrame_stub, Java_ShockwaveFlash_FlashVersion_stub, Java_ShockwaveFlash_FrameLoaded_stub, Java_ShockwaveFlash_GetVariable_stub, Java_ShockwaveFlash_GotoFrame_stub, Java_ShockwaveFlash_IsPlaying_stub, Java_ShockwaveFlash_LoadMovie_stub, Java_ShockwaveFlash_Pan_stub, Java_ShockwaveFlash_PercentLoaded_stub, Java_ShockwaveFlash_Play_stub, Java_ShockwaveFlash_SetVariable_stub, Java_ShockwaveFlash_SetZoomRect_stub, Java_ShockwaveFlash_StopPlay_stub, Java_ShockwaveFlash_TCallFrame_stub, Java_ShockwaveFlash_TCallLabel_stub, Java_ShockwaveFlash_TCurrentFrame_stub, Java_ShockwaveFlash_TCurrentLabel_stub, Java_ShockwaveFlash_TGetProperty_stub, Java_ShockwaveFlash_TGotoFrame_stub, Java_ShockwaveFlash_TGotoLabel_stub, Java_ShockwaveFlash_TPlay_stub, Java_ShockwaveFlash_TSetProperty_stub, Java_ShockwaveFlash_TStopPlay_stub, Java_ShockwaveFlash_TotalFrames_stub, Java_ShockwaveFlash_Zoom_stub, NP_GetEntryPoints, NP_Initialize, NP_Shutdown, native_ShockwaveFlash_CurrentFrame, native_ShockwaveFlash_FlashVersion, native_ShockwaveFlash_FrameLoaded, native_ShockwaveFlash_GetVariable, native_ShockwaveFlash_GotoFrame, native_ShockwaveFlash_IsPlaying, native_ShockwaveFlash_LoadMovie, native_ShockwaveFlash_Pan, native_ShockwaveFlash_PercentLoaded, native_ShockwaveFlash_Play, native_ShockwaveFlash_SetVariable, native_ShockwaveFlash_SetZoomRect, native_ShockwaveFlash_StopPlay, native_ShockwaveFlash_TCallFrame, native_ShockwaveFlash_TCallLabel, native_ShockwaveFlash_TCurrentFrame, native_ShockwaveFlash_TCurrentLabel, native_ShockwaveFlash_TGetProperty, native_ShockwaveFlash_TGotoFrame, native_ShockwaveFlash_TGotoLabel, native_ShockwaveFlash_TPlay, native_ShockwaveFlash_TSetProperty, native_ShockwaveFlash_TStopPlay, native_ShockwaveFlash_TotalFrames, native_ShockwaveFlash_Zoom, register_ShockwaveFlash, unregister_ShockwaveFlash, unuse_ShockwaveFlash, unuse_netscape_plugin_Plugin, use_ShockwaveFlash, use_netscape_plugin_Plugin
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: Adobe Systems, Inc.
copyright....: Adobe_ Flash_ Player. Copyright (c) 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327_ Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
product......: Shockwave Flash
description..: Shockwave Flash 10.0 r42
original name: npswf32.dll
internal name: Adobe Flash Player 10.0
file version.: 10,0,42,34
comments.....: n/a
signers......: Adobe Systems Incorporated
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 4:40 AM 10/28/2009
verified.....: -


___________________________________________________________________________

Soubor NPSWF32.dll přijatý 2010.02.26 20:24:47 (UTC)
Současný stav: Dokončeno
Výsledek: 0/42 (0%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.02.26 -
AhnLab-V3 5.0.0.2 2010.02.26 -
AntiVir 8.2.1.176 2010.02.26 -
Antiy-AVL 2.0.3.7 2010.02.26 -
Authentium 5.2.0.5 2010.02.26 -
Avast 4.8.1351.0 2010.02.26 -
Avast5 5.0.332.0 2010.02.26 -
AVG 9.0.0.730 2010.02.26 -
BitDefender 7.2 2010.02.26 -
CAT-QuickHeal 10.00 2010.02.26 -
ClamAV 0.96.0.0-git 2010.02.26 -
Comodo 4075 2010.02.26 -
DrWeb 5.0.1.12222 2010.02.26 -
eSafe 7.0.17.0 2010.02.25 -
eTrust-Vet 35.2.7331 2010.02.26 -
F-Prot 4.5.1.85 2010.02.26 -
F-Secure 9.0.15370.0 2010.02.26 -
Fortinet 4.0.14.0 2010.02.26 -
GData 19 2010.02.26 -
Ikarus T3.1.1.80.0 2010.02.26 -
Jiangmin 13.0.900 2010.02.25 -
K7AntiVirus 7.10.984 2010.02.26 -
Kaspersky 7.0.0.125 2010.02.26 -
McAfee 5903 2010.02.25 -
McAfee+Artemis 5903 2010.02.25 -
McAfee-GW-Edition 6.8.5 2010.02.26 -
Microsoft 1.5502 2010.02.26 -
NOD32 4899 2010.02.26 -
Norman 6.04.08 2010.02.26 -
nProtect 2009.1.8.0 2010.02.26 -
Panda 10.0.2.2 2010.02.26 -
PCTools 7.0.3.5 2010.02.26 -
Prevx 3.0 2010.02.26 -
Rising 22.36.04.04 2010.02.26 -
Sophos 4.50.0 2010.02.26 -
Sunbelt 5700 2010.02.26 -
Symantec 20091.2.0.41 2010.02.26 -
TheHacker 6.5.1.6.212 2010.02.26 -
TrendMicro 9.120.0.1004 2010.02.26 -
VBA32 3.12.12.2 2010.02.26 -
ViRobot 2010.2.26.2204 2010.02.26 -
VirusBuster 5.0.27.0 2010.02.26 -
Rozšiřující informace
File size: 3885984 bytes
MD5...: 6291009ff02c67c1957194c798e0fdce
SHA1..: 798b845729986dceff783392f512e5c37000a4e5
SHA256: c012fbe8fd5aa7ba27ecb003c97c74357a4bbaf5d45838f312690e3b2e648fe8
ssdeep: 49152:VSsARioZHxcuJNK3rGGmNxrXbiKlNrdSbskDYgQAVwwuIycPmQcYyOmBuF
g8WSrR:VSBFHxcuormz/SbsXimQclIWmeMx
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x2e7bc0
timedatestamp.....: 0x4ae7bd0e (Wed Oct 28 03:39:58 2009)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2f2407 0x2f2600 6.80 6815cf0afa5ff4eddc6b1146f209dd2f
.rdata 0x2f4000 0x800fe 0x80200 6.51 5d6c34bf3242c86f86acaca9befec344
.data 0x375000 0xf88fc 0x1ac00 6.29 d43e30749d413e2adbb07ea172d5cd87
.rodata 0x46e000 0x5e0 0x600 5.43 66ff6171c9347427d2b9c712bd6823f5
.rsrc 0x46f000 0xe408 0xe600 4.34 abbf58ba694945d3a3c449fb3dc27f08
.reloc 0x47e000 0x17082 0x17200 6.07 5488f2f766759b3048a1c2cd73b41de5

( 16 imports )
> VERSION.dll: GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
> WINMM.dll: waveOutGetPosition, waveInOpen, waveInPrepareHeader, waveInAddBuffer, waveInStart, waveOutOpen, timeGetTime, waveInGetDevCapsA, waveOutGetDevCapsA, waveInGetNumDevs, waveInStop, waveInReset, waveInUnprepareHeader, waveInClose, waveOutUnprepareHeader, waveOutPrepareHeader, waveOutWrite, waveOutClose, waveOutReset, timeGetDevCaps, timeEndPeriod, timeBeginPeriod, timeKillEvent, timeSetEvent, waveOutGetNumDevs
> WININET.dll: InternetCloseHandle, HttpQueryInfoA, InternetOpenA, InternetConnectA, HttpOpenRequestA, HttpSendRequestA, InternetReadFile
> CRYPT32.dll: CryptGetMessageCertificates, CertCreateCertificateContext, CertFindCertificateInStore, CertVerifySubjectCertificateContext, CertFreeCertificateContext, CertCloseStore, CryptVerifyMessageSignature
> RPCRT4.dll: RpcStringFreeA, UuidToStringA
> OLEAUT32.dll: -, -, -, -, -, -, -
> urlmon.dll: CopyStgMedium
> KERNEL32.dll: OpenFile, LockResource, LoadResource, SizeofResource, FindResourceA, GetModuleHandleA, DeleteFileA, WriteFile, CreateFileA, GetTempFileNameA, GetCurrentDirectoryA, CreateDirectoryA, GetEnvironmentVariableA, GlobalFree, WideCharToMultiByte, QueryPerformanceCounter, QueryPerformanceFrequency, SetThreadPriority, WaitForSingleObject, SetWaitableTimer, CreateThread, CreateWaitableTimerA, GetProcessTimes, GetCurrentProcess, GlobalUnlock, GlobalLock, GetCurrentProcessId, GlobalSize, GlobalAlloc, FreeLibrary, GetSystemInfo, GetSystemDefaultLangID, MoveFileA, GetFileAttributesA, GetUserDefaultLangID, _lwrite, SetFilePointer, ReadFile, GetFileSize, FindResourceExA, FindResourceExW, GetFileAttributesW, SetUnhandledExceptionFilter, GetTempPathA, FindClose, FindNextFileA, FindFirstFileA, InterlockedIncrement, InterlockedDecrement, GetTimeZoneInformation, GetSystemTime, SystemTimeToFileTime, CreateMutexA, CreateFileW, GetSystemDirectoryA, ExpandEnvironmentStringsA, ExpandEnvironmentStringsW, GetFileAttributesExA, SetCurrentDirectoryA, RemoveDirectoryA, SetFilePointerEx, GetFileSizeEx, CreateProcessA, UnmapViewOfFile, ReleaseMutex, MapViewOfFile, CreateFileMappingA, TerminateThread, lstrcpyA, IsDBCSLeadByteEx, UnhandledExceptionFilter, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, TerminateProcess, _lclose, FreeResource, GetModuleFileNameA, lstrlenA, RaiseException, lstrlenW, FlushInstructionCache, LCMapStringW, LCMapStringA, GetTickCount, GetCurrentThreadId, GetLocaleInfoA, SetErrorMode, GetLastError, GetVersionExA, LoadLibraryA, GetProcAddress, GetCurrentThread, SetThreadAffinityMask, VirtualQuery, IsDBCSLeadByte, GetACP, GetCPInfo, MultiByteToWideChar, ResetEvent, CreateEventA, CloseHandle, WaitForMultipleObjects, SetEvent, InterlockedExchange, InterlockedCompareExchange, Sleep, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, IsDebuggerPresent, RtlUnwind, GetCommandLineA, GetModuleHandleW, ReleaseSemaphore, CreateSemaphoreA, VirtualProtect, VirtualFree, VirtualAlloc, HeapFree, GetProcessHeap, HeapAlloc, VirtualProtectEx, HeapReAlloc, HeapCreate, HeapDestroy, ExitProcess, GetOEMCP, IsValidCodePage, HeapSize, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, GetStringTypeA, GetStringTypeW, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers, ExitThread
> USER32.dll: DialogBoxIndirectParamW, DialogBoxIndirectParamA, EndDialog, GetDesktopWindow, LoadIconA, GetDlgItem, SetWindowTextA, GetMenuItemCount, InsertMenuItemW, GetSystemMetrics, GetClipboardFormatNameA, RegisterClipboardFormatA, GetCapture, SystemParametersInfoA, ScreenToClient, GetMenuItemID, DeleteMenu, InsertMenuItemA, GetMenuItemInfoA, TrackPopupMenu, ReleaseCapture, SetCapture, GetCursorPos, WindowFromPoint, GetParent, CreateWindowExA, GetWindowRect, SetWindowPos, ShowWindow, DestroyWindow, RedrawWindow, SendNotifyMessageA, SetWindowLongA, KillTimer, MapVirtualKeyA, GetClientRect, MessageBoxA, DefWindowProcA, RegisterClassA, PostMessageA, GetFocus, GetTopWindow, LoadStringA, LoadMenuA, GetSubMenu, DestroyMenu, InvalidateRect, LoadCursorA, SetCursor, GetKeyState, BeginPaint, EndPaint, EnableMenuItem, CheckMenuItem, EnumDisplaySettingsA, SetFocus, GetWindowInfo, CopyRect, SendInput, GetKeyboardLayout, FillRect, DialogBoxParamA, DialogBoxParamW, GetForegroundWindow, SendMessageA, WaitForInputIdle, GetDC, ReleaseDC, ClientToScreen, GetMonitorInfoA, OffsetRect, SetRect, MonitorFromWindow, GetDoubleClickTime, IsWindow, GetWindowThreadProcessId, GetWindowLongA, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, GetClipboardData, IsClipboardFormatAvailable, SetTimer, UnregisterClassA
> GDI32.dll: BitBlt, SelectObject, RealizePalette, SelectPalette, ExtTextOutA, SetBkColor, CreateSolidBrush, GetDeviceCaps, SetStretchBltMode, GetStretchBltMode, GetClipBox, GetSystemPaletteEntries, Rectangle, GetStockObject, StretchDIBits, LPtoDP, CreateCompatibleBitmap, GetDIBits, DeleteObject, CreateDIBSection, GetObjectA, GetPixel, StretchBlt, DeleteDC, CreateCompatibleDC, CreateDCA, CreateFontIndirectA, GetTextMetricsA, EnumFontFamiliesA, SetBkMode, SetTextAlign, IntersectClipRect, SelectClipRgn, ExtTextOutW, SetTextColor, GetClipRgn, CreateRectRgn, GetTextAlign, GetBkMode, GetTextColor, GetBkColor, CreateFontIndirectW, SetWorldTransform, SetGraphicsMode, GetWorldTransform, SetTextCharacterExtra, CreatePen, DPtoLP, GetTextExtentPoint32W, GetCurrentObject, GetTextExtentPoint32A, CreatePalette, StartDocA, EndDoc, StrokePath, ExtCreatePen, FillPath, GdiFlush, RestoreDC, SelectClipPath, StartPage, PolyBezierTo, EndPage, SetPolyFillMode, SaveDC, BeginPath, EndPath, MoveToEx, GetFontData, GetICMProfileA, EnumFontFamiliesExW, LineTo
> COMDLG32.dll: CommDlgExtendedError, GetSaveFileNameA, PrintDlgA, GetOpenFileNameA
> ADVAPI32.dll: RegDeleteValueA, RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegCreateKeyA, RegSetValueExA, RegCloseKey
> SHELL32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHAppBarMessage, SHBrowseForFolderA
> ole32.dll: CreateBindCtx, ReleaseStgMedium, OleUninitialize, CoInitialize, OleGetClipboard, OleFlushClipboard, OleInitialize, CoUninitialize, CoTaskMemAlloc, CoCreateInstance, CoTaskMemFree, OleIsCurrentClipboard, OleSetClipboard
> mscms.dll: OpenColorProfileA, CloseColorProfile, TranslateBitmapBits, DeleteColorTransform, CreateColorTransformW
> WS2_32.dll: WSACreateEvent, WSAEventSelect, WSAEnumNetworkEvents, -, -, -, WSAAddressToStringA, -, -, WSACloseEvent, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, WSASocketA, -, -, WSAIoctl, -, -, -

( 64 exports )
DllRegisterServer, DllUnregisterServer, FlashPlayer_10_0_42_34_FlashPlayer, Flash_DisableLocalSecurity, Flash_EnforceLocalSecurity, Java_ShockwaveFlash_CurrentFrame_stub, Java_ShockwaveFlash_FlashVersion_stub, Java_ShockwaveFlash_FrameLoaded_stub, Java_ShockwaveFlash_GetVariable_stub, Java_ShockwaveFlash_GotoFrame_stub, Java_ShockwaveFlash_IsPlaying_stub, Java_ShockwaveFlash_LoadMovie_stub, Java_ShockwaveFlash_Pan_stub, Java_ShockwaveFlash_PercentLoaded_stub, Java_ShockwaveFlash_Play_stub, Java_ShockwaveFlash_SetVariable_stub, Java_ShockwaveFlash_SetZoomRect_stub, Java_ShockwaveFlash_StopPlay_stub, Java_ShockwaveFlash_TCallFrame_stub, Java_ShockwaveFlash_TCallLabel_stub, Java_ShockwaveFlash_TCurrentFrame_stub, Java_ShockwaveFlash_TCurrentLabel_stub, Java_ShockwaveFlash_TGetProperty_stub, Java_ShockwaveFlash_TGotoFrame_stub, Java_ShockwaveFlash_TGotoLabel_stub, Java_ShockwaveFlash_TPlay_stub, Java_ShockwaveFlash_TSetProperty_stub, Java_ShockwaveFlash_TStopPlay_stub, Java_ShockwaveFlash_TotalFrames_stub, Java_ShockwaveFlash_Zoom_stub, NP_GetEntryPoints, NP_Initialize, NP_Shutdown, native_ShockwaveFlash_CurrentFrame, native_ShockwaveFlash_FlashVersion, native_ShockwaveFlash_FrameLoaded, native_ShockwaveFlash_GetVariable, native_ShockwaveFlash_GotoFrame, native_ShockwaveFlash_IsPlaying, native_ShockwaveFlash_LoadMovie, native_ShockwaveFlash_Pan, native_ShockwaveFlash_PercentLoaded, native_ShockwaveFlash_Play, native_ShockwaveFlash_SetVariable, native_ShockwaveFlash_SetZoomRect, native_ShockwaveFlash_StopPlay, native_ShockwaveFlash_TCallFrame, native_ShockwaveFlash_TCallLabel, native_ShockwaveFlash_TCurrentFrame, native_ShockwaveFlash_TCurrentLabel, native_ShockwaveFlash_TGetProperty, native_ShockwaveFlash_TGotoFrame, native_ShockwaveFlash_TGotoLabel, native_ShockwaveFlash_TPlay, native_ShockwaveFlash_TSetProperty, native_ShockwaveFlash_TStopPlay, native_ShockwaveFlash_TotalFrames, native_ShockwaveFlash_Zoom, register_ShockwaveFlash, unregister_ShockwaveFlash, unuse_ShockwaveFlash, unuse_netscape_plugin_Plugin, use_ShockwaveFlash, use_netscape_plugin_Plugin
RDS...: NSRL Reference Data Set
-
pdfid.: -
sigcheck:
publisher....: Adobe Systems, Inc.
copyright....: Adobe_ Flash_ Player. Copyright (c) 1996-2009 Adobe Systems Incorporated. All Rights Reserved. Protected by U.S. Patent 6,879,327_ Patents Pending in the United States and other countries. Adobe and Flash are either trademarks or registered trademarks in the United States and/or other countries.
product......: Shockwave Flash
description..: Shockwave Flash 10.0 r42
original name: npswf32.dll
internal name: Adobe Flash Player 10.0
file version.: 10,0,42,34
comments.....: n/a
signers......: Adobe Systems Incorporated
VeriSign Class 3 Code Signing 2004 CA
Class 3 Public Primary Certification Authority
signing date.: 4:40 AM 10/28/2009
verified.....: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#11 Příspěvek od BFU »

JEště jsem rovnou vyjel log z RSIT:

Logfile of random's system information tool 1.06 (written by random/random)
Run by Admin at 2010-02-26 21:29:53
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 12 GB (56%) free of 21 GB
Total RAM: 446 MB (23% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:39, on 26.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\PROGRA~1\MICROS~2\rapimgr.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Admin\Plocha\RSIT.exe
C:\Program Files\trend micro\Admin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Secunia PSI.lnk = C:\Program Files\Secunia\PSI\psi.exe
O4 - Startup: setup_9.0.0.722_26.02.2010_20-07.lnk = C:\Program Files\Virus Removal Tool\setup_9.0.0.722_26.02.2010_20-07\startup.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{64123F00-3CE1-4784-991E-E393F395E610}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{8C744B0A-FE5E-4D21-8773-6F9C3CA9181F}: NameServer = 156.154.70.25,156.154.71.25
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: wlcrdplauncher - C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

--
End of file - 7234 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-23 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-23 79648]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"=C:\WINDOWS\system32\WLTRAY []
"AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2004-10-08 88363]
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [2004-10-08 98394]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2004-10-08 688218]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2010-01-11 1800464]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2005-02-23 77824]
"SiSPower"=SiSPower.dll,ModeAgent []
"SiS Windows KeyHook"=C:\WINDOWS\system32\keyhook.exe [2005-03-04 32768]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\Wcescomm.exe [2006-11-13 1289000]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2010-01-11 3037696]
"MoeMonitor.exe"=C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe [2010-01-14 1315152]

C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe

C:\Documents and Settings\Admin\Nabídka Start\Programy\Po spuštění
Secunia PSI.lnk - C:\Program Files\Secunia\PSI\psi.exe
setup_9.0.0.722_26.02.2010_20-07.lnk - C:\Program Files\Virus Removal Tool\setup_9.0.0.722_26.02.2010_20-07\startup.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlcrdplauncher]
C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll [2010-01-14 21840]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Admin\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"

======List of files/folders created in the last 1 months======

2010-02-26 19:18:57 ----D---- C:\WINDOWS\LastGood
2010-02-26 19:18:53 ----D---- C:\Program Files\Virus Removal Tool
2010-02-26 16:12:18 ----AD---- C:\WINDOWS\VDLL.DLL
2010-02-26 16:12:18 ----AD---- C:\WINDOWS\system32\runouce.exe
2010-02-26 16:12:18 ----AD---- C:\WINDOWS\RUNDL132.EXE
2010-02-26 16:12:18 ----AD---- C:\WINDOWS\logo_1.exe
2010-02-26 16:06:28 ----A---- C:\WINDOWS\system32\msvcr80.dll
2010-02-26 16:06:26 ----A---- C:\WINDOWS\system32\msvcp80.dll
2010-02-26 16:06:20 ----A---- C:\WINDOWS\system32\eEmpty.exe
2010-02-26 16:04:41 ----A---- C:\WINDOWS\system32\T.COM
2010-02-26 16:04:40 ----A---- C:\WINDOWS\system32\TASKMGR.COM
2010-02-26 16:04:38 ----A---- C:\WINDOWS\R.COM
2010-02-26 16:04:37 ----A---- C:\WINDOWS\REGEDIT.COM
2010-02-26 16:04:35 ----D---- C:\Program Files\Common Files\MicroWorld
2010-02-26 16:04:26 ----D---- C:\Documents and Settings\All Users\Data aplikací\MicroWorld
2010-02-26 14:17:57 ----D---- C:\Program Files\trend micro
2010-02-26 14:17:37 ----D---- C:\rsit
2010-02-15 21:29:34 ----D---- C:\Program Files\The KMPlayer
2010-02-15 21:18:40 ----D---- C:\Documents and Settings\Admin\Data aplikací\Media Player Classic
2010-02-10 16:59:59 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 16:59:52 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 16:59:45 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 16:59:37 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 16:59:30 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 16:59:21 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 16:58:33 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 16:58:18 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 16:57:52 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-02-03 23:25:22 ----D---- C:\WINDOWS\system32\LogFiles
2010-02-01 19:39:02 ----D---- C:\Program Files\CCleaner
2010-02-01 19:37:44 ----D---- C:\Program Files\Microsoft Bootvis

======List of files/folders modified in the last 1 months======

2010-02-26 19:20:49 ----SHD---- C:\System Volume Information
2010-02-26 19:20:44 ----D---- C:\WINDOWS\Prefetch
2010-02-26 19:20:33 ----D---- C:\WINDOWS\Temp
2010-02-26 19:19:23 ----HD---- C:\WINDOWS\inf
2010-02-26 19:19:23 ----D---- C:\WINDOWS\system32\drivers
2010-02-26 19:19:05 ----D---- C:\WINDOWS
2010-02-26 19:18:53 ----RD---- C:\Program Files
2010-02-26 17:29:54 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-26 17:28:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-02-26 16:12:18 ----D---- C:\WINDOWS\system32
2010-02-26 16:04:35 ----D---- C:\Program Files\Common Files
2010-02-26 15:44:31 ----D---- C:\WINDOWS\Debug
2010-02-26 11:11:36 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-02-26 08:52:39 ----D---- C:\WINDOWS\system32\Restore
2010-02-17 00:11:30 ----D---- C:\Program Files\CDBurnerXP
2010-02-15 21:28:27 ----D---- C:\Documents and Settings\Admin\Data aplikací\Spyware Terminator
2010-02-15 21:28:26 ----D---- C:\Program Files\Spyware Terminator
2010-02-10 16:59:58 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-10 16:59:55 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-10 16:59:15 ----SHD---- C:\WINDOWS\Installer
2010-02-10 16:59:14 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-02-07 11:29:45 ----RSD---- C:\WINDOWS\Fonts
2010-02-07 11:29:34 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-02-07 11:28:53 ----D---- C:\Program Files\Microsoft Works
2010-02-07 11:25:23 ----N---- C:\WINDOWS\win.ini
2010-02-07 11:25:23 ----D---- C:\Program Files\Common Files\System
2010-01-29 16:01:17 ----SD---- C:\Documents and Settings\All Users\Data aplikací\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 41460181;41460181; C:\WINDOWS\system32\DRIVERS\41460181.sys [2009-09-25 128016]
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 AmdK8;Ovladač procesoru AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2004-08-11 39424]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2010-01-11 133064]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2010-01-11 25160]
R1 setup_9.0.0.722_26.02.2010_20-07drv;setup_9.0.0.722_26.02.2010_20-07drv; C:\WINDOWS\system32\DRIVERS\4146018.sys [2009-10-09 315408]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2005-02-25 13312]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2010-01-11 17801]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2004-10-08 1270540]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-02-24 2311680]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 BCM43XX;Broadcom 802.11 ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl5.sys [2004-12-22 369024]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2008-04-14 13952]
R3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
R3 RDPDISPM;RDPDISPM; C:\WINDOWS\system32\DRIVERS\rdpdispm.sys [2010-01-14 9040]
R3 RDPVDD;RDPVDD; C:\WINDOWS\system32\DRIVERS\rdpvmp.sys [2010-01-14 19408]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2005-03-02 240640]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\System32\DRIVERS\sisnic.sys [2004-08-03 32768]
R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2004-10-08 185824]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Ovladač Miniport otevřeného hostitelského řadiče Microsoft USB; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-14 17152]
S3 a7owcaj9;a7owcaj9; C:\WINDOWS\system32\drivers\a7owcaj9.sys []
S3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
S3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-10-24 12160]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-11-12 7168]
S3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;Ovladač filtru Obnovy systému; C:\WINDOWS\System32\DRIVERS\sr.sys [2008-04-14 73344]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2010-01-11 723632]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-01-23 153376]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-09-06 71096]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2010-01-11 488960]
R2 wlcrasvc;Live Mesh Remote Desktop; C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe [2010-01-14 44880]
R2 wltrysvc;Broadcom Wireless LAN Tray Service; C:\WINDOWS\System32\wltrysvc.exe [2004-12-22 65536]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;Stavová služba ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#12 Příspěvek od motji »

Nikde nic nevidím, počítač se chová uplně normálně?
Za dva dny ho pro jistotu opět zkontrolujte webcureitem nebo AVPtoolem a uvidíte. Pokud by se Vám něco nezdálo, hned sem vložte log ze Rsitu.

Můžete pro jistotu vložit i log z druhého počítače v síti. :)
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#13 Příspěvek od BFU »

motji píše:Nikde nic nevidím, počítač se chová uplně normálně?
Za dva dny ho pro jistotu opět zkontrolujte webcureitem nebo AVPtoolem a uvidíte. Pokud by se Vám něco nezdálo, hned sem vložte log ze Rsitu.

Můžete pro jistotu vložit i log z druhého počítače v síti. :)
Notebook je hodný a nezlobí, seč to byl před těmi falešnými poplachy taky :) dám mu pár dní a pak ho znova projedu.

No jestli by jste obětovala ještě chvilku svého času a zkoukla mi druhé PC, tak tady je (pouze při logu běžel Outlook, Opera a Avast, který už od rána skenuje... za to se omlouvám, snad nevadí):

Logfile of random's system information tool 1.06 (written by random/random)
Run by Administrator at 2010-02-26 21:59:16
Systém Microsoft Windows XP Professional Service Pack 3
System drive C: has 9 GB (39%) free of 22 GB
Total RAM: 1022 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:59, on 26.2.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Trust\GXT14 Mouse\POINTERGHOST.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Trust\GXT14 Mouse\GameMouseServiceApp.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe
C:\Program Files\Trust\GXT14 Mouse\StartAutorun.exe
C:\Program Files\Trust\GXT14 Mouse\RapooV1Process.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Documents and Settings\Administrator\Plocha\RSIT.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [trustGTX14] "C:\Program Files\Trust\GXT14 Mouse\POINTERGHOST.exe" showhide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [MoeMonitor.exe] "C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Vytvořit mobilní oblíbenou položku… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F446ACAC-1F69-4367-A9C6-8A6918B5A026}: NameServer = 156.154.70.25,156.154.71.25
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: wlcrdplauncher - C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Game Mouse Communication And Update Service V1 (KmGameMouseServiceV1) - UASSOFT.COM - C:\Program Files\Trust\GXT14 Mouse\GameMouseServiceApp.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe

--
End of file - 7195 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\WGASetup.job

======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2005-06-21 155648]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2005-06-21 126976]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2002-06-26 90112]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2009-11-27 1800464]
"trustGTX14"=C:\Program Files\Trust\GXT14 Mouse\POINTERGHOST.exe [2009-05-11 4832256]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SpywareTerminatorUpdate"=C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [2009-11-27 3055616]
"MoeMonitor.exe"=C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exe [2009-12-01 1315152]
"H/PC Connection Agent"=C:\Program Files\Microsoft ActiveSync\wcescomm.exe [2006-11-13 1289000]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2009-10-30 369200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Nabídka Start^Programy^Po spuštění^Secunia PSI.lnk]
C:\PROGRA~1\Secunia\PSI\psi.exe [2009-08-21 900816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" C:\WINDOWS\system32\guard32.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxsrvc.dll [2005-06-21 348160]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlcrdplauncher]
C:\Program Files\Live Mesh\Remote Desktop\wlcrdplauncher.dll [2009-12-01 21840]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"="C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe:*:Enabled:Crawler Spyware Terminator"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Opera\opera.exe"="C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe"="C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe:*:Enabled:Live Mesh Remote Desktop"
"C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe"="C:\Documents and Settings\Administrator\Local Settings\Data aplikací\Microsoft\Live Mesh\GacBase\Moe.exe:*:Enabled:Live Mesh"
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"="C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"="C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a39788c2-db74-11de-8b95-806d6172696f}]
shell\AutoRun\command - E:\setup.exe


======List of files/folders created in the last 1 months======

2010-02-26 21:50:57 ----D---- C:\Program Files\CCleaner
2010-02-26 21:42:13 ----D---- C:\Program Files\trend micro
2010-02-26 21:41:33 ----D---- C:\rsit
2010-02-24 22:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB979306$
2010-02-16 20:00:30 ----D---- C:\Program Files\uTorrent
2010-02-16 19:59:25 ----D---- C:\Documents and Settings\Administrator\Data aplikací\uTorrent
2010-02-10 19:44:12 ----HDC---- C:\WINDOWS\$NtUninstallKB978262$
2010-02-10 19:44:03 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-02-10 19:43:55 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-02-10 19:43:46 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-02-10 19:43:38 ----HDC---- C:\WINDOWS\$NtUninstallKB978251$
2010-02-10 19:43:27 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-02-10 19:42:42 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-02-10 19:42:31 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-02-10 19:42:12 ----HDC---- C:\WINDOWS\$NtUninstallKB977165$
2010-01-30 19:04:49 ----D---- C:\WINDOWS\Trust GXT14 Mouse
2010-01-30 19:04:49 ----D---- C:\Program Files\Trust

======List of files/folders modified in the last 1 months======

2010-02-26 21:56:33 ----D---- C:\WINDOWS\Debug
2010-02-26 21:56:32 ----D---- C:\WINDOWS
2010-02-26 21:55:36 ----D---- C:\WINDOWS\Temp
2010-02-26 21:51:33 ----D---- C:\WINDOWS\Prefetch
2010-02-26 21:50:57 ----RD---- C:\Program Files
2010-02-26 21:41:37 ----D---- C:\WINDOWS\system32\CatRoot2
2010-02-26 13:58:45 ----D---- C:\Documents and Settings\All Users\Data aplikací\Spyware Terminator
2010-02-26 08:57:33 ----D---- C:\Program Files\Spyware Terminator
2010-02-26 08:43:45 ----D---- C:\Documents and Settings\Administrator\Data aplikací\Spyware Terminator
2010-02-25 22:18:31 ----N---- C:\WINDOWS\SchedLgU.Txt
2010-02-25 20:59:35 ----D---- C:\WINDOWS\system32
2010-02-25 14:56:44 ----D---- C:\Documents and Settings\Administrator\Data aplikací\AIMP
2010-02-24 22:03:00 ----HD---- C:\WINDOWS\inf
2010-02-24 22:02:58 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-02-24 22:02:56 ----D---- C:\WINDOWS\ie8updates
2010-02-24 22:02:41 ----HD---- C:\WINDOWS\$hf_mig$
2010-02-11 18:26:22 ----RSD---- C:\WINDOWS\assembly
2010-02-11 18:25:06 ----SHD---- C:\WINDOWS\Installer
2010-02-11 18:24:58 ----D---- C:\WINDOWS\WinSxS
2010-02-11 18:24:58 ----D---- C:\Program Files\Paint.NET
2010-02-10 19:44:06 ----D---- C:\WINDOWS\system32\drivers
2010-02-10 19:43:20 ----D---- C:\Documents and Settings\All Users\Data aplikací\Microsoft Help
2010-01-28 15:17:25 ----D---- C:\Documents and Settings

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2009-11-27 133064]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2009-11-27 25160]
R1 intelppm;Řadič procesoru Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40192]
R1 kbdhid;Ovladač klávesnice standardu HID; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sp_rsdrv2;Spyware Terminator Driver 2; \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-08-22 98752]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
R3 E100B;Intel(R) PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 HidUsb;Ovladač třídy standardu HID; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-06-21 807998]
R3 KMWDFilterV1;KMWDFilterV1; \??\C:\WINDOWS\System32\Drivers\RPGMOUSEV1.sys []
R3 mouhid;Ovladač myši standardu HID; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-10-24 12160]
R3 RDPDISPM;RDPDISPM; C:\WINDOWS\system32\DRIVERS\rdpdispm.sys [2009-12-01 9040]
R3 RDPVDD;RDPVDD; C:\WINDOWS\system32\DRIVERS\rdpvmp.sys [2009-12-01 19408]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-10-11 518720]
R3 usbccgp;Obecný nadřazený ovladač Microsoft USB; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Ovladač miniportu rozšířeného radiče hostitele Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Rozbočovač umožnující USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Ovladač Microsoft univerzálního hostitelského řadiče USB od společnosti Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 aia3dqys;aia3dqys; C:\WINDOWS\system32\drivers\aia3dqys.sys []
S3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvw32.sys []
S3 PSI;PSI; C:\WINDOWS\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2009-09-28 7168]
S3 usb_rndisx;Adaptér USB RNDIS; C:\WINDOWS\system32\DRIVERS\usb8023x.sys [2008-04-14 12800]
S3 usbprint;Třída USB Printer; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
S3 usbscan;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 usbstor;Ovladač velkokapacitního paměťového zařízení USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\WINDOWS\system32\DRIVERS\wceusbsh.sys [2006-11-06 28672]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2009-11-27 723632]
R2 KmGameMouseServiceV1;Game Mouse Communication And Update Service V1; C:\Program Files\Trust\GXT14 Mouse\GameMouseServiceApp.exe [2009-05-11 354304]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2009-09-06 71096]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-07-15 45056]
R2 sp_rssrv;Spyware Terminator Realtime Shield Service; C:\Program Files\Spyware Terminator\sp_rsser.exe [2009-11-27 488960]
R2 wlcrasvc;Live Mesh Remote Desktop; C:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exe [2009-12-01 44880]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-30 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 idsvc;Služba Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 NetTcpPortSharing;Služba sdílení portů Net.Tcp; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------

Děkuji mnohokrát :)

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#14 Příspěvek od motji »

Log vypadá čistý, viruta nevidím.

:arrow: tyhle IP adresy znáte?
156.154.70.25,156.154.71.25

:arrow: Otestujte na www.virustotal.com

C:\WINDOWS\system32\Drivers\iqvw32.sys



-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

BFU
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 26 úno 2010 14:02

Re: PRosím o kontrolu logu po návštěve Win32: Virtob

#15 Příspěvek od BFU »

motji píše:Log vypadá čistý, viruta nevidím.

:arrow: tyhle IP adresy znáte?
156.154.70.25,156.154.71.25

:arrow: Otestujte na http://www.virustotal.com

C:\WINDOWS\system32\Drivers\iqvw32.sys



-Do okénka zkopírujte cestu k souboru , pokud napíše, že soubor byl už testován, dejte otestovat znovu.
-Sem vložte link s výsledky.
IP adresy - přiznám se, netuším. Podle whois.com je to asi cosi z ameriky, že. No napadají mě dvě věci - přes comodo používám jejich "secure dns" a v americe mám taky hosting na mail. Víc společného s touto zemí asi vědomě nemám, takže bohužel moc netuším.

Ad ovladač:

Soubor iqvw32.sys přijatý 2010.02.26 21:23:09 (UTC)
Současný stav: Dokončeno
Výsledek: 0/42 (0%)
Formátované
Vytisknout výsledky Antivirus Verze Poslední aktualizace Výsledek
a-squared 4.5.0.50 2010.02.26 -
AhnLab-V3 5.0.0.2 2010.02.26 -
AntiVir 8.2.1.176 2010.02.26 -
Antiy-AVL 2.0.3.7 2010.02.26 -
Authentium 5.2.0.5 2010.02.26 -
Avast 4.8.1351.0 2010.02.26 -
Avast5 5.0.332.0 2010.02.26 -
AVG 9.0.0.730 2010.02.26 -
BitDefender 7.2 2010.02.26 -
CAT-QuickHeal 10.00 2010.02.26 -
ClamAV 0.96.0.0-git 2010.02.26 -
Comodo 4075 2010.02.26 -
DrWeb 5.0.1.12222 2010.02.26 -
eSafe 7.0.17.0 2010.02.25 -
eTrust-Vet 35.2.7331 2010.02.26 -
F-Prot 4.5.1.85 2010.02.26 -
F-Secure 9.0.15370.0 2010.02.26 -
Fortinet 4.0.14.0 2010.02.26 -
GData 19 2010.02.26 -
Ikarus T3.1.1.80.0 2010.02.26 -
Jiangmin 13.0.900 2010.02.25 -
K7AntiVirus 7.10.984 2010.02.26 -
Kaspersky 7.0.0.125 2010.02.26 -
McAfee 5904 2010.02.26 -
McAfee+Artemis 5904 2010.02.26 -
McAfee-GW-Edition 6.8.5 2010.02.26 -
Microsoft 1.5502 2010.02.26 -
NOD32 4899 2010.02.26 -
Norman 6.04.08 2010.02.26 -
nProtect 2009.1.8.0 2010.02.26 -
Panda 10.0.2.2 2010.02.26 -
PCTools 7.0.3.5 2010.02.26 -
Prevx 3.0 2010.02.26 -
Rising 22.36.04.04 2010.02.26 -
Sophos 4.50.0 2010.02.26 -
Sunbelt 5700 2010.02.26 -
Symantec 20091.2.0.41 2010.02.26 -
TheHacker 6.5.1.6.212 2010.02.26 -
TrendMicro 9.120.0.1004 2010.02.26 -
VBA32 3.12.12.2 2010.02.26 -
ViRobot 2010.2.26.2204 2010.02.26 -
VirusBuster 5.0.27.0 2010.02.26 -
Rozšiřující informace
File size: 30880 bytes
MD5...: ca941360c4d987b35f270e1b84591046
SHA1..: 8092980b6c1815738bd48c6a78ad7227b5ebf92e
SHA256: 55b136d9bfb13796c5f8e63941172cdaa720ace4ffc80787abcbab5b6fcbbf07
ssdeep: 384:On29Sid622jc5Z6aaAf4uKm2WOY167R7oHNq/unJOopYJLu1M6j+4bC6Z:Iw
VHf4udn2CJeLWMm9bCG
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x3a8169
timedatestamp.....: 0x4ac3fe2b (Thu Oct 01 00:56:11 2009)
machinetype.......: 0x14c (I386)

( 6 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3288 0x3400 6.50 24997c6574db4ae6e97fb2136c5fc58a
.rdata 0x5000 0x3ff 0x400 5.15 92ff3b495b9d26308dfa4044518839c2
.data 0x6000 0x3a1e60 0x200 1.25 5efdf7cb8ab4c13c2198cf190ce6ca8e
INIT 0x3a8000 0x746 0x800 5.74 845ad271329ca317aa9328df6aae7548
.rsrc 0x3a9000 0x3f8 0x400 3.40 9532cdfdc5c04bdb29b03f47553b22b7
.reloc 0x3aa000 0x13c8 0x1400 1.50 f334f52618d2d06dbae7b17a46d3040f

( 2 imports )
> ntoskrnl.exe: WRITE_REGISTER_USHORT, WRITE_REGISTER_ULONG, ExAllocatePoolWithTag, ExFreePoolWithTag, MmGetPhysicalAddress, DbgPrint, sprintf, vsprintf, IoFreeMdl, MmMapLockedPages, MmBuildMdlForNonPagedPool, IoAllocateMdl, MmUnmapIoSpace, MmUnmapLockedPages, _aulldiv, MmAllocateContiguousMemory, _aullrem, MmFreeContiguousMemory, WRITE_REGISTER_UCHAR, ObfDereferenceObject, KeWaitForSingleObject, IofCallDriver, IoBuildSynchronousFsdRequest, KeInitializeEvent, ZwClose, RtlFreeAnsiString, strstr, RtlUnicodeStringToAnsiString, ZwEnumerateValueKey, ZwOpenKey, wcsncpy, IoGetDeviceObjectPointer, IoGetDeviceInterfaces, ObReferenceObjectByPointer, KeTickCount, KeBugCheckEx, READ_REGISTER_ULONG, READ_REGISTER_USHORT, READ_REGISTER_UCHAR, IofCompleteRequest, IoCreateDevice, IoCreateSymbolicLink, RtlInitUnicodeString, IoDeleteSymbolicLink, MmMapIoSpace, IoDeleteDevice
> HAL.dll: KeQueryPerformanceCounter, KeStallExecutionProcessor, WRITE_PORT_ULONG, WRITE_PORT_USHORT, WRITE_PORT_UCHAR, READ_PORT_ULONG, READ_PORT_USHORT, READ_PORT_UCHAR, KeGetCurrentIrql

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
packers (Kaspersky): PE_Patch
sigcheck:
publisher....: Intel Corporation
copyright....: Copyright (C) 2002-2006 Intel Corporation All Rights Reserved.
product......: Intel(R) iQVW32.SYS
description..: Intel(R) Network Adapter Diagnostic Driver
original name: iQVW32.SYS
internal name: iQVW32.SYS
file version.: 1.03.0.4 built by: WinDDK
comments.....: n/a
signers......: Intel Corporation
VeriSign Class 3 Code Signing 2009-2 CA
Class 3 Public Primary Certification Authority
signing date.: 1:56 AM 10/1/2009
verified.....: -

Odpovědět