Re: Prosím o kontrolu logu - zavirovaný NTB
Napsal: 18 lis 2010 00:28
Ke konci UsbFixu jsem dostal hlášku
Probíhá vypnutí systému. Uložte všechny rozpracované soubory a odhlaste se. Neuložené změny budou ztraceny. Vypnutí vyvolal NT AUTHORITY\SYSTEM
Čas do vypnutí 00:00:30
Zpráva
Systémový proces C:\WINDOWS\system32\lsass.exe neočekávaně skončil se stavovým kódem 0. Systém bude nyní ukončem a restartován.
Jinak tady je z něj log
############################## | UsbFix 7.014 | [Deletion]
User: Terulee (Administrator) # UZIVATEL-7DCD8A [ ]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 23:58:07 | 17/11/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Pentium(R) M processor 1.70GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: ESET NOD32 Antivirus 4.2 4.2 [Enabled | (!) Outdated]
RAM -> 1023 Mb
C:\ (%systemdrive%) -> Fixed drive # 56 Gb (20 Mb free - 35%) [] # NTFS
D:\ -> CD-ROM
F:\ -> Removable drive # 2 Gb (2 Mb free - 100%) [] # FAT32
################## | Files # Infected Folders |
Deleted ! C:\Documents and Settings\Terulee\qihtsu.exe
Deleted ! C:\Documents and Settings\Terulee\wuaucldt.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\034.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\183.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\282.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\308.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\378.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\435.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\442.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\473.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\523.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\552.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\577.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\634.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\656.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\673.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\684.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\784.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\882.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\883.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\905.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\925.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\955.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\1224515.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\1251803.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\2237.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\319788.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\42945.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\472256.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\5D6843~1.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\61032.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\70685.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\71952.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\8323.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\8929.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\9831.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\AutoRun.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\lsass.exe
Deleted ! C:\WINDOWS\regedit.com
Deleted ! C:\WINDOWS\rundl132.exe
Deleted ! C:\log.txt
Deleted ! F:\log.txt
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[17/11/2010 - 14:13:32 | A | 0] C:\$$TEMP$$.~~~
[27/11/2009 - 14:07:34 | D ] C:\84180e2e932956edb553445f2b
[21/11/2009 - 14:27:33 | N | 0] C:\AUTOEXEC.BAT
[26/02/2010 - 19:25:40 | SH | 211] C:\boot.ini
[14/04/2008 - 13:00:00 | RASH | 4952] C:\Bootfont.bin
[17/11/2010 - 15:26:42 | SD ] C:\ComboFix
[21/11/2009 - 14:27:33 | A | 0] C:\CONFIG.SYS
[24/12/2009 - 20:05:29 | D ] C:\Documents and Settings
[23/11/2009 - 09:43:19 | D ] C:\DRIVERS
[21/11/2009 - 14:27:33 | RASH | 0] C:\IO.SYS
[01/04/2010 - 08:06:53 | A | 103] C:\mbam-error.txt
[21/11/2009 - 14:27:33 | RASH | 0] C:\MSDOS.SYS
[27/11/2009 - 12:44:24 | RD ] C:\MSOCache
[14/04/2008 - 13:00:00 | RASH | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | RASH | 250576] C:\ntldr
[17/11/2010 - 23:56:40 | ASH | 1610612736] C:\pagefile.sys
[17/11/2010 - 14:19:13 | RD ] C:\Program Files
[17/11/2010 - 14:43:01 | D ] C:\Qoobox
[18/11/2010 - 00:05:26 | SHD ] C:\RECYCLER
[17/11/2010 - 15:22:28 | A | 395] C:\rkill.log
[26/02/2010 - 19:29:49 | D ] C:\rsit
[27/02/2010 - 20:52:58 | SHD ] C:\System Volume Information
[18/11/2010 - 00:05:26 | D ] C:\UsbFix
[18/11/2010 - 00:05:30 | A | 3239] C:\UsbFix.txt
[18/11/2010 - 00:04:53 | D ] C:\WINDOWS
[16/11/2010 - 20:57:35 | A | 193024] C:\winn27.exe
[16/11/2010 - 05:58:16 | A | 91136] C:\winnt7.exe
[17/11/2010 - 23:54:22 | A | 1224471] F:\UsbFix.exe
[17/11/2010 - 23:56:40 | A | 1306] F:\BOOTEX.LOG
[17/11/2010 - 15:38:48 | A | 6153352] F:\mbam-setup-1.46.exe
[03/03/2010 - 11:20:02 | SHD ] F:\FOUND.000
################## | Vaccin |
A log ze SystemLook
SystemLook 04.09.10 by jpshortstuff
Log created at 00:16 on 18/11/2010 by Terulee
Administrator - Elevation successful
========== filefind ==========
Searching for "cdrom.sys"
C:\WINDOWS\system32\dllcache\cdrom.sys --a--c- 98240 bytes [04:59 16/11/2010] [09:37 17/11/2010] 512D1E14138FDE84E86665CFCF911A96
C:\WINDOWS\system32\drivers\cdrom.sys --a---- 98240 bytes [12:00 14/04/2008] [09:37 17/11/2010] 512D1E14138FDE84E86665CFCF911A96
-= EOF =-
Probíhá vypnutí systému. Uložte všechny rozpracované soubory a odhlaste se. Neuložené změny budou ztraceny. Vypnutí vyvolal NT AUTHORITY\SYSTEM
Čas do vypnutí 00:00:30
Zpráva
Systémový proces C:\WINDOWS\system32\lsass.exe neočekávaně skončil se stavovým kódem 0. Systém bude nyní ukončem a restartován.
Jinak tady je z něj log
############################## | UsbFix 7.014 | [Deletion]
User: Terulee (Administrator) # UZIVATEL-7DCD8A [ ]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 23:58:07 | 17/11/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Pentium(R) M processor 1.70GHz
Systém Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: ESET NOD32 Antivirus 4.2 4.2 [Enabled | (!) Outdated]
RAM -> 1023 Mb
C:\ (%systemdrive%) -> Fixed drive # 56 Gb (20 Mb free - 35%) [] # NTFS
D:\ -> CD-ROM
F:\ -> Removable drive # 2 Gb (2 Mb free - 100%) [] # FAT32
################## | Files # Infected Folders |
Deleted ! C:\Documents and Settings\Terulee\qihtsu.exe
Deleted ! C:\Documents and Settings\Terulee\wuaucldt.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\034.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\183.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\282.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\308.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\378.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\435.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\442.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\473.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\523.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\552.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\577.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\634.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\656.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\673.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\684.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\784.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\882.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\883.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\905.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\925.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\955.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\1224515.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\1251803.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\2237.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\319788.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\42945.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\472256.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\5D6843~1.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\61032.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\70685.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\71952.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\8323.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\8929.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\9831.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\AutoRun.exe
Deleted ! C:\DOCUME~1\Terulee\LOCALS~1\Temp\lsass.exe
Deleted ! C:\WINDOWS\regedit.com
Deleted ! C:\WINDOWS\rundl132.exe
Deleted ! C:\log.txt
Deleted ! F:\log.txt
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[17/11/2010 - 14:13:32 | A | 0] C:\$$TEMP$$.~~~
[27/11/2009 - 14:07:34 | D ] C:\84180e2e932956edb553445f2b
[21/11/2009 - 14:27:33 | N | 0] C:\AUTOEXEC.BAT
[26/02/2010 - 19:25:40 | SH | 211] C:\boot.ini
[14/04/2008 - 13:00:00 | RASH | 4952] C:\Bootfont.bin
[17/11/2010 - 15:26:42 | SD ] C:\ComboFix
[21/11/2009 - 14:27:33 | A | 0] C:\CONFIG.SYS
[24/12/2009 - 20:05:29 | D ] C:\Documents and Settings
[23/11/2009 - 09:43:19 | D ] C:\DRIVERS
[21/11/2009 - 14:27:33 | RASH | 0] C:\IO.SYS
[01/04/2010 - 08:06:53 | A | 103] C:\mbam-error.txt
[21/11/2009 - 14:27:33 | RASH | 0] C:\MSDOS.SYS
[27/11/2009 - 12:44:24 | RD ] C:\MSOCache
[14/04/2008 - 13:00:00 | RASH | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | RASH | 250576] C:\ntldr
[17/11/2010 - 23:56:40 | ASH | 1610612736] C:\pagefile.sys
[17/11/2010 - 14:19:13 | RD ] C:\Program Files
[17/11/2010 - 14:43:01 | D ] C:\Qoobox
[18/11/2010 - 00:05:26 | SHD ] C:\RECYCLER
[17/11/2010 - 15:22:28 | A | 395] C:\rkill.log
[26/02/2010 - 19:29:49 | D ] C:\rsit
[27/02/2010 - 20:52:58 | SHD ] C:\System Volume Information
[18/11/2010 - 00:05:26 | D ] C:\UsbFix
[18/11/2010 - 00:05:30 | A | 3239] C:\UsbFix.txt
[18/11/2010 - 00:04:53 | D ] C:\WINDOWS
[16/11/2010 - 20:57:35 | A | 193024] C:\winn27.exe
[16/11/2010 - 05:58:16 | A | 91136] C:\winnt7.exe
[17/11/2010 - 23:54:22 | A | 1224471] F:\UsbFix.exe
[17/11/2010 - 23:56:40 | A | 1306] F:\BOOTEX.LOG
[17/11/2010 - 15:38:48 | A | 6153352] F:\mbam-setup-1.46.exe
[03/03/2010 - 11:20:02 | SHD ] F:\FOUND.000
################## | Vaccin |
A log ze SystemLook
SystemLook 04.09.10 by jpshortstuff
Log created at 00:16 on 18/11/2010 by Terulee
Administrator - Elevation successful
========== filefind ==========
Searching for "cdrom.sys"
C:\WINDOWS\system32\dllcache\cdrom.sys --a--c- 98240 bytes [04:59 16/11/2010] [09:37 17/11/2010] 512D1E14138FDE84E86665CFCF911A96
C:\WINDOWS\system32\drivers\cdrom.sys --a---- 98240 bytes [12:00 14/04/2008] [09:37 17/11/2010] 512D1E14138FDE84E86665CFCF911A96
-= EOF =-