Rootkit
Napsal: 20 kvě 2012 10:47
Hajzlík usídlil se mi v pc nyní sou procesy už ok zde je log z combofixu
ComboFix 12-05-20.01 - Karel Finger 20.05.2012 11:32:26.1.2 - x86
Systém Microsoft Windows XP Professional 5.1.2600.3.1250.420.1029.18.2046.1627 [GMT 2:00]
Spuštěný z: c:\root\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
VAROVÁNÍ - NA TOMTO POČÍTAČI NENÍ NAINSTALOVÁNA KONZOLA PRO ZOTAVENÍ !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Karel Finger\WINDOWS
C:\root
c:\root\ComboFix.exe
c:\windows\$NtUninstallKB53453$
c:\windows\$NtUninstallKB53453$\1335533399\@
c:\windows\$NtUninstallKB53453$\1335533399\cfg.ini
c:\windows\$NtUninstallKB53453$\1335533399\Desktop.ini
c:\windows\$NtUninstallKB53453$\1335533399\L\pkeascfl
c:\windows\$NtUninstallKB53453$\1335533399\U\00000001.@
c:\windows\$NtUninstallKB53453$\1335533399\U\00000002.@
c:\windows\$NtUninstallKB53453$\1335533399\U\00000004.@
c:\windows\$NtUninstallKB53453$\1335533399\U\80000000.@
c:\windows\$NtUninstallKB53453$\1335533399\U\80000004.@
c:\windows\$NtUninstallKB53453$\1335533399\U\80000032.@
c:\windows\$NtUninstallKB53453$\1335533399\version
c:\windows\$NtUninstallKB53453$\49092765
c:\windows\system32\dds_trash_log.cmd
c:\windows\system32\roboot.exe
c:\windows\system32\SET54.tmp
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-04-20 do 2012-05-20 )))))))))))))))))))))))))))))))
.
.
2012-05-19 21:26 . 2012-05-19 21:26 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Raxco
2012-05-19 21:26 . 2012-05-19 21:57 -------- d-----w- c:\program files\Raxco
2012-05-19 20:12 . 2012-05-19 20:12 205072 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2012-05-18 12:55 . 2012-05-18 12:55 -------- d-----w- c:\windows\system32\drivers\NIS\1307010.005
2012-05-09 20:11 . 2012-05-19 20:23 -------- d-----w- C:\Downloads
2012-05-09 02:04 . 2012-05-09 02:25 -------- d--h--w- c:\windows\$hf_mig$
2012-05-07 08:57 . 2012-05-07 08:57 -------- d-----w- c:\documents and settings\Karel Finger\Local Settings\Data aplikací\SkinSoft
2012-05-06 08:26 . 2012-05-06 08:26 -------- d-----w- c:\program files\Free OCR to Word
2012-04-28 19:13 . 2012-04-28 19:13 -------- d-----w- c:\documents and settings\All Users\Data aplikací\Martau
2012-04-28 19:13 . 2012-04-28 19:14 -------- d-----w- c:\program files\Total Uninstall 6
2012-04-27 18:34 . 2012-04-27 18:34 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-24 20:10 . 2012-04-24 20:10 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-24 20:10 . 2012-04-24 20:10 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-24 20:10 . 2012-04-24 20:10 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
2012-04-24 12:59 . 2012-04-24 12:59 -------- d-----w- c:\windows\system32\drivers\NIS\1307000.009
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-19 19:45 . 2008-04-14 06:51 6656 ----a-w- c:\windows\system32\lpcio.dll
2012-05-04 20:13 . 2012-04-03 01:34 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-04 20:13 . 2011-05-15 19:15 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-27 18:34 . 2011-12-13 21:47 772552 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-04-15 15:48 . 2012-04-15 15:48 53248 ----a-r- c:\documents and settings\Karel Finger\Data aplikací\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2012-04-14 15:12 . 2012-04-14 15:09 119296 ----a-w- c:\windows\system32\zlib.dll
2012-04-11 13:55 . 2008-04-14 08:06 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-11 13:55 . 2008-04-14 05:45 1862272 ----a-w- c:\windows\system32\win32k.sys
2012-04-11 13:55 . 2008-04-14 06:06 2150400 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-26 19:48 . 2011-01-21 15:45 60872 ----a-w- c:\windows\system32\S32EVNT1.DLL
2012-03-26 19:48 . 2011-01-21 15:45 141944 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2012-03-24 16:47 . 2011-02-26 16:27 82320 ----a-w- c:\windows\system32\drivers\ISODrive.sys
2012-03-17 08:45 . 2006-05-02 09:12 293888 ----a-w- c:\windows\system32\drivers\ADIHdAud.sys
2012-03-17 08:45 . 2006-04-26 22:42 93952 ----a-w- c:\windows\system32\drivers\aeaudio.sys
2012-03-17 08:45 . 2006-03-17 10:18 392960 ----a-w- c:\windows\system32\drivers\senfilt.sys
2012-03-17 08:45 . 2006-02-06 07:54 28160 ----a-w- c:\windows\system32\PostProc.dll
2012-03-17 08:45 . 2003-08-19 11:36 65536 ----a-w- c:\windows\system32\a3d.dll
2012-03-17 08:45 . 2001-09-19 05:47 765952 ----a-w- c:\windows\system\crlds3d.dll
2012-03-01 10:59 . 2008-04-14 06:52 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-03-01 10:59 . 2008-04-14 06:52 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 10:59 . 2008-04-14 06:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-02-29 14:10 . 2008-04-14 06:52 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-14 06:51 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-14 05:50 385024 ----a-w- c:\windows\system32\html.iec
2012-02-23 13:25 . 2012-03-17 07:37 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-04-24 20:10 . 2012-02-26 09:25 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2009-12-14 4377960]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2009-12-14 962272]
"Acronis Služba Plánovač2"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-12-14 377600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2012-03-17 868352]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1387288]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-01-21 92168]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
c:\documents and settings\All Users\Nabídka Start\Programy\Po spuštění\
USB Sharing.lnk - c:\program files\USB Sharing\usbshare.exe [2011-10-21 139264]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2010-10-28 10:13 64592 ----a-w- c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0auto_reactivate c:\bootwiz\asrm.bin
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\utorrent-portable\\utorrent.exe"=
"c:\\Program Files\\EfficientPIM\\EfficientPIM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
R0 mv614x;mv614x;c:\windows\system32\drivers\mv614x.sys [16.2.2006 10:21 35200]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1307000.009\symds.sys [24.4.2012 14:59 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1307000.009\symefa.sys [24.4.2012 14:59 905336]
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\drivers\tdrpm251.sys [21.1.2011 17:12 902432]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [23.12.2011 12:04 10240]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120507.001\BHDrvx86.sys [8.5.2012 22:00 821880]
R1 ccSet_NIS;Norton Internet Security Settings Manager;c:\windows\system32\drivers\NIS\1307000.009\ccsetx86.sys [24.4.2012 14:59 132744]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1307000.009\ironx86.sys [24.4.2012 14:59 149624]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [21.1.2011 18:09 12184]
R2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\19.7.0.9\ccsvchst.exe [24.4.2012 14:59 138232]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [15.2.2012 14:30 158856]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [17.3.2012 8:35 106104]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Data aplikací\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120518.001\IDSXpx86.sys [19.5.2012 13:08 356792]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18.3.2010 13:16 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [3.4.2012 3:34 257696]
S3 ALSysIO;ALSysIO;\??\c:\docume~1\KARELF~1\LOCALS~1\Temp\ALSysIO.sys --> c:\docume~1\KARELF~1\LOCALS~1\Temp\ALSysIO.sys [?]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys --> c:\windows\system32\drivers\LGBusEnum.sys [?]
S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys --> c:\windows\system32\drivers\LGVirHid.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [24.4.2012 22:10 129976]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18.3.2010 13:16 753504]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
sskbfd
tosrfec
bdfsdrv
upsmonservice
.
Obsah adresáře 'Naplánované úlohy'
.
2012-05-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 20:13]
.
.
------- Doplňkový sken -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = local
IE: &Download with DAM - c:\program files\Tensons\Download Accelerator Manager\\addUrl.htm
IE: Download &All with DAM - c:\program files\Tensons\Download Accelerator Manager\\addAllUrls.htm
IE: Download with &Media Finder
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Run DAM Media&Grabber - c:\program files\Tensons\Download Accelerator Manager\\runMg.htm
IE: {{DA42DC2A-5456-482B-BB8A-593272304F67}
FF - ProfilePath - c:\documents and settings\Karel Finger\Data aplikací\Mozilla\Firefox\Profiles\h9v4fxn9.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2832595&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - InnoGames International Customized Web Search
FF - prefs.js: browser.startup.homepage - about:blank
FF - user.js: nglayout.initialpaint.delay - 100
FF - user.js: content.notify.ontimer - true
FF - user.js: content.notify.interval - 100000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 4
FF - user.js: network.http.max-persistent-connections-per-server - 2
FF - user.js: extensions.BabylonToolbar_i.id - 4c4141b90000000000000018f36508fa
FF - user.js: extensions.BabylonToolbar_i.hardId - 4c4141b90000000000000018f36508fa
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15357
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1723:28
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101067
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-20 11:37
Windows 5.1.2600 Service Pack 3 NTFS
.
skenování skrytých procesů ...
.
skenování skrytých položek 'Po spuštění' ...
.
skenování skrytých souborů ...
.
sken byl úspešně dokončen
skryté soubory: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\19.7.0.9\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\19.7.0.9\diMaster.dll\" /prefetch:1"
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-1482476501-362288127-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{370F93AB-C1C9-DDD1-797E-0FE7CC76263F}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"hamnbdbpfnpgljll"=hex:61,61,00,00
"hamnbdbppnjhlhjj"=hex:61,61,00,00
"iaioefihmgffjfdfkk"=hex:6a,61,70,62,67,67,6e,69,6b,63,6c,64,65,68,63,67,64,66,
6d,65,00,26
"hacollfkmfjkhfbg"=hex:6a,61,70,62,68,67,6b,6a,6a,67,6c,64,6a,6c,6a,69,69,6d,
62,6f,00,26
.
[HKEY_USERS\S-1-5-21-1482476501-362288127-682003330-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7b,da,2a,20,d1,e2,2a,d9,c2,22,81,62,1c,3d,49,71,a0,46,cb,34,ef,49,b3,
62,04,3f,5b,1c,01,45,db,28,35,d9,2f,f6,92,5f,b6,03,2f,7a,0d,06,bb,2d,f6,c8,\
"??"=hex:12,44,69,7d,ab,0e,8e,c6,e6,5f,d7,78,64,63,90,43
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{370F93AB-C1C9-DDD1-797E-0FE7CC76263F}\InProcServer32*]
"iaombdgfdfinkcmhfb"=hex:61,61,00,00
"iaombdgfdfooeffohg"=hex:61,61,00,00
"jaomnflihknlndiknpem"=hex:6a,61,70,62,67,67,6e,69,6b,63,6c,64,65,68,63,67,64,
66,6d,65,00,26
"iaomdgnibppdlbpnbj"=hex:6a,61,70,62,68,67,6b,6a,6a,67,6c,64,6a,6c,6a,69,69,6d,
62,6f,00,26
.
--------------------- Knihovny navázané na běžící procesy ---------------------
.
- - - - - - - > 'winlogon.exe'(1368)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
.
- - - - - - - > 'explorer.exe'(3472)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Raxco\PerfectDisk10\PDAgent.exe
c:\windows\system32\RunDLL32.exe
c:\program files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
.
**************************************************************************
.
Celkový čas: 2012-05-20 11:39:44 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-05-20 09:39
.
Před spuštěním: Volných bajtů: 33 760 038 912
Po spuštění: Volných bajtů: 33 804 054 528
.
- - End Of File - - 07F8BC2909B2475856365ACB0F500033