[ Príspevkov: 12 ] 
AutorSpráva
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
NapísalOffline : 21.06.2008 20:55 | Win32:Rootkit-gen co s tym?

Takže pekne poporiadku:

Avast mi našiel toto:
Možná hrozba
Názov súboru: C:\WINDOWS\system32\hxaqsper.sys
Typ: skryté služby

nedal sa odstrániť, iba ignorovať

potom mi vypísalo:
avast! zistil vírus v operačnej pamäti. Pretože je veľmi nebezpečné s počítačom pracovať... odporúčame reštartovať a skontrolovať ešte keď vírus nie je aktívny v pamäti.

spravil som, avast čosi našiel, odstranil, nabehol widows a zas to tam bolo

cely proces znova, akurát už nič nenašiel, no keď nabehol windows, tak:

Našiel sa rootkit!
V systéme sa našiel podozrivý skrytý ovjekt(rootkit). Môže to byť príznak nákazy škodlivým kódom. Odporúčame tento objekt okamžite odstrániť.

Názov súboru: C:\WINDOWS\system32\hxaqsper.sys
Typ: skryté služby
Názov vzorky: Win32:Rootkit-gen[Rtk]

dal som odstrániť, tvárilo sa akože ho odstránilo

po reštarte znova tá istá hláška

čo sa s tým dá robiť?
tu je log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:50:38, on 21. 6. 2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\system32\PMSveH.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PMHandler.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Notebook Hardware Control\nhc.exe
C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATnotes\ATnotes.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.zoznam.sk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.lenovo.com/us/en/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Odkazy
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [PMHandler] C:\WINDOWS\system32\PMHandler.exe
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [TPWAUDAP] C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Zástupce stránky vlastností sběrnice High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TVT Scheduler Proxy] C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ATnotes.exe] C:\Program Files\ATnotes\ATnotes.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Zdroje informácií - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O14 - IERESET.INF: START_PAGE_URL=http://www.lenovo.com/us/en/
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !saswinlogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fn+F5 Service (FNF5SVC) - Lenovo. - C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: PMSveH - Lenovo - C:\WINDOWS\system32\PMSveH.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: System Update (SUService) - Lenovo Group Limited - c:\program files\lenovo\system update\suservice.exe
O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
O23 - Service: TVT Scheduler - Lenovo Group Limited - C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe

--
End of file - 10564 bytes


Offline

Užívateľ
Užívateľ
Win32:Rootkit-gen co s tym?

Registrovaný: 02.09.07
Prihlásený: 20.11.17
Príspevky: 6419
Témy: 298 | 298
Bydlisko: Žilina
Vek: 24
NapísalOffline : 21.06.2008 21:06 | Win32:Rootkit-gen co s tym?

Log je cisty.

Skus combofix - http://www.pcforum.sk/cistime-napadnuty ... 27265.html


_________________
NTB: Dell Vostro 5470 - Core i5-4200U, GT 740M, 8GB DDR3-1600, Crucial MX100 256GB, 14" 1366x768
Audio: KRK RoKit 5 G2 White, Lexicon Alpha, M-Audio Axiom 25 MKII, AKG Y55
Phone: Samsung Galaxy S8
Vozenie: Alfa Romeo 159 SW 1.9JTDm 110kW - DPF/EGR/SWIRL OFF, BOSE SOUND
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
Napísal autor témyOffline : 21.06.2008 21:35 | Win32:Rootkit-gen co s tym?

ComboFix 08-06-20.4 - danny 2008-06-21 21:12:20.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1250.420.1029.18.537 [GMT 2:00]
Running from: C:\Documents and Settings\danny\Plocha\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LocalService\Data aplikací\758559962.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Data aplikací\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\lsprst7.dll
C:\WINDOWS\system32\ssprs.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_CBEVTSVC


((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.

2008-06-21 16:07 . 2008-06-21 16:07 <DIR> d-------- C:\Program Files\Trend Micro
2008-06-21 15:55 . 2008-06-21 15:55 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-06-21 15:55 . 2008-06-21 15:55 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-21 15:07 . 2004-09-13 17:45 <DIR> d--h----- C:\Documents and Settings\Administrator.DILLIT\ćablony
2008-06-21 15:07 . 2008-06-21 21:20 <DIR> d-------- C:\Documents and Settings\Administrator.DILLIT\Plocha
2008-06-21 15:07 . 2004-09-13 17:45 <DIR> d--h----- C:\Documents and Settings\Administrator.DILLIT\Okolnˇ tisk rny
2008-06-21 15:07 . 2004-09-13 17:45 <DIR> d--h----- C:\Documents and Settings\Administrator.DILLIT\Okolnˇ sˇś
2008-06-21 15:07 . 2004-09-13 18:00 <DIR> dr------- C:\Documents and Settings\Administrator.DILLIT\Oblˇben‚ polo§ky
2008-06-21 15:07 . 2004-09-13 17:45 <DIR> dr------- C:\Documents and Settings\Administrator.DILLIT\Nabˇdka Start
2008-06-21 15:07 . 2004-09-13 18:00 <DIR> dr------- C:\Documents and Settings\Administrator.DILLIT\Dokumenty
2008-06-21 15:07 . 2004-09-13 17:45 <DIR> dr-h----- C:\Documents and Settings\Administrator.DILLIT\Data aplikacˇ
2008-06-21 15:07 . 2008-03-12 19:04 <DIR> d-------- C:\Documents and Settings\Administrator.DILLIT\Bluetooth Software
2008-06-21 15:07 . 2008-06-21 15:07 <DIR> d-------- C:\Documents and Settings\Administrator.DILLIT
2008-06-21 14:17 . 2008-06-21 14:17 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-21 14:12 . 2008-06-21 15:30 <DIR> d-------- C:\SDFix
2008-06-21 10:50 . 2008-06-21 10:50 <DIR> dr------- C:\Documents and Settings\LocalService\Oblˇben‚ polo§ky
2008-06-21 10:48 . 2008-06-21 10:48 109,056 --a------ C:\WINDOWS\system32\lphcrc4j0eva3.exe
2008-06-21 10:48 . 2008-06-21 10:48 90,838 --a------ C:\WINDOWS\system32\phcrc4j0eva3.bmp
2008-06-21 10:48 . 2008-06-21 10:48 60,928 --a------ C:\WINDOWS\system32\blphcrc4j0eva3.scr
2008-06-19 18:04 . 2008-06-21 21:21 61,874 --a------ C:\WINDOWS\system32\hxaqsper.sys
2008-06-19 13:37 . 2008-06-19 13:37 691,545 --a------ C:\WINDOWS\unins000.exe
2008-06-19 13:37 . 2008-06-19 13:37 2,544 --a------ C:\WINDOWS\unins000.dat
2008-06-19 13:04 . 2008-06-19 13:04 0 --a------ C:\WINDOWS\nsreg.dat
2008-06-19 12:12 . 2008-06-19 12:12 <DIR> d-------- C:\dvdC
2008-06-19 11:06 . 2008-06-19 12:12 <DIR> d-------- C:\dvd
2008-06-18 20:27 . 2008-06-11 16:48 4,001,179 --a------ C:\2008_RT_riesenia.rar
2008-06-18 18:45 . 2008-06-10 21:37 13,463,532 --a------ C:\skuska RT 23.05.2007.rar
2008-06-15 21:14 . 2004-08-17 15:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-15 21:14 . 2004-08-17 15:45 14,848 --a------ C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-15 21:13 . 2008-06-15 21:13 <DIR> d-------- C:\Documents and Settings\Owner\Bluetooth Software
2008-06-10 18:22 . 2008-06-10 18:22 <DIR> d-------- C:\Matrix.Revolutions.Revisited.2004.DVDR.PAL.CZSub-DVDrCZ
2008-06-05 01:33 . 2008-06-05 01:53 <DIR> d-------- C:\kebodvd
2008-05-30 23:54 . 2008-05-30 23:54 <DIR> d-------- C:\Program Files\Common Files\Control Panels
2008-05-30 23:33 . 2008-05-30 23:33 <DIR> d-------- C:\Program Files\QuickTime
2008-05-30 23:12 . 2008-05-30 23:12 <DIR> d-------- C:\Program Files\Bonjour
2008-05-30 23:06 . 2008-05-30 23:06 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-05-23 21:38 . 2008-05-23 21:38 1,025 --a------ C:\WINDOWS\system32\sysprs7.tgz
2008-05-23 21:38 . 2008-05-23 21:38 1,025 --a------ C:\WINDOWS\system32\sysprs7.dll
2008-05-23 21:38 . 2008-05-23 21:38 1,025 --a------ C:\WINDOWS\system32\clauth2.dll
2008-05-23 21:38 . 2008-05-23 21:38 1,025 --a------ C:\WINDOWS\system32\clauth1.dll
2008-05-23 21:38 . 2008-05-31 00:28 219 --a------ C:\WINDOWS\system32\lsprst7.tgz
2008-05-23 21:38 . 2008-05-31 00:28 87 --a------ C:\WINDOWS\system32\ssprs.tgz
2008-05-23 17:21 . 2004-08-03 23:10 51,328 --a------ C:\WINDOWS\system32\drivers\msdv.sys
2008-05-23 17:21 . 2004-08-03 23:10 51,328 --a------ C:\WINDOWS\system32\dllcache\msdv.sys
2008-05-23 17:21 . 2004-08-03 23:10 48,128 --a------ C:\WINDOWS\system32\drivers\61883.sys
2008-05-23 17:21 . 2004-08-03 23:10 48,128 --a------ C:\WINDOWS\system32\dllcache\61883.sys
2008-05-23 17:21 . 2004-08-03 23:10 38,912 --a------ C:\WINDOWS\system32\drivers\avc.sys
2008-05-23 17:21 . 2004-08-03 23:10 38,912 --a------ C:\WINDOWS\system32\dllcache\avc.sys
2008-05-22 19:35 . 2008-05-22 19:37 <DIR> d-------- C:\daemon
2008-05-21 18:31 . 2008-05-21 18:32 <DIR> d-------- C:\Program Files\ATnotes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-21 18:35 22,528 ----a-w C:\WINDOWS\system32\drivers\nhcDriver.sys
2008-06-19 12:53 --------- d-----w C:\Program Files\Google
2008-06-19 11:38 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-16 14:56 --------- d-----w C:\Program Files\Seznam DVD
2008-06-16 11:38 --------- d-----w C:\Program Files\Opera
2008-05-30 21:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-05-23 08:36 --------- d-----w C:\Program Files\Anvil Studio
2008-04-29 12:43 --------- d-----w C:\Program Files\DivX
2008-04-29 12:42 --------- d-----w C:\Program Files\AskTBar
2008-04-23 20:08 --------- d-----w C:\Program Files\uTorrent
2008-04-23 20:00 --------- d-----w C:\Program Files\BitTorrent
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-18 15:00 15360]
"ATnotes.exe"="C:\Program Files\ATnotes\ATnotes.exe" [2005-01-05 15:45 1015808]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PMHandler"="C:\WINDOWS\system32\PMHandler.exe" [2006-05-20 10:28 24576]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2005-10-20 15:18 339968]
"OmniPass"="C:\Program Files\Softex\OmniPass\scureapp.exe" [2006-02-28 01:20 2076672]
"NotebookHardwareControl"="C:\Program Files\Notebook Hardware Control\nhc.exe" [2007-05-04 02:33 2629632]
"TPWAUDAP"="C:\Program Files\Lenovo\HOTKEY\TpWAudAp.exe" [2006-09-06 17:38 54824]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-19 15:51 774233]
"Zástupce stránky vlastností sběrnice High Definition Audio"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 15:50 88204 C:\WINDOWS\AGRSMMSG.exe]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 13:17 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 13:13 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 13:17 118784]
"TVT Scheduler Proxy"="C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 10:34 487424]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-18 15:00 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 10:13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
C:\Program Files\Softex\OmniPass\opxpgina.dll 2006-02-28 01:21 49152 C:\Program Files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
C:\Program Files\Lenovo\HOTKEY\tphklock.dll 2007-12-14 17:36 28672 C:\Program Files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Nabídka Start^Programy^Po spuštění^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Nabídka Start\Programy\Po spuštění\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\c:^documents and settings^danny^nabídka start^programy^po spuštění^powerreg schedulerv2.exe]
path=C:\Documents and Settings\danny\Nabídka Start\Programy\Po spuštění\PowerReg SchedulerV2.exe
backup=C:\WINDOWS\pss\PowerReg SchedulerV2.exeStartup
--a------ 2007-05-10 22:46 624248 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\acrobat assistant 8.0]
--a------ 2007-05-10 22:46 624248 C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\adobe_id0eythm]
--a------ 2007-03-20 16:40 1884160 C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-10-09 11:28 139264 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2006-11-12 12:48 157592 C:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
--a------ 2005-11-29 11:55 196696 C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 21:24 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-02-01 17:22 21898024 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2007-10-10 07:28 36352 C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
"C:\\Program Files\\Anvil Studio\\astudio.exe"=
"C:\\Program Files\\miranda\\miranda32.exe"=
"C:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\Opera\\Opera.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:@xpsp2res.dll,-22002
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R1 PMHler;PMHler;C:\WINDOWS\system32\drivers\PMHler.sys [2005-12-21 15:09]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 FNF5SVC;Fn+F5 Service;C:\Program Files\LENOVO\HOTKEY\FNF5SVC.exe [2007-04-09 11:24]
R3 PSched;Plánovač paketů technologie QoS;C:\WINDOWS\system32\DRIVERS\psched.sys [2004-08-18 15:00]
R3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-10-17 17:16]
S3 MMIOPORT;MMIOPORT;C:\WINDOWS\system32\drivers\MMIOPORT.sys [2000-03-03 05:16]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b99f0c36-1123-11dd-b586-000fb0cbdb13}]
\Shell\AutoRun\command - E:\.\run\autorun.exe
\Shell\open\Command - E:\.\run\autorun.exe

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-21 21:20:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\Program Files\Softex\OmniPass\opxpgina.dll

PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Softex\OmniPass\SCUREDLL.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe
C:\Program Files\Softex\OmniPass\OmniServ.exe
C:\MATLAB6p5\bin\win32\matlab.exe
C:\WINDOWS\system32\PMSveH.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Lenovo\System Update\SUService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
.
**************************************************************************
.
Completion time: 2008-06-21 21:30:23 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-21 19:29:51

Adresářů: 19, Volných bajtů: 25,497,300,992
Adres ý…: 22, Volněch bajt…: 25,402,957,824

231 --- E O F --- 2008-03-31 22:00:56


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 12.06.08
Prihlásený: 16.09.10
Príspevky: 440
Témy: 4 | 4
NapísalOffline : 21.06.2008 21:51 | Win32:Rootkit-gen co s tym?

Skript pre ComboFix:

Kód:
Collect::
C:\WINDOWS\system32\lphcrc4j0eva3.exe
C:\WINDOWS\system32\phcrc4j0eva3.bmp
C:\WINDOWS\system32\blphcrc4j0eva3.scr
C:\WINDOWS\system32\hxaqsper.sys

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b99f0c36-1123-11dd-b586-000fb0cbdb13}]


Na ploche sa vytvori archiv, zabal ho do dalsieho s heslom "infected" a posli mi ho prosim na mail, vdaka.


Otestuj na www.virustotal.com tieto subory:

Kód:
C:\WINDOWS\system32\sysprs7.dll
C:\WINDOWS\system32\drivers\61883.sys


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
Napísal autor témyOffline : 21.06.2008 22:21 | Win32:Rootkit-gen co s tym?

dik
skript prebehol v pohode, archiv vytvorilo
aky mas mail? aby som ti to poslal? nikde ho nevidim

a este idem dat otestovat tie subory:)


Offline

Užívateľ
Užívateľ
Win32:Rootkit-gen co s tym?

Registrovaný: 02.09.07
Prihlásený: 20.11.17
Príspevky: 6419
Témy: 298 | 298
Bydlisko: Žilina
Vek: 24
NapísalOffline : 21.06.2008 22:22 | Win32:Rootkit-gen co s tym?

eKosak@azet.sk


_________________
NTB: Dell Vostro 5470 - Core i5-4200U, GT 740M, 8GB DDR3-1600, Crucial MX100 256GB, 14" 1366x768
Audio: KRK RoKit 5 G2 White, Lexicon Alpha, M-Audio Axiom 25 MKII, AKG Y55
Phone: Samsung Galaxy S8
Vozenie: Alfa Romeo 159 SW 1.9JTDm 110kW - DPF/EGR/SWIRL OFF, BOSE SOUND
Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
Napísal autor témyOffline : 21.06.2008 22:27 | Win32:Rootkit-gen co s tym?

:) ok poslal som

co sa tyka tych suborov tak pri kazdom to dpadlo takto:

Současný stav: Dokončeno
Výsledek: 0/33 (0%)

co je dufam dobre


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 12.06.08
Prihlásený: 16.09.10
Príspevky: 440
Témy: 4 | 4
NapísalOffline : 21.06.2008 22:47 | Win32:Rootkit-gen co s tym?

Vdaka. Je este nejaky problem?

Start => Spustit => "combofix /u" a je to hotovo. :)


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
Napísal autor témyOffline : 21.06.2008 23:22 | Win32:Rootkit-gen co s tym?

no vyzera ze to bude vsetko v poriadku, akurat mi neukazuje ikonu avastu na liste hoci rezidentna ochrana je podla vsetkeho spustena, cim to moze byt?


Offline

Užívateľ
Užívateľ
Obrázok užívateľa

Registrovaný: 03.11.06
Prihlásený: 15.03.10
Príspevky: 20
Témy: 8 | 8
Napísal autor témyOffline : 21.06.2008 23:48 | Win32:Rootkit-gen co s tym?

kazdopadne dik moc za cas a hlavne za pomoc, mas u mna pivko ;)


Offline

Skúsený užívateľ
Skúsený užívateľ
Obrázok užívateľa

Registrovaný: 12.06.08
Prihlásený: 16.09.10
Príspevky: 440
Témy: 4 | 4
NapísalOffline : 22.06.2008 0:12 | Win32:Rootkit-gen co s tym?

Avast podrobne nepoznam, ale podla toho, co vidim, by sa spustat mal aj proces, ktory zobrazuje ikonku.

Heh...


Offline

Skúsený užívateľ
Skúsený užívateľ
Win32:Rootkit-gen co s tym?

Registrovaný: 10.07.07
Prihlásený: 02.11.17
Príspevky: 1060
Témy: 0 | 0
Bydlisko: Bratislava
NapísalOffline : 25.06.2008 2:50 | Win32:Rootkit-gen co s tym?

hej,
ALE posli este raz aktualny vypis z hijackthis


_________________
Nebo je modre, voda je mokra...
 [ Príspevkov: 12 ] 


Win32:Rootkit-gen co s tym?



Podobné témy

 Témy  Odpovede  Zobrazenia  Posledný príspevok 
V tomto fóre nie sú ďalšie neprečítané témy.

Čo s tým?

v Webdesign

22

978

02.01.2008 1:26

borec

V tomto fóre nie sú ďalšie neprečítané témy.

Čo s tým ???

v Optické zariadenia

12

475

11.01.2011 19:14

Ixtlan

V tomto fóre nie sú ďalšie neprečítané témy.

Horúčka - čo s tým?

v Zdravie, medicína, choroby a liečenie

11

2451

27.04.2008 22:33

jaji

V tomto fóre nie sú ďalšie neprečítané témy.

Vitaz.tym.sk - koment

v Webdesign

11

587

02.01.2010 0:43

xsound031

V tomto fóre nie sú ďalšie neprečítané témy.

Zvysi sa tym vykon???

v Operačné systémy Unix a Linux

6

243

07.02.2012 18:04

majky358

V tomto fóre nie sú ďalšie neprečítané témy.

Co je s tym ?

v Databázy

2

576

02.02.2008 10:33

tatysp

V tomto fóre nie sú ďalšie neprečítané témy.

WEBDESIGN - iwax.tym.sk

v Webdesign

7

690

01.02.2007 11:12

jord

V tomto fóre nie sú ďalšie neprečítané témy.

Co s tym je?

v Operačné systémy Microsoft

18

681

04.09.2006 11:46

caster

V tomto fóre nie sú ďalšie neprečítané témy.

USB čo je s tým?

v Ostatné zariadenia

3

169

06.02.2014 13:50

Staňa9

V tomto fóre nie sú ďalšie neprečítané témy.

Zbierate nieco? sem s tym!

[ Choď na stránku:Choď na stránku: 1, 2 ]

v Voľný čas a hobby

57

3927

27.06.2013 18:24

dixi

V tomto fóre nie sú ďalšie neprečítané témy.

blue screen co s tym

v Antivíry a antispywary

12

1479

28.10.2007 12:56

tearan

V tomto fóre nie sú ďalšie neprečítané témy.

cierna obrazovka co s tym ?

v Ostatné

5

262

15.04.2012 22:41

MacherSVK

V tomto fóre nie sú ďalšie neprečítané témy.

DVD printable - čo s tým?

v Ostatné programy

1

737

24.01.2009 0:20

JanoF

V tomto fóre nie sú ďalšie neprečítané témy.

CO JE S TYM DISKOM?

v Pevné disky a radiče

13

561

04.12.2007 22:02

OmeGa

V tomto fóre nie sú ďalšie neprečítané témy.

xperia x8 .. čo s tým?

v Smartfóny a tablety

3

191

06.05.2012 0:02

shiro

V tomto fóre nie sú ďalšie neprečítané témy.

Vypadava mi klavesnica, co s tym?

v Externé zariadenia

3

365

01.03.2010 17:24

The Jackal



© 2005 - 2017 PCforum, edited by JanoF