Komp po wirusach,trojanach i rootkitach- log

Proszę o sprawdzenie loga, gdyż miałem bardzo dużo wirusów. Z góry dziękuję.

i jeszcze jeden :slight_smile:

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]

"ATICCC" = ""C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"" [null data]

"RemoteControl" = ""C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]

"NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]

"HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]

"ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]

"osCheck" = ""C:\Program Files\Norton Internet Security\osCheck.exe"" ["Symantec Corporation"]

"Symantec PIF AlertEng" = ""C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"" ["Symantec Corporation"]

"Acronis Scheduler2 Service" = ""C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"" ["Acronis"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\(Default) = (no title provided)

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll" ["Symantec Corporation"]

{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}\(Default) = "flashget urlcatch"

  -> {HKLM...CLSID} = "FGCatchUrl"

                   \InProcServer32\(Default) = "D:\Flesh get\jccatch.dll" ["www.flashget.com"]

{F156768E-81EF-470C-9057-481BA8380DBA}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "FlashGet GetFlash Class"

                   \InProcServer32\(Default) = "D:\Flesh get\getflash.dll" ["www.flashget.com"]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{EFA24E62-B078-11d0-89E4-00C04FC9E26E}" = "History Band"

  -> {HKLM...CLSID} = "History Band"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]

"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"

  -> {HKLM...CLSID} = "SimpleShlExt Class"

                   \InProcServer32\(Default) = "C:\Program Files\ATI Technologies\ATI.ACE\atiacmxx.dll" [empty string]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

"{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.ux.pl 2.1.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

"{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.ux.pl 2.1.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

"{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.ux.pl 2.1.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

"{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.ux.pl 2.1.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

"{60CE0473-50F7-417B-A10F-6921827B9CA8}" = "Acronis PrivacyExpert Shell Extension Class"

  -> {HKLM...CLSID} = "CPrivexShellExt Object"

                   \InProcServer32\(Default) = "D:\Acronis\PrivacyExpert\PrivShellExt.dll" [null data]


HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\

"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

  -> {HKLM...CLSID} = "WPDShServiceObj Class"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]


HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\

<> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\

{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = ""C:\Program Files\OpenOffice.ux.pl 2.1.0\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}"

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension"

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found]

PrivShellExt\(Default) = "{60CE0473-50F7-417B-A10F-6921827B9CA8}"

  -> {HKLM...CLSID} = "CPrivexShellExt Object"

                   \InProcServer32\(Default) = "D:\Acronis\PrivacyExpert\PrivShellExt.dll" [null data]

Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"

  -> {HKLM...CLSID} = "IEContextMenu Class"

                   \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NORTON~1\NavShExt.dll" ["Symantec Corporation"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

MkS_Vir\(Default) = "{E64226E0-9DA1-479E-8265-8D65BA327BD4}"

  -> {HKLM...CLSID} = "MkS_Vir Shell Extension"

                   \InProcServer32\(Default) = "/u\mksshell.dll" [file not found]

PrivexShellExt\(Default) = "{60CE0473-50F7-417B-A10F-6921827B9CA8}"

  -> {HKLM...CLSID} = "CPrivexShellExt Object"

                   \InProcServer32\(Default) = "D:\Acronis\PrivacyExpert\PrivShellExt.dll" [null data]

Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"

  -> {HKLM...CLSID} = "IEContextMenu Class"

                   \InProcServer32\(Default) = "C:\PROGRA~1\NORTON~1\NORTON~1\NavShExt.dll" ["Symantec Corporation"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]



Group Policies {policy setting}:

--------------------------------


Note: detected settings may not have any effect.


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "C:\WINDOWS\web\wallpaper\Idylla.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\WINDOWS\web\wallpaper\Idylla.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]



Startup items in "cies-364hqd8t2h6n" & "All Users" startup folders:

-------------------------------------------------------------------


C:\Documents and Settings\All Users\Menu Start\Programy\Autostart

"HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]



Enabled Scheduled Tasks:

------------------------


"Norton Internet Security - Run Full System Scan - cies-364hqd8t2h6n" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Dane aplikacji\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15

%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05



Toolbars, Explorer Bars, Extensions:

------------------------------------


Toolbars


HKLM\Software\Microsoft\Internet Explorer\Toolbar\

"{90222687-F593-4738-B738-FBEE9C7B26DF}" = "NCO Toolbar"

  -> {HKLM...CLSID} = "Show Norton Toolbar"

                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll" ["Symantec Corporation"]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{D6E814A0-E0C5-11D4-8D29-0050BA6940E3}\

"ButtonText" = "FlashGet"

"MenuText" = "FlashGet"

Logi są ok.

Skąd wiesz, że miałeś sporo śmieci, w tym wirusy i trojany?

Pobierz program AVG Anti-Spyware zrób update i przeskanuj.

BO przeskanowałem nortonem i znalazł dość dużo. Głównie chodzi mi o zagrożenia typu “rootkit”. Jak to zwalczyć?

Pokaż dwa logi z Gmer’a wykonane przy takich ustawieniach:

  1. Zakładka Rootkit >>> zaznaczone wszystko oprócz Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta

  2. Zakładka Rootkit >>> zaznaczone tylko Usługi i Pokazuj wszystko >>> kliknij Szukaj >>> czekaj cierpliwie aż skończy >>> Kopiuj >>> wklej do posta

Jeśli wszystkie logi nie zmieszczą się bezpośrednio do posta, to umieść je w jakimś serwisie hostingowym jako pliki *.txt, a tu tylko zlinkuj.

Do adam9870:

Rootkit scan 2007-05-04 20:53:40

Windows 5.1.2600 Dodatek Service Pack 2


GMER 1.0.12.12244 - http://www.gmer.net


---- System - GMER 1.0.12 ----


SSDT 82176840 ZwAlertResumeThread

SSDT 821AB0C0 ZwAlertThread

SSDT 821A2D98 ZwAllocateVirtualMemory

SSDT 820690B8 ZwConnectPort

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateFile

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateKey

SSDT 8211C698 ZwCreateMutant

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateProcess

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateProcessEx

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateSection

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwCreateThread

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwDeleteFile

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwDeleteKey

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwDeleteValueKey

SSDT 8205B0B8 ZwFreeVirtualMemory

SSDT 821285B0 ZwImpersonateAnonymousToken

SSDT 82127988 ZwImpersonateThread

SSDT 821CBF30 ZwMapViewOfSection

SSDT 8212AF90 ZwOpenEvent

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwOpenFile

SSDT 8205ED78 ZwOpenProcessToken

SSDT 82054508 ZwOpenThreadToken

SSDT 820571A8 ZwResumeThread

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwSetContextThread

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwSetInformationFile

SSDT 82055990 ZwSetInformationProcess

SSDT 82053780 ZwSetInformationThread

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwSetValueKey

SSDT 82120C28 ZwSuspendProcess

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwSuspendThread

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwTerminateProcess

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwTerminateThread

SSDT 82056548 ZwUnmapViewOfSection

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwWriteFile

SSDT \SystemRoot\system32\DRIVERS\psh_drv.sys ZwWriteVirtualMemory


---- Kernel code sections - GMER 1.0.12 ----


? C:\WINDOWS\system32\DRIVERS\update.sys    


---- EOF - GMER 1.0.12 ----

Jest późno ale nic nie wiedzę, jest czysto :wink:

Dzieki za sprawdzenie tych logów. Co moze być przyczyną mulenia kompa? Moja konfiguracja to: Athlon 3200+ Ram 512MB dysk 80 GB WDC graf. Radeon X1600 Pro 512MB i jakas tam płyta główna Gigabyte. Mam zainstalowany system Windows XP, do ochrony antywirusowej używam Nortona 2007. Z góry dziękuję.

Proponuję posiedzieć trochę nad tym tematem:

:arrow: http://forum.dobreprogramy.pl/viewtopic.php?t=76580

Powyłączać zbędne programy z autostartu i zastanowić się, kiedy ostatni raz było robione czyszczenie komputera od środka (tj. rozkręcanie, odkurzanie, wycieranie etc)

Komputer jest regularnie czyszczony “od środka” raz w miesiącu, to w zupełności wystarcza, ponieważ nie ma tam wiele kurzu. Przeprowadzam regularnie defragmentacje, scan disk, urzywam na dodatek Ccleaner.

Może byc jakaś inna przyczyna?