djpuzon
(Puzon1982)
23 Listopad 2007 14:38
#1
Mój problem dotyczy dokładnie tego samego Trojana myślałem że nie będę zaśmiecał niepotrzebnie forum nowym tematem skoro sprawa dotyczy tej samej rzeczy. Więc wg mnie uwaga i przerzucenie do smietnika jest nie na miejscu.
moj log z Combofix przedstawia się nastepująco:
ComboFix 07-11-19.3 - Puzonek 2007-11-23 15:50:35.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1250.1.1045.18.633 [GMT 1:00] Running from: C:\Documents and Settings\Puzonek\Pulpit\ComboFix.exe . ((((((((((((((((((((((((( Files Created from 2007-10-23 to 2007-11-23 ))))))))))))))))))))))))))))))) . 2007-11-23 06:47 2007-11-22 16:33 2007-11-22 16:16 15,920 --a------ C:\WINDOWS\system32\drivers\PdiPorts.sys 2007-11-22 16:16 11,776 --a------ C:\WINDOWS\system32\drivers\pdiddcci.sys 2007-11-22 16:14 2007-11-22 16:14 2007-11-22 15:58 2007-11-20 12:24 2007-11-18 16:59 2007-11-18 16:59 2007-11-18 16:59 2007-11-18 16:03 2007-11-18 15:36 3,974,440 --a------ C:\WINDOWS\system32\AdvrCntr3.dll 2007-11-18 15:30 2007-11-17 23:00 2007-11-17 23:00 2007-11-17 11:42 2007-11-17 11:42 2007-11-17 10:01 2007-11-17 10:01 2007-11-17 09:24 2007-11-17 00:56 976,896 --a------ C:\WINDOWS\system32\sqlrcmd.dll 2007-11-17 00:27 2007-11-17 00:11 2007-11-17 00:05 2007-11-15 06:47 2007-11-14 23:30 2007-11-14 16:37 2007-11-12 18:23 2007-11-12 18:23 2007-11-12 16:27 2007-11-11 15:56 2007-11-11 09:13 2007-11-09 18:54 2007-11-09 18:45 2007-11-08 19:52 2007-11-08 19:51 2007-11-08 19:51 2007-11-08 19:51 249,856 --a------ C:\WINDOWS\system32\pdfmona.dll 2007-11-08 19:51 51,716 --a------ C:\WINDOWS\system32\pdf995mon.dll 2007-11-08 19:35 2007-11-08 19:35 2007-11-08 19:28 2007-11-08 19:11 1,024 --a------ C:\WINDOWS\system32\pdfeditor.dat 2007-11-08 19:09 2007-11-08 16:17 53,768 --a------ C:\WINDOWS\system32\drivers\epfwtdi.sys 2007-11-08 16:17 50,696 --a------ C:\WINDOWS\system32\drivers\epfw.sys 2007-11-08 16:17 30,728 --a------ C:\WINDOWS\system32\drivers\epfwndis.sys 2007-11-08 16:10 27,656 --a------ C:\WINDOWS\system32\drivers\easdrv.sys 2007-11-08 16:09 33,800 --a------ C:\WINDOWS\system32\drivers\eamon.sys 2007-11-06 20:57 2007-11-06 16:32 2007-11-06 16:20 2007-11-06 06:37 2007-11-04 14:18 2007-10-30 18:22 2007-10-30 18:13 2007-10-30 17:24 2007-10-30 16:46 81,984 --a------ C:\WINDOWS\system32\bdod.bin 2007-10-30 16:43 2007-10-30 06:52 2007-10-30 06:52 2007-10-29 20:05 2007-10-29 16:20 26,496 --a–c— C:\WINDOWS\system32\dllcache\usbstor.sys 2007-10-26 15:51 2007-10-26 15:49 2007-10-26 15:49 2007-10-26 15:26 2007-10-26 05:57 2007-10-25 18:35 2007-10-25 17:48 2007-10-25 17:48 2007-10-25 17:48 24,072 --a------ C:\WINDOWS\system32\uxtuneup.dll 2007-10-25 17:47 2007-10-25 17:47 2007-10-25 17:35 2007-10-25 17:09 2007-10-25 17:09 2007-10-25 16:13 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-10-25 15:32 2007-10-25 15:31 2007-10-24 18:50 2007-10-23 23:19 2007-10-23 23:00 2007-10-23 22:52 2007-10-23 22:24 2007-10-23 22:15 2007-10-23 20:43 2007-10-23 20:43 2007-10-23 20:43 2007-10-23 20:43 2007-10-23 05:59 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-22 17:09 --------- d-----w C:\Program Files\BitComet 2007-11-22 17:09 --------- d-----w C:\Program Files\ArtIcons Pro 2007-11-22 15:16 --------- d–h--w C:\Program Files\InstallShield Installation Information 2007-11-17 08:37 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Bluetooth 2007-10-30 16:54 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Kaspersky Lab Setup Files 2007-10-30 05:51 --------- d-----w C:\Program Files\Common Files\InstallShield 2007-10-25 15:22 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys 2007-10-24 20:44 --------- d-----w C:\Program Files\PhotoZoom Pro 2 2007-10-22 15:55 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\BitTorrent DNA 2007-10-22 15:52 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\BitTorrent 2007-10-22 15:22 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Hagel Technologies 2007-10-22 15:21 --------- d-----w C:\Program Files\JockerSoft 2007-10-22 15:17 360,576 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys 2007-10-22 14:43 --------- d-----w C:\Program Files\MagicDisc 2007-10-20 09:27 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\Ashampoo 2007-10-20 09:23 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\ashampoo 2007-10-20 08:57 --------- d-----w C:\Program Files\Neoretix 2007-10-20 07:58 --------- d-----w C:\Program Files\GDI 2007-10-20 07:37 --------- d-----w C:\Program Files\Kaza Gold 4.1a 2007-10-20 07:34 --------- d-----w C:\Program Files\Kaza Gold 2007-10-19 23:26 65,709 ----a-w C:\WINDOWS\BricoPackUninst.cmd 2007-10-19 23:26 6,118 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd 2007-10-19 23:26 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll 2007-10-19 14:56 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\Media Player Classic 2007-10-18 05:44 --------- d-----w C:\Program Files\Malicious Software Removal Tool 2007-10-18 05:42 --------- d-----w C:\Program Files\MSXML 6.0 2007-10-18 05:42 --------- d-----w C:\Program Files\MSXML 4.0 2007-10-18 05:25 --------- d-----w C:\Program Files\Windows Media Connect 2 2007-10-18 05:04 --------- d-----w C:\Program Files\VSD Software 2007-10-18 05:02 --------- d-----w C:\Program Files\Dir2File 2007-10-18 04:55 --------- d-----w C:\Program Files\HighMAT CD Writing Wizard 2007-10-16 21:28 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\Winamp 2007-10-16 20:47 --------- d-----w C:\Program Files\Java 2007-10-16 20:45 --------- d-----w C:\Program Files\Common Files\Java 2007-10-16 19:58 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\GRETECH 2007-10-16 19:58 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\GRETECH 2007-10-16 19:56 --------- d-----w C:\Program Files\K-Lite Codec Pack 2007-10-16 19:56 --------- d-----w C:\Program Files\GRETECH 2007-10-16 19:53 --------- d-----w C:\Program Files\Real Alternative 2007-10-16 19:53 --------- d-----w C:\Program Files\Media Player Classic 2007-10-16 19:26 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji.BitTornado 2007-10-16 18:59 --------- d-----w C:\Program Files\xp-AntiSpy 2007-10-16 18:15 --------- d-----w C:\Program Files\Prolink 2007-10-16 18:10 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Microsoft Help 2007-10-16 18:06 --------- d-----w C:\Program Files\Microsoft Works 2007-10-16 18:04 --------- d-----w C:\Program Files\Microsoft.NET 2007-10-16 18:02 --------- d-----w C:\Program Files\Microsoft Visual Studio 8 2007-10-16 17:57 --------- d-----w C:\Program Files\MSBuild 2007-10-16 17:54 --------- d-----w C:\Documents and Settings\Puzonek\Dane aplikacji\Gadu-Gadu 2007-10-16 17:52 --------- d-----w C:\Program Files\Gadu-Gadu 2007-10-16 17:51 --------- d-----w C:\Program Files\Reference Assemblies 2007-10-16 17:49 --------- d-----w C:\Program Files\Winamp 2007-10-16 17:28 --------- d-----w C:\Program Files\ATI Technologies 2007-10-16 17:26 --------- d-----w C:\Program Files\C-Media 3D Audio 2007-10-16 17:19 --------- d-----w C:\Program Files\Intel 2007-10-16 16:39 --------- d-----w C:\Program Files\PowerQuest 2007-10-16 16:33 --------- d-----w C:\Program Files\microsoft frontpage 2007-10-16 16:30 --------- d-----w C:\Program Files\Usługi online 2007-09-28 16:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2007-09-28 16:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2007-09-28 16:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll 2007-09-04 16:56 164,352 ----a-w C:\WINDOWS\system32\unrar.dll 2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\AUDIO3D.DLL . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-03 23:44] “BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe” [2007-06-27 19:03] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] “Cmaudio”=“RunDll32 cmicnfg.cpl” [] “ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2004-09-29 06:15] “GrooveMonitor”=“C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe” [2006-10-26 23:47] “PowerS”=“C:\WINDOWS\PowerS.exe” [2001-08-03 16:56] “SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe” [2007-09-25 00:11] “PWRISOVM.EXE”=“C:\Program Files\PowerISO\PWRISOVM.EXE” [2007-04-09 13:23] “egui”=“C:\Program Files\ESET\ESET Smart Security\egui.exe” [2007-11-08 16:13] “Win Messenger”=“messenger.exe” [] “NeroFilterCheck”=“C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe” [2007-03-01 15:57] “DT LGE”=“C:\Program Files\Portrait Displays\forteManager\DTHtml.exe” [2007-06-12 12:32] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] “Win Messenger”=“messenger.exe” [] [HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] “CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” [2004-08-03 23:44] C:\Documents and Settings\Puzonek\Menu Start\Programy\Autostart\ MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2007-10-22 15:42:46] C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\ Remote Controller.lnk - C:\Program Files\Prolink\PlayTV Pro\TVRMVCR.EXE [2007-10-16 19:15:07] TV Scheduler.lnk - C:\Program Files\Prolink\PlayTV Pro\TVSCHL.EXE [2007-10-16 19:15:07] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] “ForceClassicControlPanel”= 1 (0x1) “NoChangeKeyboardNavigationIndicators”= 0 (0x0) “NoSharedDocuments”= 1 (0x1) “NoRecentDocsMenu”= 1 (0x1) “NoSMConfigurePrograms”= 1 (0x1) R1 easdrv;easdrv;C:\WINDOWS\system32\DRIVERS\easdrv.sys R1 epfwtdi;epfwtdi;C:\WINDOWS\system32\DRIVERS\epfwtdi.sys R2 BT848;BtCap, WDM Video Capture;C:\WINDOWS\system32\drivers\BT848.SYS R2 BTTUNER;BtTuner, WDM TV Tuner;C:\WINDOWS\system32\drivers\BTTUNER.SYS R2 BTXBAR;BtXBar, WDM Crossbar;C:\WINDOWS\system32\drivers\BTXBAR.SYS R2 eamon;EAMON;C:\WINDOWS\system32\DRIVERS\eamon.sys R2 ekrn;Eset Service;“C:\Program Files\ESET\ESET Smart Security\ekrn.exe” R2 epfw;epfw;C:\WINDOWS\system32\DRIVERS\epfw.sys R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe -k netsvcs R3 Epfwndis;Eset Personal Firewall;C:\WINDOWS\system32\DRIVERS\Epfwndis.sys S3 EhttpSrv;Eset HTTP Server;“C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe” S3 USBSTOR;Sterownik magazynu masowego USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp . Contents of the ‘Scheduled Tasks’ folder “2007-11-09 16:23:37 C:\WINDOWS\Tasks\1-Click Maintenance.job” - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-23 15:52:05 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-23 15:52:42 C:\ComboFix2.txt … 2007-11-23 15:43 . — E O F —
Gutek
(Gutek)
23 Listopad 2007 23:06
#2
Otwórz Notatnik i wklej w nim to:
Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG >>> kliknij dwa razy na utworzony plik FIX.REG i potwierdź dodanie do rejestru >>> restart.
Pobierz program SDFix
djpuzon
(Puzon1982)
24 Listopad 2007 00:54
#3
oto mój log z SDfix po wszystkich zalecanych czynnościach
SDFix: Version 1.115 Run by Puzonek on 2007-11-24 at 01:42 Microsoft Windows XP [Wersja 5.1.2600] Running From: C:\SDFix Safe Mode: Checking Services: Restoring Windows Registry Values Restoring Windows Default Hosts File Rebooting… Normal Mode: Checking Files: No Trojan Files Found Removing Temp Files… ADS Check: C:\WINDOWS No streams found. C:\WINDOWS\system32 No streams found. C:\WINDOWS\system32\svchost.exe No streams found. C:\WINDOWS\system32\ntoskrnl.exe No streams found. Final Check: catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-24 01:46:25 Windows 5.1.2600 Dodatek Service Pack 2 NTFS scanning hidden processes … scanning hidden services & system hive … scanning hidden registry entries … [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A\1\5\1c] “Order”=hex:08,00,00,00,02,00,00,00,b8,01,00,00,01,00,00,00,04,00,00,00,8c,… scanning hidden files … scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services: ------------------ Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] “C:\Program Files\Skype\Phone\Skype.exe”=“C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype” [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] Remaining Files: --------------- Files with Hidden Attributes: Finished!
Gutek
(Gutek)
24 Listopad 2007 14:21
#4