![]() |
|
#1
| |||
| |||
| Hi guys .. es vienkārši atver e-pastu un saņēma hit ar Antivirus XP 2.008 vīrusu. Aprunāt tikt vaļā no tā. Any help much appreciated .. |
|
#3
| |||
| |||
| Sorry mate I dont saprotu .. Ko tu gribi darīt ar to visu? |
|
#4
| ||||||||||||
| ||||||||||||
| Veikt laiks informācijas izlasīšanai un tad palaist programmatūras un pēc log failus, lai varam redzēt, kas notiek ar jūsu datoru.
__________________
Mana sistēma: Hybr! D
|
|
#5
| |||
| |||
| Heres logs: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 07/05/2008 at 05:20 Application Version: 4.15.1000 Core Noteikumi Database Version: 3.497 Trace Noteikumi Database Version: 1488 Scan type: Quick Scan Kopā Scan Time: 00:10:14 Atmiņas vienības skenēts: 268 Memory draudiem detected: 1 Reģistra vienības skenēts: 407 Reģistrs draudiem detected: 26 File preces skenēts: 6.977 File draudiem detected: 175 Rogue.AntiVirus XP 2.008 C: \ Program Files \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE C: \ Program Files \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Kā reģistrēties Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ License Agreement.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Reģistrācija Antivirus XP 2008.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2008 \ Uninstall.lnk C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Antivirus XP 2.008 C: \ AA \ RHCPV6J0EREL \ RHCPV6J0EREL.EXE Rogue.Dropper / Gen [lphctv6j0erel] C: \ WINDOWS \ SYSTEM32 \ LPHCTV6J0EREL.EXE C: \ WINDOWS \ SYSTEM32 \ LPHCTV6J0EREL.EXE Adware.Tracking Cookie C: \ Documents and Settings \ Denijs \ Cookies \ danny @ apkalpo-SYS [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ burstnet [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@media.adrevolver [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ clickbank [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ advertpro [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@e-2dj6wjnywnc5eeo.stats.esomniture [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ tribalfusion [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@adserver.mediarun [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 192 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adviva [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ehg-mgnlimited.hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @-video [2 sex]. Txt D: \ Documents and Settings \ Denijs \ Cookies \ danny @ mediaplex [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@stat.onestat [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adrevenue [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.videhost [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.pugetsoundsoftwar e [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ reklāmu [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ DoubleClick [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@www.burstnet [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@tracking.summitmedia. co [1]. txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@bs.serving-sys [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ tacoda [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ s [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ Kontera [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@data.coremetrics [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ questionmarket [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ roiservice [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adbrite [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@counter.hitslink [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@adserving.muppetism [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ cgi-bin [4]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@vhost.oddcast [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@rotator.adjuggler [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@s1.trafficmaxx [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@www.stilemedia [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.ookla [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ neocounter2 [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ad1.doublepimp [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@te.kontera [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 9167811 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adrevolver [3]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ indextools [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ sexyandshocking [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ yadro [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@w00tpublishers.wootme dia [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@dynamic.media.adrevol ver [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@e-2dj6wfkokkcjcao.stats.esomniture [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ atwola [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ Zedo [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adecn [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@mobilefun.112.2o7 [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@m1.webstats.motigo [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adrevolver [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 1068755026 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ specificclick [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ firstchoice [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 2o7 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ TradeDoubler [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.techguy [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adultadworld [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ehg-bestbuy.hitbox [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ firstchoice [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ehg-twi.hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ad.yieldmanager [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ revsci [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@statse.webtrendslive [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@exchange.ggmedia [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adlegend [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ cgi-bin [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@shopping.112.2o7 [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ehg-iwantoneofthose.hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.digitalrock.co [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 63701567 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ uvertīra [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ad1.clickhype [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ bluestreak [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ statcounter [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ atdmt [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ads.pubmatic [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 247realmedia [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@avgtechnologies.112.2 o7 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ bravenet [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@heavycom.122.2o7 [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@stat.dealtime [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@adopt.euroclick [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@server.iad.liveperson [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ fastclick [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ statīvs [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ adtech [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ palielināt [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@ehg-systemax.hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ stilemedia [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ gostats [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@network-ca.247realmedia [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ AdRotator [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ 1048893890 [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ cgi-bin [3]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@www.clash-media [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny @ indexstats [2]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@test.coremetrics [1]. Txt C: \ Documents and Settings \ Denijs \ Cookies \ danny@eas.apm.emediate [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ adtech [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@ehg-iwantoneofthose.hitbox [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ sextracker [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@ad.yieldmanager [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@metacafe.122.2o7 [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@stat.onestat [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@counter4.sextracker [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ DoubleClick [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ atdmt [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@as1.falkag [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@hg1.hitbox [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@c1.zedo [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@counter13.sextracker [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@counter15.sextracker [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ hitbox [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ adrevolver [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ adrevolver [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ Zedo [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ targetnet [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny@adopt.hbmediapro [2]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ 2o7 [1]. Txt C: \ Documents and Settings \ Denijs \ Local Settings \ Temp \ Cookies \ danny @ atwola [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@stats.searchtrack [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ atdmt [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ piecpadsmit [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@www.fifteen [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@e-2dj6wflisidjkko.stats.esomniture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ adtech [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@marksandspencer.122 ,2 o7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ adrevolver [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@perf.overture [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ WindowsMedia [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ statcounter [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@msnportal.112.2o7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ konti [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@e-2dj6wflyckcjabo.stats.esomniture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ehg-debenhams.hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@paypal.112.2o7 [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@tracker.roitesting [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ bravenet [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@adopt.euroclick [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ indexstats [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@data4.perf.overture [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@bs.serving-sys [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ revsci [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ mediaplex [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@etype.adbureau [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@112.2o7 [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ehg-bskyb.hitbox [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@ads.telegraph.co [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie@statse.webtrendsliv e [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ questionmarket [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ apkalpo-SYS [1]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ TradeDoubler [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ indextools [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ 2o7 [2]. Txt C: \ Documents and Settings \ Rozzie \ Cookies \ rozzie @ reklāmu [2]. Txt Rogue.AntiSpywareExpert HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC # NextInstance HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # Service HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # Legacy HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # ConfigFlags HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # Class HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # ClassGUID HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 # DeviceDesc HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 \ Control HKLM \ SYSTEM \ CurrentControlSet \ Enum \ root \ LEGACY_CBE VTSVC \ 0.000 \ Control # ActiveService HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Ty pe HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # St māksla HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Er rorControl HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Im agePath HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Di splayName HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Ob jectName HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc # Op t HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ Se curity HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ Se curity # Security HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # 0 HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # Count HKLM \ SYSTEM \ CurrentControlSet \ Services \ CbEvtSvc \ En um # NextInstance NotHarmful.Sysinternals Bluescreen Screen Saver C: \ WINDOWS \ SYSTEM32 \ BLPHCTV6J0EREL.SCR Trojan.Unclassified / CBEvtSvc C: \ WINDOWS \ SYSTEM32 \ CBEVTSVC.EXE C: \ WINDOWS \ Prefetch \ CBEVTSVC.EXE-2F4C36CD.pf Trojan.Unknown Izcelsme C: \ WINDOWS \ SYSTEM32 \ PHCTV6J0EREL.BMP Malwarebytes "Anti-Malware 1,19 Database versija: 924 Windows 5.1.2600 Service Pack 3 19:22:42 05/07/2008 mbam-log-7-5-2008 (19-22-42). txt Scan type: Full Scan (C: \ | D: \ | E: \ |) Objekti skenēts: 113.635 Pagājušo laiku: 42 minūte (s), 4 second (s) Memory Processes Inficētie: 0 Memory Modules Inficētie: 0 Registry Keys Inficētie: 1 Reģistra vērtības Inficētie: 0 Registry Data Items Infected: 2 Mapes Inficētie: 0 Faili Inficētie: 4 Atmiņas procesi Inficētie: (No ļaunprātīgs preces konstatētas) Memory Modules Inficētie: (No ļaunprātīgs preces konstatētas) Registry Keys Inficētie: HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Software iesniedzēju (Rogue.Multiple) -> Karantīnā ievietotie un svītrots veiksmīgi. Reģistra vērtības Inficētie: (No ļaunprātīgs preces konstatētas) Registry Data Items Infected: HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Labs: (0) -> Karantīnā ievietotie un svītrots veiksmīgi. HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Labs: (0) -> Karantīnā ievietotie un svītrots veiksmīgi. Mapes Inficētie: (No ļaunprātīgs preces konstatētas) Faili Inficētie: C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP2 \ A0000029.exe (Trojan.Downloader) -> Karantīnā ievietotie un svītrots veiksmīgi. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP2 \ A0000047.dll (Rogue.AntivirusXP2008) -> Karantīnā ievietotie un svītrots veiksmīgi. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP4 \ A0000262.exe (Trojan.Downloader) -> Karantīnā ievietotie un svītrots veiksmīgi. C: \ System Volume Information \ _restore (CB12E2D1-8CFA-4FCC-A08D-7A3A985B54E4) \ RP4 \ A0000485.dll (Rogue.AntivirusXP2008) -> Karantīnā ievietotie un svītrots veiksmīgi. JavaRa 1,08 Pārcelšanās Log.Report seko pēc līniju .------------------------------------ JavaRa atcelšanas procesā tika uzsākta 05 Sat Jul 19:49:54 2.008 Atrasts un noņemt: C: \ Program Files \ Java \ jre1.6.0_05Found un noņemt: SOFTWARE \ JavaSoft \ Java Runtime Environment \ 1.4Found un noņemt: SOFTWARE \ Classes \ JavaWebStart.isInstalled.1.5.0.0F ound un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_02Found un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_04Found un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_06Found un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_09Found un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_10Found un noņemt: Software \ JavaSoft \ Java2D \ 1.5.0_11Found un noņemt: SOFTWARE \ Classes \ JavaPlugin.150_02Found un noņemt: SOFTWARE \ Classes \ JavaPlugin.150_04Found un noņemt: SOFTWARE \ Classes \ JavaPlugin.150_06Found un noņemt: SOFTWARE \ Classes \ JavaPlugin.150_09Found un noņemt: SOFTWARE \ Classes \ JavaPlugin.150_10--------------------------------- --- Pabeigts ziņojumus. Thanks guys |
|
#6
| |||
| |||
| Need HijackThis log tagad. |
|
#7
| |||
| |||
| Ups sorry. Te tā ir: Logfile of Trend Micro HijackThis v2.0.2 Scan saglabāts 20:24:21, uz 05/07/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running procesiem: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe C: \ Program Files \ SPAMfighter \ sfus.exe C: \ Windows \ Explorer.exe C: \ WINDOWS \ AGRSMMSG.exe C: \ WINDOWS \ System32 \ OSD.EXE C: \ WINDOWS \ system32 \ SB.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ Program Files \ SPAMfighter \ SFAgent.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ rundll32.exe D: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe C: \ Program Files \ Messenger \ msmsgs.exe C: \ Program Files \ Amerikas Alerts \ UnitedAlerts.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe C: \ Program Files \ DNS \ btdna.exe C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ WINDOWS \ system32 \ sistray.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearch.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearchIndexer.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ WinZip \ WZQKPICK.EXE C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearchFilter.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://news.bbc.co.uk/sport1/hi/football/default.stm R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.toysrus.co.uk/ R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.toysrus.co.uk/ R3 - URLSearchHook: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (file missing) O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6,0 \ Reader \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8.333-CF10577473F7) - C: \ Program Files \ Google \ googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4.638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 3.0.1225.9868 \ s wg.dll O2 - BHO: MSN Search Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll O3 - Toolbar: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (file missing) O3 - Toolbar: MSN Search Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll O3 - Toolbar: & Google - (2318C2B1-4.965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ googletoolbar3.dll O4 - HKLM \ .. \ Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM \ .. \ Run: [OSD]% SystemRoot% \ System32 \ OSD.EXE O4 - HKLM \ .. \ Run: [SB] C: \ WINDOWS \ system32 \ SB.exe O4 - HKLM \ .. \ Run: [SynTPLpr] C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [SiSUSBRG] C: \ WINDOWS \ SiSUSBrg.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [reālā Monitor] C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe-s O4 - HKLM \ .. \ Run: [UserFaultCheck]% systemroot% \ system32 \ dumprep 0-u O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKLM \ .. \ Run: [SiSPower] Rundll32.exe SiSPower.dll, ModeAgent O4 - HKLM \ .. \ Run: [mmtask] "C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe" O4 - HKLM \ .. \ Run: [SPAMfighter Agent] "C: \ Program Files \ SPAMfighter \ SFAgent.exe" Update kavēšanās 60 O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,, BluetoothAuthenticationAgent O4 - HKLM \ .. \ Run: [SMrhcpv6j0erel] C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe" O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Program Files \ Messenger \ msmsgs.exe" / background O4 - HKCU \ .. \ Run: [Apvienotā Alerts] C: \ Program Files \ Amerikas Alerts \ UnitedAlerts.exe O4 - HKCU \ .. \ Run: [SWG] C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNS \ btdna.exe" O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-18 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User "SISTĒMA") O4 - HKUS \. DEFAULT \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O4 - Global Startup: Utility Tray.lnk = C: \ WINDOWS \ system32 \ sistray.exe O4 - Global Startup: Windows Desktop Search.lnk = C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearch.exe O4 - Global Startup: WinZip Quick Pick.lnk = C: \ Program Files \ WinZip \ WZQKPICK.EXE Ø8 - ārpus konteksta menu item: & Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsearch.html Ø8 - ārpus konteksta menu item: & ICQ Toolbar Search - res: / / C: \ Program Files \ ICQToolbar \ toolbaru.dll / search.html Ø8 - ārpus konteksta menu item: & MSN Search - res: / / C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll / search.htm Ø8 - ārpus konteksta izvēlnes vienums: Atpakaļsaites - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmbacklinks.html Ø8 - ārpus konteksta izvēlnes vienums: Cached Snapshot Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmcache.html Ø8 - ārpus konteksta menu item: E & ksportēt uz Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ Micros ~ 3 \ Office10 \ EXCEL.EXE/3000 Ø8 - ārpus konteksta izvēlnes vienums: Atvērt jaunā background tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ en-gb \ msntabres.dll/229? 4f61d6b2c8414b81896dc6b3a393b615 Ø8 - ārpus konteksta izvēlnes vienums: Atvērt jaunu zināšanu tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ en-gb \ msntabres.dll/230? 4f61d6b2c8414b81896dc6b3a393b615 Ø8 - ārpus konteksta izvēlnes vienums: Līdzīgas lapas - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsimilar.html Ø8 - ārpus konteksta izvēlnes vienums: Tulko angļu valodā - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmtrans.html Ø9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll Ø9 - Extra button: (no name) - (e2e2dd38-d088-4.134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe Ø9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20.001 - (e2e2dd38-d088-4.134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe Ø9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø9 - Extra button: Medion-UK - (CE67CBC2-5CCB-4FC4-BA83-51AE4878170C) -- http://www.medion.co.uk (file missing) (HKCU) Ø16 - DPF: RaptisoftGameLoader -- http://www.miniclip.com/hamsterball/...gameloader.cab Ø16 - DPF: (17.492.023-C23A-453E-A040-C7C580BBF700) (Windows Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?Link...04&clcid=0x409 Ø16 - DPF: (1803B9EF-9.905-4F34-AFC4-05D1BAB28801) (RegUserCfgUI klase) -- http://us.dl1.yimg.com/download.yaho...1/yregucfg.cab Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl klase) -- http://v5.windowsupdate.microsoft.co...?1106745510172 Ø16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl klase) -- http://www.update.microsoft.com/micr...?1215253028000 Ø16 - DPF: (B38870E4-7ECB-40DA-8C6A-595F0A5519FF) (MsnMessengerSetupDownloadControl klase) -- http://messenger.msn.com/download/Ms...Downloader.cab Ø16 - DPF: (BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B) (Zylom Spēles Player) -- http://game07.zylom.com/activex/zylomgamesplayer.cab Ø16 - DPF: (E8F628B5-259A-4.734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://driveragent.com/files/driveragent.cab Ø20 - Winlogon Paziņot:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe O23 - Service: eTrust Antivirus reālā Server (InoRT) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe O23 - Service: eTrust Antivirus Darbs Server (InoTask) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C: \ Program Files \ SPAMfighter \ sfus.exe -- End of failu - 10.438 bytes |
|
#8
| |||
| |||
| Vēl kādu darbu darīt. Lejupielādēt SDFix.exe un saglabājiet to savā datorā. Dubultklikšķis SDFix.exe un tā izrakstu failus uz% systemdrive% (Drive, kas satur Windows Direktoriju, parasti C: \ SDFix) Tagad tad pārstartējiet datoru Safe Mode darot šādi:
---------- Next Iesniegt sludinājumu SDFix log NEW HijackThis log |
|
#9
| |||
| |||
| OK Nākamais logs SDFix: Version 1,201 Vada Danny no 05/07/2008 at 21:08 Microsoft Windows XP [Version 5.1.2600] Running From: C: \ Dziesmas \ SDFix Checking Pakalpojumi : Atjaunot noklusējuma drošības Vērtības Atjaunot Default Hosts fails Rebooting Checking Files : Nē Trojan Files Found Noņemot Temp faili ADS Pārbaudīt : Galīgā pārbaude : catchme 0.3.1361.2 W2K/XP/Vista - rootkit / Stealth malware detektoru, ar Gmer, http://www.gmer.net Rootkit scan 2008/07/05 21:21:39 Windows 5.1.2600 Service Pack 3 NTFS skenēšana slēptās procesi ... skenēšana slēptās pakalpojumi un sistēmas stropa ... [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ BTHPORT \ Parameters \ Keys \ 000c55050b1d] [HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet003 \ Services \ B THPORT \ Parameters \ Keys \ 000c55050b1d] skenēšana slēptos reģistra ierakstus ... [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Prefetcher] "TracesProcessed" = DWORD: 000000aa "TracesSuccessful" = DWORD: 00000005 skenēšana slēptos failus ... scan sekmīgi pabeigta slēptās procesiem: 0 slēptās pakalpojumi: 0 slēptos failus: 0 Remaining Pakalpojumi : Authorized Application Key Export: [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ servic es \ sharedaccess \ Parameters \ firewallpolicy \ standarta profils \ authorizedapplications \ list] "% windir% \ \ system32 \ \ sessmgr.exe" = "% windir% \ \ syste M32 \ \ sessmgr.exe: *: enabled: @ xpsp2res.dll, -22.019" "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InoRpc.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InoRpc.exe: *: Enabled: eTrust Antivirus - RPC Server " "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InocIT.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ InocIT.exe: *: Enabled: eTrust Antivirus - Vietējās Scanner " "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Realmon.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Realmon.exe: *: Enabled: eTrust Antivirus - reālā kontrolēt " "C: \ \ Program Files \ \ Messenger \ \ msmsgs.exe" = "C: \ \ Program Files \ \ Messenger \ \ msmsgs.exe: *: Enabled: Windows Messenger" "C: \ \ Program Files \ \ Amerikas Alerts \ \ UnitedAlerts.exe" = "C: \ \ Program Files \ \ Amerikas Alerts \ \ UnitedAlerts.exe" "C: \ \ Program Files \ \ ICQ \ \ Icq.exe" = "C: \ \ Program Files \ \ ICQ \ \ Icq.exe: *: Enabled: ICQ" "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Shellscn.exe" = "C: \ \ Program Files \ \ CA \ \ eTrust Antivirus \ \ Shellscn.exe: *: Enabled: Shellscn" "C: \ \ Program Files \ \ iTunes \ \ iTunes.exe" = "C: \ \ Program Files \ \ iTunes \ \ iTunes.exe: *: Enabled: iTunes" "C: \ \ StubInstaller.exe" = "C: \ \ StubInstaller.exe: *: E nabled: limewire swarmed uzstādītājam" "C: \ \ Program Files \ \ limewire \ \ LimeWire.exe" = "C: \ \ Program Files \ \ limewire \ \ LimeWire.exe: *: Enabled: limewire" "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe: *: Enabled: MSN Messenger 7.5" "C: \ \ Program Files \ \ BitTorrent_DNA \ \ dna.exe" = "C: \ \ Program Files \ \ BitTorrent_DNA \ \ dna.exe: *: Enabled: BitTorren t DNS" "C: \ \ Program Files \ \ DNS \ \ btdna.exe" = "C: \ \ Program Files \ \ DNS \ \ btdna.exe: *: Enabled: DNS" "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe: *: Enabled: @ xpsp3res.dll, -20.000" [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ servic es \ sharedaccess \ Parameters \ firewallpolicy \ domainpr ofile \ authorizedapplications \ list] "% windir% \ \ system32 \ \ sessmgr.exe" = "% windir% \ \ syste M32 \ \ sessmgr.exe: *: enabled: @ xpsp2res.dll, -22.019" "C: \ \ Program Files \ \ Amerikas Alerts \ \ UnitedAlerts.exe" = "C: \ \ Program Files \ \ Amerikas Alerts \ \ UnitedAlerts.exe" "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ MSN Messenger \ \ msnmsgr.exe: *: Enabled: MSN Messenger 7.5" "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe: *: Enabled: @ xpsp3res.dll, -20.000" Remaining Faili : Failus ar Slēpts Rekvizīti : Treš 26 janvāris 2005 4.704 A.SH. --- "C: \ WINDOWS \ system32 \ KGyGaAvL.sys" Treš 13 jūlijs 2005 4.348 .. SH. --- "C: \ Documents and Settings \ All Users \ DRM \ DRMv1.bak" Sest 5 jūlijs 2008 0 A.SH. --- "C: \ Documents and Settings \ All Users \ DRM \ Cache \ Indiv01.tmp" Pirm 13 jūnijs 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ Mar15.tmp" Pirm 13 jūnijs 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ Mar9.tmp" Pirm 13 jūnijs 2005 7.420 A.. H. --- "C: \ Documents and Settings \ Rozzie \ Local Settings \ Temp \ MarA.tmp" Sest 5 jūlijs 2008 96 A.. H. --- "C: \ Documents and Settings \ All Users \ Application Data \ avg8 (2) \ scanlogs \ srmcheck.tmp" Treš 13 jūlijs 2005 4.348 ... H. --- "C: \ Documents and Settings \ Denijs \ My Documents \ My Music \ License Backup \ drmv1key.bak" Treš 25 janvāris 2006 20 A.. H. --- "C: \ Documents and Settings \ Denijs \ My Documents \ My Music \ License Backup \ drmv1lic.bak" Treš 13 jūlijs 2005 312 A.SH. --- "C: \ Documents and Settings \ Denijs \ My Documents \ My Music \ License Backup \ drmv2key.bak" Noslēgusies! un Logfile of Trend Micro HijackThis v2.0.2 Scan saglabāts 21:33:52, uz 05/07/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running procesiem: C: \ WINDOWS \ System32 \ Smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ WINDOWS \ system32 \ Spoolsv.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe C: \ Program Files \ SPAMfighter \ sfus.exe C: \ Windows \ Explorer.exe C: \ WINDOWS \ AGRSMMSG.exe C: \ WINDOWS \ System32 \ OSD.EXE C: \ WINDOWS \ system32 \ SB.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ Program Files \ SPAMfighter \ SFAgent.exe C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ rundll32.exe D: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe C: \ Program Files \ Messenger \ msmsgs.exe C: \ Program Files \ Amerikas Alerts \ UnitedAlerts.exe C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe C: \ Program Files \ DNS \ btdna.exe C: \ WINDOWS \ system32 \ wuauclt.exe C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ WINDOWS \ system32 \ sistray.exe C: \ WINDOWS \ system32 \ Msiexec.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearch.exe C: \ Program Files \ WinZip \ WZQKPICK.EXE C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearchIndexer.exe C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearchFilter.exe C: \ Program Files \ Internet Explorer \ iexplore.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://news.bbc.co.uk/sport1/hi/football/default.stm R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.toysrus.co.uk/ R1 - HKCU \ Software \ Microsoft \ Internet Connection Wizard, ShellNext = http://www.toysrus.co.uk/ R3 - URLSearchHook: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (file missing) O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6,0 \ Reader \ ActiveX \ AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin Internet Explorer - (3049C3E9-B461-4BC5-8870-4C09146192CA) - C: \ Program Files \ Real \ RealPlayer \ rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8.333-CF10577473F7) - C: \ Program Files \ Google \ googletoolbar3.dll O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4.638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 3.0.1225.9868 \ s wg.dll O2 - BHO: MSN Search Toolbar Helper - (BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll O3 - Toolbar: ICQ Toolbar - (855F3B16-6D32-4fe6-8A56-BBB695989046) - C: \ Program Files \ ICQToolbar \ toolbaru.dll (file missing) O3 - Toolbar: MSN Search Toolbar - (BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0) - C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll O3 - Toolbar: & Google - (2318C2B1-4.965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ googletoolbar3.dll O4 - HKLM \ .. \ Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM \ .. \ Run: [OSD]% SystemRoot% \ System32 \ OSD.EXE O4 - HKLM \ .. \ Run: [SB] C: \ WINDOWS \ system32 \ SB.exe O4 - HKLM \ .. \ Run: [SynTPLpr] C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe O4 - HKLM \ .. \ Run: [SiSUSBRG] C: \ WINDOWS \ SiSUSBrg.exe O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe O4 - HKLM \ .. \ Run: [reālā Monitor] C: \ PROGRA ~ 1 \ CA \ eTrust ~ 1 \ realmon.exe-s O4 - HKLM \ .. \ Run: [UserFaultCheck]% systemroot% \ system32 \ dumprep 0-u O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKLM \ .. \ Run: [SiSPower] Rundll32.exe SiSPower.dll, ModeAgent O4 - HKLM \ .. \ Run: [mmtask] "C: \ Program Files \ MusicMatch \ MusicMatch Jukebox \ mmtask.exe" O4 - HKLM \ .. \ Run: [SPAMfighter Agent] "C: \ Program Files \ SPAMfighter \ SFAgent.exe" Update kavēšanās 60 O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Common Files \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKLM \ .. \ Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,, BluetoothAuthenticationAgent O4 - HKLM \ .. \ Run: [SMrhcpv6j0erel] C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ jusched.exe" O4 - HKCU \ .. \ Run: [MSMSGS] "C: \ Program Files \ Messenger \ msmsgs.exe" / background O4 - HKCU \ .. \ Run: [Apvienotā Alerts] C: \ Program Files \ Amerikas Alerts \ UnitedAlerts.exe O4 - HKCU \ .. \ Run: [SWG] C: \ Program Files \ Google \ GoogleToolbarNotifier \ GoogleToolbarNo tifier.exe O4 - HKCU \ .. \ Run: [BitTorrent DNA] "C: \ Program Files \ DNS \ btdna.exe" O4 - HKCU \ .. \ Run: [WMPNSCFG] C: \ Program Files \ Windows Media Player \ WMPNSCFG.exe O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKUS \ S-1-5-18 \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User "SISTĒMA") O4 - HKUS \. DEFAULT \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ CTFMON.EXE (User 'Default user') O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O4 - Global Startup: Utility Tray.lnk = C: \ WINDOWS \ system32 \ sistray.exe O4 - Global Startup: Windows Desktop Search.lnk = C: \ Program Files \ MSN Toolbar Suite \ DS \ 02.05.0001.1119 \ en-gb \ bin \ WindowsSearch.exe O4 - Global Startup: WinZip Quick Pick.lnk = C: \ Program Files \ WinZip \ WZQKPICK.EXE Ø8 - ārpus konteksta menu item: & Google Search - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsearch.html Ø8 - ārpus konteksta menu item: & ICQ Toolbar Search - res: / / C: \ Program Files \ ICQToolbar \ toolbaru.dll / search.html Ø8 - ārpus konteksta menu item: & MSN Search - res: / / C: \ Program Files \ MSN Toolbar Suite \ TB \ 02.05.0000.1082 \ en-gb \ msntb.dll / search.htm Ø8 - ārpus konteksta izvēlnes vienums: Atpakaļsaites - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmbacklinks.html Ø8 - ārpus konteksta izvēlnes vienums: Cached Snapshot Page - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmcache.html Ø8 - ārpus konteksta menu item: E & ksportēt uz Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ Micros ~ 3 \ Office10 \ EXCEL.EXE/3000 Ø8 - ārpus konteksta izvēlnes vienums: Atvērt jaunā background tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ en-gb \ msntabres.dll/229? 4f61d6b2c8414b81896dc6b3a393b615 Ø8 - ārpus konteksta izvēlnes vienums: Atvērt jaunu zināšanu tab - res: / / C: \ Program Files \ MSN Toolbar Suite \ TAB \ 02.05.0001.1119 \ en-gb \ msntabres.dll/230? 4f61d6b2c8414b81896dc6b3a393b615 Ø8 - ārpus konteksta izvēlnes vienums: Līdzīgas lapas - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmsimilar.html Ø8 - ārpus konteksta izvēlnes vienums: Tulko angļu valodā - res: / / C: \ Program Files \ Google \ GoogleToolbar1.dll/cmtrans.html Ø9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll Ø9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_06 \ bin \ ssv.dll Ø9 - Extra button: (no name) - (e2e2dd38-d088-4.134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe Ø9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20.001 - (e2e2dd38-d088-4.134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe Ø9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe Ø9 - Extra button: Medion-UK - (CE67CBC2-5CCB-4FC4-BA83-51AE4878170C) -- http://www.medion.co.uk (file missing) (HKCU) Ø16 - DPF: RaptisoftGameLoader -- http://www.miniclip.com/hamsterball/...gameloader.cab Ø16 - DPF: (17.492.023-C23A-453E-A040-C7C580BBF700) (Windows Genuine Advantage Validation Tool) -- http://go.microsoft.com/fwlink/?Link...04&clcid=0x409 Ø16 - DPF: (1803B9EF-9.905-4F34-AFC4-05D1BAB28801) (RegUserCfgUI klase) -- http://us.dl1.yimg.com/download.yaho...1/yregucfg.cab Ø16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl klase) -- http://v5.windowsupdate.microsoft.co...?1106745510172 Ø16 - DPF: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) (MUWebControl klase) -- http://www.update.microsoft.com/micr...?1215253028000 Ø16 - DPF: (B38870E4-7ECB-40DA-8C6A-595F0A5519FF) (MsnMessengerSetupDownloadControl klase) -- http://messenger.msn.com/download/Ms...Downloader.cab Ø16 - DPF: (BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B) (Zylom Spēles Player) -- http://game07.zylom.com/activex/zylomgamesplayer.cab Ø16 - DPF: (E8F628B5-259A-4.734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://driveragent.com/files/driveragent.cab Ø20 - Winlogon Paziņot:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRpc.exe O23 - Service: eTrust Antivirus reālā Server (InoRT) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoRT.exe O23 - Service: eTrust Antivirus Darbs Server (InoTask) - Computer Associates International, Inc - C: \ Program Files \ CA \ eTrust Antivirus \ InoTask.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C: \ Program Files \ SPAMfighter \ sfus.exe -- End of failu - 10.422 bytes |
|
#10
| |||
| |||
| Man ir nepieciešams vairāk informācijas par pāris failus. Post šeit saites uz rezultātiem, kad pabeigta. Scan Aizdomīgie File (s) Visit Virustotal (Ja vairāk nekā vienu failu vajadzībām skenētas tie jāveic atsevišķi un žurnāliem ievietojis katram vienam)
Kods: C: \ Program Files \ rhcpv6j0erel \ rhcpv6j0erel.exe
Kods: C: \ Program Files \ Amerikas Alerts \ UnitedAlerts.exe |
![]() |
|
| Bookmarks |
Similar Threads | ||||
| Pavediens | Thread Starter | Forums | Replies | Last Post |
| Kaspersky Antivirus 2009, ESET NOD32 Antivirus, McAfee VirusScan Enterprise | runoades | Vīrusu, spiegprogrammatūru un drošība | 2 | 3 decembris 2008 13:54 |
| AntiVirus XP 2008!! | ParsleyAigh | Vīrusu, spiegprogrammatūru un drošība | 53 | 3 septembris, 2008 16:28 |
| WinPatrol 2.008 | evilfantasy | Vīrusu, spiegprogrammatūru un drošība | 0 | 25 aprīlis 2008 16:03 |
| Wooohhhhhooooooooo !!!!!!!!!!! 2.008 !!!!!!!! | cheesewheels99 | Off Topic Discussion | 4 | 7 janvāris 2008 07:52 |
| Best Antivirus | Vlad | Vīrusu, spiegprogrammatūru un drošība | 29 | 10 oktobris 2007 12:47 |
| Thread Tools | |
| |