kisebb-sajáttőke

Magazine
Go Back   Számítógép Juice > Számítógépes szoftver > Vírus, kémprogram és biztonság

Register


 Default 

Fertőzött MultiPacked.Multi.Generic Malware!




Reply
 
Téma eszközök
  #1  
Old Június 23 2009, 10:38
Csoport tagja
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Nemrég letöltött egy témát kérelmet. A telepítés, a Kaspersky kéri a riasztási mondván számítógép fertőzött MultiPacked.Multi.Generic malware. Saját Kaspersky abbahagyta, és a windows téma ment-Beragadtam Windows klasszikus. Segíts kérlek!
  #2  
Old Június 23 2009, 11:25
Moderátor Csoport
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Próbálj meg minden a naplók segítségével innen. http://www.computer-juice.com/forums...-posting-7476/
__________________

  #3  
Old Június 24 2009, 11:44
Moderátor Csoport
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Úgy néz ki, mint a fórum volt a hiba. Kérem elküldeni ezeket DDS logs.

Letöltés DDS tól | ITT | vagy | ITT | vagy | ITT | és menthetjük az asztalra.

Vista felhasználóinak jobb klikk a DDS és válasszuk a Futtatás rendszergazdaként (kap egy UAC gyors, kérjük, amely lehetővé teszi)

* XP Duplakattintásra DDS futtatni azt.
* Ha a víruskereső és tűzfal blokkolja próbálja DDS akkor kérjük, hogy ne fuss.
* Amikor befejezte DDS nyílik a két (2) logs.

1) DDS.txt
2) Attach.txt

* Ment naplófájlokhoz mind az asztalra.
* Kérjük másolja be az egész tartalmát is bejelentkezik a következő választ.

Megjegyzés: DDS fog oktatni, hogy a post Attach.txt naplót letiltatni.
Kérjük, csak postai úton, mint amit bármely más, a napló másolatát és beilleszteni a válasz.
__________________

  #4  
Old Június 24 2009, 13:55
Csoport tagja
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

DDS (Ver_09-05-14,01) - NTFSx86
Által működtetett Egér a 16:53:23.36, sze 06/24/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1294 [GMT -4:00]

AV: Kaspersky Internet Security * On-hozzáférés szkennelés fogyatékkal * (Frissítve) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security engedélyezve * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)

============== Futó folyamatokat ===============

C: \ WINDOWS \ System32 \ Svchost-k DcomLaunch
Svchost.exe
C: \ WINDOWS \ System32 \ Svchost.exe-k netsvcs
C: \ WINDOWS \ System32 \ Svchost.exe-k WudfServiceGroup
Svchost.exe
C: \ WINDOWS \ System32 \ Spoolsv.exe
C: \ Program Files \ Creative \ Shared Files \ CTAudSvc.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ System32 \ CTHELPER.EXE
C: \ WINDOWS \ System32 \ CTXFIHLP.EXE
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE
C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ kötet Panel \ VolPanlu.exe
C: \ WINDOWS \ System32 \ Rundll32.exe
C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe
C: \ Program Files \ iTunes \ iTunesHelper.exe
C: \ WINDOWS \ SYSTEM32 \ CTXFISPI.EXE
C: \ WINDOWS \ System32 \ Ctfmon.exe
C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe
C: \ PROGRA ~ 1 \ mikrók ~ 4 \ rapimgr.exe
Svchost.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
C: \ WINDOWS \ System32 \ nvsvc32.exe
C: \ WINDOWS \ System32 \ PnkBstrA.exe
C: \ WINDOWS \ System32 \ Svchost.exe-k imgsvc
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Entertainment Center \ EAXLoadr.exe
C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
C: \ WINDOWS \ System32 \ Svchost.exe-k HTTPFilter
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ LimeWire \ LimeWire.exe
C: \ Documents and Settings \ Mouse \ Desktop \ dds.com

============== Pseudo HJT Jelentés ===============

uStart page = hxxp: / / google.com /
uInternet Beállítások, ProxyOverride = *. helyi
BHO: Adobe PDF Reader Link Helper (06849e9f-c8d7-4d59-b87d-784b7d6be0b3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
BHO: Skype add-on (koponya) (22bf413b-c6d2-4d91-82a9-a0f997ba588c) - C: \ Program Files \ Skype \ Eszköztárak \ Internet Explorer \ SkypeIEPlugin.dll
BHO: IEVkbdBHO Class: (59273ab4-e7d3-40f9-a1a8-6fa9cca1862c) - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ievkbd.dll
BHO: Java (TM) Plug-In SSV Helper 2: (dbc80044-a445-435b-bc74-9c25c1c588a9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: (e7e6f031-17ce-4c07-bc86-eabfe594f69c) - C: \ Program Files \ Java \ jre6 \ lib \ bevethet \ jqs \ IE \ jqs_plugin.dll
TB: Veoh Browser Plug-in: (d0943516-5076-4020-a3b5-aefaf26ab263) - C: \ Program Files \ veoh hálózatok \ veoh \ plugins \ reg \ VeohToolbar.dll
EB: (32683183-48a0-441b-a342-7c2a440a9478) - No File
uRun: [Ctfmon.exe] C: \ Windows \ System32 \ Ctfmon.exe
uRun: [H / PC Connection Agent] "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe"
mRun: [NvCplDaemon] Rundll32.exe C: \ Windows \ System32 \ NvCpl.dll, NvStartup
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [CTDVDDET] "C: \ Program Files \ kreatív \ Sound Blaster X-Fi \ dvdaudio \ CTDVDDET.EXE"
mRun: [RCSystem] "C: \ Program Files \ kreatív \ megosztott fájlokat \ module loader \ DLLML.exe" RCSystem *-Indítópult
mRun: [AudioDrvEmulator] "C: \ Program Files \ kreatív \ megosztott fájlokat \ module loader \ dllml.exe" -1 audiodrvemulator "C: \ Program Files \ kreatív \ megosztott fájlokat \ module loader \ audio emulator \ AudDrvEm.dll"
mRun: [VolPanel] "C: \ Program Files \ kreatív \ Sound Blaster X-Fi \ hangerõnövelõ Panel \ VolPanlu.exe" / r
mRun: [NvMediaCenter] Rundll32.exe C: \ Windows \ System32 \ NvMcTray.dll, NvTaskbarInit
mRun: [AVP] "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe"
mRun: [QuickTime Task] "C: \ Program Files \ QuickTime \ QTTask.exe"-atboottime
mRun: [AppleSyncNotifier] C: \ Program Files \ Common Files \ Apple \ mobilkészülék Support \ bin \ AppleSyncNotifier.exe
mRun: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
IE: Add hozzá a Szalaghirdetés blokkolása - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportálás a Microsoft Excel - C: \ PROGRA ~ 1 \ mikrók ~ 2 \ Office10 \ EXCEL.EXE/3000
IE: (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe
IE: (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
IE: (1F460357-8A94-4D71-9CA3-AA4ACF32ED8E) - (85E0B171-04FA-11D1-B7DA-00A0C90348D6) - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ SCIEPlgn.dll
IE: (2EAF5BB1-070F-11D3-9307-00C04FAE2D4F) - (2EAF5BB0-070F-11D3-9307-00C04FAE2D4F) - C: \ PROGRA ~ 1 \ mikrók ~ 4 \ INetRepl.dll
IE: (2EAF5BB2-070F-11D3-9307-00C04FAE2D4F) - (2EAF5BB0-070F-11D3-9307-00C04FAE2D4F) - C: \ PROGRA ~ 1 \ mikrók ~ 4 \ INetRepl.dll
IE: (77BF5300-1474-4EC7-9980-D32B190E9B07) - (77BF5300-1474-4EC7-9980-D32B190E9B07) - C: \ Program Files \ Skype \ Eszköztárak \ Internet Explorer \ SkypeIEPlugin.dll
DPF: A Microsoft XML Parser for Java - file: / / c: \ windows \ Java \ classes \ xmldso.cab
DPF: (17492023-C23A-453E-A040-C7C580BBF700) - hxxp: / / go.microsoft.com / fwlink /? Linkid = 39204
DPF: (45B69029-F3AB-4204-92DE-D5140C3E8E74) - hxxps: / / portal.apogentech.com / vdesk / terminál / InstallerControl.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
DPF: (57C76689-F052-487B-A19F-855AFDDF28EE) - hxxps: / / portal.apogentech.com/vdesk/terminal/f5InspectionHost.cab # version = 6030,2008,0904,1939
DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: (CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) - hxxp: / / java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: (E615C9EA-AD69-4AE9-83C9-9D906A0ACA6D) - hxxps: / / portal.apogentech.com/policy/download_binary.php/win32/f5syschk.cab # Version = 6030,2008,0904,1947
Handler: cdo - (CD00020A-8B95-11D1-82dB-00C04FB1625D) - C: \ Program Files \ Common Files \ Microsoft Shared \ Webmappák \ PKMCDO.DLL
Handler: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ PROGRA ~ 1 \ Common ~ 1 \ Skype \ SKYPE4 ~ 1.DLL
Értesítés:! SASWinLogon - C: \ Program Files \ superantispyware \ SASWINLO.DLL
Értesítés: klogon - C: \ Windows \ System32 \ klogon.dll
AppInit_DLLs: c: \ PROGRA ~ 1 \ Kasper ~ 1 \ Kasper ~ 1 \ mzvkbd.dll, C: \ PROGRA ~ 1 \ Kasper ~ 1 \ Kasper ~ 1 \ adialhk.dll, C: \ PROGRA ~ 1 \ r kaspe ~ 1 \ Kasper ~ 1 \ kloehk.dll
SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ Windows \ System32 \ WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: (5ae067d3-9afb-48e0-853a-ebb7f4a000da) - C: \ Program Files \ superantispyware \ SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath --

============= SZOLGÁLTATÁSAINK / drivers ===============

R0 kl1; Kl1, C: \ Windows \ System32 \ Drivers \ kl1.sys [2007-10-31 112144]
R0 klbg; Kaspersky Lab Boot Guard Illesztőprogram c: \ Windows \ System32 \ Drivers \ klbg.sys [2008-1-29 33808]
R1 klif; Kaspersky Lab Illesztőprogram c: \ Windows \ System32 \ Drivers \ klif.sys [2008-4-18 213520]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ superantispyware \ SASKUTIL.SYS [2008-2-29 55024]
R1 UGURU; UGURU, C: \ Windows \ System32 \ Drivers \ uGuru.sys [2008-5-12 14592]
R2 AVP, Kaspersky Internet Security, C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe-r -> c: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe-r [? ]
R2 Viewpoint Manager Service; Viewpoint Service Manager, C: \ Program Files \ szempontból \ Common \ ViewpointService.exe [2008-12-7 24652]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, C: \ Windows \ System32 \ Drivers \ klfltdev.sys [2008-3-13 26640]
R3 klim5, a Kaspersky Anti-Virus NDIS Filter; c: \ Windows \ System32 \ Drivers \ klim5.sys [2007-12-13 24592]
R3 SASENUM; SASENUM, C: \ Program Files \ superantispyware \ SASENUM.SYS [2006-2-16 4096]
S1 SASDIFSV; SASDIFSV, C: \ Program Files \ superantispyware \ SASDIFSV.SYS [2008-2-29 9968]
S2 Cubase32; Cubase32, C: \ Windows \ System32 \ Drivers \ Kuba se32.sys [2009-4-5 11808]
S3 IlvMoneyDRIVER53; IlvMoneyDRIVER53 c: \ windows \ syste M32 \ Drivers \ IlvMoney1215.sys [2008-8-21 30080]

=============== Létrehozva Utolsó 30 ================

2009-06-17 13:58 <DIR> - d ----- C: \ Program Files \ LSoft Technologies
2009-06-13 12:32 <DIR> - d ----- C: \ Program Files \ iPod
2009-06-13 12:32 <DIR> - d ----- C: \ Program Files \ iTunes

==================== Find3M ====================


============= CÉL: 16:54:12.42 ===============


Kivéve ha külön utasítást, nem felad Ez a log.
KÉRÉSÉRE, ZIP IT UP & csatolja

DDS (Ver_09-05-14,01)

Microsoft Windows XP Professional
Indító eszköz: \ Device \ HarddiskVolume1
Telepítés dátuma: 5/12/2008 2:38:20 PM
System Uptime: 6/24/2009 12:33:35 PM (4 óra)

Alaplap: http://www.abit.com.tw/ | | IP35 PRO (P35 + ICH9R)
Processzor: Intel (R) Pentium (R) 4 CPU 2.80GHz | Socket 775 | 3024/216mhz

==== Lemezkarbantartó Partitions =========================

V: eltávolítható
C: van rögzítve (NTFS) - 128 GIB összesen 60,146 GIB ingyenes.
D: FIXED (NTFS) - 69 GIB összesen 60,479 GIB ingyenes.
E: a CD-ROM (CDFS)
F: is CDROM (CDFS)
G: rögzítették (NTFS) - 245 GIB összesen 138,326 GIB ingyenes.
H: a CD-ROM ()
I: a CD-ROM ()
J: a CD-ROM ()
K: CDROM ()

==== Disabled Eszközkezelőt Items =============

Class GUID: (4D36E972-E325-11CE-BFC1-08002BE10318)
Leírás: Realtek RTL8169/8110 Family Gigabit Ethernet NIC
Device ID: PCI \ VEN_10EC & DEV_8167 & SUBSYS_1083147B & REV_10 \ 4 & BB2 9FA6 & 0 & 00F0
Gyártó: Realtek Semiconductor Corp.
Név: Realtek RTL8169/8110 Family Gigabit Ethernet NIC # 3
PNP Device ID: PCI \ VEN_10EC & DEV_8167 & SUBSYS_1083147B & REV_10 \ 4 & BB2 9FA6 & 0 & 00F0
Szolgáltatás: RTL8023xp

Class GUID: (4D36E972-E325-11CE-BFC1-08002BE10318)
Leírás: A MAC-híd miniport
Device ID: ROOT \ MS_BRIDGEMP \ 0000
Gyártó: Microsoft
Név: MAC Bridge miniport
PNP Device ID: ROOT \ MS_BRIDGEMP \ 0000
Szolgáltatás: BridgeMP

==== Rendszer visszaállítási pontok ===================

RP202: 3/26/2009 6:14:01 PM - System Checkpoint
RP203: 3/27/2009 9:06:08 PM - System Checkpoint
RP204: 3/30/2009 12:43:20 PM - System Checkpoint
RP205: 4/1/2009 5:11:23 PM - System Checkpoint
RP206: 4/3/2009 3:31:49 PM - System Checkpoint
RP207: 4/6/2009 11:30:33 PM - System Checkpoint
RP208: 4/8/2009 1:48:55 AM - Removed MapleStory GL.
RP209: 4/8/2009 1:49:05 AM - Telepített MapleStory.
RP210: 4/8/2009 2:00:33 AM - Removed MapleStory.
RP211: 4/8/2009 2:12:11 AM - Telepített MapleStory.
RP212: 4/9/2009 1:53:58 PM - System Checkpoint
RP213: 4/11/2009 6:22:36 AM - System Checkpoint
RP214: 4/14/2009 11:18:28 AM - System Checkpoint
RP215: 4/15/2009 5:50:23 PM - Software Distribution Service 3,0
RP216: 4/18/2009 1:32:37 AM - System Checkpoint
RP217: 4/21/2009 2:37:36 PM - System Checkpoint
RP218: 4/22/2009 5:07:27 PM - System Checkpoint
RP219: 4/24/2009 2:41:28 PM - System Checkpoint
RP220: 4/25/2009 10:07:27 PM - System Checkpoint
RP221: 4/28/2009 6:48:10 AM - telepített Java (TM) 6 Update 13
RP222: 5/2/2009 7:23:06 PM - System Checkpoint
RP223: 5/3/2009 11:36:18 PM - System Checkpoint
RP224: 5/5/2009 2:29:10 PM - System Checkpoint
RP225: 5/6/2009 8:29:33 PM - System Checkpoint
RP226: 5/7/2009 3:00:17 AM - Software Distribution Service 3,0
RP227: 5/7/2009 11:16:03 PM - Telepített Windows XP WgaNotify.
RP228: 5/9/2009 11:12:42 PM - System Checkpoint
RP229: 5/10/2009 5:10:12 PM - System Checkpoint
RP230: 5/11/2009 9:02:07 PM - System Checkpoint
RP231: 5/13/2009 12:26:07 AM - Software Distribution Service 3,0
RP232: 5/14/2009 2:28:00 PM - Removed ZU-ONLINE
RP233: 5/15/2009 2:47:49 PM - System Checkpoint
RP234: 5/17/2009 1:28:31 AM - System Checkpoint
RP235: 5/17/2009 4:58:00 PM - Telepített LG USB Modem driver
RP236: 5/19/2009 11:34:48 AM - System Checkpoint
RP237: 5/20/2009 12:47:48 PM - System Checkpoint
RP238: 5/23/2009 10:08:08 AM - System Checkpoint
RP239: 6/1/2009 10:03:10 PM - System Checkpoint
RP240: 6/2/2009 10:03:30 PM - System Checkpoint
RP241: 6/3/2009 11:47:56 PM - System Checkpoint
RP242: 6/5/2009 11:10:53 PM - System Checkpoint
RP243: 6/7/2009 2:46:24 PM - System Checkpoint
RP244: 6/9/2009 11:32:41 PM - System Checkpoint
RP245: 6/10/2009 5:52:30 PM - System Checkpoint
RP246: 6/10/2009 11:00:09 PM - Software Distribution Service 3,0
RP247: 6/12/2009 12:14:34 PM - System Checkpoint
RP248: 6/13/2009 1:12:33 PM - System Checkpoint
RP249: 6/14/2009 9:20:14 PM - System Checkpoint
RP250: 6/15/2009 9:53:46 PM - System Checkpoint
RP251: 6/17/2009 12:27:01 AM - System Checkpoint
RP252: 6/21/2009 7:28:06 PM - System Checkpoint
RP253: 6/22/2009 8:08:50 PM - System Checkpoint
RP254: 6/23/2009 2:54:41 PM - Removed Garmin City Navigator NT Észak-Amerika 2009-frissítés
RP255: 6/23/2009 2:58:20 PM - Removed palmOne
RP256: 6/24/2009 3:58:18 PM - System Checkpoint

Telepített programok ==== ======================


==== Eseménynapló üzenetek Múlt hét ========


==== End Of File ===========================
  #5  
Old Június 24 2009, 14:05
Moderátor Csoport
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Letöltés ComboFix © subs az egyik a lenti linkeket. Győződjön meg róla, top menteni a Desktop.

Link # 1
Link # 2

** Megjegyzés: Fontos, hogy a telefon közvetlenül az asztalra

NEM távon ez még!

Megjegyzés: Az alábbi utasításokat hoztak létre külön erre a felhasználót. Ha nem ez a felhasználó, NEM alábbi irányokba, mivel azok károsíthatják a működését a rendszer

Törölje ezeket a fájlokat / mappákat, az alábbiak szerint:

1. Menj a Start > Fut > Type Notepad.exe , és kattintson OK megnyitásához Jegyzettömbbe.
Azt kell a Jegyzettömb, nem Wordpad.
2. Másolja az alábbi szöveget a kód mezőbe, kiemelve az összes szöveget, és nyomja meg Ctrl + C

Kód:
Killall: DDS: uInternet Beállítások, ProxyOverride = *. helyi EB: (32683183-48a0-441b-a342-7c2a440a9478) - No File Explorer: (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll Driver: Viewpoint Manager Service Folder:: C: \ Program Files \ szempontból
3. Ugrás a Jegyzettömb ablak, és kattintson Szerkesztés > Beillesztés
4. Ezután kattintson a Fájl > Ment
5. A fájl neve CFScript.txt - Mentsük a fájlt az asztalra
6. Ezután húzza a CFScript (tartsuk lenyomva a bal egérgombot, miközben húzza a fájlt), és dobja el (engedje el a bal egérgombot) a ComboFix.exe mint látod a screenshot alább. Fontos: Végezze el ezt az utasítást figyelmesen!



ComboFix kezdődik végrehajtásához, kövesse az instrukciókat.
Újraindítás után (amennyiben azt kéri, hogy reboot), majd egy naplót az Ön számára.
Post hogy log (Combofix.txt) a következő választ.

Megjegyzés: Ne mouseclick ComboFix az ablakon, miközben az fut. Ezt okozhatja a rendszer befagyasztja
__________________

  #6  
Old Június 25 2009, 08:45
Csoport tagja
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Egér 06/24/2009 17:18.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1452 [GMT -4:00]
Running From: c: \ documents and settings \ Mouse \ Desktop \ ComboFix.exe
Command kapcsolók használhatók: c: \ documents and settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-hozzáférés szkennelés fogyatékkal * (Frissítve) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security engedélyezve * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

Egyéb ((((((((((((((((((((((((((((((((((((((( Törlések ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

C: \ Program Files \ szempontból
c: \ újrahasznosítóhoz \ S-1-5-21-1957994488-1801674531-1177238915-1004
c: \ újrahasznosítóhoz \ S-1-5-21-789336058-2025429265-1644491937-1003
C: \ Windows \ System32 \ Drivers \ kl1.sys
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ Program Files \ szempontból \ Common \ ViewpointService.exe
C: \ Program Files \ szempontból \ Common \ VistaBoot.sdll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ AxMetaStream.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ ClassIDs.ini
C: \ Program Files \ szempontból \ Viewpoint Media Player \ ComponentMgr.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ MetaStreamID.ini
C: \ Program Files \ szempontból \ Viewpoint Media Player \ MtsAxInstaller.exe
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ AOLUserShell.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ Cursors.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ JpegReader.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ Mts3Reader.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ SceneComponent.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ SreeDMMX.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ SWFView.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ VETScriptInterpreter.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ VMPSpeech.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ NewComponents \ VMPVideo2.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ npViewpoint.dll
C: \ Program Files \ szempontból \ Viewpoint Media Player \ npViewpoint.xpt
c: \ újrahasznosítóhoz \ S-1-5-21-1957994488-1801674531-1177238915-1004 \ Desktop.ini
c: \ újrahasznosítóhoz \ S-1-5-21-1957994488-1801674531-1177238915-1004 \ Info2
c: \ újrahasznosítóhoz \ S-1-5-21-789336058-2025429265-1644491937-1003 \ Desktop.ini
c: \ újrahasznosítóhoz \ S-1-5-21-789336058-2025429265-1644491937-1003 \ Info2
c: \ windows \ emMON.exe
c: \ Windows \ System32 \ Codecs \ 7zAES.dll
c: \ Windows \ System32 \ Codecs \ AES.dll
c: \ Windows \ System32 \ Codecs \ Branch.dll
c: \ Windows \ System32 \ Codecs \ BZip2.dll
c: \ Windows \ System32 \ Codecs \ Copy.dll
c: \ Windows \ System32 \ Codecs \ Deflate.dll
c: \ Windows \ System32 \ Codecs \ LZMA.dll
c: \ Windows \ System32 \ Codecs \ PPMd.dll
c: \ Windows \ System32 \ Codecs \ Rar29.dll
c: \ Windows \ System32 \ Codecs \ Swap.dll
C: \ Windows \ System32 \ Drivers \ ctoss2k.sys
c: \ Windows \ System32 \ Formátumok \ 7z.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers / Services )))))))) )))))))))))))))))))))))))))))))))))))))))
.

------- \ Legacy_ILVMONEYDRIVER53
------- \ Legacy_VIEWPOINT_MANAGER_SERVICE
------- \ Service_IlvMoneyDRIVER53
------- \ Service_Viewpoint Service Manager
------- \ Legacy_ossrv
------- \ Service_ossrv


((((((((((((((((((((((((( Files létrehozott 2009/05/24 a 2009/06/24 ))))))))))) ))))))))))))))))))))
.

2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w C: \ Program Files \ LSoft Technologies
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-C - AW-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw C: \ Windows \ System32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w C: \ Games
2009-06-10 20:13. 2009-05-07 15:32 345600-C ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-C ---- w-c: \ windows \ system32 \ dllcache \ rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Jelentés )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 23:25. 2008-05-16 03:35 d -------- ----- w-c: \ documents and settings \ All Users \ Application Data \ Kaspersky Lab
2009-06-24 21:26. 2008-05-16 03:35 761888 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.dat
2009-06-24 21:26. 2008-05-16 03:35 64388 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.idx
2009-06-24 21:26. 2008-05-16 03:35 4571424 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.dat
2009-06-24 21:26. 2008-05-16 03:35 29696 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.idx
2009-06-24 21:09. 2008-05-17 00:25 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w C: \ Program Files \ Pando Networks
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw C: \ Windows \ System32 \ Drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw C: \ Windows \ System32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw C: \ Documents and Settings \ All Users \ Application Data \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w C: \ Program Files \ Common Files \ Apple
2009-05-20 16:16. 2008-05-16 03:36 94643 ---- aw C: \ Windows \ System32 \ Drivers \ klick.dat
2009-05-20 16:16. 2008-05-16 03:36 105395 ---- aw C: \ Windows \ System32 \ Drivers \ klin.dat
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w C: \ Program Files \ InstallShield Installation Information
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw C: \ Windows \ System32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw C: \ Windows \ System32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w C: \ Windows \ System32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ vasárnap \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-26 01:13. 2009-04-26 00:43 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ Move Networks
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw C: \ Windows \ System32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw C: \ Windows \ System32 \ rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw C: \ Documents and Settings \ Mouse \ Local Settings \ Application Data \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw C: \ Windows \ System32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Megjegyzés * empty entries & legit default bejegyzések nem jelennek meg
REGEDIT4

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Ctfmon.exe" = "C: \ Windows \ System32 \ Ctfmon.exe" [2008-04-14 15360]
"H / PC Connection Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "C: \ Windows \ System32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ kötet Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "C: \ Windows \ System32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Task" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - C: \ Windows \ System32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - C: \ Windows \ System32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \! SASWinLogon]
2009-01-01 04:29 356352 ---- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ SafeBoot \ Minimal \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Adobe Gamma Loader.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = C: \ Windows \ PSS \ Adobe Gamma Loader.lnkCommon Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult HOTSYNCSHORTCUTNAME.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = C: \ Windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Microsoft Office.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Microsoft Office.lnk
backup = C: \ Windows \ PSS \ Microsoft Office.lnkCommon Indítópult

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Shared Tools \ msconfig \ Services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp scheduler 3" = 2 (0x2)
"Mdm" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center \ Monitoring \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ System32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh Networks \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Application Data \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ angol \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync alkalmazás
"% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Phone \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Enabled: ActiveSync szolgáltatás
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Boot Guard Illesztőprogram c: \ Windows \ System32 \ Drivers \ klbg.sys [1/29/2008 6:29 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 55024]
R1 UGURU; UGURU, C: \ Windows \ System32 \ Drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, C: \ Windows \ System32 \ Drivers \ klfltdev.sys [3/13/2008 7:02 26640]
R3 klim5, a Kaspersky Anti-Virus NDIS Filter; c: \ Windows \ System32 \ Drivers \ klim5.sys [12/13/2007 1:28 24592]
S2 Cubase32; Cubase32, C: \ Windows \ System32 \ Drivers \ Kuba se32.sys [4/5/2009 7:02 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 4096]

--- Egyéb szolgáltatások / Drivers --- In Memory

* NewlyCreated * - SASDIFSV
.
Tartalma az "Ütemezett feladatok" mappába

2009/06/13: c: \ windows \ feladatok \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009/06/24: c: \ windows \ feladatok \ Malwarebytes "Anti-Malware.job
- C: \ PROGRA ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
- - - - ÁRVAELLÁTÁS REMOVED - - - --

SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard


.
Kiegészítő Scan ------- -------
.
uStart page = hxxp: / / google.com /
IE: Add hozzá a Szalaghirdetés blokkolása - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportálás a Microsoft Excel - C: \ PROGRA ~ 1 \ mikrók ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: A Microsoft XML Parser for Java - file: / / c: \ windows \ Java \ classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

CatchMe 0.3.1398 W2K/XP/Vista - Rootkit / stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-24 19:25
5/1/2600 Windows Service Pack 3 NTFS

szkennelés rejtett folyamatok ...

scanning hidden autostart entries ...

scanning hidden files ...

scan sikeresen befejeződött
hidden files: 0

************************************************** ************************
.
--------------------- Zárt REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, e8, E1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, D1,
34, D2, D9, C8, 28,51, AF, B0, 29, A3, 98, a9, C3, A8, 8a, 5e, D3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, C2, C2, dc, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8-as, 42, 2f, C4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, DF, 4d, 25,
C2, 62,83,25, da, ec, 7e, 55,20, C9, 26, A3, f2, 65, ed, 80,3 e, e4, f6, ff, 7C, 85, E0, 43, D4, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, e0, 57,5 a, 93,61, f2, a1, b4, 61,82,
BB, AB, d5, 3e, 1e, 9e, e0, 57,5 A, 93,61,6 f, 0e, 5c, ae, EK, 4f, e7, 8d, 86,8 c, 21,01, lehet, 91, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, b9 A6, 33,6 c, cd, 91, d7, 7a, 29,97,
c7, 40,4 b, cd, 44, cd, b9 A6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4d, 73, A8-as, 13, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: DF, 20,58,62, 78,6 b, vö, C8, 7e, 4a, d5, 24,8 d,
3a, 49, C4, B0, 18, ed, A7, 3f, 8d, 37, A4-es, 29, b5, 53,9 A, D3, 4a, 02,51, DF, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, BA, B1, f8, 68,02,09, D4, 0b, f3, 53,
BC, 62,26,31,77, e1, BA, B1, f8, 68,02,77, C3, de, c6, 98,79, 54,2 C, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 A, 48, fc, e8, 04,4 a, f1, df, 00, d5, 43, ff,
f8, 0f, F3, 83,6 c, 56,8 b, a0, 85,96, AB, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, e8, 04, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, EA, f8, C4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, c6, f6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3D, ce, EA, 26, 2d, 45, AA, 78,0 b, ba, 41,78,8 a,
C9, 90,04-, B1-, CD-t, 45,5 a, a8, C4, f8, b9, 6b, C6, A2, 44,8 d, 59, A6, f5, 3d, CE, EA, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, B7, cc, b5, b9, 7f, 41, e7, 5D, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, D5, EB, BC, 2f 6b e1, 69,31, AC, dd, ba, 7f, 02,2 A, B7, CC, b5, b9, 7f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, EA, 66,7 f, d4, 3b, 6b, 70, A5-ös, 97,0 a, 6e, 8a,
CF, 52,73, fa, EA, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7B, 08,64,6 c, 43,2 d, 1e, AA, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ H-€ | yyyy ¤ • € | U • V ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - -> "Winlogon.exe" (1028)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ Windows \ System32 \ klogon.dll

- - - - - - -> "Explorer.exe" (3748)
c: \ Windows \ System32 \ WPDShServiceObj.dll
c: \ Windows \ System32 \ PortableDeviceTypes.dll
c: \ Windows \ System32 \ PortableDeviceApi.dll
.
------------------------ Other Running Processes ----------------------- --
.
C: \ Program Files \ Creative \ Shared Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ Windows \ System32 \ nvsvc32.exe
c: \ Windows \ System32 \ PnkBstrA.exe
c: \ Windows \ System32 \ Rundll32.exe
c: \ PROGRA ~ 1 \ mikrók ~ 4 \ rapimgr.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Entertainment Center \ EAXLoadr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ Windows \ System32 \ wscntfy.exe
c: \ Windows \ System32 \ CTxfispi.exe
.
************************************************** ************************
.
Teljesítés ideje: 2009-06-24 19:29 - a gép újraindítása
ComboFix-karantén-files.txt 2009-06-24 23:29
ComboFix2.txt 2008-05-20 17:05

Pre-Run: 65511231488 bájt szabad
Post-Run: 67799437312 bájt szabad

WindowsXP-KB310994-SP2-Pro-BootDisk lemezről-HUN.exe
[boot loader]
timeout = 2
default = multi (0) disk (0) rdisk (1) partition (1) \ WINDOW S
[operating systems]
c: \ cmdcons \ bootsect.dat = "Microsoft Windows helyreállítási konzol" / cmdcons
multi (0) disk (0) rdisk (1) partition (1) \ WINDOWS = "Micro soft Windows XP Professional" / noexecute = OptIn / fastdetect
multi (0) disk (0) rdisk (0) partition (1) \ WINDOWS = "Micro soft Windows XP Professional" / fastdetect / noexecute = OptIn

Jelenlegi = 3 Default = 3 sikertelen = 1 LastKnownGood = 4 Beállítja = 1,2,3,4
335 --- EOF --- 2009-06-11 03:03
  #7  
Old Június 25 2009, 09:58
Moderátor Csoport
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Törölje ezeket a fájlokat / mappákat, az alábbiak szerint:

1. Menj a Start > Fut > Type Notepad.exe , és kattintson OK megnyitásához Jegyzettömbbe.
Azt kell a Jegyzettömb, nem Wordpad.
2. Másolja az alábbi szöveget a kód mezőbe, kiemelve az összes szöveget, és nyomja meg Ctrl + C

Kód:
Killall: RegLock:: [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C - D8D3582C741C) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98 - D0152D08C8B9) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B - 3E52D94DB145) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B - 37E957082D6D) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073 - C02FF9619B6F) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D - 1411304BCD84) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ H-€ | yyyy ¤ • € | U • V ~ *]
3. Ugrás a Jegyzettömb ablak, és kattintson Szerkesztés > Beillesztés
4. Ezután kattintson a Fájl > Ment
5. A fájl neve CFScript.txt - Mentsük a fájlt az asztalra
6. Ezután húzza a CFScript (tartsuk lenyomva a bal egérgombot, miközben húzza a fájlt), és dobja el (engedje el a bal egérgombot) a ComboFix.exe mint látod a screenshot alább. Fontos: Végezze el ezt az utasítást figyelmesen!



ComboFix kezdődik végrehajtásához, kövesse az instrukciókat.
Újraindítás után (amennyiben azt kéri, hogy reboot), majd egy naplót az Ön számára.
Post hogy log (Combofix.txt) a következő választ.

Megjegyzés: Ne mouseclick ComboFix az ablakon, miközben az fut. Ezt okozhatja a rendszer befagyasztja

----------

Is hadd tudja, hogy a számítógépen fut most.

.
__________________

  #8  
Old Június 25 2009, 16:17
Csoport tagja
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Egér 06/25/2009 19:04.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1597 [GMT -4:00]
Running From: c: \ documents and settings \ Mouse \ Desktop \ ComboFix.exe
Command kapcsolók használhatók: c: \ documents and settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-hozzáférés szkennelés fogyatékkal * (Frissítve) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security fogyatékos * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

Egyéb ((((((((((((((((((((((((((((((((((((((( Törlések ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

C: \ Windows \ System32 \ Drivers \ kl1.sys

.
((((((((((((((((((((((((( Files létrehozott 2009/05/25 a 2009/06/25 ))))))))))) ))))))))))))))))))))
.

2009-06-24 23:28. 2009-06-24 23:28 -------- dc ---- w-c: \ windows \ system32 \ dllcache \ cache
2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w C: \ Program Files \ LSoft Technologies
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-C - AW-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw C: \ Windows \ System32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w C: \ Games
2009-06-10 20:13. 2009-05-07 15:32 345600-C ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-C ---- w-c: \ windows \ system32 \ dllcache \ rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Jelentés )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-25 23:11. 2008-05-16 03:35 d -------- ----- w-c: \ documents and settings \ All Users \ Application Data \ Kaspersky Lab
2009-06-25 23:09. 2008-05-16 03:35 761888 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.dat
2009-06-25 23:09. 2008-05-16 03:35 64388 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.idx
2009-06-25 23:09. 2008-05-16 03:35 4571424 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.dat
2009-06-25 23:09. 2008-05-16 03:35 29696 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.idx
2009-06-24 23:59. 2008-01-29 22:29 33808 ---- aw C: \ Windows \ System32 \ Drivers \ klbg.sys
2009-06-24 23:59. 2009-02-05 00:58 33808 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ klbg.sys
2009-06-24 23:59. 2008-05-16 03:36 94643 ---- aw C: \ Windows \ System32 \ Drivers \ klick.dat
2009-06-24 23:59. 2008-05-16 03:36 105395 ---- aw C: \ Windows \ System32 \ Drivers \ klin.dat
2009-06-24 23:59. 2008-07-17 23:08 213520 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ XP \ klif.sys
2009-06-24 23:59. 2008-07-17 23:08 861448 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ updater.dll
2009-06-24 21:09. 2008-05-17 00:25 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w C: \ Program Files \ Pando Networks
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw C: \ Windows \ System32 \ Drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw C: \ Windows \ System32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw C: \ Documents and Settings \ All Users \ Application Data \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w C: \ Program Files \ Common Files \ Apple
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w C: \ Program Files \ InstallShield Installation Information
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw C: \ Windows \ System32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw C: \ Windows \ System32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w C: \ Windows \ System32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ vasárnap \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw C: \ Windows \ System32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw C: \ Windows \ System32 \ rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw C: \ Documents and Settings \ Mouse \ Local Settings \ Application Data \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw C: \ Windows \ System32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-24_23.25.37 )))))))))))) )))))))))))))))))))))))))))))
.
+ 2008-03-26 00:07. 2008-03-26 00:07 24592 C: \ Windows \ System32 \ Drivers \ klim5.sys
- 2007-12-13 17:28. 2008-03-26 00:07 24592 C: \ Windows \ System32 \ Drivers \ klim5.sys
+ 2009-06-24 23:28. 2008-10-16 19:09 51224 C: \ Windows \ System32 \ dllcache \ cache \ wuauclt.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 82432 C: \ Windows \ System32 \ dllcache \ cache \ ws2_32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 26112 C: \ Windows \ System32 \ dllcache \ cache \ Userinit.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 14336 C: \ Windows \ System32 \ dllcache \ cache \ Svchost.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 57856 C: \ Windows \ System32 \ dllcache \ cache \ Spoolsv.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 17408 C: \ Windows \ System32 \ dllcache \ cache \ powrprof.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 13312 C: \ Windows \ System32 \ dllcache \ cache \ Lsass.exe
+ 2009-06-24 23:28. 2008-04-13 18:39 24576 C: \ Windows \ System32 \ dllcache \ cache \ Kbdclass.sys
+ 2009-06-24 23:28. 2008-04-13 18:53 36608 C: \ Windows \ System32 \ dllcache \ cache \ ip6fw.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 15360 C: \ Windows \ System32 \ dllcache \ cache \ Ctfmon.exe
- 2008-04-18 17:53. 2009-02-05 00:58 213520 C: \ Windows \ System32 \ Drivers \ klif.sys
+ 2008-04-18 17:53. 2009-06-24 23:59 213520 C: \ Windows \ System32 \ Drivers \ klif.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 507904 C: \ Windows \ System32 \ dllcache \ cache \ winlogon.exe
+ 2009-06-24 23:28. 2009-04-29 04:46 666624 C: \ Windows \ System32 \ dllcache \ cache \ Wininet.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 578560 C: \ Windows \ System32 \ dllcache \ cache \ User32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 295424 C: \ Windows \ System32 \ dllcache \ cache \ Termsrv.dll
+ 2009-06-24 23:28. 2008-06-20 11:51 361600 C: \ Windows \ System32 \ dllcache \ cache \ Tcpip.sys
+ 2009-06-24 23:28. 2009-02-06 11:11 110592 C: \ Windows \ System32 \ dllcache \ cache \ Services.exe
+ 2009-06-24 23:28. 2008-04-13 19:20 182656 C: \ Windows \ System32 \ dllcache \ cache \ ndis.sys
+ 2009-06-24 23:28. 2009-03-21 14:06 989696 C: \ Windows \ System32 \ dllcache \ cache \ Kernel32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 110080 C: \ Windows \ System32 \ dllcache \ cache \ imm32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 167936 C: \ Windows \ System32 \ dllcache \ cache \ appmgmts.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 1614848 C: \ Windows \ System32 \ dllcache \ cache \ sfcfiles.dll
+ 2009-06-24 23:28. 2009-02-06 11:06 2145280 C: \ Windows \ System32 \ dllcache \ cache \ Ntoskrnl.exe
+ 2009-06-24 23:28. 2009-02-06 10:32 2023936 C: \ Windows \ System32 \ dllcache \ cache \ ntkrnlpa.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 1033728 C: \ Windows \ System32 \ dllcache \ cache \ explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Megjegyzés * empty entries & legit default bejegyzések nem jelennek meg
REGEDIT4

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Ctfmon.exe" = "C: \ Windows \ System32 \ Ctfmon.exe" [2008-04-14 15360]
"H / PC Connection Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "C: \ Windows \ System32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ kötet Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "C: \ Windows \ System32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Task" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - C: \ Windows \ System32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - C: \ Windows \ System32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \! SASWinLogon]
2009-01-01 04:29 356352 ---- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ SafeBoot \ Minimal \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Adobe Gamma Loader.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = C: \ Windows \ PSS \ Adobe Gamma Loader.lnkCommon Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult HOTSYNCSHORTCUTNAME.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = C: \ Windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Microsoft Office.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Microsoft Office.lnk
backup = C: \ Windows \ PSS \ Microsoft Office.lnkCommon Indítópult

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Shared Tools \ msconfig \ Services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp scheduler 3" = 2 (0x2)
"Mdm" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center \ Monitoring \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ System32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh Networks \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Application Data \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ angol \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync alkalmazás
"% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Phone \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Enabled: ActiveSync szolgáltatás
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Boot Guard Illesztőprogram c: \ Windows \ System32 \ Drivers \ klbg.sys [1/29/2008 6:29 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 55024]
R1 UGURU; UGURU, C: \ Windows \ System32 \ Drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, C: \ Windows \ System32 \ Drivers \ klfltdev.sys [3/13/2008 7:02 26640]
R3 klim5, a Kaspersky Anti-Virus NDIS Filter; c: \ Windows \ System32 \ Drivers \ klim5.sys [3/25/2008 8:07 24592]
S2 Cubase32; Cubase32, C: \ Windows \ System32 \ Drivers \ Kuba se32.sys [4/5/2009 7:02 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 4096]
.
Tartalma az "Ütemezett feladatok" mappába

2009/06/13: c: \ windows \ feladatok \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009/06/25: c: \ windows \ feladatok \ Malwarebytes "Anti-Malware.job
- C: \ PROGRA ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
.
Kiegészítő Scan ------- -------
.
uStart page = hxxp: / / google.com /
IE: Add hozzá a Szalaghirdetés blokkolása - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportálás a Microsoft Excel - C: \ PROGRA ~ 1 \ mikrók ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: A Microsoft XML Parser for Java - file: / / c: \ windows \ Java \ classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

CatchMe 0.3.1398 W2K/XP/Vista - Rootkit / stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-25 19:11
5/1/2600 Windows Service Pack 3 NTFS

szkennelés rejtett folyamatok ...

scanning hidden autostart entries ...

scanning hidden files ...

scan sikeresen befejeződött
hidden files: 0

************************************************** ************************
.
--------------------- Zárt REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, e8, E1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, D1,
34, D2, D9, C8, 28,51, AF, B0, 29, A3, 98, a9, C3, A8, 8a, 5e, D3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, C2, C2, dc, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8-as, 42, 2f, C4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, DF, 4d, 25,
C2, 62,83,25, da, ec, 7e, 55,20, C9, 26, A3, f2, 65, ed, 80,3 e, e4, f6, ff, 7C, 85, E0, 43, D4, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, e0, 57,5 a, 93,61, f2, a1, b4, 61,82,
BB, AB, d5, 3e, 1e, 9e, e0, 57,5 A, 93,61,6 f, 0e, 5c, ae, EK, 4f, e7, 8d, 86,8 c, 21,01, lehet, 91, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, b9 A6, 33,6 c, cd, 91, d7, 7a, 29,97,
c7, 40,4 b, cd, 44, cd, b9 A6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4d, 73, A8-as, 13, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: DF, 20,58,62, 78,6 b, vö, C8, 7e, 4a, d5, 24,8 d,
3a, 49, C4, B0, 18, ed, A7, 3f, 8d, 37, A4-es, 29, b5, 53,9 A, D3, 4a, 02,51, DF, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, BA, B1, f8, 68,02,09, D4, 0b, f3, 53,
BC, 62,26,31,77, e1, BA, B1, f8, 68,02,77, C3, de, c6, 98,79, 54,2 C, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 A, 48, fc, e8, 04,4 a, f1, df, 00, d5, 43, ff,
f8, 0f, F3, 83,6 c, 56,8 b, a0, 85,96, AB, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, e8, 04, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, EA, f8, C4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, c6, f6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3D, ce, EA, 26, 2d, 45, AA, 78,0 b, ba, 41,78,8 a,
C9, 90,04-, B1-, CD-t, 45,5 a, a8, C4, f8, b9, 6b, C6, A2, 44,8 d, 59, A6, f5, 3d, CE, EA, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, B7, cc, b5, b9, 7f, 41, e7, 5D, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, D5, EB, BC, 2f 6b e1, 69,31, AC, dd, ba, 7f, 02,2 A, B7, CC, b5, b9, 7f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, EA, 66,7 f, d4, 3b, 6b, 70, A5-ös, 97,0 a, 6e, 8a,
CF, 52,73, fa, EA, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7B, 08,64,6 c, 43,2 d, 1e, AA, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ H-€ | yyyy ¤ • € | U • V ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - -> "Winlogon.exe" (1028)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ Windows \ System32 \ klogon.dll

- - - - - - -> "Explorer.exe" (212)
c: \ Windows \ System32 \ WPDShServiceObj.dll
c: \ Windows \ System32 \ PortableDeviceTypes.dll
c: \ Windows \ System32 \ PortableDeviceApi.dll
.
------------------------ Other Running Processes ----------------------- --
.
C: \ Program Files \ Creative \ Shared Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ Windows \ System32 \ nvsvc32.exe
c: \ Windows \ System32 \ PnkBstrA.exe
c: \ Windows \ System32 \ Rundll32.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Entertainment Center \ EAXLoadr.exe
c: \ PROGRA ~ 1 \ mikrók ~ 4 \ rapimgr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ Windows \ System32 \ CTxfispi.exe
c: \ Windows \ System32 \ wscntfy.exe
.
************************************************** ************************
.
Teljesítés ideje: 2009-06-25 19:14 - a gép újraindítása
ComboFix-karantén-files.txt 2009-06-25 23:14
ComboFix2.txt 2009-06-24 23:29
ComboFix3.txt 2008-05-20 17:05

Pre-Run: 67819319296 bájt szabad
Post-Run: 67883995136 bájt szabad

Jelenlegi = 3 Default = 3 sikertelen = 1 LastKnownGood = 4 Beállítja = 1,2,3,4
310 --- EOF --- 2009-06-11 03:03
  #9  
Old Június 25 2009, 18:13
Moderátor Csoport
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

Sajnálom, hogy észre valamit.

Törölje ezeket a fájlokat / mappákat, az alábbiak szerint:

1. Menj a Start > Fut > Type Notepad.exe , és kattintson OK megnyitásához Jegyzettömbbe.
Azt kell a Jegyzettömb, nem Wordpad.
2. Másolja az alábbi szöveget a kód mezőbe, kiemelve az összes szöveget, és nyomja meg Ctrl + C

Kód:
Killall: RegLock:: [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (47629D4B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (604BB98A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (684373FB-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (74554CCD-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (7EB537F9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (948395E8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (DE5654CA-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Classes \ CLSID \ (E39C35E8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (EACAFCE5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (F8F02ADD-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (FEE45DE2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *] [HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Installer \ UserData \ LocalSystem \ Components \ H-€ | yyyy ¤ • € | U • V ~ *]
3. Ugrás a Jegyzettömb ablak, és kattintson Szerkesztés > Beillesztés
4. Ezután kattintson a Fájl > Ment
5. A fájl neve CFScript.txt - Mentsük a fájlt az asztalra
6. Ezután húzza a CFScript (tartsuk lenyomva a bal egérgombot, miközben húzza a fájlt), és dobja el (engedje el a bal egérgombot) a ComboFix.exe mint látod a screenshot alább. Fontos: Végezze el ezt az utasítást figyelmesen!



ComboFix kezdődik végrehajtásához, kövesse az instrukciókat.
Újraindítás után (amennyiben azt kéri, hogy reboot), majd egy naplót az Ön számára.
Post hogy log (Combofix.txt) a következő választ.

Megjegyzés: Ne mouseclick ComboFix az ablakon, miközben az fut. Ezt okozhatja a rendszer befagyasztja

----------

Is hadd tudja, hogy a számítógépen fut most.

.
__________________

  #10  
Old Június 26 2009, 00:59
Csoport tagja
 
Default Fertőzött MultiPacked.Multi.Generic Malware!

ComboFix 09-06-23.01 - Egér 06/26/2009 3:47.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1564 [GMT -4:00]
Running From: c: \ documents and settings \ Mouse \ Desktop \ ComboFix.exe
Command kapcsolók használhatók: c: \ documents and settings \ Mouse \ Desktop \ CFScript.txt
AV: Kaspersky Internet Security * On-hozzáférés szkennelés fogyatékkal * (Frissítve) (2C4D4BC6-0793-4956-A9F9-E252435469C0)
FW: Kaspersky Internet Security fogyatékos * * (2C4D4BC6-0793-4956-A9F9-E252435469C0)
.

Egyéb ((((((((((((((((((((((((((((((((((((((( Törlések ))))))))) ))))))))))))))))))))))))))))))))))))))))
.

C: \ Windows \ System32 \ Drivers \ kl1.sys

.
((((((((((((((((((((((((( Files létrehozott 2009/05/26 a 2009/06/26 ))))))))))) ))))))))))))))))))))
.

2009-06-24 23:28. 2009-06-24 23:28 -------- dc ---- w-c: \ windows \ system32 \ dllcache \ cache
2009-06-23 18:47. 2009-06-24 16:37 117760 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL
2009-06-17 17:58. 2009-06-17 18:10 -------- d ----- w C: \ Program Files \ LSoft Technologies
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iPod
2009-06-13 16:32. 2009-06-13 16:32 -------- d ----- w C: \ Program Files \ iTunes
2009-06-13 16:28. 2009-06-13 16:29 -------- d ----- w C: \ Program Files \ QuickTime
2009-06-13 16:23. 2009-06-13 16:23 75048 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Apple Computer \ Installer Cache \ iTunes 8.2.0.23 \ SetupAdmin.exe
2009-06-10 23:14. 2001-08-18 02:36 462848-C - AW-c: \ windows \ system32 \ dllcache \ a3dapi.dll
2009-06-10 23:14. 2001-08-18 02:36 462848 ---- aw C: \ Windows \ System32 \ a3dapi.dll
2009-06-10 23:13. 2009-06-11 07:20 -------- d ----- w C: \ Descent3
2009-06-10 23:13. 2009-06-10 23:13 -------- d ----- w C: \ Games
2009-06-10 20:13. 2009-05-07 15:32 345600-C ---- w-c: \ windows \ system32 \ dllcache \ Localspl.dll
2009-06-10 20:13. 2009-04-15 14:51 585216-C ---- w-c: \ windows \ system32 \ dllcache \ rpcrt4.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Jelentés )))))))) ))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-26 07:54. 2008-05-16 03:35 d -------- ----- w-c: \ documents and settings \ All Users \ Application Data \ Kaspersky Lab
2009-06-26 07:52. 2008-05-16 03:35 761888 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.dat
2009-06-26 07:52. 2008-05-16 03:35 64388 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.idx
2009-06-26 07:52. 2008-05-16 03:35 4571424 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox.dat
2009-06-26 07:52. 2008-05-16 03:35 29696 - sha-w-c: \ Windows \ System32 \ Drivers \ fidbox2.idx
2009-06-25 23:24. 2008-01-29 22:29 33808 ---- aw C: \ Windows \ System32 \ Drivers \ klbg.sys
2009-06-25 23:24. 2008-05-16 03:36 94643 ---- aw C: \ Windows \ System32 \ Drivers \ klick.dat
2009-06-25 23:24. 2008-05-16 03:36 105395 ---- aw C: \ Windows \ System32 \ Drivers \ klin.dat
2009-06-25 23:24. 2009-02-05 00:58 33808 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ klbg.sys
2009-06-25 23:24. 2008-07-17 23:08 213520 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ XP \ klif.sys
2009-06-25 23:24. 2008-07-17 23:08 861448 ---- aw C: \ Documents and Settings \ All Users \ Application Data \ Kaspersky Lab \ AVP8 \ Data \ Updater \ Temporary Files \ temporaryFolder \ AutoPatches \ kav8exec \ 8.0.0.3 57 \ updater.dll
2009-06-24 21:09. 2008-05-17 00:25 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ LimeWire
2009-06-24 16:37. 2008-05-19 02:02 -------- d ----- w C: \ Program Files \ SUPERAntiSpyware
2009-06-23 19:00. 2008-10-16 02:40 -------- d ----- w C: \ Program Files \ Pando Networks
2009-06-23 18:59. 2008-11-29 18:36 -------- d ----- w C: \ Program Files \ palmOne
2009-06-21 23:00. 2009-02-09 03:50 138184 ---- aw C: \ Windows \ System32 \ Drivers \ PnkBstrK.sys
2009-06-21 23:00. 2009-02-09 03:50 183112 ---- aw C: \ Windows \ System32 \ PnkBstrB.exe
2009-06-18 22:35. 2008-06-17 15:40 -------- d ----- w C: \ Program Files \ Diablo II
2009-06-18 22:31. 2008-06-02 00:09 -------- d --- aw C: \ Documents and Settings \ All Users \ Application Data \ TEMP
2009-06-17 22:51. 2008-05-15 04:41 d -------- ----- w-c: \ documents and settings \ Mouse \ Application Data \ uTorrent
2009-06-13 16:32. 2008-08-19 04:10 -------- d ----- w C: \ Program Files \ Common Files \ Apple
2009-05-17 20:58. 2009-05-17 20:58 -------- d ----- w C: \ Program Files \ LG Electronics
2009-05-17 20:58. 2008-05-12 09:20 -------- d - h - w C: \ Program Files \ InstallShield Installation Information
2009-05-17 20:57. 2008-05-12 09:20 -------- d ----- w C: \ Program Files \ Common Files \ InstallShield
2009-05-07 15:32. 2003-03-31 12:00 345600 ---- aw C: \ Windows \ System32 \ Localspl.dll
2009-04-29 04:46. 2003-03-31 12:00 666624 ---- aw C: \ Windows \ System32 \ Wininet.dll
2009-04-29 04:46. 2008-05-16 21:18 81920 ------ w C: \ Windows \ System32 \ ieencode.dll
2009-04-28 10:48. 2008-05-17 00:24 -------- d ----- w C: \ Program Files \ Java
2009-04-28 10:47. 2009-04-28 10:47 152576 ---- aw C: \ Documents and Settings \ Mouse \ Application Data \ vasárnap \ Java \ jre1.6.0_13 \ lzma.dll
2009-04-17 12:26. 2003-03-31 12:00 1847168 ---- aw C: \ Windows \ System32 \ Win32k.sys
2009-04-15 14:51. 2003-03-31 12:00 585216 ---- aw C: \ Windows \ System32 \ rpcrt4.dll
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe1_B5F7ED63E4D54BE694F0 F06A2CCC5374.exe
2009-04-08 06:13. 2009-04-08 06:13 45056 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ MapleStory.exe_B5F7ED63E4D54BE694F0F 06A2CCC5374_1.exe
2009-04-08 06:13. 2009-04-08 06:13 10134 ---- ar-c: \ documents and settings \ Mouse \ Application Data \ Microsoft \ Installer \ (B5F7ED63-E4D5-4BE6-94F0-F06A2CCC5374) \ ARPPRODUCTICON.exe
2009-04-05 23:39. 2008-05-16 02:24 23032 ---- aw C: \ Documents and Settings \ Mouse \ Local Settings \ Application Data \ GDIPFONTCACHEV1.DAT
2009-04-05 23:27. 2009-04-05 23:28 5433520 ---- aw C: \ Windows \ System32 \ SpoonUninstall.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-06-24_23.25.37 )))))))))))) )))))))))))))))))))))))))))))
.
+ 2008-03-26 00:07. 2008-03-26 00:07 24592 C: \ Windows \ System32 \ Drivers \ klim5.sys
- 2007-12-13 17:28. 2008-03-26 00:07 24592 C: \ Windows \ System32 \ Drivers \ klim5.sys
+ 2009-06-24 23:28. 2008-10-16 19:09 51224 C: \ Windows \ System32 \ dllcache \ cache \ wuauclt.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 82432 C: \ Windows \ System32 \ dllcache \ cache \ ws2_32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 26112 C: \ Windows \ System32 \ dllcache \ cache \ Userinit.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 14336 C: \ Windows \ System32 \ dllcache \ cache \ Svchost.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 57856 C: \ Windows \ System32 \ dllcache \ cache \ Spoolsv.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 17408 C: \ Windows \ System32 \ dllcache \ cache \ powrprof.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 13312 C: \ Windows \ System32 \ dllcache \ cache \ Lsass.exe
+ 2009-06-24 23:28. 2008-04-13 18:39 24576 C: \ Windows \ System32 \ dllcache \ cache \ Kbdclass.sys
+ 2009-06-24 23:28. 2008-04-13 18:53 36608 C: \ Windows \ System32 \ dllcache \ cache \ ip6fw.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 15360 C: \ Windows \ System32 \ dllcache \ cache \ Ctfmon.exe
- 2008-04-18 17:53. 2009-02-05 00:58 213520 C: \ Windows \ System32 \ Drivers \ klif.sys
+ 2008-04-18 17:53. 2009-06-25 23:24 213520 C: \ Windows \ System32 \ Drivers \ klif.sys
+ 2009-06-24 23:28. 2008-04-14 00:12 507904 C: \ Windows \ System32 \ dllcache \ cache \ winlogon.exe
+ 2009-06-24 23:28. 2009-04-29 04:46 666624 C: \ Windows \ System32 \ dllcache \ cache \ Wininet.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 578560 C: \ Windows \ System32 \ dllcache \ cache \ User32.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 295424 C: \ Windows \ System32 \ dllcache \ cache \ Termsrv.dll
+ 2009-06-24 23:28. 2008-06-20 11:51 361600 C: \ Windows \ System32 \ dllcache \ cache \ Tcpip.sys
+ 2009-06-24 23:28. 2009-02-06 11:11 110592 C: \ Windows \ System32 \ dllcache \ cache \ Services.exe
+ 2009-06-24 23:28. 2008-04-13 19:20 182656 C: \ Windows \ System32 \ dllcache \ cache \ ndis.sys
+ 2009-06-24 23:28. 2009-03-21 14:06 989696 C: \ Windows \ System32 \ dllcache \ cache \ Kernel32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 110080 C: \ Windows \ System32 \ dllcache \ cache \ imm32.dll
+ 2009-06-24 23:28. 2008-04-14 00:11 167936 C: \ Windows \ System32 \ dllcache \ cache \ appmgmts.dll
+ 2009-06-24 23:28. 2008-04-14 00:12 1614848 C: \ Windows \ System32 \ dllcache \ cache \ sfcfiles.dll
+ 2009-06-24 23:28. 2009-02-06 11:06 2145280 C: \ Windows \ System32 \ dllcache \ cache \ Ntoskrnl.exe
+ 2009-06-24 23:28. 2009-02-06 10:32 2023936 C: \ Windows \ System32 \ dllcache \ cache \ ntkrnlpa.exe
+ 2009-06-24 23:28. 2008-04-14 00:12 1033728 C: \ Windows \ System32 \ dllcache \ cache \ explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
* Megjegyzés * empty entries & legit default bejegyzések nem jelennek meg
REGEDIT4

[HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Run]
"Ctfmon.exe" = "C: \ Windows \ System32 \ Ctfmon.exe" [2008-04-14 15360]
"H / PC Connection Agent" = "C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" [2006-11-13 1289000]

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run]
"NvCplDaemon" = "C: \ Windows \ System32 \ NvCpl.dll" [2008-05-03 13529088]
"CTDVDDET" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ DVDAudio \ CTDVDDET.EXE" [2003-06-18 45056]
"RCSystem" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"AudioDrvEmulator" = "C: \ Program Files \ Creative \ Shared Files \ Module Loader \ DLLML.exe" [2005-11-04 49152]
"VolPanel" = "C: \ Program Files \ Creative \ Sound Blaster X-Fi \ kötet Panel \ VolPanlu.exe" [2006-07-28 122880]
"NvMediaCenter" = "C: \ Windows \ System32 \ NvMcTray. Dll" [2008-05-03 86016]
"AVP" = "C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ avp.exe" [2009-02-05 201992]
"QuickTime Task" = "C: \ Program Files \ QuickTime \ QTTask.exe" [2009-05-26 413696]
"AppleSyncNotifier" = "C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleSyncNotifier.exe" [2009-05-14 177472]
"iTunesHelper" = "C: \ Program Files \ iTunes \ iTunesHelper.exe" [2009-06-05 292136]
"CTHelper" = "CTHELPER.EXE" - C: \ Windows \ System32 \ CtHelper.exe [2008-02-21 19456]
"CTxfiHlp" = "CTXFIHLP.EXE" - C: \ Windows \ System32 \ Ctxfihlp.exe [2008-02-21 19968]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks]
"(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2009-01-01 77824]

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \! SASWinLogon]
2009-01-01 04:29 356352 ---- aw C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL

[HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ SafeBoot \ Minimal \ Wdf01000.sys]
@ = "Driver"

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Adobe Gamma Loader.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Gamma Loader.lnk
backup = C: \ Windows \ PSS \ Adobe Gamma Loader.lnkCommon Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult HOTSYNCSHORTCUTNAME.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ HOTSYNCSHORTCUTNAME.lnk
backup = C: \ Windows \ PSS \ n HOTSYNCSHORTCUTNAME.lnkCommo Indítópult

[HKLM \ ~ \ startupfolder \ C: ^ Documents and Settings ^ All Users ^ Start Menu ^ Programs ^ ^ Indítópult Microsoft Office.lnk]
path = c: \ documents and settings \ All Users \ Start Menu \ Programs \ Startup \ Microsoft Office.lnk
backup = C: \ Windows \ PSS \ Microsoft Office.lnkCommon Indítópult

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Shared Tools \ msconfig \ Services]
"StyleXPService" = 2 (0x2)
"PLFlash DeviceIoControl Service" = 2 (0x2)
"NMIndexingService" = 3 (0x3)
"Nero BackItUp scheduler 3" = 2 (0x2)
"Mdm" = 2 (0x2)
"ZuneNetworkSvc" = 3 (0x3)
"WMPNetworkSvc" = 3 (0x3)
"npkcmsvc" = 2 (0x2)
"JavaQuickStarterService" = 2 (0x2)
"IDriverT" = 3 (0x3)
"iPod Service" = 3 (0x3)
"idsvc" = 3 (0x3)
"Adobe LM Service" = 3 (0x3)

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center]
"AntiVirusOverride" = dword: 00000001

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Security Center \ Monitoring \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile]
"EnableFirewall" = 0 (0x0)

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ AuthorizedApplications \ List]
"% windir% \ \ System32 \ \ Sessmgr.exe" =
"c: \ \ Program Files \ \ uTorrent \ \ uTorrent.exe" =
"c: \ \ Program Files \ \ Veoh Networks \ \ Veoh \ \ VeohClient.exe" =
"c: \ \ Program Files \ \ LimeWire \ \ LimeWire.exe" =
"c: \ \ Program Files \ \ Sierra \ \ FEAR \ \ FEAR.exe" =
"c: \ \ Program Files \ \ Xfire \ \ xfire.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx9.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Dx10.exe" =
"c: \ \ Program Files \ \ Ubisoft \ \ Assassin's Creed \ \ AssassinsCreed_Launcher.exe" =
"c: \ \ Documents and Settings \ \ All Users \ \ Application Data \ \ Kaspersky Lab Setup Files \ \ Kaspersky Internet Security 2009 \ \ angol \ \ setup.exe" =
"C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ rapimgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync RAPI Manager
"C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe" = C: \ Program Files \ Microsoft ActiveSync \ wcescomm.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync Connection Manager
"C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe" = C: \ Program Files \ Microsoft ActiveSync \ WCESMgr.exe: 169.254.2.0/255.255.255.0: Enabled: ActiveSync alkalmazás
"% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" =
"c: \ \ Program Files \ \ Skype \ \ Phone \ \ Skype.exe" =
"c: \ \ Program Files \ \ Common Files \ \ AOL \ \ Loader \ \ aolload.exe" =
"c: \ \ Program Files \ \ AIM6 \ \ aim6.exe" =
"c: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" =
"c: \ \ Program Files \ \ iTunes \ \ iTunes.exe" =

[HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo wildwolf \ standardprofile \ GloballyOpenPorts \ List]
"6112: TCP" = 6112: TCP: Diablo 2
"26675: TCP" = 26675: TCP: 169.254.2.0/255.255.255.0: Enabled: ActiveSync szolgáltatás
"58398: TCP" = 58398: TCP: Pando Media Booster
"58398: UDP" = 58398: UDP: Pando Media Booster

R0 klbg; Kaspersky Lab Boot Guard Illesztőprogram c: \ Windows \ System32 \ Drivers \ klbg.sys [1/29/2008 6:29 33808]
R1 SASDIFSV; SASDIFSV, C: \ Program Files \ SUPERAntiSpyware \ SASDIFSV.SYS [2/29/2008 4:03 9968]
R1 SASKUTIL; SASKUTIL, C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [2/29/2008 4:03 55024]
R1 UGURU; UGURU, C: \ Windows \ System32 \ Drivers \ uGuru.sys [5/12/2008 5:23 AM 14592]
R3 KLFLTDEV; Kaspersky Lab KLFltDev, C: \ Windows \ System32 \ Drivers \ klfltdev.sys [3/13/2008 7:02 26640]
R3 klim5, a Kaspersky Anti-Virus NDIS Filter; c: \ Windows \ System32 \ Drivers \ klim5.sys [3/25/2008 8:07 24592]
S2 Cubase32; Cubase32, C: \ Windows \ System32 \ Drivers \ Kuba se32.sys [4/5/2009 7:02 11808]
S3 SASENUM; SASENUM, C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [2/16/2006 4:51 4096]
.
Tartalma az "Ütemezett feladatok" mappába

2009/06/13: c: \ windows \ feladatok \ AppleSoftwareUpdate.job
- C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe [2008-07-30 17:34]

2009/06/26: c: \ windows \ feladatok \ Malwarebytes "Anti-Malware.job
- C: \ PROGRA ~ 1 \ MALWAR ~ 1 \ mbam.exe [2008-05-19 00:52]
.
.
Kiegészítő Scan ------- -------
.
uStart page = hxxp: / / google.com /
IE: Add hozzá a Szalaghirdetés blokkolása - C: \ Program Files \ Kaspersky Lab \ Kaspersky Internet Security 2009 \ ie_banner_deny.htm
IE: E & xportálás a Microsoft Excel - C: \ PROGRA ~ 1 \ mikrók ~ 2 \ Office10 \ EXCEL.EXE/3000
DPF: A Microsoft XML Parser for Java - file: / / c: \ windows \ Java \ classes \ xmldso.cab
DPF: (463ED66E-431B-11D2-ADB0-0080C83DA4EB) - hxxps: / / w3s.webmoney.ru/WMAcceptor.dll
FF - ProfilePath --
.

************************************************** ************************

CatchMe 0.3.1398 W2K/XP/Vista - Rootkit / stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-26 03:54
5/1/2600 Windows Service Pack 3 NTFS

szkennelés rejtett folyamatok ...

scanning hidden autostart entries ...

scanning hidden files ...

scan sikeresen befejeződött
hidden files: 0

************************************************** ************************
.
--------------------- Zárt REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (47629D4 B-2AD3-4e50-B716-A66C15C63153) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b" = hex: 2e, e8, E1, 00, eb, 16,2 b, de, ff, 66,8 f, 81, D1,
34, D2, D9, C8, 28,51, AF, B0, 29, A3, 98, a9, C3, A8, 8a, 5e, D3, 39,87, e2, 63,26, f1, 3f, C8, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (604BB98 A-A94F-4a5c-A67C-D8D3582C741C) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b" = hex: 71,3 b, 04,66, 8b, 46,0 d, 96, C2, C2, dc, e4, A8,
65,45,2 e, 71,3 b, 04,66,8 b, 46,0 d, 96,21,7 c, aa, e9, A8-as, 42, 2f, C4, 6a, 9c, d6, 61, af, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (684373F B-9CD8-4e47-B990-5A4466C16034) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2c81e34222e8052573023a60d06dd016" = hex: 25, da, ec, 7e, 55,20, C9, 26, eb, A7, DF, 4d, 25,
C2, 62,83,25, da, ec, 7e, 55,20, C9, 26, A3, f2, 65, ed, 80,3 e, e4, f6, ff, 7C, 85, E0, 43, D4, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (74554CC D-F60F-4708-AD98-D0152D08C8B9) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"2582ae41fb52324423be06337561aa48" = hex: 3e, 1e, 9e, e0, 57,5 a, 93,61, f2, a1, b4, 61,82,
BB, AB, d5, 3e, 1e, 9e, e0, 57,5 A, 93,61,6 f, 0e, 5c, ae, EK, 4f, e7, 8d, 86,8 c, 21,01, lehet, 91, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (7EB537F 9-A916-4339-B91B-DED8E83632C0) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472" = hex: cd, 44, cd, b9 A6, 33,6 c, cd, 91, d7, 7a, 29,97,
c7, 40,4 b, cd, 44, cd, b9 A6, 33,6 c, cd, 49,19,95,11,6 f, ac, 43,68, F5, 1d, 4d, 73, A8-as, 13, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (948395E 8-7A56-4fb1-843B-3E52D94DB145) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d" = hex: DF, 20,58,62, 78,6 b, vö, C8, 7e, 4a, d5, 24,8 d,
3a, 49, C4, B0, 18, ed, A7, 3f, 8d, 37, A4-es, 29, b5, 53,9 A, D3, 4a, 02,51, DF, 20,58,62,78,6 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (AC3ED30 B-6F1A-4bfc-A4F6-2EBDCCD34C19) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b" = hex: 31,77, e1, BA, B1, f8, 68,02,09, D4, 0b, f3, 53,
BC, 62,26,31,77, e1, BA, B1, f8, 68,02,77, C3, de, c6, 98,79, 54,2 C, fb, A7, 78, e6, 12,2 f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (DE5654C A-EB84-4df9-915B-37E957082D6D) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d" = hex: 01,3 A, 48, fc, e8, 04,4 a, f1, df, 00, d5, 43, ff,
f8, 0f, F3, 83,6 c, 56,8 b, a0, 85,96, AB, d5, 19,39,90, da, 30, 2a, 05,01,3 a, 48, fc, e8, 04, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (E39C35E 8-7488-4926-92B2-2F94619AC1A5) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3" = hex: f6, 0f, 4e, 58, 98,5 b, 89, C9, 6a, EA, f8, C4, 82,
1a, 7f, d8, 51, fa, 6e, 91,28,9 e, 14, cc, 82, ac, 7a, 83, eb, 90, 81, c6, f6, 0f, 4e, 58,98,5 b, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (EACAFCE 5-B0E2-4288-8073-C02FF9619B6F) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b" = hex: 3D, ce, EA, 26, 2d, 45, AA, 78,0 b, ba, 41,78,8 a,
C9, 90,04-, B1-, CD-t, 45,5 a, a8, C4, f8, b9, 6b, C6, A2, 44,8 d, 59, A6, f5, 3d, CE, EA, 26,2 d, 45, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (F8F02AD D-7366-4186-9488-C21CB8B3DCEC) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6" = hex: 2a, B7, cc, b5, b9, 7f, 41, e7, 5D, 45,06,19,5 e,
30,20, e6, e3, 0e, 66, D5, EB, BC, 2f 6b e1, 69,31, AC, dd, ba, 7f, 02,2 A, B7, CC, b5, b9, 7f, \

[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ (FEE45DE 2-A467-4bf9-BF2D-1411304BCD84) \ InprocServer32 *]
"ThreadingModel" = "Apartman"
@ = "c: \ \ WINDOWS \ \ System32 \ \ OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2" = hex: fa, EA, 66,7 f, d4, 3b, 6b, 70, A5-ös, 97,0 a, 6e, 8a,
CF, 52,73, fa, EA, 66,7 f, d4, 3b, 6b, 70,30,24, ea, 79, a1, 7B, 08,64,6 c, 43,2 d, 1e, AA, 22, \

[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ Curr entVersion \ Installer \ UserData \ LocalSystem \ Componen ts \ H-€ | yyyy ¤ • € | U • V ~ *]
"AB141C35E9F4BF344B9FC010BB17F68A" = ""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - -> "Winlogon.exe" (672)
C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.DLL
c: \ Windows \ System32 \ klogon.dll

- - - - - - -> "Explorer.exe" (288)
c: \ Windows \ System32 \ WPDShServiceObj.dll
c: \ Windows \ System32 \ PortableDeviceTypes.dll
c: \ Windows \ System32 \ PortableDeviceApi.dll
.
------------------------ Other Running Processes ----------------------- --
.
C: \ Program Files \ Creative \ Shared Files \ CTAudSvc.exe
C: \ Program Files \ Common Files \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe
C: \ Program Files \ Bonjour \ mDNSResponder.exe
c: \ Windows \ System32 \ nvsvc32.exe
c: \ Windows \ System32 \ PnkBstrA.exe
c: \ Windows \ System32 \ Rundll32.exe
C: \ Program Files \ Creative \ Sound Blaster X-Fi \ Entertainment Center \ EAXLoadr.exe
c: \ PROGRA ~ 1 \ mikrók ~ 4 \ rapimgr.exe
C: \ Program Files \ iPod \ bin \ iPodService.exe
c: \ Windows \ System32 \ wscntfy.exe
c: \ Windows \ System32 \ CTxfispi.exe
.
************************************************** ************************
.
Teljesítés ideje: 2009-06-26 3:57 - a gép újraindítása
ComboFix-karantén-files.txt 2009-06-26 07:57
ComboFix2.txt 2009-06-25 23:14
ComboFix3.txt 2009-06-24 23:29
ComboFix4.txt 2008-05-20 17:05

Pre-Run: 67824807936 bájt szabad
Post-Run: 67888648192 bájt szabad

Jelenlegi = 3 Default = 3 sikertelen = 1 LastKnownGood = 4 Beállítja = 1,2,3,4
311 --- EOF --- 2009-06-11 03:03
Reply

Register
Téma eszközök




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Számítógép Juice.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd. SEO by vBSEO © 2009, Crawlability, Inc.