|
tnevellnac1 -> Cevap: bittorrent.exe win32LovGate ve diger birçok virüs için çözüm!!! (21 Kasım 2008; 0:16:13)
|
bahsettiğim dosyaları combofix programı sayesinde temizleyebildim. verdiği raporu sizinle paylaşıyorum: ComboFix 08-11-19.08 - XP-SP3 2008-11-20 23:49:06.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1254.1.1055.18.226 [GMT 2:00] Running from: c:\documents and settings\XP-SP3\Desktop\ComboFix.exe * Created a new restore point [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR] . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\abk.bat c:\windows\system32\gasretyw0.dll c:\windows\system32\kamsoft.exe C:\yannh.cmd D:\abk.bat D:\yannh.cmd H:\yannh.cmd . ((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 ))))))))))))))))))))))))))))))) . 2008-11-20 22:44 . 2008-05-21 14:28 7,994 --a------ C:\yama.vbs 2008-11-20 20:03 . 2008-11-20 20:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Acronis 2008-11-20 19:50 . 2008-11-20 19:50 <DIR> d-------- c:\program files\Common Files\Acronis 2008-11-20 19:50 . 2008-11-20 19:50 <DIR> d-------- c:\program files\Acronis 2008-11-20 19:50 . 2008-11-20 19:50 249,152 --a------ c:\windows\system32\drivers\timntr.sys 2008-11-20 19:50 . 2008-11-20 19:50 96,320 --a------ c:\windows\system32\drivers\snapman.sys 2008-11-20 19:50 . 2008-11-20 19:50 30,688 --a------ c:\windows\system32\drivers\tifsfilt.sys 2008-11-20 17:21 . 2008-11-20 17:21 96,976 --a------ c:\windows\system32\drivers\klin.dat 2008-11-20 17:21 . 2008-11-20 17:21 87,855 --a------ c:\windows\system32\drivers\klick.dat 2008-11-20 17:20 . 2008-11-20 17:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2008-11-20 17:20 . 2008-11-20 23:52 32 --ahs---- c:\windows\system32\drivers\fidbox2.idx 2008-11-20 17:20 . 2008-11-20 23:52 32 --ahs---- c:\windows\system32\drivers\fidbox2.dat 2008-11-20 17:20 . 2008-11-20 23:52 32 --ahs---- c:\windows\system32\drivers\fidbox.idx 2008-11-20 17:20 . 2008-11-20 23:52 32 --ahs---- c:\windows\system32\drivers\fidbox.dat 2008-11-20 14:40 . 2008-11-20 14:40 <DIR> d-------- c:\program files\Team JPN 2008-11-20 14:23 . 2008-11-20 23:04 85,504 -r-hs---- c:\windows\system32\gasretyw1.dll 2008-11-18 00:18 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll 2008-11-17 23:55 . 2008-11-17 23:55 <DIR> d-------- c:\windows\Logs 2008-11-17 23:23 . 2008-03-05 15:56 3,786,760 --a------ c:\windows\system32\d3dx9_37.dll 2008-11-17 21:44 . 2008-11-17 21:44 <DIR> d--h----- c:\program files\Zero G Registry 2008-11-17 21:44 . 2008-11-17 21:44 <DIR> d--h----- c:\documents and settings\XP-SP3\InstallAnywhere 2008-11-17 21:33 . 2008-11-17 21:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive 2008-11-13 20:24 . 2008-11-13 20:24 <DIR> d-------- C:\Vestel 2008-11-13 15:29 . 2008-11-13 15:29 272 --a------ C:\sqmdata02.sqm 2008-11-13 15:29 . 2008-11-13 15:29 200 --a------ C:\sqmnoopt02.sqm 2008-11-06 21:49 . 2008-11-06 21:49 <DIR> d-------- c:\program files\Business Objects 2008-11-06 19:05 . 2008-11-06 19:05 236 --a------ C:\sqmdata01.sqm 2008-11-06 19:05 . 2008-11-06 19:05 200 --a------ C:\sqmnoopt01.sqm 2008-11-02 02:07 . 2008-11-02 02:07 236 --a------ C:\sqmdata00.sqm 2008-11-02 02:07 . 2008-11-02 02:07 200 --a------ C:\sqmnoopt00.sqm 2008-10-31 22:08 . 2008-10-31 22:08 <DIR> d--hs---- c:\windows\ftpcache 2008-10-31 13:42 . 2001-11-21 19:12 12,160 --a------ c:\windows\system32\drivers\mouhid.sys 2008-10-31 13:42 . 2001-11-21 19:12 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys 2008-10-28 15:34 . 2008-10-28 15:34 <DIR> d-------- c:\program files\MSXML 4.0 2008-10-28 15:33 . 2008-04-14 13:00 221,184 --a------ c:\windows\system32\wmpns.dll 2008-10-27 11:44 . 2008-06-14 19:33 272,000 --------- c:\windows\system32\drivers\bthport.sys 2008-10-27 11:44 . 2008-06-14 19:33 272,000 -----c--- c:\windows\system32\dllcache\bthport.sys 2008-10-27 11:39 . 2008-08-14 15:23 2,191,104 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe 2008-10-27 11:39 . 2008-08-14 15:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe 2008-10-27 11:39 . 2008-08-14 15:23 2,067,968 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe 2008-10-27 11:39 . 2008-08-14 15:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe 2008-10-27 11:18 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe 2008-10-25 20:53 . 2008-10-25 20:53 <DIR> d-------- c:\program files\Apple Software Update 2008-10-25 20:53 . 2008-10-25 20:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-20 21:54 --------- d-----w c:\program files\lg_fwupdate 2008-11-19 15:54 --------- d-----w c:\program files\ESET 2008-11-17 19:35 --------- d-----w c:\documents and settings\XP-SP3\Application Data\Sports Interactive 2008-10-27 08:04 70,992 ----a-w c:\windows\system32\XAPOFX1_2.dll 2008-10-27 08:04 514,384 ----a-w c:\windows\system32\XAudio2_3.dll 2008-10-27 08:04 235,856 ----a-w c:\windows\system32\xactengine3_3.dll 2008-10-27 08:04 23,376 ----a-w c:\windows\system32\X3DAudio1_5.dll 2008-10-18 14:15 --------- d-----w c:\documents and settings\XP-SP3\Application Data\Apple Computer 2008-10-16 12:13 202,776 ----a-w c:\windows\system32\wuweb.dll 2008-10-16 12:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll 2008-10-16 12:12 561,688 ----a-w c:\windows\system32\wuapi.dll 2008-10-16 12:12 323,608 ----a-w c:\windows\system32\wucltui.dll 2008-10-16 12:09 92,696 ----a-w c:\windows\system32\cdm.dll 2008-10-16 12:09 51,224 ----a-w c:\windows\system32\wuauclt.exe 2008-10-16 12:09 43,544 ----a-w c:\windows\system32\wups2.dll 2008-10-16 12:08 34,328 ----a-w c:\windows\system32\wups.dll 2008-10-11 08:33 --------- d-----w c:\program files\Common Files\Activ Software 2008-10-11 08:33 --------- d-----w c:\program files\Activ Software 2008-10-11 08:33 --------- d-----w c:\documents and settings\All Users\Application Data\Activ Software 2008-10-11 08:31 --------- d-----w c:\program files\QuickTime 2008-10-11 08:30 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer 2008-10-11 07:12 --------- d-----w c:\program files\Windows Live 2008-10-11 07:12 --------- d-----w c:\program files\Microsoft 2008-10-11 07:10 --------- d-----w c:\program files\Common Files\Windows Live 2008-10-11 06:53 --------- d-----w c:\program files\Winamp 2008-10-11 06:53 --------- d-----w c:\documents and settings\XP-SP3\Application Data\Winamp 2008-10-10 02:52 452,440 ----a-w c:\windows\system32\d3dx10_40.dll 2008-10-10 02:52 4,379,984 ----a-w c:\windows\system32\D3DX9_40.dll 2008-10-10 02:52 2,036,576 ----a-w c:\windows\system32\D3DCompiler_40.dll 2008-09-27 17:04 --------- d-----w c:\program files\EA Sports 2008-09-21 21:54 --------- d-----w c:\program files\PDF Split-Merge v2.1 2008-09-21 19:41 --------- d-----w c:\documents and settings\XP-SP3\Application Data\Design Science 2008-09-21 18:34 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help 2008-09-21 18:27 --------- d-----w c:\program files\MathType 2008-09-20 18:16 --------- d-----w c:\program files\ABBYY FineReader 6.0 Sprint 2008-09-15 15:25 1,846,400 ----a-w c:\windows\system32\win32k.sys 2008-09-08 21:03 51,712 ----a-w c:\windows\system32\sirenacm.dll 2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll 2008-08-20 22:01 155,995 ----a-w c:\windows\java\Packages\ETZN9Z5F.ZIP 2008-08-20 20:05 315,392 ----a-w c:\windows\HideWin.exe 2004-10-01 12:00 102,400 ----a-w c:\program files\Uninstall_CDS.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NBJ"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-02-13 7557120] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 97792] "WhitneyXerox_S2P"="c:\program files\Xerox\Xerox WorkCentre PE220 Series\RCP\Scan2Pc.exe" [2005-08-16 131072] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 206224] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 217088] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 475136] "PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-07-07 229376] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-09-28 98304] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-02-13 86016] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 217088] "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-08-20 311296] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-09-28 102400] "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2006-03-14 1397760] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 101232] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-11-28 988701] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2005-11-28 118784] "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe] "RTHDCPL"="RTHDCPL.EXE" [2007-02-26 c:\windows\RTHDCPL.exe] "nwiz"="nwiz.exe" [2006-02-13 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "nltide_2"="shell32" [X] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.divxa32"= msaud32_divx.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\Turkish\\setup.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\WINDOWS\\ALCMTR.EXE"= "c:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe"= "c:\\WINDOWS\\system32\\NeroCheck.exe"= "c:\\Program Files\\QuickTime\\qttask.exe"= "c:\\Program Files\\Xerox\\Xerox WorkCentre PE220 Series\\RCP\\FaxRCP.exe"= "c:\\WINDOWS\\system32\\userinit.exe"= "c:\\Program Files\\Team JPN\\Football Manager 2009\\fm.exe"= "c:\\WINDOWS\\system32\\wscntfy.exe"= "c:\\WINDOWS\\system32\\drwtsn32.exe"= "c:\\Program Files\\Winamp\\winampa.exe"= "c:\\DOCUME~1\\XP-SP3\\LOCALS~1\\Temp\\winaamj.exe"= "c:\\DOCUME~1\\XP-SP3\\LOCALS~1\\Temp\\wingfvsr.exe"= "c:\\DOCUME~1\\XP-SP3\\LOCALS~1\\Temp\\winygvw.exe"= R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784] R0 videX32;videX32;c:\windows\system32\DRIVERS\videX32.sys [2008-08-20 9216] R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\DRIVERS\xfilt.sys [2008-08-20 17920] R1 BIOS;BIOS;\??\c:\windows\system32\drivers\BIOS.sys [2008-08-20 13696] R3 aic32p;aic32p;\??\c:\windows\system32\drivers\klkrhn.sys [] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-03-25 24592] S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys [2001-08-17 18688] S3 ovt530;WC-OML300;c:\windows\system32\Drivers\ov530vid.sys [2006-02-08 173939] . Contents of the 'Scheduled Tasks' folder 2008-11-15 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] . - - - - ORPHANS REMOVED - - - - HKCU-Run-PowerBar - (no file) . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com.tr/ IE: Microsoft Excel'e &Ver - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: {BB513461-EEDC-497B-A19D-36E91ABD8B46} = 4.2.2.2,4.2.2.3 O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd c:\windows\system32\atl.dll - c:\windows\system32\mfc42.dll c:\windows\system32\msvcrt.dll c:\windows\system32\olepro32.dll c:\windows\Downloaded Program Files\mfc42u.dll c:\windows\Downloaded Program Files\reportparameterdialog.dll c:\windows\Downloaded Program Files\CRViewer.dll c:\windows\Downloaded Program Files\sviewhlp.dll c:\windows\Downloaded Program Files\swebrs.dll O16 -: {6F0892F7-0D44-41C3-BF07-7599873FAA04} hxxp://reporteokul.meb.gov.tr/crystalreportviewers115/ActiveXControls/activexviewer.cab c:\windows\Downloaded Program Files\crviewer.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-20 23:54:17 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . c:\program files\Ahead\InCD\InCDsrv.exe c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\windows\ATKKBService.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe c:\windows\system32\wscntfy.exe c:\windows\system32\telnet.exe c:\windows\system32\telnet.exe c:\docume~1\XP-SP3\LOCALS~1\Temp\winaamj.exe c:\docume~1\XP-SP3\LOCALS~1\Temp\wingfvsr.exe c:\docume~1\XP-SP3\LOCALS~1\Temp\winygvw.exe . ************************************************************************** . Completion time: 2008-11-20 23:59:08 - machine was rebooted ComboFix-quarantined-files.txt 2008-11-20 21:59:01 Pre-Run: 6.463.983.616 bayt boş Post-Run: 6,544,576,512 bayt boş 232 --- E O F --- 2008-10-28 13:39:39
|
|
|
|