Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

SkyNET.sys pomoc!

[es] :: Zaštita :: SkyNET.sys pomoc!

[ Pregleda: 6339 | Odgovora: 15 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon SkyNET.sys pomoc!07.09.2009. u 19:37 - pre 191 meseci
imam veliki problem sa ovim,pre par dana skenirao sam komp sa Spybot - Search & Destroy i on mi je pronasao ovo



normalno,isao sam na FIX i program ga je izbrisao,posle toga pokusavam da pokrenem Progdvb(za satelitsku karticu,skystar2) i prijavljuje mi neki gresku da mi nedostaje neki fajl,pogledam u device manager i vidim da prijavljuje neku gresku za skystar2 karticu i da nesto nije uredu sa driver-om,odradim reinstall drivera i opet pocne da radi. posle toga opet skeniram,opet pronadje taj skynet.sys,opet ga obrisem i opet moram da instaliram driver-e da bi radilo. tako sam se smarao sa tim par puta i podignem sistem,sveza instalacija,driveri,opet instaliram skystar2 karticu,skeniram sa Spybot-om i opet je sve tu,dignem sistem opet i problem stoji kao da nisam dizao sistem. onda sam pomislio da disk gde mi stoje driver od kartice da on ima virus u sebi iako taj disk imam sigurno bar 3 godine i da mi nikad nije pravio problem,nadjem na netu te driver-e,skinem,narezem,opet podignem sistem,i ista prica plus AVG pocinje povremeno da izbacuje ovo prozore








pokusam da skeniram sa Combofix-om,ali nesto nece,iskljucim anti-virus,izbaci mi onaj prozorcic o garancije,kliknem na yes,izbaci mi onaj plavi prozor i nista se ne desava,prozor stoji prazan 30 minuta.....
znaci Spybot ga pronadje i izbrise ali posle toga ne mogu vise da koristim skystar2 i ne mogu da gledam satelim,e sad neko moje misljenje je da se taj virus mora izbaciti iz tog fajla a da taj fajl ostane posto je on ocito deo tog drivera...



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:37:18 PM, on 9/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: PowerInstall Softcam Updater.lnk = C:\Program Files\Free Pack\PSU\PSU.EXE
O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACCF4E71-DF7D-4AC5-87F3-A71C79AE137B}: NameServer = 93.93.192.2,93.93.192.3
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 3617 bytes
 
Odgovor na temu

valjan
Janko Valencik
Software Deployer
Schneider Electric
Novi Sad

Moderator
Član broj: 158605
Poruke: 3531
*.dynamic.sbb.rs.



+553 Profil

icon Re: SkyNET.sys pomoc!07.09.2009. u 21:16 - pre 191 meseci
Iz onih AVG izvestaja vidim da imas veoma gadnog gosta - Downadup, odnosno Conficker. Da te utesim, ima ga jos nekoliko miliona racunara sirom planete. U temi http://www.elitesecurity.org/t369192-kako-da-izbrisem-conflicker smo pricali kako se uklanja, pa ti je moj savet da prvo zakrpis Windows onako kako smo opisali u toj temi, jer retko koji antivirus moze da pomogne ako ti crvi mogu uci u komp na mala vrata i blokirati sam AV program. To je kao da stavis nocnog cuvara, a ne pozakljucavas vrata i ne zatvoris prozore, i onda udje ko hoce, klepi cuvara po glavi i ti se posle ujutro slikaj. Znaci, prvo ocisti Confickera i zakrpi Windows onako kako je opisano u pomenutoj temi, a onda se javi sa logovima da vidimo sta jos imas za ciscenje na kompu...
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 14:12 - pre 191 meseci
skenirao sam sa Dr.Web CureIt,on je pronasao neka dva virusa koja je ocistio,instalirao sam i one zakrpe,ponovo skenirao sa Spybot-om i on mi opet prijavljuje SkyNET.sys

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:12:18 PM, on 9/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\Program Files\Girder\Girder.exe
C:\Program Files\Free Pack\PSU\PSU.EXE
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Girder3.lnk = C:\Program Files\Girder\Girder.exe
O4 - Startup: PowerInstall Softcam Updater.lnk = C:\Program Files\Free Pack\PSU\PSU.EXE
O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACCF4E71-DF7D-4AC5-87F3-A71C79AE137B}: NameServer = 93.93.192.2,93.93.192.3
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 3814 bytes
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 14:22 - pre 191 meseci
sad sam pokusao da skeniram i sa Combofix-om ali nece,samo plavi prozorcic i nista se ne desava



vidim da je na C particiji napravio ovo



a u ovom bug.txt je ovo


PUSHD "C:\32788R22FWJFW"

SET "Comspec=C:\WINDOWS\system32\cmd.execf"

IF NOT EXIST C:\WINDOWS\system32\cmd.exe GOTO Not_NT

VER 1>OsVer

GREP.cfxxe -F "5.1.2" OsVer 1>XP.mac

IF 0 == 0 GOTO NT

SET "Ver_CF=09-09-07.05"

IF NOT EXIST NircmdB.exe COPY /Y Nircmd.cfxxe NircmdB.exe
1 file(s) copied.

PEV UZIP License\pv_5_2_2.zip .\

MOVE /Y PV.exe PV.cfxxe

IF NOT EXIST PEV.cfxxe COPY /Y PEV.exe PEV.cfxxe
1 file(s) copied.

GREP.cfxxe -isq "ProductType.*WinNT" WinNT00 || GOTO Not_NT

SED "/^PATH=/I!d; s///; s/\x22//g" Oripath 1>OriPath00

PEV -rtf -s+901 .\OriPath00 && (
SED -r "s/\x22//g; s/(.{900}).*/\1/; s/;[^;]*$//" OriPath00 1>OriPath01
FOR /F "TOKENS=*" %G IN (OriPath01) DO @SET "PATH=C:\32788R22FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;%G"
)

IF NOT EXIST OriPath01 FOR /F "TOKENS=*" %G IN (OriPath00) DO SET "PATH=C:\32788R22FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;%G"

SET "PATH=C:\32788R22FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem"
Killing 'runonce.exe'
Killing 'grpconv.exe'
Killing 'procmon.exe'
Killing 'ANDRE.EXE'
Killing 'TOLO.exe'
Killing 'Merlin.scr'
Killing 'jalang.exe'
Killing 'jalangkung.exe'
Killing 'jantungan.exe'
Killing 'DOSEN.exe'
Killing 'C3W3K4MPUS.exe'
pv: No matching processes found

PEV -rtf --c:##5# .\* and { License.exe or 32788R22FWJFW.exe or OsVer.exe or WinNT.exe or N_.exe } 1>temp00 && (
PV -o%f * 1>temp01
PEV -tf -t!o --files:temp01 --c:##5#b#f# 1>temp02
GREP -Fif temp00 temp02 1>temp03
SED "/.* /!d; s///" temp03 1>temp04
SED ":a; $!N; s/\n/\x22 \x22/; ta; s/.*/\x22&\x22/" temp04 1>temp05
FOR /F "TOKENS=*" %G IN (temp05) DO @NIRCMD KILLPROCESS %G
)
Active code page: 1252
Could Not Find C:\32788R22FWJFW\AbortB

CALL :MDCheck
Could Not Find C:\32788R22FWJFW\md5sum00.pif

PEV -rtf -md54C31434B834B14D226AEA1A0A5C172C4 .\md5sum.pif || CALL :MDFaiL ChkSum_Fail
.\md5sum.pif

PEV -tf --files:files.pif --c:##5#b#f# 1>mdCheck00.dat

GREP -vs "^!MD5:" mdCheck00.dat 1>mdCheck0a.dat

GREP -Fvf md5sum.pif mdCheck0a.dat 1>mdCheck01.dat && CALL :MDFaiL

GOTO :EOF

=============================================

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Administrator\Application Data
cfExt=cfxxe
CFLDR=32788R22FWJFW
Chksum=4C31434B834B14D226AEA1A0A5C172C4
CLIENTNAME=Console
Command switches used=Command switches used
CommonProgramFiles=C:\Program Files\Common Files
Completion time=Completion time
COMPUTERNAME=ACA-6506012B686
ComSpec=C:\WINDOWS\system32\cmd.execf
Connecting to=Connecting to
Connecting to ComboFix servers=Connecting to ComboFix servers
Cryptography Services Error=Cryptography Services Error
Disclaimer=The following websites are not in any way affiliated to ComboFix:~n~n http://www.combofix.org/~n http://www.combofixdownload.com/~n~nIf you have purchased anything from them, I suggest you instruct your~nfinanciers to cancel the transaction.~n~n ----------------------- -----------------------~n~nA guide on proper ComboFix usage may be found at:~nhttp://www.bleepingcomputer.co...ow-to-use-combofix~n~nComboFix is meant for private use. It should never be used in an~nunsupervised environment. If infections are found, it will automatically~nreboot the machine to complete the removal process. Please ensure all~nopened windows are closed before proceeding.~n~nThis software is provided 'as is', without warranty of any kind. All~nimplied warranties are expressly disclaimed. If you do not agree to the~nabove terms, please click No to exit" "DISCLAIMER OF WARRANTY ON SOFTWARE.
DLLs Loaded Under Running Processes=DLLs Loaded Under Running Processes
Drivers/Services=Drivers/Services
Fail2Delete=failed to delete
File Associations=File Associations
File Replicators=File Replicators
Files Infected - Patched=Files Infected - Patched
FIREFOX POLICIES=FIREFOX POLICIES
FP_NO_HOST_CHECK=NO
hidden files=hidden files
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Administrator
is infected=is infected
is missing=is missing
KMD=CF20818.exe
LANG_CF=EN
Line1=Please wait.
Line10=ComboFix has detected the presence of rootkit activity and needs to reboot the machine~nKindly note down on paper, the name of each file. We may need it later~n~n%~G" "Rootkit !!
Line10A=ComboFix has detected the presence of rootkit activity and needs to reboot the machine" "Rootkit !!
Line11=Scanning for infected files . . .
Line12=This typically doesn't take more than 10 minutes
Line13=However, scan times for badly infected machines may easily double
Line14=%G ...... driver unloaded successfully.
Line15=Rootkit driver %G is still present. A rootkit scan is required
Line16=ComboFix has changed your clock settings.
Line17=Do not change it back. It shall be restored later
Line18=ComboFix encountered a terminal error!! Please upload this file - C:\ComboFix_error.dat
Line19=to: http://www.bleepingcomputer.com/submit-malware.php?channel=4
Line2=ComboFix is preparing to run.
Line20=Preparing Log Report.
Line21=Do not run any programs until ComboFix has finished
Line22=No new files created in this timespan
Line23=*Note* empty entries ^& legit default entries are not shown
Line24=Contents of the 'Scheduled Tasks' folder
Line25=Almost done . . This window will close in a short while
Line26=Please wait a few seconds for the report log to pop up
Line27=ComboFix's log shall be located at C:\COMBOFIX.TXT
Line28=Rebooting Windows . . . Please wait
Line29=Please allow ComboFix to reboot the machine.
Line3=You need Administrative privileges to run this tool" "Not Admin !!
Line30=Overlay aborted ... Please run ComboFix once more
Line31=Date Error: ~%CurrDate.yyyy-MM-dd%~n~nCheck your settings" "DATE ERROR
Line32=C:\WINDOWS\system32\HAL.DLL is missing !!~n~nIt's IMPORTANT that you DO NOT reboot/shutdown the machine~n~nPost to the forums for immediate help. Do not click OK until further instructed" "CRITICAL WARNING !!
Line33=ComboFix needs to submit malware files for further analysis.~n~nPlease ensure that you're connected to the internet before clicking OK" "Submit Files for further analysis
Line34=Submit malware to Bleeping Computer for analysis.
Line35=Copy/Paste the filepath below into the box above and click Send.
Line36=Infected copy of %~1 was found and disinfected
Line36A=Restored copy from - %~2
Line37=%~1 . . . is infected!!
Line38=((((((((((((((((((((((((( Files Created from %thirty% to %dateX% )))))))))))))))))))))))))))))))
Line39=(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
Line4=C:\WINDOWS\regedit.exe is missing~n~nCopy one from another machine" "Terminal Error - Missing file
Line40=Webserver appears to be temporarily inaccessible.~nFor your convenience, ComboFix created a submissions form located at:~n~n* C:\CF-Submit.htm~n~nPlease use that to manually upload it later. " "Upload Failed!!
Line41=((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
Line42=((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
Line43=Deleting Files:
Line43A=Deleting Folders:
Line44=- REDUCED FUNCTIONALITY MODE -
Line45=SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.
Line46=scanning hidden processes ...
Line47=scanning hidden autostart entries ...
Line48=scanning hidden files ...
Line49=-- Snapshot reset to current date --
Line5=Current date is ~%CurrDate.yyyy-MM-dd%. ComboFix has expired~n~nClick 'Yes' to run in REDUCED FUNCTIONALITY mode~n~nClick 'No' to exit" "Version_%ver_CF%
Line50=ComboFix is uninstalled" "Info
Line51=Will only install the Recovery Console for Windows XP
Line52=Boot Partition cannot be enumerated correctly
Line53=%BootDir%Boot.ini is not correctly formated
Line54=This machine already has the Recovery Console installed.~n~nAborting operations
Line55=Please click 'YES' in the End User License Agreement (EULA) dialog that follows ..." "Installing the Recovery Console
Line56=Installation file - %~G - cannot be found
Line57=You didn't select YES~n~nInstallation is aborted
Line58=Contents of %BootDir%cmdcons are not in order.~n~nPlease disable your security programs before trying again
Line59=Congratulations!!! The Microsoft Recovery Console was successfully installed.~n~nOn each restart of the machine, a black screen will offer you the option to boot into recovery console mode.~nFor normal use, just ignore the black screen. Windows shall boot normally in 2 seconds~n~nClick 'Yes' to continue scanning for malware" "Info
Line6=Were you trying to run CFScript?~n~nThe name, CFScript appears to be incorrectly spelt" "CFScript Name Error
Line60=Click 'Yes' to continue scanning for malware~n~nClick 'No' to exit" "What's next ?
Line62=There's a newer version of ComboFix available.~n~nWould you like to update ComboFix?" "Update
Line63=--- WARNING !! ---~n~nA critical update is required.~n~nComboFix shall now update itself.~n~n--- WARNING !! ---" "Mandatory Update
Line64=Failed to download updated copy.~n~nWill continue with existing copy" "Failed Download
Line65=ComboFix shall now restart" "Updated
Line66=Interference detected~n~nPlease perform a Rootkit Scan" "Abort!
Line67=You cannot rename ComboFix as %FileName%~n~nPlease use another name, preferbaly made up of alphanumeric characters
Line68=%cd% not in expected location~n~n Inform sUBs now!!
Line69=ComboFix effected repairs on missing C:\WINDOWS\system32\hal.dll
Line7=Attempting to create a new System Restore point
Line70=This machine does not have the 'Microsoft Windows recovery console' installed~n~nWithout it, ComboFix shall not attempt the fixing of some serious infections.~n~nClick 'Yes' to have ComboFix download/install it.~n~nNOTE: this requires an active internet connection." "Microsoft Windows Recovery Console
Line71=Click 'Yes' if this is a WINDOWS XP *HOME EDITION* machine" "XP Home Edition
Line72=Failed to download required files. Aborting ... ~n~nShall continue scanning for malware
Line73=Internal error! Failed to enumerate download path. ~n~nAborting ... Shall continue scanning for malware
Line74=You do not appear to be connected to the internet. Kindly connect before clicking 'OK'
Line75=The following files were trying to attach to ComboFix. They shall be disabled~nKindly note down on paper, the name of each file. We may need it later~n~n%~G" "Parasites found !!
Line76=ComboFix has detected the following real time scanner(s) to be active:~n~n%G~n~nAntivirus and intrusion prevention programs are known to interfere~nwith ComboFix's running. This may lead to unpredictable results or~npossible machine damage.~n~nPlease disable these scanners before clicking 'OK'." "Warning !!
Line77=%G~n~nThe above real time scanner(s) are still active but ComboFix shall~ncontinue to run. Kindly note that this is at your own risk" "Warning !!
Line78=%~1 was missing
Line79=%~1 . . . is missing!!
Line8=Rich text formats (RTF) are unacceptable !!~n~nPlease save CFScript commands as a textfile, using Notepad.exe" "ERROR - Script format is incorrect
Line80=!! ALERT !! It is NOT SAFE to continue!~n~nThe contents of the ComboFix package has been compromised.~nPlease download a fresh copy from:~n~nhttp://www.bleepingcomputer.co...x/how-to-use-combofix~n~nNote: You may be infected with a file patching virus 'Virut'" "Error
Line81=ComboFix's script appears tampered. It is not safe to continue.~nComboFix shall now exit. Please inform the forum helper that's aiding~nyou. Unless further instructed to do so, do not run ComboFix again." "Failed Verification
Line82=Webserver appears to be temporarily inaccessible.~nFor your convenience, a zipped file has been created at:~n~nC:\CFCollect.zip~n~nPlease upload the file to BleepingComputer~n~nDo not forget to fill in the 'Comments' section" "Upload Failed!!
Line83=[COLOR=RED]NETSVCS REQUIRES REPAIRS - current entries shown[/COLOR]
Line84=http://download.bleepingcomputer.com/sUBs/ComboFix.exe~nhttp://www.forospyware.com/sUBs/ComboFix.exe~n~nComboFix.exe may be downloaded from any of the above sites. If you~nhave downloaded from some other site, there's a likely chance that it~nmay be tainted. For peace of mind, I suggest that you delete the current~ncopy and get a fresh one." "Caution
Line85=[color=red]Manual Fix is required for restoring CommonStartup[/color]
Line9=Rootkit driver %G is present. ... attempting disinfection
Line90=ComboFix needs to perform a deeper scan
Line91=This should not take more than 10-15 minutes
Line92=Infected HTML files detected.
Line93=ComboFix will now attempt to disinfect
Line94=This is going to take some time
Line95=Disinfection complete !!! ... continuing Log Report preparation
Line96=Recovery in Progress . . .
Line97=WARNING !! Do not manually reboot the machine yourself
LOCKED REGISTRY KEYS=LOCKED REGISTRY KEYS
LOGONSERVER=\\ACA-6506012B686
machine was rebooted=machine was rebooted
not completed=not completed
NUMBER_OF_PROCESSORS=2
ORPHANS REMOVED=ORPHANS REMOVED
OS=Windows_NT
Other Running Processes=Other Running Processes
Other Services/Drivers In Memory=Other Services/Drivers In Memory
Path=C:\32788R22FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.cfxxe;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
Possible infected sites=Possible infected sites
Post-Run=Post-Run
Pre-Run=Pre-Run
Previous Run=Previous Run
PROCESS=PROCESS
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=0f06
ProgramFiles=C:\Program Files
PROMPT=$
Qrntn=C:\Qoobox\Quarantine
RecoveryConsole=WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
Resident AV is active=Resident AV is active
RestorePoint= * Created a new restore point
RKEY_=hklm\software\microsoft\windows nt\currentversion\windows
Running from=Running from
scan completed successfully=scan completed successfully
SESSIONNAME=Console
sfxcmd="C:\Documents and Settings\Administrator\Desktop\ComboFix.exe"
sfxname=C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Stage=Completed Stage_
Supplementary Scan=Supplementary Scan
SYSTEM=C:\WINDOWS\system32
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
The following files were disabled during the run=The following files were disabled during the run
TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
Upload was successful=Upload was successful
Uploading files to server=Uploading files to server
USERDOMAIN=ACA-6506012B686
USERNAME=Administrator
USERPROFILE=C:\Documents and Settings\Administrator
Ver_CF=09-09-07.05
windir=C:\WINDOWS

=============================================


IF NOT DEFINED sfxname GOTO END

GREP -F \ temp01 && CALL :Aux

GREP -Fi "C:\WINDOWS\system32\userinit.exe" Userinit00 || (SWREG ADD "hklm\software\microsoft\windows nt\currentversion\winlogon" /v Userinit /d "C:\WINDOWS\system32\userinit.exe," )
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,

SET SfxCmd 1>SET00

SED -r "/SfxCmd=/I!d; s///; s/\s*$//; s/^(\x22[^\x22]*\x22|[^\x22]\S*) +//; s/^\x22*C:\\Documents and Settings\\Administrator\\Desktop\\ComboFix.exe\x22*//I; s/^([^\x22]\S*)/@SET SfxCmd=\x22\1\x22/; s/^(\x22.*)/@SET SfxCmd=\1/" SET00 1>sfx.cmd

DEL /A/F SET00

ATTRIB +R "C:\Documents and Settings\Administrator\Desktop\ComboFix.exe"

CALL sfx.cmd

CALL AV.cmd

SET /a AVCount+=1

NIRCMD EXEC HIDE PV -d9000 -kf CSCRIPT.EXE

CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:08 av.vbs

PV -kf CSCRIPT.exe PV.*
Killing 'CSCRIPT.exe'
Killing 'PV.*'

IF NOT EXIST AvBlack00 GREP -Fisf AVBlack resident.txt 1>AvBlack00 && (
SED -r "s/\x22//g; s/.*\) //; s/.*(\{.{8}-.{4}-.{4}-.{4}-.{12}\}).*/\1/" AvBlack00 1>AvBlack01
FOR /F "TOKENS=*" %G IN (AvBlack01) DO @CSCRIPT.EXE //NOLOGO //E:VBSCRIPT //T:5 wmi_rem.vbs "%~G"
NIRCMD EXEC HIDE PV -d6000 -kf CSCRIPT.EXE
CSCRIPT.exe //NOLOGO //E:VBSCRIPT //B //T:08 av.vbs
PV -kf CSCRIPT.exe PV.*
)

GREP -Fivf AVWhite resident.txt | GREP -E "^(AV|SP): .*enabled\* \(" 1>AVChk && (
SED -r "s/^AV:/antivirus: /; s/^SP:/antispyware: /; s/ \*(On-access scanning |)enabled\*.*//" AVChk | SED ":a; $!N;s/\n/~n/;ta" 1>AVChkB
NIRCMD LOOP 2 80 BEEP 3000 200
IF 1 LEQ 1 FOR /F "TOKENS=*" %G IN (AVChkB) DO @NIRCMD INFOBOX "ComboFix has detected the following real time scanner(s) to be active:~n~n%G~n~nAntivirus and intrusion prevention programs are known to interfere~nwith ComboFix's running. This may lead to unpredictable results or~npossible machine damage.~n~nPlease disable these scanners before clicking 'OK'." "Warning !!" "" && GOTO Av-check
IF 1 GTR 1 FOR /F "TOKENS=*" %G IN (AVChkB) DO @NIRCMD INFOBOX "%G~n~nThe above real time scanner(s) are still active but ComboFix shall~ncontinue to run. Kindly note that this is at your own risk" "Warning !!" ""
)

DEL /A/F/Q AVChk? AvWhite AvBlack AvBlack0?

SET AVCount=

IF EXIST vista.mac CALL :Vista

GREP -Fx "REGEDIT4" Fin.dat || (
ECHO.1>"C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tdsstdss"
PEV -rtf "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\tdsstdss" || (
ECHO.1>wtf_tdssserv
CALL c.bat
GOTO END
)

GOTO AbortD
)
REGEDIT4

IF /I "C:\32788R22FWJFW" NEQ "C:\32788R22FWJFW" GOTO Abort

IF EXIST "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\32788R22FWJFW32788R22FWJFW.log" DEL /A/F "C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\32788R22FWJFW32788R22FWJFW.log"

COPY /Y /B "C:\WINDOWS\system32\cmd.execf" "C:\WINDOWS\system32\CF20818.exe"
1 file(s) copied.

SET "COMSPEC=C:\WINDOWS\system32\CF20818.exe"

FOR /F "TOKENS=*" %G IN ("C:\Documents and Settings\Administrator\Desktop\ComboFix.exe") DO (
SET "FileName=%~NG"
SET "FilePath=%~DPG"
)

(
SET "FileName=ComboFix"
SET "FilePath=C:\Documents and Settings\Administrator\Desktop\"
)

SET FileName 1>FileName

GREP -ix "FileName=[-[:alnum:]@.]*" FileName || GOTO AbortB
FileName=ComboFix

DIR /AD/B C:\* 1>DirName00

GREP -ivx ComboFix DirName00 1>DirName01

GREP -Fisqx "ComboFix" DirName01 && CALL :NameChk

IF EXIST DirName0? DEL /A/F/Q DirName0?

IF EXIST Oldsfxname00 DEL /A/F Oldsfxname00

IF EXIST "\ComboFix\" (
SWXCACLS "\ComboFix" /RESET /Q
RD /S/Q "\ComboFix"
IF EXIST "\ComboFix\" (
PV -kf *.cfxxe
RD /S/Q "\ComboFix"
)
IF EXIST "\ComboFix\" (
HANDLE "C:\ComboFix" 1>temp00
SED -R "/.* pid: (\d*) +(\S*):.*/I!d;s//@ECHO.y|Handle -c \2 -p \1/" temp00 1>temp00.bat
CALL temp00.bat
DEL /A/F temp00.bat temp00
RD /S/Q "\ComboFix"
)
)

IF EXIST "\ComboFix\" RD /S/Q "\ComboFix"

IF EXIST "\ComboFix\" GOTO :EOF

PEV UZIP "License\streamtools.zip" License && MOVE /Y License\SF.exe 1>N_\27680 2>&1

GREP -Eisq "=.\/u.$" sfx.cmd && IF EXIST MsName.bat (ECHO.@SET SfxCmd= 1>sfx.cmd ) ELSE echo..1>ItsBeenPhun

DEL /A/F prep.done MsName.bat

CD ..

(


ECHO.MD "\ComboFix"
ECHO.ATTRIB -H -S "\32788R22FWJFW\*"
ECHO.MOVE /y "\32788R22FWJFW\*" "\ComboFix"
ECHO.RD /S/Q "\32788R22FWJFW"
IF EXIST "\32788R22FWJFW.0.tmp\" ECHO.RD /S/Q "\32788R22FWJFW.0.tmp"
IF EXIST "C:\32788R22FWJFW\ItsBeenPhun" ECHO.NIRCMD EXEC2 HIDE "C:\ComboFix" "C:\WINDOWS\system32\CF20818.exe" /c c.bat
IF NOT EXIST "C:\32788R22FWJFW\ItsBeenPhun" ECHO.START "." /d"C:\ComboFix" "C:\WINDOWS\system32\CF20818.exe" /k c.bat
ECHO.PV -kf cmd.exe cmd.execf
ECHO.DEL /A/F C:\Start_.cmd
) 1>Start_.cmd

SET "PATH=C:\ComboFix;C:\32788R22FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem"

HIDEC "C:\WINDOWS\system32\CF20818.exe" /F:OFF /D /C C:\Start_.cmd

NIRCMD WAIT 20
 
Odgovor na temu

valjan
Janko Valencik
Software Deployer
Schneider Electric
Novi Sad

Moderator
Član broj: 158605
Poruke: 3531
*.adsl.eunet.rs.



+553 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 14:54 - pre 191 meseci
Samo si instalirao zakrpe, ili si ispratio uputstvo korak po korak i OBRISAO conficker crva?
Evo ti direktan link do tacno tog posta sa uputstvom, namerno sam ti dao link za celu temu jer ima jos korisnih uputstava i saveta:
http://www.elitesecurity.org/p2328142
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 16:11 - pre 191 meseci
Da li biste mogli da zapakujete skynet.sys u ".rar"/".zip" sa password-om "virus", upload-ujete na Rapidshare i posaljete mi link preko PP?
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 16:23 - pre 191 meseci
poslato
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 16:49 - pre 191 meseci
Veoma je moguce da je FP. Sada cu da im posaljem, pa javljam odgovor.
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!08.09.2009. u 17:15 - pre 191 meseci
Citat:
Dashkes: Veoma je moguce da je FP. Sada cu da im posaljem, pa javljam odgovor.

hvala

Citat:
valjan: Samo si instalirao zakrpe, ili si ispratio uputstvo korak po korak i OBRISAO conficker crva?
Evo ti direktan link do tacno tog posta sa uputstvom, namerno sam ti dao link za celu temu jer ima jos korisnih uputstava i saveta:
http://www.elitesecurity.org/p2328142


odradio sam sve ovo,skenirao,izbrisao,instalirao drivere i opet je tu...
 
Odgovor na temu

valjan
Janko Valencik
Software Deployer
Schneider Electric
Novi Sad

Moderator
Član broj: 158605
Poruke: 3531
*.adsl.eunet.rs.



+553 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 07:18 - pre 191 meseci
Citat:
izida: odradio sam sve ovo,skenirao,izbrisao,instalirao drivere i opet je tu...


Siri se preko mreze ili preko zarazenih USB flasheva. Ako si instalirao one zakrpe, prvi izvor si eliminisao. Ostaje samo da proveris USB flasheve koje si kacio u medjuvremenu.
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 08:36 - pre 191 meseci
USB flash nije prisao mom racunaru bar jedno godinu dana
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 08:47 - pre 191 meseci
Obrisi ikonicu combofixa sa desktopa, nemoj da deinstaliras, samo obrisi.
Skini odavde CF http://download.bleepingcomputer.com/sUBs/ComboFix.exe na desktop
Iskljuci AV i tea timer, ako ne znas kako onda deinstaliraj Spybot dok ne zavrsimo, pa posle instaliraj ponovo.
pokreni combofix i za sve sto te pita odgovori potvrdno.
Kad zavrsi postavi log fajl.

Ne diraj plavi prozor programa dok Combofix radi !!!
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 12:42 - pre 191 meseci
Combofix je uspeo da skenira posle cekanja od jedno 2 sata,prvo mi je bio prazan plavi prozorcic jedno 30minuta,posle toga se pojavila poruka da nemam onu konzolu i da trebam da kliknem na yes da je skine,posle se u tom plavom prozorcicu pojavila adresa od MS i opet je tako stojalo jedno 30 minuta dok je nije skinuo,posle toga je skenirao normalno,restarovao se racunar i posle restarta mi je bila zuta ikonica od skystar2 kartice,odem na device manager i ova poruka stoji

skeniram sa Spybot-om i opet ga pronadje

odem na FIX,izbrise ga i to je to,ali meni treba taj fajl da bi radila satelitska televizija
evo log-a od Combofix-a

ComboFix 09-09-08.06 - Administrator 09/09/2009 12:23.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.507 [GMT 2:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_SKYNET
-------\Service_SKYNET


((((((((((((((((((((((((( Files Created from 2009-08-09 to 2009-09-09 )))))))))))))))))))))))))))))))
.

2009-09-08 17:54 . 2009-09-08 17:54 -------- d-----w- c:\program files\Webteh
2009-09-08 16:35 . 2009-09-09 09:13 -------- d-----w- C:\New Folder
2009-09-08 16:05 . 2009-09-08 16:05 -------- d-----w- c:\windows\ServicePackFiles
2009-09-08 15:28 . 2009-09-08 15:28 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-09-08 13:41 . 2009-09-08 13:41 -------- d-----w- c:\program files\Ubisoft
2009-09-08 13:12 . 2009-09-08 13:12 -------- d-----w- c:\program files\Trend Micro
2009-09-08 13:03 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-09-08 13:03 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-09-08 00:08 . 2009-09-08 00:10 -------- d-----w- c:\program files\Girder
2009-09-07 23:56 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2009-09-07 23:56 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2009-09-07 23:56 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2009-09-07 23:56 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2009-09-07 23:56 . 2009-06-02 16:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2009-09-07 23:56 . 2009-09-07 23:57 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-09-07 23:35 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-07 23:34 . 2009-09-07 23:42 -------- d-----w- c:\documents and settings\Administrator\DoctorWeb
2009-09-07 18:27 . 2009-09-08 23:35 -------- d-----w- c:\documents and settings\Administrator\Tracing
2009-09-07 18:22 . 2009-09-07 18:22 -------- d-----w- c:\program files\Microsoft
2009-09-07 18:22 . 2009-09-07 18:22 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-07 18:22 . 2009-09-07 18:22 -------- d-----w- c:\program files\Windows Live
2009-09-07 18:11 . 2009-09-07 18:11 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-07 17:57 . 2009-09-07 17:57 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ACD Systems
2009-09-07 17:57 . 2009-09-07 17:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\ACD Systems
2009-09-07 17:56 . 2009-09-07 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-09-07 17:56 . 2009-09-07 17:56 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-09-07 17:56 . 2009-09-07 17:56 -------- d-----w- c:\program files\ACD Systems
2009-09-07 17:53 . 2009-09-07 17:53 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Downloaded Installations
2009-09-07 16:17 . 2009-09-07 16:17 0 ----a-w- c:\windows\ativpsrm.bin
2009-09-07 16:15 . 2007-12-20 19:05 593920 ------w- c:\windows\system32\ati2sgag.exe
2009-09-07 16:14 . 2009-09-07 16:14 -------- d-----w- C:\ATI
2009-09-07 16:10 . 2009-09-07 16:10 -------- d-----w- c:\program files\Free Pack
2009-09-07 16:08 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2009-09-07 16:08 . 2004-08-03 22:59 57472 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-09-07 16:07 . 2004-08-03 22:56 74240 -c--a-w- c:\windows\system32\dllcache\usbui.dll
2009-09-07 16:07 . 2004-08-03 22:56 74240 ----a-w- c:\windows\system32\usbui.dll
2009-09-07 16:05 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-07 16:05 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-09-07 16:05 . 2009-09-09 09:16 -------- d--h--w- c:\documents and settings\Default User
2009-09-07 16:05 . 2009-09-08 16:03 -------- d-----w- c:\documents and settings\All Users
2009-09-07 16:05 . 2009-09-07 14:19 -------- d-----w- C:\Documents and Settings
2009-09-07 16:03 . 2009-02-06 17:24 2180480 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-07 16:03 . 2009-02-06 17:22 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-07 16:03 . 2009-02-06 16:49 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-09-07 16:03 . 2009-02-06 16:49 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-08 20:26 . 2009-09-07 14:43 196608 ----a-w- c:\windows\system32\drivers\aStandard.bin
2009-09-08 16:58 . 2009-09-07 15:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 13:41 . 2009-09-07 14:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-07 18:27 . 2009-09-07 14:24 12912 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-07 15:52 . 2009-09-07 15:52 -------- d-----w- c:\program files\DVBViewerTE
2009-09-07 15:51 . 2009-09-07 15:51 -------- d-----w- c:\program files\TechniSat DVB
2009-09-07 15:28 . 2009-09-07 15:28 -------- d-----w- c:\documents and settings\Administrator\Application Data\Ashampoo
2009-09-07 15:28 . 2009-09-07 15:28 -------- d-----w- c:\documents and settings\All Users\Application Data\ashampoo
2009-09-07 15:28 . 2009-09-07 15:28 -------- d-----w- c:\program files\Ashampoo
2009-09-07 15:16 . 2009-09-07 15:16 0 ----a-w- c:\windows\nsreg.dat
2009-09-07 15:12 . 2009-09-07 15:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-07 15:01 . 2009-09-07 14:50 -------- d-----w- c:\documents and settings\All Users\Application Data\comodo
2009-09-07 14:59 . 2009-09-07 14:59 -------- d-----w- c:\program files\CCleaner
2009-09-07 14:53 . 2009-09-07 14:44 -------- d-----w- c:\documents and settings\Administrator\Application Data\ATI
2009-09-07 14:50 . 2009-09-07 14:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Comodo
2009-09-07 14:50 . 2009-09-07 14:50 87056 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-07 14:50 . 2009-09-07 14:50 79760 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-09-07 14:50 . 2009-09-07 14:50 24208 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-07 14:50 . 2009-09-07 14:50 143104 ----a-w- c:\windows\system32\guard32.dll
2009-09-07 14:50 . 2009-09-07 14:50 -------- d-----w- c:\program files\COMODO
2009-09-07 14:49 . 2009-09-07 14:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-07 14:49 . 2009-09-07 14:49 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-07 14:48 . 2009-09-07 14:48 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-07 14:48 . 2009-09-07 14:48 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-07 14:48 . 2009-09-07 14:48 -------- d-----w- c:\program files\AVG
2009-09-07 14:48 . 2009-09-07 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-07 14:43 . 2009-09-07 14:43 -------- d-----w- c:\program files\My Company Name
2009-09-07 14:41 . 2009-09-07 14:38 -------- d-----w- c:\program files\ATI Technologies
2009-09-07 14:41 . 2009-09-07 14:41 -------- d-----w- c:\program files\Common Files\ATI Technologies
2009-09-07 14:37 . 2009-09-07 14:24 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-07 14:32 . 2009-09-07 14:32 -------- d-----w- c:\program files\Attansic
2009-09-07 14:25 . 2009-09-07 14:25 -------- d-----w- c:\program files\Realtek
2009-09-07 14:24 . 2009-09-07 14:24 315392 ----a-w- c:\windows\HideWin.exe
2009-09-07 14:21 . 2009-09-07 14:21 -------- d-----w- c:\program files\Intel
2009-09-07 14:15 . 2009-09-07 14:15 -------- d-----w- c:\program files\microsoft frontpage
2009-09-07 14:12 . 2009-09-07 14:12 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-05 09:11 . 2004-08-04 01:07 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:53 . 2004-08-04 01:07 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:53 . 2004-08-04 01:07 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 18:55 . 2004-08-04 01:07 58880 ----a-w- c:\windows\system32\atl.dll
2009-06-26 16:18 . 2004-08-04 01:07 659456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-04 01:07 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 18:36 . 2004-08-04 01:07 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-04 01:07 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-04 01:07 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-04 01:07 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-04 01:07 471552 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-04 01:07 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-04 01:07 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-04 01:07 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-04 01:07 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-04 01:07 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-04 01:07 138240 ----a-w- c:\windows\system32\mqad.dll
2009-06-25 18:36 . 2004-08-04 01:07 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2009-06-22 11:49 . 2004-08-04 01:07 19968 ----a-w- c:\windows\system32\mqbkup.exe
2009-06-22 11:49 . 2004-08-04 01:07 117248 ----a-w- c:\windows\system32\mqtgsvc.exe
2009-06-22 11:49 . 2004-08-04 01:07 4608 ----a-w- c:\windows\system32\mqsvc.exe
2009-06-22 11:48 . 2004-08-04 01:07 91776 ----a-w- c:\windows\system32\drivers\mqac.sys
2009-06-12 11:50 . 2004-08-04 01:07 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 11:50 . 2004-08-04 01:07 76288 ----a-w- c:\windows\system32\telnet.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-03 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-21 36864]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2007-05-08 1953792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-07 2007832]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2009-09-07 1655552]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-12 16126464]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-04-06 1822720]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Girder3.lnk - c:\program files\Girder\Girder.exe [2009-9-8 1830912]
PowerInstall Softcam Updater.lnk - c:\program files\Free Pack\PSU\PSU.EXE [2009-7-16 60081]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2009-9-7 344064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-07 14:49 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^AP Launch.lnk]
path=c:\documents and settings\Administrator\Start Menu\Programs\Startup\AP Launch.lnk
backup=c:\windows\pss\AP Launch.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's H.A.W.X\\HAWX.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/7/2009 4:48 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/7/2009 4:49 PM 108552]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [9/7/2009 4:50 PM 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [9/7/2009 4:50 PM 24208]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [9/7/2009 4:48 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/7/2009 4:48 PM 297752]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [9/7/2009 4:32 PM 38656]
R4 atidgllk;atidgllk;c:\windows\atidgllk.sys [9/7/2009 4:43 PM 5376]
.
.
------- Supplementary Scan -------
.
TCP: {ACCF4E71-DF7D-4AC5-87F3-A71C79AE137B} = 93.93.192.2,93.93.192.3
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\e0f6f2re.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.elitesecurity.org/f101-PC-DVB-kartice
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-09 12:26
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3308)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ATKKBService.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-09-09 12:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-09 10:30

Pre-Run: 38,792,306,688 bytes free
Post-Run: 38,751,600,640 bytes free

217 --- E O F --- 2009-09-08 16:08
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 12:59 - pre 191 meseci
Kao sto sam i mislio. FP.
Citat:
Hello,

thank you for reporting this issue. I can confirm that it is a false
positive.
The official correction of this issue will be released on Wednesday
2009-09-16.

Attached is a corrected TrojansC.sbi file so this false positive does
not appear again on your computer.
Save the attached TrojansC.sbi file to your Spybot S&D includes folder
(by default: c:\Program Files\Spybot - Search & Destroy\Includes\ ) and
overwrite the old one.

best regards


P.S. izida, poslao sam Vam link ka TrojansC.sbi datoteci.

[Ovu poruku je menjao Dashkes dana 09.09.2009. u 14:10 GMT+1]
 
Odgovor na temu

izida
stojanovic aleksandar
bgd

Član broj: 97823
Poruke: 1886
93.93.194.*

Sajt: www.youtube.com/watch?v=9..


+22 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 13:14 - pre 191 meseci
znaci da ubavim ovo sto si mi poslao u Includes,instaliram ponovo drivere i da uzivam?
ako je tako onda hvala!!!!
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: SkyNET.sys pomoc!09.09.2009. u 13:45 - pre 191 meseci
Nemas ti ovde nista cista masina
Deinstaliraj combofix

Start\ run \ combofix /u enter
 
Odgovor na temu

[es] :: Zaštita :: SkyNET.sys pomoc!

[ Pregleda: 6339 | Odgovora: 15 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.