lefuttattam hjacket csökkentett módban, ez lett az eredmény itt már írja azt két fájlt is:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:55:50, on 2008.03.26.
Platform: Windows XP Szervizcsomag 2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20696)
Boot mode: Safe mode
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Rendszergazda\Asztal\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [OutpostMonitor] C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe /tray /noservice
O4 - HKLM\..\Run: [OutpostFeedBack] "C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" /dump:os_startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: OP_CACHE.ATR (User 'Default user')
O4 - .DEFAULT User Startup: OP_CACHE.IDX (User 'Default user')
O4 - Startup: OP_CACHE.ATR
O4 - Startup: OP_CACHE.IDX
O4 - Global Startup: OP_CACHE.ATR
O4 - Global Startup: OP_CACHE.IDX
O8 - Extra context menu item: E&xportálás Microsoft Excel formátumba -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Kutatás - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\agnitum\outpos~1\wl_hook.dll
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 3332 bytes
utána lelfutattam a combofixet is ahogy írtad, viszont nem volt restart még:
ComboFix 08-03-25.3 - Rendszergazda 2008-03-26 9:08:55.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1038.18.1729 [GMT 1:00]
Running from: C:\Documents and Settings\Rendszergazda\Asztal\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\taskmgr.com
.
((((((((((((((((((((((((( Files Created from 2008-02-26 to 2008-03-26 )))))))))))))))))))))))))))))))
.
2008-03-25 20:44 . 2002-11-28 10:22 89,360 -ra------ C:\WINDOWS\system32\VB5DB.DLL
2008-03-25 20:44 . 2002-11-28 10:22 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
2008-03-25 20:44 . 2002-11-28 10:22 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
2008-03-25 20:44 . 2002-11-28 10:22 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
2008-03-25 20:44 . 2002-11-28 10:22 29,184 -ra------ C:\WINDOWS\system32\MSINET.oca
2008-03-25 20:44 . 2002-11-28 10:22 26,064 -ra------ C:\WINDOWS\system32\xmlinst.exe
2008-03-25 20:44 . 2002-11-28 10:22 24,576 -ra------ C:\WINDOWS\system32\msxml3a.dll
2008-03-23 16:23 . 2008-03-23 16:28 <DIR> d-------- C:\Program Files\CCleaner
2008-03-23 12:10 . 2008-03-25 09:36 26 --a------ C:\WINDOWS\Lic.xxx
2008-03-23 12:09 . 2004-08-17 16:48 152,576 --a------ C:\WINDOWS\R.COM
2008-03-23 12:09 . 2004-08-17 16:48 140,288 --a------ C:\WINDOWS\system32\T.COM
2008-03-17 22:20 . 2003-06-19 01:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-17 22:20 . 2008-03-17 22:20 388 --a------ C:\WINDOWS\ODBC.INI
2008-03-17 22:19 . 2008-03-20 15:38 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-17 22:19 . 2008-03-17 22:19 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-03-15 20:15 . 2008-01-30 09:30 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-03-12 08:50 . 2008-03-12 08:50 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-12 07:51 . 2008-03-25 20:44 <DIR> d-------- C:\Program Files\Ubisoft
2008-03-10 16:27 . 2008-03-15 18:26 <DIR> d-------- C:\Documents and Settings\Rendszergazda\Application Data\dvdcss
2008-02-27 21:33 . 2008-02-27 21:33 <DIR> d-------- C:\WINDOWS\system32\AGEIA
2008-02-27 21:33 . 2008-02-28 12:24 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-27 21:33 . 2008-02-28 12:24 <DIR> d-------- C:\Program Files\AGEIA Technologies
2008-02-27 21:12 . 2008-02-27 21:12 <DIR> d-------- C:\Program Files\THQ
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-26 08:06 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\uTorrent
2008-03-25 23:56 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\Skype
2008-03-25 19:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-25 16:06 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2008-03-25 07:31 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\skypePM
2008-03-23 15:15 --------- d-----w C:\Program Files\Symantec
2008-03-23 15:15 --------- d-----w C:\Program Files\Norton Internet Security
2008-03-23 15:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-23 15:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-23 15:05 --------- d-----w C:\Program Files\3DO
2008-03-14 07:56 --------- d-----w C:\Program Files\Anti Trojan Elite
2008-03-12 06:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-12 06:35 --------- d-----w C:\Program Files\SEGA
2008-03-08 14:04 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-03-08 14:04 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-03-04 11:23 --------- d-----w C:\Program Files\Trojan Remover
2008-02-28 11:24 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-28 11:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-24 20:06 --------- d-----w C:\Program Files\CDRDiagnostic
2008-02-22 21:26 --------- d-----w C:\Program Files\Dynamic Gaming Systems
2008-02-22 00:00 --------- d-----w C:\Program Files\Common Files\Skype
2008-02-21 18:23 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-21 18:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-21 17:59 --------- d-----w C:\Program Files\Skype
2008-02-21 17:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-02-21 17:54 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\Simply Super Software
2008-02-20 19:04 --------- d-----w C:\Program Files\Windows Live
2008-02-20 15:13 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-20 15:12 --------- d-----w C:\Program Files\UltraISO
2008-02-20 15:04 --------- d-----w C:\Program Files\Common Files\EZB Systems
2008-02-20 15:01 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\vlc
2008-02-20 13:23 --------- d-----w C:\Program Files\Winamp
2008-02-20 12:24 --------- d-----w C:\Program Files\uTorrent
2008-02-20 09:14 --------- d-----w C:\Program Files\UPHClean
2008-02-20 09:14 --------- d-----w C:\Program Files\TC PowerPack
2008-02-20 09:14 --------- d-----w C:\Program Files\D-Tools
2008-02-19 22:34 --------- d-----w C:\Program Files\KONAMI
2008-02-19 20:28 --------- d-----w C:\Documents and Settings\Rendszergazda\Application Data\Agnitum
2008-02-19 20:27 --------- d-----w C:\Program Files\Agnitum
2008-02-19 20:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Agnitum
2008-02-18 09:48 --------- d-----w C:\Program Files\Need for Speed ProStreet
2008-02-18 09:17 --------- d-----w C:\Program Files\VideoLAN
2008-02-18 08:44 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-18 08:42 --------- d-----w C:\Program Files\Nero
2008-02-18 07:14 --------- d-----w C:\Program Files\Analog Devices
2008-02-18 07:11 --------- d-----w C:\Program Files\DIFX
2008-02-18 07:06 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-02-18 02:47 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-18 02:46 --------- d-----w C:\Program Files\Microsoft WSE
2008-02-18 02:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-18 02:45 --------- d-----w C:\Program Files\Reference Assemblies
2008-02-18 02:45 --------- d-----w C:\Program Files\MSXML 6.0
2008-02-18 02:45 --------- d-----w C:\Program Files\MSBuild
2008-02-18 02:39 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-18 02:38 --------- d-----w C:\Program Files\Java
2008-02-18 02:38 --------- d-----w C:\Program Files\Common Files\Java
2008-01-30 09:30 76,288 ----a-w C:\WINDOWS\system32\usbui.dll
2008-01-30 09:30 75,776 ----a-w C:\WINDOWS\system32\storprop.dll
2008-01-30 09:30 57,728 ----a-w C:\WINDOWS\system32\drivers\redbook.sys
2008-01-30 09:29 3,072 ----a-w C:\WINDOWS\system32\drivers\audstub.sys
2008-01-30 08:43 28,672 ----a-w C:\WINDOWS\system32\setupold.exe
2008-01-30 08:43 100,736 ----a-w C:\WINDOWS\system32\drivers\nvatabus.sys
2008-01-30 08:30 82,944 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-01-30 08:29 60,288 ----a-w C:\WINDOWS\system32\drivers\drmk.sys
2008-01-30 08:29 52,864 ----a-w C:\WINDOWS\system32\drivers\DMusic.sys
2008-01-30 08:29 2,944 ----a-w C:\WINDOWS\system32\drivers\drmkaud.sys
2008-01-30 08:29 142,464 ----a-w C:\WINDOWS\system32\drivers\aec.sys
2008-01-30 08:27 937,984 ----a-w C:\WINDOWS\system32\wmnetmgr.dll
2008-01-30 08:26 96,768 ----a-w C:\WINDOWS\system32\srvsvc.dll
2008-01-30 08:25 91,136 ----a-w C:\WINDOWS\system32\mtxoci.dll
2008-01-30 08:24 981,760 ----a-w C:\WINDOWS\system32\mfc42u.dll
2008-01-30 08:23 991,744 ----a-w C:\WINDOWS\system32\drmv2clt.dll
2008-01-30 08:22 97,792 ----a-w C:\WINDOWS\system32\comrepl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-17 16:47 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OutpostMonitor"="C:\PROGRA~1\Agnitum\OUTPOS~1\op_mon.exe" [2007-12-08 16:51 1744384]
"OutpostFeedBack"="C:\Program Files\Agnitum\Outpost Firewall Pro\feedback.exe" [2007-12-04 14:45 405504]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceCopyAclwithFile"= 0 (0x0)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceCopyAclwithFile"= 0 (0x0)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoSMConfigurePrograms"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"StartMenuLogoff"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\agnitum\outpos~1\wl_hook.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 SandBox;SandBox;C:\WINDOWS\system32\DRIVERS\SandBox.sys [2007-11-29 18:23]
R3 afw;Agnitum firewall driver;C:\WINDOWS\system32\DRIVERS\afw.sys [2007-12-03 13:40]
S2 acssrv;Agnitum Client Security Service;C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe [2007-12-04 14:47]
S3 ASWFilt;ASWFilt;C:\WINDOWS\system32\Filt\ASWFilt.dll [2007-11-29 18:24]
S3 ATE_PROCMON;ATE_PROCMON;C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\SETUP.EXE /AUTORUN
\Shell\configure\command - F:\SETUP.EXE
\Shell\install\command - F:\SETUP.EXE
*Newly Created Service* - SRSERVICE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-26 09:10:08
Windows 5.1.2600 Szervizcsomag 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\OP_CACHE.ATR 2520 bytes
C:\WINDOWS\OP_CACHE.IDX 1260 bytes
C:\WINDOWS\system32\OP_CACHE.ATR 52488 bytes
C:\WINDOWS\system32\OP_CACHE.IDX 26244 bytes
C:\WINDOWS\system32\drivers\OP_CACHE.ATR 5472 bytes
C:\WINDOWS\system32\drivers\OP_CACHE.IDX 2736 bytes
scan completed successfully
hidden files: 6
**************************************************************************
.
Completion time: 2008-03-26 9:10:22
ComboFix-quarantined-files.txt 2008-03-26 08:10:20