Results 1 to 21 of 21

Thread:

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location:
    Posts: 754

    - , autorun.inf myfolder, . explorer.exe Unlocker. , , . .inf :

    Code:
    [autorun]
    useautoplay=1
    shellexecute=myfolder\myfile.exe
    myfile.exe ( ), ... service-. .log HiJackThis:

    Code:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 12:02:01, on 16.5.2010 .
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal
    
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RunDLL32.exe
    D:\Programs\Vista Drive Icon\DrvIcon.exe
    D:\Programs\Glass\Glass2k.exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\Programs\TaskSwitch XP\TaskSwitchXP.exe
    C:\Program Files\Vista Rainbar\Rainmeter.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\BitMeter\BitMeter2.exe
    D:\Programs\TClock\tclock.exe
    D:\Programs\Wallpaper Master\Wallpaper.exe
    D:\Programs\Y'z Toolbar\YzToolBar.exe
    C:\WINDOWS\System32\svchost.exe
    D:\Programs\Glass\Glass2k.exe
    D:\Programs\Firefox\FirefoxPortable.exe
    D:\Programs\Firefox\App\firefox\firefox.exe
    C:\Documents and Settings\Name\Desktop\HiJackThis.exe
    
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.skype.com/go/help.guides.ieaddon?lang=en
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
    O1 - Hosts: 66.98.148.65 auto.search.msn.com
    O1 - Hosts: 66.98.148.65 auto.search.msn.es
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [DrvIcon] D:\Programs\Vista Drive Icon\DrvIcon.exe
    O4 - HKLM\..\Run: [MOD] C:\Program Files\Microangelo\muamgr.exe
    O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
    O4 - HKLM\..\Run: [Glass2k] D:\Programs\Glass\Glass2k.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TaskSwitchXP] D:\Programs\TaskSwitch XP\TaskSwitchXP.exe
    O4 - HKCU\..\Run: [Vista Rainbar] C:\Program Files\Vista Rainbar\Rainmeter.exe
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [uTorrent] "D:\Programs\uTorrent\utorrent.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: TClock.lnk = D:\Programs\TClock\tclock.exe
    O4 - Startup: Wallpaper.lnk = D:\Programs\Wallpaper Master\Wallpaper.exe
    O4 - Startup: YzToolBar.lnk = D:\Programs\Y'z Toolbar\YzToolBar.exe
    O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\BitMeter\BitMeter2.exe
    O4 - Global Startup: SystemExplorerDisabled
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted IP range: http://192.168.1.1
    O15 - ESC Trusted IP range: http://192.168.1.1
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
    O23 - Service: gadzlI - Unknown owner - D:\Programs\PC Wizard\Data\pcwizntl.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
    
    --
    End of file - 5613 bytes
    : , , , . , , .exe ( IE, ); , Firefox - ?

  2. #2
    Registered User der's Avatar
    Join Date: Jun:2005
    Location: spain
    Posts: 185
    | ASUS P5K3 DELUXE/WIFI-AP | DDR3 Kingston 1600 4x2GB | INTEL CORE 2 QUAD QX9650 EXTREME | POWER APEX 800W | HDD 500GB WESTERN DIGITAL BLACK SATA II |HDD 500GB WESTERN DIGITAL CAVIAR BLUE SATA III | VGA PNY 8800 ULTRA 768MB DDR3 |

  3. #3
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location:
    Posts: 754
    , , .

    Quote Originally Posted by bsb View Post
    .
    , , ...

    : !

  4. #4

  5. #5
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location:
    Posts: 754
    .

  6. #6
    Registered User
    Join Date: Oct:2003
    Location:
    Posts: 4,317
    - "" sdra64.exe,
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.ex e,C:\WINDOWS\system32\sdra64.exe,

    , . . (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\W indows NT\CurrentVersion\Winlogon), userinit.exe. .
    sdra64 ( ) .

  7. #7
    Windows 8 Fanatic speedycars's Avatar
    Join Date: May:2005
    Location:
    Posts: 3,090
    Kaspersky .
    P35-DS3P|C2D E8500@4GHz L2-6MB|6GB DDR2@844MHz|GALAXY 9800GT 512MB DDR3|WD 1TB '-32MB |POWERED BY FORTRON BLUE STORM PRO 500W|M$ +|SAMSUNG 226BW|CREATIVE X-FI PLATINUM FATAL1TY CHAMPION+INSPIRE T7900
    BGPatch.com <-- ! ツ

  8. #8
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location:
    Posts: 754
    Quote Originally Posted by speedycars View Post
    Kaspersky .
    Virus Remover , , , .

  9. #9
    Registered User jossbomon's Avatar
    Join Date: Nov:2008
    Location:
    Posts: 226
    . , "Local Disk".

  10. #10
    Banned
    Join Date: Oct:2003
    Location:
    Posts: 5,259
    100% , , 2 :

    - read-only

    -
    Fsutil file createnew G:\dummy 450256729
    ( , , , , )


    4 - 2 16GB 2 x 32GB -
    autorun- .
    Last edited by Softman; 17th May 2010 at 15:24.

  11. #11
    Registered User brnn's Avatar
    Join Date: Jun:2006
    Location:
    Posts: 754
    Quote Originally Posted by Softman View Post
    100% , , 2 :

    - read-only

    - ( , , , , )

    4 - 2 16GB 2 x 32GB -
    autorun- .
    , .

  12. #12
    Registered User SeT's Avatar
    Join Date: Aug:2002
    Location: Sofia
    Posts: 6,865
    , / ?

  13. #13
    Banned
    Join Date: Oct:2003
    Location:
    Posts: 5,259
    Quote Originally Posted by SeT View Post
    , / ?
    - ( )
    - ( , )
    , / 50 , - (8GB 42 )

  14. #14
    Registered User SeT's Avatar
    Join Date: Aug:2002
    Location: Sofia
    Posts: 6,865
    , .
    , .

  15. #15
    Registered User
    Join Date: Feb:2008
    Location:
    Posts: 5,585
    - . , ,, autorun . .

  16. #16
    Registered User Shnureaga's Avatar
    Join Date: Jun:2008
    Location:
    Posts: 2,002
    Panda vaccine. , - .
    Asrock B450 Steel Legend / Ryzen 5 3600 stock w/ Jonsbo CR-1000 / TeamForce 32GB (4x8GB) 3200 MHz / SP 512GB + 14TB int & 10TB ext / ASRock RX 5600 XT Phantom Gaming 6GB OC / CM Silent Pro 700W / Acer V277 IPS @FullHD 75Hz + HP w2207 / Corsair 600T + 2x 200mm / Mad Catz R.A.T. TE / '

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Copyright © 1999-2011 . .
iskamPC.com | mobility.BG | Bloody's Techblog | | 3D Vision Blog |