Results 1 to 21 of 21
Hybrid View
-
16th May 2010 12:05 #1
- , autorun.inf myfolder, . explorer.exe Unlocker. , , . .inf :
myfile.exe ( ), ... service-. .log HiJackThis:Code:[autorun] useautoplay=1 shellexecute=myfolder\myfile.exe
: , , , . , , .exe ( IE, ); , Firefox - ?Code:Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 12:02:01, on 16.5.2010 . Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RunDLL32.exe D:\Programs\Vista Drive Icon\DrvIcon.exe D:\Programs\Glass\Glass2k.exe C:\WINDOWS\system32\ctfmon.exe D:\Programs\TaskSwitch XP\TaskSwitchXP.exe C:\Program Files\Vista Rainbar\Rainmeter.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\BitMeter\BitMeter2.exe D:\Programs\TClock\tclock.exe D:\Programs\Wallpaper Master\Wallpaper.exe D:\Programs\Y'z Toolbar\YzToolBar.exe C:\WINDOWS\System32\svchost.exe D:\Programs\Glass\Glass2k.exe D:\Programs\Firefox\FirefoxPortable.exe D:\Programs\Firefox\App\firefox\firefox.exe C:\Documents and Settings\Name\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.skype.com/go/help.guides.ieaddon?lang=en R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe, O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [DrvIcon] D:\Programs\Vista Drive Icon\DrvIcon.exe O4 - HKLM\..\Run: [MOD] C:\Program Files\Microangelo\muamgr.exe O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe O4 - HKLM\..\Run: [Glass2k] D:\Programs\Glass\Glass2k.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TaskSwitchXP] D:\Programs\TaskSwitch XP\TaskSwitchXP.exe O4 - HKCU\..\Run: [Vista Rainbar] C:\Program Files\Vista Rainbar\Rainmeter.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [uTorrent] "D:\Programs\uTorrent\utorrent.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: TClock.lnk = D:\Programs\TClock\tclock.exe O4 - Startup: Wallpaper.lnk = D:\Programs\Wallpaper Master\Wallpaper.exe O4 - Startup: YzToolBar.lnk = D:\Programs\Y'z Toolbar\YzToolBar.exe O4 - Global Startup: Bitmeter2.lnk = C:\Program Files\BitMeter\BitMeter2.exe O4 - Global Startup: SystemExplorerDisabled O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted IP range: http://192.168.1.1 O15 - ESC Trusted IP range: http://192.168.1.1 O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: gadzlI - Unknown owner - D:\Programs\PC Wizard\Data\pcwizntl.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe -- End of file - 5613 bytes
-
16th May 2010 12:25 #2| ASUS P5K3 DELUXE/WIFI-AP | DDR3 Kingston 1600 4x2GB | INTEL CORE 2 QUAD QX9650 EXTREME | POWER APEX 800W | HDD 500GB WESTERN DIGITAL BLACK SATA II |HDD 500GB WESTERN DIGITAL CAVIAR BLUE SATA III | VGA PNY 8800 ULTRA 768MB DDR3 |
-
16th May 2010 12:50 #3
-
16th May 2010 13:00 #4
-
16th May 2010 13:18 #5
-
16th May 2010 12:28 #6Registered User
Join Date: Oct:2003
Location:
Posts: 4,317
- "" sdra64.exe,
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.ex e,C:\WINDOWS\system32\sdra64.exe,
, . . (HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\W indows NT\CurrentVersion\Winlogon), userinit.exe. .
sdra64 ( ) .
-
16th May 2010 13:26 #7
Kaspersky .
P35-DS3P|C2D E8500@4GHz L2-6MB|6GB DDR2@844MHz|GALAXY 9800GT 512MB DDR3|WD 1TB '-32MB |POWERED BY FORTRON BLUE STORM PRO 500W|M$ +|SAMSUNG 226BW|CREATIVE X-FI PLATINUM FATAL1TY CHAMPION+INSPIRE T7900
BGPatch.com <-- ! ツ
-
16th May 2010 15:38 #8
-
17th May 2010 14:59 #9
-
17th May 2010 15:14 #10Banned
Join Date: Oct:2003
Location:
Posts: 5,259
100% , , 2 :
- read-only
-( , , , , )Fsutil file createnew G:\dummy 450256729
4 - 2 16GB 2 x 32GB -
autorun- .Last edited by Softman; 17th May 2010 at 15:24.
-
17th May 2010 16:27 #11
-
17th May 2010 15:29 #12
-
17th May 2010 15:37 #13Banned
Join Date: Oct:2003
Location:
Posts: 5,259
-
17th May 2010 16:27 #14
-
2nd May 2011 21:51 #15Registered User
Join Date: Feb:2008
Location:
Posts: 5,585
- . , ,, autorun . .
-
2nd May 2011 21:56 #16
Panda vaccine. , - .
Asrock B450 Steel Legend / Ryzen 5 3600 stock w/ Jonsbo CR-1000 / TeamForce 32GB (4x8GB) 3200 MHz / SP 512GB + 14TB int & 10TB ext / ASRock RX 5600 XT Phantom Gaming 6GB OC / CM Silent Pro 700W / Acer V277 IPS @FullHD 75Hz + HP w2207 / Corsair 600T + 2x 200mm / Mad Catz R.A.T. TE / '




Reply With Quote


R9 280,
7th May 2023, 21:28 in