13 Paź 2006, 14:44
13 Paź 2006, 15:09
O20 - Winlogon Notify: Nls - C:\WINNT\system32\fpj6031se.dll
O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\oiqw24sc2.dll
O20 - Winlogon Notify: Controls Folder - C:\WINDOWS\system32\i45vs01.dll
O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\fgyfeft591.dll
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32jj898fws.dll
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\38hw0djsjcq.dll
O20 - Winlogon Notify: Reliability - C:\WINDOWS\system32\oiodwbcq.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\30i90kfdsq.dll
O20 - Winlogon Notify: Themes - D:\WINDOWS\system32\28ufhnmsnje.dll
O20 - Winlogon Notify: ShellScrap - C:\WINDOWS\system32\si398fbx.dll
O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\c3f3345f0i.dll
O20 - Winlogon Notify: Shell - C:\WINDOWS\system32\if46hgsq5.dll
O20 - Winlogon Notify: Reinstall - C:\WINDOWS\system32\qxc2f4r5d.dll
O20 - Winlogon Notify: Reliability - C:\WINDOWS\system32\ 38djw783.dll
O20 - Winlogon Notify: App Management - C:\WINDOWS\system32\drvdrvxcxe45.dll
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system\32d34r4.dll
O20 - Winlogon Notify: Themes - D:\WINDOWS\system\32m7hd4fre.dll
O20 - Winlogon Notify: Extensions - C:\WINNT\system32\hr2805fue.dll
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 64.91.255.87 http://www.dcsresearch.com
O2 - BHO: Media Player support DLL - {2DC9D850-144D-11E1-B3C9-10805E499D95} - C:\WINDOWS\System32\mplay32.dll
O4 - HKLM..Run: [ntsmod] C:\WINDOWS\system32\ntsmod.exe
O4 - HKLM..Run: [nsvcin] C:\WINDOWS\system32\n20050308.exe
"Component 'mswinsck.ocx' or one of its dependencies not correctly registered: a file is missing or invalid"
http://www.ascentive.com/support/new/support_dll.phtml?dllname=MSWINSCK.OCX
http://securityresponse.symantec.com/avcenter/FxSpL2Me.exe
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\CLSID\{D82BE2B0-5764-11D0-A96E-00C04FD705A2}]
@="IShellFolderBand"
[HKEY_CLASSES_ROOT\CLSID\{D82BE2B0-5764-11D0-A96E-00C04FD705A2}\InProcServer32]
@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,
00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,68,00,
65,00,6c,00,6c,00,33,00,32,00,2e,00,64,00,6c,00,6c,00,00,00
"ThreadingModel"="Apartment"
15 Paź 2006, 00:34
O2 - BHO: BL Class - {28F65FCB-D130-11D8-BA48-8BE0C49AF370} - C:\WINDOWS\System32\popup_bl.dll
REGEDIT4
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{28F65FCB-D130-11D8-BA48-8BE0C49AF370}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{28F65FCB-D130-11D8-BA48-8BE0C49AF370}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\CLSID\{CF70455E-EDC1-4067-B824-CD0314BC3B2E}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Interface\{05AAE5E5-47A1-4F65-8C32-8913EAD54DBF}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Interface\{A77BD0A1-A8FA-48C0-8FFF-5A4DDCAD4581}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Popup_bl.BL.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Popup_bl.BL]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Popup_bl.onClick.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\Popup_bl.onClick]
15 Paź 2006, 00:48
O4 - HKLM..Run: [˘Ş¸ď0/4»}Ą ăx‡5_C:\Program Files\IST\svcistsvc.exe] C:\WINNT\ujbawef.exe
O4 - HKLM..Run: [FFWgtS] C:\WINNT\ujbawef.exe
O4 - HKLM..Run: [IST Service] C:\Program Files\IST\svcistsvc.exe
O4 - HKLM..Run: [˘‰¸ď0 4Ă4}¤Áś5]C:\Program Files\IST\svcistsvc.exe] C:\HGITBJ.EXE
O4 - HKLM..Run: [9jbXG] C:\HGITBJ.EXE
http://securityresponse.symantec.com/avcenter/FxIstbar.exe
15 Paź 2006, 00:58
http://cexx.org/lspfix.htm
15 Paź 2006, 01:09
O4 - HKCU..Run: [Lqjogrt] C:WINDOWS\System32\??plorer.exe
O4 - HKCU..Run: [Upwzxru] C:\WINDOWS\System32\??plorer.exe
O4 - HKCU..Run: [Mcbqh] C:\WINNT\system32\t?skmgr.exe
15 Paź 2006, 12:32
O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\system32\eq.dll
O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\AppPatchinfow.dll
O20 - Winlogon Notify: infow - C:\WINDOWS\AppPatchinfow.dll
O20 - Winlogon Notify: req - C:\WINDOWS\system32\eq.dll
....
O2 - BHO: MSEvents Object - {44240BB5-BD7D-4D49-A1AA-8AB0F3D3CB44} - C:\WINDOWS\Configabrole.dll
O20 - Winlogon Notify: abrole - C:\WINDOWS\Configabrole.dll
....
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINNT\system32\oppnl.dll
O2 - BHO: MSEvents Object - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - C:\WINNT\system32\qomnk.dll
O20 - Winlogon Notify: oppnl - C:\WINNT\SYSTEM32\oppnl.dll
O20 - Winlogon Notify: qomnk - C:\WINNT\system32\qomnk.dll
....
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\System32\vtsqo.dll
O2 - BHO: MSEvents Object - {79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A} - C:\WINDOWS\System32\vtstt.dll
O20 - Winlogon Notify: vtsqo - C:\WINDOWS\SYSTEM32\vtsqo.dll
O20 - Winlogon Notify: vtstt - C:\WINDOWS\System32\vtstt.dll
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerShellExecuteHooks
INFECTION WARNING! "{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}" = "*U" (unwritable string)
{CLSID}InProcServer32(Default) = "C:\WINDOWS\System32\vtsqo.dll" [null data]
O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\system32\tdev.dll
O20 - Winlogon Notify: tdev - C:\WINDOWS\SYSTEM32\tdev.dll
....
O2 - BHO: CIEPl Object - {0612F71E-934B-4D92-B8E8-2E29EA78EB03} - C:\WINNT\System32\mcconfig.dll
O20 - Winlogon Notify: ansgudxn - C:\WINNT\SYSTEM32\ansgudxn.dll
O20 - Winlogon Notify: ekdmpcsp - C:\WINNT\SYSTEM32\ekdmpcsp.dll
O20 - Winlogon Notify: mcconfig - C:\WINNT\SYSTEM32\mcconfig.dll
O20 - Winlogon Notify: qsvlgycb - C:\WINNT\SYSTEM32\qsvlgycb.dll
O20 - Winlogon Notify: rsrnwete - C:\WINNT\SYSTEM32\srnwete.dll
O20 - Winlogon Notify: trnvadod - C:\WINNT\SYSTEM32\trnvadod.dll
....
O2 - BHO: CIEPl Object - {F85E86D8-F796-4C97-AAA2-26664A98A42C} - C:\WINDOWS\System32\mcconfig.dll
O20 - AppInit_DLLs: C:\WINDOWS\System32\yjgwdjlw.dll
O20 - Winlogon Notify: mcconfig - C:\WINDOWS\SYSTEM32\mcconfig.dll
http://securityresponse.symantec.com/avcenter/FixVundo.exe
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
VundoFix V2.15 by Atri
--------------------------------------------------------------------------------------
Listing files contained in the vundofix folder.
--------------------------------------------------------------------------------------
killvundo.bat
process.exe
ReadMe.txt
vundo.reg
vundofix.txt
--------------------------------------------------------------------------------------
Filepaths entered
--------------------------------------------------------------------------------------
The filepath entered was C:\WINDOWS\SYSTEM32\qomnk.dll
The second filepath entered was C:\WINDOWS\SYSTEM32\knmoq.*
--------------------------------------------------------------------------------------
Log from Process
--------------------------------------------------------------------------------------
Killing PID 560 'smss.exe'
Killing PID 1940 'explorer.exe'
Killing PID 648 'winlogon.exe'
Killing PID 648 'winlogon.exe'
Killing PID 648 'winlogon.exe'
Killing PID 648 'winlogon.exe'
Killing PID 648 'winlogon.exe'
--------------------------------------------------------------------------------------
Deleted sucessfully C:\WINDOWS\SYSTEM32\tdev.dll.
Deleted sucessfully C:\WINDOWS\SYSTEM32\vedt.*.
Fixing Registry
--------------------------------------------------------------------------------------
29 Lis 2006, 22:16
O4 - HKLM..Run: [VirusBurst] C:\Program Files\VirusBurst\VirusBurst.exe /h
titiau.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{1559e6c1-7e5e-4461-9457-6a2dea85eb9f}"="eeler"
[HKEY_CLASSES_ROOT\CLSID\{1559e6c1-7e5e-4461-9457-6a2dea85eb9f}\InProcServer32]
@="C:\WINDOWS\system32\titiau.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1559e6c1-7e5e-4461-9457-6a2dea85eb9f}\InProcServer32]
@="C:\WINDOWS\system32\titiau.dll"
O21 - SSODL: eeler - {1559e6c1-7e5e-4461-9457-6a2dea85eb9f} - C:\WINDOWS\system32\titiau.dll
httge.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{7be183d2-a42d-4915-bf60-ec86fbf002cf}"="horologium"
[HKEY_CLASSES_ROOT\CLSID\{7be183d2-a42d-4915-bf60-ec86fbf002cf}\InProcServer32]
@="C:\WINDOWS\system32\httge.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7be183d2-a42d-4915-bf60-ec86fbf002cf}\InProcServer32]
@="C:\WINDOWS\system32\httge.dll"
O21 - SSODL: horologium - {7be183d2-a42d-4915-bf60-ec86fbf002cf} - C:\WINDOWS\system32\httge.dll
gqagksr.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b166be07-30a4-4d38-b781-44528a630706}"="hydrodictyon"
[HKEY_CLASSES_ROOT\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"
O21 - SSODL: hydrodictyon - {b166be07-30a4-4d38-b781-44528a630706} - C:\WINDOWS\system32\gqagksr.dll
O2 - BHO: IEExtension Class - {1F6FE2C2-6040-4645-9053-7F689AFFE176} - C:\Program Files\VirusBlast\BlastIEmonitor.dll
O4 - HKLM..Run: [VirusBlast] C:\Program Files\VirusBlast\VirusBlast.exe /s
INTCODEC:
C:\Program Files\IntCodec\isamonitor.exe
C:\Program Files\IntCodec\pmsngr.exe
C:\Program Files\IntCodec\pmmon.exe
C:\Program Files\IntCodec\isamini.exe
C:\Program Files\SpyQuake2.com\Spy-Quake2.exe
C:\Program Files\SpyQuake2.com\Spy-Quake2.exe
O2 - BHO: (no name) - {1da7dbe8-c51b-4ae4-bc6e-21863349b0b4} - C:\Program Files\IntCodec\isaddon.dll
O3 - Toolbar: Protection Bar - {a2595f37-48d0-46a1-9b51-478591a97764} - C:\Program Files\IntCodec\iesplugin.dll
O4 - HKLM..Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\WINDOWS\system32\viruxz.dll
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run {++}
"homepage.monitor.exe" = "C:\Program Files\IntCodec\isamonitor.exe" [null data]
"pmsngr.exe" = "C:\Program Files\IntCodec\pmsngr.exe" [null data]
MEDIA-CODEC:
C:\Program Files\Media-Codec\isamonitor.exe
C:\Program Files\Media-Codec\pmsngr.exe
C:\Program Files\Media-Codec\pmmon.exe
C:\Program Files\Media-Codec\isamini.exe
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\Media-Codec\isaddon.dll
O2 - BHO: (no name) - {70CAA88C-1ACC-5937-70F1-079C79B97ECD} - C:\WINDOWS\system32\ystjivb.dll
O2 - BHO: (no name) - {7a932ed2-1737-4ab8-b84d-c71779958551} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\Media-Codec\iesplugin.dll
O4 - Startup: .protected
O21 - SSODL: hubbsi - {7b1eeccd-0a6d-4ad5-8ac1-4af5722b3885} - C:\WINDOWS\system32\vwlummc.dll (file missing)
HKLM\SOFTWARE\Microsoft\Windows\Current\Version\Policies\Explorer\Run {++}
"homepage.monitor.exe" = "C:\Program Files\Media-Codec\isamonitor.exe" [null data]
"pmsngr.exe" = "C:\Program Files\Media-Codec\pmsngr.exe" [null data]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
INFECTION WARNING! "{C1A8B6A1-2C81-1C3D-A3C6-A1CCDB10B47F}" = "Windows Update"
{HKCU...CLSID} = (no title provided)
InProcServer32(Default) = "C:\WINDOWS\system32\ioctrl.dll" [file not found]
PCODEC:
C:\Program Files\PCODEC\isamonitor.exe
C:\Program Files\PCODEC\pmsngr.exe
C:\Program Files\PCODEC\isamini.exe
C:\Program Files\PCODEC\pmmon.exe
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\PCODECi\saddon.dll
O3 - Toolbar: Protection Bar - {860c2f6b-ca82-4282-9187-beccbb66f0af} - C:\Program Files\PCODEC\iesplugin.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - C:\windows\system32\viruxz.dll (file missing)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run {++}
"homepage.monitor.exe" = "C:\Program Files\PCODEC\isamonitor.exe" [null data]
"pmsngr.exe" = "C:\Program Files\PCODEC\pmsngr.exe" [null data]
{numerki} O2 i O3 mogą ulegać zmianie. W identyfikatorze O21 mogą pojawiać się inne pliki niż powyżej pokazane. Masa wariacji. Oto lista dll:
28 Lip 2011, 13:35
"Taskmgr.exe Aplikacja została uruchomiona z powodzeniem, ale została zamknięta ze względów bezpieczeństwa. Stało się tak, dlatego, że aplikacja został zainfekowana przez złośliwy program, który może stanowić zagrożenie dla systemu operacyjnego. Zaleca się zainstalowanie niezbędnego modułu heurystycznego i wykonania pełnego skanowania komputera w celu eksterminacji szkodliwych programów."
% AppData% \ Hotfix.exe
% AppData% \ {RANDOM}. Bat
HKEY_CURRENT_USER \ Software \ PAV
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings | "WarnonBadCertRecving" = "0"
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Internet Settings | "WarnOnPostRedirect" = "0"
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon | "Shell" = "% AppData% \ Hotfix.exe"
10 Kwi 2012, 14:04
Win32/Conficker.A
W32.Downadup
W32/Downadup.A
Conficker.A
Net-Worm.Win32.Kido.bt
W32/Conficker.worm
Worm/Conficker