26 Mar 2012, 17:20
26 Mar 2012, 18:04
W GMER przeskanowałem tylko dysk D: ponieważ , tam znajdują się pliki z podejrzanym keyloggerem według kaspersky w folderze Metin2.
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\ZDPSp50.sys -- (ZDPSp50)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\ZDCndis5.SYS -- (ZDCndis5)
DRV - File not found [Kernel | Boot | Stopped] -- -- (Yaf13)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\KRZYSZ~1.KOM\USTAWI~1\Temp\sony_ssm.sys -- (sony_ssm.sys)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\Program Files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner32.sys -- (RivaTuner32)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\KRZYSZ~1.KOM\USTAWI~1\Temp\PCD65X3.sys -- (PCD65X3)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\KRZYSZ~1.KOM\USTAWI~1\Temp\PCD65X2.sys -- (PCD65X2)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- F:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | Auto | Stopped] -- D:\Program Files\Anti Keylogger Elite\AKEProtect.sys -- (AKEProtect)
IE - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - No CLSID value found
IE - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\URLSearchHook: {b317125e-2f10-4388-bf1f-2c31c6cd89ed} - SOFTWARE\Classes\CLSID\{b317125e-2f10-4388-bf1f-2c31c6cd89ed}\InprocServer32 File not found
IE - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: \"URL\" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3031817
IE - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: \"URL\" = http://www.bigseekpro.com/search/browser/hypercam/{F618E1F2-AFBD-4045-A2CA-91882E1F2DD4}?q={searchTerms}
IE - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\SearchScopes\{2877A654-1C9F-4cb5-8438-16022B2FDD9C}: \"URL\" = http://www.starwebsearch.com/results.php?q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: \"Yahoo\"
FF - prefs.js..browser.search.selectedEngine: \"Yahoo\"
FF - prefs.js..keyword.URL: \"http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=382950&p=\"
FF - prefs.js..browser.search.param.yahoo-fr: \"chr-greentree_ff&type=382950&ilc=12\"
[2011-11-08 13:56:40 | 000,000,000 | ---D | M] (SFT_Polska Community Toolbar) -- C:\Documents and Settings\krzysztof.KOMPUTER\Dane aplikacji\Mozilla\Firefox\Profiles\vwrtasvu.Domyślny użytkownik\extensions\{5c5b9468-d672-4eb7-b52f-b5afabf28c5b}
[2010-03-17 15:46:46 | 000,000,000 | ---D | M] (SeekService) -- C:\Program Files\Mozilla Firefox\extensions\{86009AEF-9162-4EBC-B698-FF71D7B6B049}
O2 - BHO: (DigitalPowered Toolbar) - {b317125e-2f10-4388-bf1f-2c31c6cd89ed} - C:\Program Files\DigitalPowered\tbDigi.dll File not found
O3 - HKLM\..\Toolbar: (DigitalPowered Toolbar) - {b317125e-2f10-4388-bf1f-2c31c6cd89ed} - C:\Program Files\DigitalPowered\tbDigi.dll File not found
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-21-854245398-1454471165-725345543-1003\..\Toolbar\WebBrowser: (DigitalPowered Toolbar) - {B317125E-2F10-4388-BF1F-2C31C6CD89ED} - C:\Program Files\DigitalPowered\tbDigi.dll File not found
O4 - HKLM..\Run: [Best Antivirus] C:/Program Files/Best Antivirus/BestAntivirus.exe File not found
O4 - HKLM..\Run: [Best Antivirus Agent] C:/Program Files/Best Antivirus/BestAntivirusAgent.exe File not found
O4 - HKLM..\Run: [Best Antivirus Updater] C:/Program Files/Best Antivirus/BestAntivirusUpdater.exe File not found
O4 - HKU\S-1-5-21-854245398-1454471165-725345543-1003..\Run: [AdobeBridge] File not found
O4 - Startup: C:\Documents and Settings\krzysztof\Menu Start\Programy\Autostart\csrss.exe ()
O8 - Extra context menu item: Funkcja Google Sidewiki - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html File not found
O20 - Winlogon\Notify\dimsntfy: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
[2012-03-21 21:01:42 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2012-03-26 13:25:00 | 000,001,042 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-03-26 12:54:25 | 000,000,278 | ---- | M] () -- C:\WINDOWS\tasks\ASC4_PerformanceMonitor.job
[2012-03-26 12:54:24 | 000,001,038 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-03-26 12:54:24 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag_Startup.job
[2012-03-26 12:54:24 | 000,000,260 | ---- | M] () -- C:\WINDOWS\tasks\WGASetup.job
[2011-11-18 14:15:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.KOMPUTER.001\Dane aplikacji\Search Settings
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdobeCS4ServiceManager"=-
"SoundMan"=-
"HP Software Update"=-
"SunJavaUpdateSched"=-
:Commands
[clearallrestorepoints]
[emptytemp]
27 Mar 2012, 15:45
27 Mar 2012, 21:12
28 Mar 2012, 16:45
28 Mar 2012, 16:57
Podaj także dokładną lokalizację wykrywanego pliku.
28 Mar 2012, 18:08
28 Mar 2012, 22:11
:OTL
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\AmdTools.sys -- (AmdTools)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Documents and Settings\krzysztof.KOMPUTER\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe" File not found
[2012-03-28 16:28:04 | 000,001,036 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-03-28 16:28:01 | 000,001,032 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
Java(TM) 6 Update 29
Adobe Reader 7.0.5 - Polish
31 Mar 2012, 12:01
31 Mar 2012, 14:09
Nie wykonano akcji.
Service Pack 3 XP i IE8 Nie chcą się zainstalować. Service pack w połowie instalacji pokazuje błąd i następuje reset komputera i IE8 nie che skończyć 3ciego pkt instalacji .
chkdsk c: /f
02 Kwi 2012, 16:17
02 Kwi 2012, 16:33
cd /d "%ProgramFiles%\Windows Resource Kits\Tools"
subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"SFCScan"=dword:0000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"AutoChkTimeOut"=dword:0000000
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
"BootExecute"=hex(7):00,00
Czy istnieje jakiś program zabezpieczający przed w przynajmniej 95% przed keyloggerami ??
02 Kwi 2012, 18:24
02 Kwi 2012, 18:41
ponieważ po zainstalowaniu SP3 się wyłączyła
02 Kwi 2012, 19:08