manji kapital -

Magazine
Go Back   Computer soka > Computer Software > Virus, Spyware i sigurnost


Register


Reply
 
Thread Tools
  #1  
Old 3. lipnja 2009, 01:39
Novi član grupe
 
Ja sam išla malare protiv zlonamjernih programa, ali je ne uzimajući osloboditi od svih virusa / memory modules / registery ključeva
Također sam išla kidnapovati i ukloniti ovaj neki. Dll's pronađeno po malwarebytes, ali ne i sve ode.


Malwarebytes' Anti-zaštita od zlonamjernih programa 1,37
Database Version: 2216
5/1/2600 Windows Service Pack 2

02/06/2009 22:04:31
mbam-log-2009-06-02 (22-04-31). txt

Scan type: Quick Scan
Objekti skenirane: 89008
Proteklo vrijeme: 3 minute (s), 23 Drugi (a / e)

Memory Processes zaraženih: 0
Memorijske module zaraženih: 3
Ključevi registra zaraženih: 13
Registry Values zaraženih: 0
Registry Data Items zaraženih: 2
Mape zaraženih: 2
Zaražene datoteke: 7

Memory Processes zaraženih:
(Nema stavki otkrivenih zlonamjernih)

Memorijske module zaraženih:
C: \ WINDOWS \ system32 \ dwkljtof.dll (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
C: \ WINDOWS \ system32 \ becbn.dll (Trojan.Agent) -> Delete na ponovno podizanje sustava.
C: \ WINDOWS \ system32 \ xanyzwy.dll (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.

Ključevi registra zaraženih:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Obavijesti \ feuyhaok (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
HKEY_CLASSES_ROOT \ CLSID \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (0e8459fd-48f1-af07-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_CLASSES_ROOT \ CLSID \ (0e8459fd-48f1-af07-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (0e8459fd-48f1-af07-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ b mbgzbpm (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ b mbgzbpm (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ bmbgzbpm (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> karanteni i uspješno izbrisan.
HKEY_CLASSES_ROOT \ CLSID \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> karanteni i uspješno izbrisan.
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> karanteni i uspješno izbrisan.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> karanteni i uspješno izbrisan.

Registry Values zaraženih:
(Nema stavki otkrivenih zlonamjernih)

Registry Data Items zaraženih:
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> karanteni i uspješno izbrisan.
HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> karanteni i uspješno izbrisan.

Mape zaraženih:
C: \ WINDOWS \ system32 \ append.dll (Trojan.Agent) -> karanteni i uspješno izbrisan.
C: \ WINDOWS \ system32 \ xlib254.dll (Trojan.Agent) -> karanteni i uspješno izbrisan.

Zaražene datoteke:
C: \ Windows \ system32 \ xanyzwy.dll (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
C: \ WINDOWS \ system32 \ dwkljtof.dll (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
C: \ WINDOWS \ system32 \ becbn.dll (Trojan.Agent) -> Delete na ponovno podizanje sustava.
C: \ Windows \ system32 \ zfmhjbu.dll (Trojan.Vundo.H) -> Delete na ponovno podizanje sustava.
C: \ Windows \ system32 \ bekbn.dll (Trojan.Agent) -> karanteni i uspješno izbrisan.
C: \ Windows \ System32 \ Drivers \ jcnfgawt.sys (Rootkit.Agent) -> Delete na ponovno podizanje sustava.
C: \ Windows \ System32 \ Drivers \ sjbxdggg.sys (Rootkit.Agent) -> Delete na ponovno podizanje sustava.





Logfile of Trend Micro HijackThis v2.0.2
Scan spremljena u 22:52:36, dana 02/06/2009
Platforma: Windows XP SP2 (Winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Pokretanje procesa:
C: \ Windows \ System32 \ smss.exe
C: \ windows \ system32 \ csrss.exe
C: \ windows \ system32 \ Winlogon.exe
C: \ windows \ system32 \ services.exe
C: \ windows \ system32 \ lsass.exe
C: \ windows \ system32 \ Svchost.exe
C: \ windows \ system32 \ Svchost.exe
C: \ Windows \ System32 \ Svchost.exe
C: \ windows \ system32 \ Svchost.exe
C: \ Windows \ System32 \ Svchost.exe
C: \ Windows \ System32 \ Svchost.exe
C: \ windows \ explorer.exe
C: \ windows \ system32 \ spoolsv.exe
C: \ Windows \ SOUNDMAN.EXE
C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe
C: \ programa ~ 1 \ Agnitum \ OUTPOS ~ 1 \ op_mon.exe
C: \ windows \ system32 \ carpserv.exe
C: \ programa ~ 1 \ AVG \ AVG8 \ avgtray.exe
C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
C: \ windows \ system32 \ Ctfmon.exe
C: \ programa ~ 1 \ Agnitum \ OUTPOS ~ 1 \ acs.exe
C: \ Windows \ System32 \ astsrv.exe
C: \ programa ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ MDM.EXE
C: \ Program Files \ Common Files \ Nero \ Nero BackItUp 4 \ NBService.exe
C: \ windows \ system32 \ oodag.exe
C: \ programa ~ 1 \ AVG \ AVG8 \ avgam.exe
C: \ programa ~ 1 \ AVG \ AVG8 \ avgrsx.exe
C: \ programa ~ 1 \ AVG \ AVG8 \ avgnsx.exe
C: \ Windows \ System32 \ Svchost.exe
C: \ windows \ system32 \ wscntfy.exe
C: \ Windows \ System32 \ Svchost.exe
C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ Source Engine \ OSE.EXE
C: \ Program Files \ zajedničko Files \ Mozilla zajedničku \ firefox.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.virginmedia.com/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://www.tiny.com
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Postavke, ProxyOverride = *. lokalne
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6F6E-4B53-A66E-4E65E497C8C0) - C: \ Program Files \ AVG \ AVG8 \ avgssie.dll
O2 - BHO: "klikni za poziv" BHO - (5C255C8A-E604-49b4-9D64-90988571CECB) - C: \ Program Files \ Windows Live \ Messenger \ wlchtc.dll
O2 - BHO: Groove GFS Browser Helper - (72853161-30C5-4D22-B7F9-0BBC1D38A37E) - C: \ Program Files \ Microsoft Office \ Office12 \ GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: (no name) - (936182df-5f7a-4d1e-a86f-a6d0f061e70a) - c: \ windows \ system32 \ xanyzwy.dll
O2 - BHO: Java ™ Plug-in 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ rasporediti \ jqs \ ie \ jqs_plugin.dll
O4 - HKLM \ .. \ Run: [ATIPTA] "C: \ Program Files \ ATI Technologies \ ATI Control Panel \ atiptaxx.exe"
O4 - HKLM \ .. \ Run: [PinnacleDriverCheck] C: \ WINDOWS \ System32 \ PSDrvCheck.exe
O4 - HKLM \ .. \ Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ WINDOWS \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [InCD] C: \ Program Files \ ispred \ InCD \ InCD.exe
O4 - HKLM \ .. \ Run: [ATICCC] "C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe" runtime-Delay
O4 - HKLM \ .. \ Run: [OutpostMonitor] C: \ programa ~ 1 \ Agnitum \ OUTPOS ~ 1 \ op_mon.exe / tas / noservice
O4 - HKLM \ .. \ Run: [CARPService] carpserv.exe
O4 - HKLM \ .. \ Run: [AVG8_TRAY] C: \ programa ~ 1 \ AVG \ AVG8 \ avgtray.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe"
O4 - HKLM \ .. \ RunServices: [RegisterDropHandler] C: \ programa ~ 1 \ TEXTBR ~ 1.0 \ Bin \ REGIST ~ 1.EXE
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ windows \ system32 \ Ctfmon.exe
O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ System32 \ Ctfmon.exe (User 'Default user')
O8 - Extra kontekst meni stavka: E & zvezi u Microsoft Excel - res: / / C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra 'Tools' MENUITEM: S & kraj OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Outpost Firewall Pro Quick naštimati - (44627E97-789B-40d4-B5C2-58BD171129A1) - C: \ Program Files \ Agnitum \ Outpost Firewall Pro \ ie_bar.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ programa ~ 1 \ MIC273 ~ 1 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL = http://www.tiny.com
O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ Program Files \ Microsoft Office \ Office12 \ GrooveSystemServices.dll
O18 - Protocol: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C: \ Program Files \ AVG \ AVG8 \ avgpp.dll
O20 - Winlogon Obavijesti: avgrsstarter - C: \ Windows \ System32 \ avgrsstx.dll
O20 - Winlogon Obavijesti: feuyhaok - C: \ Windows \ System32 \ xanyzwy.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown vlasnika - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe (file missing)
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd - C: \ programa ~ 1 \ Agnitum \ OUTPOS ~ 1 \ acs.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd - C: \ Windows \ System32 \ astsrv.exe
O23 - Service: ati brza tipka Poller - ATI Technologies Inc - C: \ Windows \ System32 \ Ati2evxx.exe
O23 - Service: ATI Smart - Unknown vlasnika - C: \ WINDOWS \ system32 \ ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C: \ Program Files \ Common Files \ Autodesk Shared \ Service \ AdskScSrv.exe
O23 - Service: Autodesk Licensing Service Network - Autodesk, Inc - C: \ Program Files \ Common Files \ Autodesk Shared \ Service \ AdskNetSrv.exe
O23 - Service: AVG8 upozoravanje (avg8wd) - AVG Technologies CZ, sro - C: \ programa ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown vlasnika - C: \ windows \
O23 - Service: Bonjour Service - Unknown vlasnika - C: \ Program Files \ Bonjour \ mDNSResponder.exe (file missing)
O23 - Service: EpsonBidirectionalService - Unknown vlasnika - C: \ Program Files \ Common Files \ EPSON \ EBAPI \ eEBSVC.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc - C: \ Program Files \ Common Files \ Macrovision Shared \ FLEXnet Izdavač \ FNPLicensingService.exe
O23 - Service: gearsec - OPREMA Software - C: \ windows \ system32 \ gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C: \ Program Files \ ispred \ InCD \ InCDsrv.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: Quick Početničko Java (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
O23 - Service: License Management Service ESD - element5 - C: \ Program Files \ Common Files \ element5 Shared \ Service \ Licence Manager ESD.exe
O23 - Service: Nero BackItUp Planer 4,0 - Nero AG - C: \ Program Files \ Common Files \ Nero \ Nero BackItUp 4 \ NBService.exe
O23 - Service: O & O prevariti - O & O Software GmbH - C: \ windows \ system32 \ oodag.exe
O23 - Service: PC Tools Pomoćne službe (sdauxservice) - PC Tools - C: \ Program Files \ Spyware Doctor \ pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C: \ Program Files \ Spyware Doctor \ pctsSvc.exe
O23 - Service: ThreatFire (threatfire) - PC Tools - C: \ Program Files \ Spyware Doctor \ TFEngine \ TFService.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown vlasnika - C: \ windows \

--
End of file - 7951 bytes


Bilo koji pomoć ugoditi, računalo će poludjeti zaključavanje zadaća voditelj, pretraživanjem je bol sa stalnom pop up prozore, neki programi su onemogućeni. Mislim potpuni re-instalirati. Ali samo želim stabilnih sustava za back-up datoteke.
  #2  
Old 3. lipnja 2009, 10:31
Moderator / ica grupe
 
Preuzimanje DDS by sUBs i spremite ju na radnu površinu. Alternate DDS download link

Vista korisnici desni klik na dds i odaberite Pokreni kao administrator (dobit ćete prompt UAC, molimo dopustiti)

* XP korisnici Dvaput kliknite na dds da ga vode.
* Ako vaš vatrozid ili protuvirusni pokušati blokirati DDS molimo dopustiti Internet to trčanje.
* Kada završite, DDS će otvoriti dva (2) logove.

1) DDS.txt
2) Attach.txt

* Spremite oba logove na Vašu radnu površinu.
* Molimo Vas da kopirate i zalijepite cijeli sadržaj oba prijavljuje u sljedećoj odgovor.

Napomena: DDS će narediti da se u post Attach.txt prijavite kao privitak.
Molimo post samo ga kao što bi bilo koji drugi log by kopirajte i zalijepite ga u odgovor.
__________________

Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer soka.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO by vBSEO © 2009, Crawlability, Inc