mai mică de capital,

Magazine
Go Back   Computer JUICE > Computer Software > Nume, Spyware & Securitate

Register


 Default 

Trojan Vundo. H (Hijackthis / malwarebytes)




Reply
 
Thread Tools
  #1  
Old 3 iunie 2009, 01:39
Noile state Group
 
Default Trojan Vundo. H (Hijackthis / malwarebytes)

Am fugit malare anti-malware-ului, dar acesta nu este eliminarea tuturor virusurilor / module de memorie / registery chei
De asemenea, am fugit şi hijack acest îndepărtat unele. Dll a constatat, cu malwarebytes a mers, dar nu toate.


Malwarebytes' Anti-Malware 1.37
Baza de date versiune: 2216
Windows 5.1.2600 Service Pack 2

02/06/2009 22:04:31
mbam-log-2009-06-02 (22-04-31). txt

Scan type: Quick Scan
Obiecte scanate: 89008
Timpul scurs: 3 minute (s), 23 secunde (s)

Memory Processes Infected: 0
Memory Modules Infected: 3
Chei de Registry Infected: 13
Registry Values Infected: 0
Registrul de date Elemente Infected: 2
Folders Infected: 2
Files Infected: 7

Memory Processes Infected:
(Nici un rău elemente detectat)

Memory Modules Infected:
C: \ Windows \ system32 \ dwkljtof.dll (Trojan.Vundo.H) -> Delete pe reboot.
C: \ Windows \ system32 \ becbn.dll (Trojan.Agent) -> Delete pe reboot.
C: \ Windows \ system32 \ xanyzwy.dll (Trojan.Vundo.H) -> Delete pe reboot.

Chei de Registry Infected:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> Delete pe reboot.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ feuyhaok (Trojan.Vundo.H) -> Delete pe reboot.
HKEY_CLASSES_ROOT \ CLSID \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> Delete pe reboot.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (0e8459fd-af07-48f1-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_CLASSES_ROOT \ CLSID \ (0e8459fd-af07-48f1-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (0e8459fd-af07-48f1-8cd1-3884d15eaf47) (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Services \ b mbgzbpm (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet002 \ Services \ b mbgzbpm (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Servic es \ bmbgzbpm (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (936182df-5f7a-4d1e-a86f-a6d0f061e70a) (Trojan.Vundo.H) -> carantină şi a fost şters cu succes.
HKEY_CLASSES_ROOT \ CLSID \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> carantină şi a fost şters cu succes.
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Ext \ Stats \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> carantină şi a fost şters cu succes.
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Explorer \ Browser Helper Objects \ (10c0b0c0-fc01-473b-8ebb-4376353f96e4) (Trojan.Agent) -> carantină şi a fost şters cu succes.

Registry Values Infected:
(Nici un rău elemente detectat)

Registrul de date Elemente Infected:
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> carantină şi a fost şters cu succes.
HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curre ntVersion \ Policies \ System \ DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> carantină şi a fost şters cu succes.

Folders Infected:
C: \ Windows \ system32 \ append.dll (Trojan.Agent) -> carantină şi a fost şters cu succes.
C: \ Windows \ system32 \ xlib254.dll (Trojan.Agent) -> carantină şi a fost şters cu succes.

Files Infected:
C: \ Windows \ system32 \ xanyzwy.dll (Trojan.Vundo.H) -> Delete pe reboot.
C: \ Windows \ system32 \ dwkljtof.dll (Trojan.Vundo.H) -> Delete pe reboot.
C: \ Windows \ system32 \ becbn.dll (Trojan.Agent) -> Delete pe reboot.
C: \ Windows \ system32 \ zfmhjbu.dll (Trojan.Vundo.H) -> Delete pe reboot.
C: \ Windows \ system32 \ bekbn.dll (Trojan.Agent) -> carantină şi a fost şters cu succes.
C: \ Windows \ system32 \ drivers \ jcnfgawt.sys (Rootkit.Agent) -> Delete pe reboot.
C: \ Windows \ system32 \ drivers \ sjbxdggg.sys (Rootkit.Agent) -> Delete pe reboot.





Logfile de Trend Micro HijackThis v2.0.2
Scan salvate la 22:52:36, pe 02.06.2009
Platforma: Windows XP SP2 (WINNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Rularea procese:
C: \ windows \ system32 \ smss.exe
C: \ windows \ system32 \ csrss.exe
C: \ windows \ system32 \ winlogon.exe
C: \ windows \ system32 \ services.exe
C: \ windows \ system32 \ lsass.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ Explorer.exe
C: \ windows \ system32 \ Spoolsv.exe
C: \ windows \ SOUNDMAN.EXE
C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe
C: \ PROGRA ~ 1 \ Agnitum \ OUTPOS ~ 1 \ op_mon.exe
C: \ windows \ system32 \ carpserv.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray.exe
C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
C: \ windows \ system32 \ Ctfmon.exe
C: \ PROGRA ~ 1 \ Agnitum \ OUTPOS ~ 1 \ acs.exe
C: \ windows \ system32 \ astsrv.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ MDM.EXE
C: \ Program Files \ Common Files \ Nero \ Nero BackItUp 4 \ NBService.exe
C: \ windows \ system32 \ oodag.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgam.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgrsx.exe
C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgnsx.exe
C: \ windows \ system32 \ svchost.exe
C: \ windows \ system32 \ wscntfy.exe
C: \ windows \ system32 \ svchost.exe
C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe
C: \ Program Files \ Common Files \ Microsoft Shared \ Sursa Motor \ OSE.EXE
C: \ Program Files \ Common Files \ Mozilla Shared \ firefox.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe

R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.virginmedia.com/
R1 - HKLM \ SOFTWARE \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://www.tiny.com
R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Setări, ProxyOverride = *. local
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - (3CA2F312-6F6E-4B53-A66E-4E65E497C8C0) - C: \ Program Files \ AVG \ AVG8 \ avgssie.dll
O2 - BHO: Faceţi clic-pentru-Apel BHO - (5C255C8A-E604-49b4-9D64-90988571CECB) - C: \ Program Files \ Windows Live \ Messenger \ wlchtc.dll
O2 - BHO: Groove SFG Browser Helper - (72853161-30C5-4D22-B7F9-0BBC1D38A37E) - C: \ Program Files \ Microsoft Office \ Office12 \ GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in-Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Program Files \ Common Files \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O2 - BHO: (no name) - (936182df-5f7a-4d1e-a86f-a6d0f061e70a) - c: \ windows \ system32 \ xanyzwy.dll
O2 - BHO: Java ™, Plug-in 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ implica \ jqs \ ie \ jqs_plugin.dll
O4 - HKLM \ .. \ Run: [ATIPTA] "C: \ Program Files \ ATI Technologies \ ATI Control Panel \ atiptaxx.exe"
O4 - HKLM \ .. \ Run: [PinnacleDriverCheck] C: \ Windows \ system32 \ PSDrvCheck.exe
O4 - HKLM \ .. \ Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM \ .. \ Run: [NeroFilterCheck] C: \ Windows \ system32 \ NeroCheck.exe
O4 - HKLM \ .. \ Run: [INCD] C: \ Program Files \ Ahead \ INCD \ InCD.exe
O4 - HKLM \ .. \ Run: [ATICCC] "C: \ Program Files \ ATI Technologies \ ATI.ACE \ cli.exe" runtime-Întârzierea
O4 - HKLM \ .. \ Run: [OutpostMonitor] C: \ PROGRA ~ 1 \ Agnitum \ OUTPOS ~ 1 \ op_mon.exe / tava / noservice
O4 - HKLM \ .. \ Run: [CARPService] carpserv.exe
O4 - HKLM \ .. \ Run: [AVG8_TRAY] C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgtray.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe"
O4 - HKLM \ .. \ RunServices: [RegisterDropHandler] C: \ PROGRA ~ 1 \ TEXTBR ~ 1.0 \ bin \ REGIST ~ 1.EXE
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ windows \ system32 \ Ctfmon.exe
O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ Windows \ system32 \ Ctfmon.exe (User 'Default user')
O8 - Extra context menu item: E & xportaţi la Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ milionimi ~ 2 \ Office12 \ EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra 'Tools' MENUITEM: S & la sfârşitul OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ PROGRA ~ 1 \ milionimi ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - (44627E97-789B-40d4-B5C2-58BD171129A1) - C: \ Program Files \ Agnitum \ Outpost Firewall Pro \ ie_bar.dll
O9 - Extra button: Cercetare - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MIC273 ~ 1 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL = http://www.tiny.com
O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ Program Files \ Microsoft Office \ Office12 \ GrooveSystemServices.dll
O18 - Protocol: linkscanner - (F274614C-63F8-47D5-A4D1-FBDDE494F8D1) - C: \ Program Files \ AVG \ AVG8 \ avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C: \ windows \ system32 \ avgrsstx.dll
O20 - Winlogon Notify: feuyhaok - C: \ windows \ system32 \ xanyzwy.dll
O23 - Service: Lavasoft Ad-Conştient Service (aawservice) - Unknown owner - C: \ Program Files \ Lavasoft \ Ad-Conştient \ aawservice.exe (fişierul lipseşte)
O23 - Service: Agnitum Client Security Service (acssrv) - Agnitum Ltd. - C: \ PROGRA ~ 1 \ Agnitum \ OUTPOS ~ 1 \ acs.exe
O23 - Service: AST Service (astcc) - Nalpeiron Ltd. - C: \ windows \ system32 \ astsrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc - C: \ windows \ system32 \ Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C: \ Windows \ system32 \ ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C: \ Program Files \ Common Files \ Autodesk Shared \ Service \ AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc - C: \ Program Files \ Common Files \ Autodesk Shared \ Service \ AdskNetSrv.exe
O23 - Service: AVG8 Watchdog (avg8wd) - AVG Technologies CZ, sro - C: \ PROGRA ~ 1 \ AVG \ AVG8 \ avgwdsvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C: \ windows \
O23 - Service: Bonjour Service - Unknown owner - C: \ Program Files \ Bonjour \ mDNSResponder.exe (fişierul lipseşte)
O23 - Service: EpsonBidirectionalService - Unknown owner - C: \ Program Files \ Common Files \ EPSON \ EBAPI \ eEBSVC.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc - C: \ Program Files \ Common Files \ Macrovision Shared \ FLEXnet Publisher \ FNPLicensingService.exe
O23 - Service: gearsec - ECHIPAMENTELOR Software - C: \ windows \ system32 \ gearsec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: INCD Helper (InCDsrv) - Nero AG - C: \ Program Files \ Ahead \ INCD \ InCDsrv.exe
O23 - Service: iPod Service - Apple Inc - C: \ Program Files \ iPod \ bin \ iPodService.exe
O23 - Service: Java rapida pentru începători (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
O23 - Service: License Management Service ESD - element5 - C: \ Program Files \ Common Files \ element5 Shared \ Service \ Licenta Manager ESD.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C: \ Program Files \ Common Files \ Nero \ Nero BackItUp 4 \ NBService.exe
O23 - Service: O & O Defrag - O & O Software GmbH - C: \ windows \ system32 \ oodag.exe
O23 - Service: PC Tools auxiliare Service (sdauxservice) - PC Tools - C: \ Program Files \ Spyware Doctor \ pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdcoreservice) - PC Tools - C: \ Program Files \ Spyware Doctor \ pctsSvc.exe
O23 - Service: ThreatFire (threatfire) - PC Tools - C: \ Program Files \ Spyware Doctor \ TFEngine \ TFService.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C: \ windows \

--
Sfârşit de fişier - 7951 bytes


Orice ajutor va rog, computerul va nebun de blocare a Task Manager, navigarea este o durere cu constanta de tip pop up, unele programe sunt dezactivate. Mă gândesc de o re-instala. Dar, vreau doar sistem stabil de back-up la fisiere.
  #2  
Old 3 iunie 2009, 10:31
Moderator Group
 
Default Trojan Vundo. H (Hijackthis / malwarebytes)

Descărca DDS de sUBs şi salvaţi-l pe desktop. Alternativă DDS download link

Vista utilizatori click dreapta pe DDS şi selectaţi Executare ca administrator (veţi primi o UAC prompt, vă rugăm să îi permită)

* XP users Faceţi dublu clic pe DDS să îl rulaţi.
* Dacă antivirus sau firewall, încercaţi să blocaţi DDS atunci vă rugăm să îi permită să ruleze.
* După ce aţi terminat DDS va deschide două (2) jurnalele.

1) DDS.txt
2) Attach.txt

* Salvaţi ambele jurnalele de pe desktop.
* Vă rugăm să copiaţi şi să inseraţi întregul conţinut al ambele jurnalele la următoarea replică.

Notă: DDS va instrui te pentru a posta Attach.txt jurnal ca o ataşare.
Vă rugăm să-l doar post pe care l-aţi orice alt jurnal de copiaţi şi lipiţi-o în răspunsul.
__________________

Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer Suc.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd. SEO de vBSEO © 2009, Crawlability, Inc