Buna ziua,
am pc-ul infectat de un virus care BD nu la recunoscut. va postez unele screenshot-uri. Daca aveti nevoie de mai multe detalii, spunetimi.
astept indicatii pentru al elimina.
adaug si log-ul de hijackthis
Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11.48.33, on 02/12/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16544)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\Programmi\File comuni\Acronis\Schedule2\schedul2.exeC:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\WINDOWS\ATKKBService.exeC:\Programmi\Bonjour\mDNSResponder.exeC:\WINDOWS\system32\inetsrv\inetinfo.exeC:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\mdm.exeC:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exeC:\WINDOWS\system32\nvsvc32.exeC:\Programmi\Raxco\PerfectDisk\PDAgent.exeC:\Programmi\Analog Devices\SoundMAX\SMAgent.exeC:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exeC:\Programmi\RealVNC\VNC4\WinVNC4.exeC:\Programmi\File comuni\BitDefender\BitDefender Communicator\xcommsvr.exeC:\Programmi\File comuni\BitDefender\BitDefender Update Service\livesrv.exeC:\Programmi\BitDefender\BitDefender 2008\vsserv.exeC:\WINDOWS\Explorer.EXEC:\Programmi\Raxco\PerfectDisk\PDEngine.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Programmi\Java\jre1.6.0_03\bin\jusched.exeC:\Programmi\BitDefender\BitDefender 2008\bdagent.exeC:\Programmi\Acronis\TrueImageHome\TrueImageMonitor.exeC:\Programmi\Acronis\TrueImageHome\TimounterMonitor.exeC:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exeC:\Programmi\iTunes\iTunesHelper.exeC:\WINDOWS\system32\ctfmon.exeC:\Programmi\Logitech\SetPoint\SetPoint.exeC:\Programmi\File comuni\Logitech\KhalShared\KHALMNPR.EXEC:\Programmi\iPod\bin\iPodService.exeC:\Programmi\iTunes\iTunes.exeC:\WINDOWS\system32\ujmuvahd.exeC:\WINDOWS\system32\rundll32.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\system32\msdtc.exeC:\WINDOWS\system32\lpislldp.exeC:\Programmi\Mozilla Firefox\firefox.exeC:\Programmi\Winamp\winamp.exeC:\Programmi\Trend Micro\HijackThis\HijackThis.exeC:\WINDOWS\system32\wbem\wmiprvse.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = CollegamentiO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dllO3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Programmi\BitDefender\BitDefender 2008\IEToolbar.dllO3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\hmaoxnis.dllO4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXEO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [EPSON Stylus Photo R240 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE /F "C:\WINDOWS\TEMP\E_S6A.tmp" /EF "HKLM"O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Programmi\BitDefender\BitDefender 2008\IEShow.exe"O4 - HKLM\..\Run: [BDAgent] "C:\Programmi\BitDefender\BitDefender 2008\bdagent.exe"O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Programmi\Acronis\TrueImageHome\TrueImageMonitor.exeO4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Programmi\Acronis\TrueImageHome\TimounterMonitor.exeO4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programmi\File comuni\Acronis\Schedule2\schedhlp.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Nero\Lib\NeroCheck.exeO4 - HKLM\..\Run: [NBKeyScan] "C:\Programmi\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [slide.exe] C:\Programmi\Slide\Slide.exeO4 - HKCU\..\Run: [AlcoholAutomount] "C:\Programmi\Alcohol Soft\Alcohol 120\axcmd.exe" /automountO4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exeO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - Global Startup: Logitech SetPoint.lnk = C:\Programmi\Logitech\SetPoint\SetPoint.exeO8 - Extra context menu item: &Scarica con FlashGet - C:\Programmi\FlashGet\jc_link.htmO8 - Extra context menu item: &Scarica tutto con FlashGet - C:\Programmi\FlashGet\jc_all.htmO8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Converti in Adobe PDF - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Converti nel file PDF esistente - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Converti selezione in Adobe PDF - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Converti selezione in file PDF esistente - res://C:\Programmi\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programmi\FlashGet\FlashGet.exeO9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Programmi\FlashGet\FlashGet.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1187202703187O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1187538333296O17 - HKLM\System\CCS\Services\Tcpip\..\{5A3B2F23-875A-496A-860C-303919A41D6C}: NameServer = 62.94.0.1,212.216.112.222O17 - HKLM\System\CS1\Services\Tcpip\..\{5A3B2F23-875A-496A-860C-303919A41D6C}: NameServer = 62.94.0.1,212.216.112.222O17 - HKLM\System\CS2\Services\Tcpip\..\{5A3B2F23-875A-496A-860C-303919A41D6C}: NameServer = 62.94.0.1,212.216.112.222O20 - AppInit_DLLs: C:\WINDOWS\system32\__c00DE5EB.datO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Programmi\Lavasoft\Ad-Aware 2007\aawservice.exeO23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programmi\File comuni\Acronis\Schedule2\schedul2.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Programmi\File comuni\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exeO23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Programmi\Symantec\pcAnywhere\awhost32.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programmi\Bonjour\mDNSResponder.exeO23 - Service: DomainService - - C:\WINDOWS\system32\ujmuvahd.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmi\File comuni\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exeO23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Programmi\File comuni\BitDefender\BitDefender Update Service\livesrv.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programmi\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Nero\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PDAgent - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDAgent.exeO23 - Service: PDEngine - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDEngine.exeO23 - Service: PDExchange - Raxco Software, Inc. - C:\Programmi\Raxco\PerfectDisk\PDExchange.exeO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programmi\Analog Devices\SoundMAX\SMAgent.exeO23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exeO23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Programmi\BitDefender\BitDefender 2008\vsserv.exeO23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Programmi\RealVNC\VNC4\WinVNC4.exeO23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Programmi\File comuni\BitDefender\BitDefender Communicator\xcommsvr.exe--End of file - 12265 bytes
o scansionare cu bitdefender (nu imi permite ca sa sterg sau sa mut virusul in carantina):
Salut Cesar,
Intr-adevar, sunt cateva obiecte suspecte in log-ul HijackThis!. Din pacate, nu am timp chiar acum sa ma uit foarte atent pe log-ul tau (o sa ma uit putin mai tarziu, si o sa-ti spun exact ce sa faci).
Poti sa te uiti in log-ul de scanare al BD si sa postezi calea catre fisierele infectate (eventual si din ce cauza nu se poate lua nicio masura impotriva lor)?
Cris.
ultimile doua scanari:
p.s. acuma imi iese si mesajul urmator:
/applications/core/interface/file/attachment.php?id=1089" data-fileid="1089" rel="">1196451747_1_01.xml
/applications/core/interface/file/attachment.php?id=1090" data-fileid="1090" rel="">1196595941_1_02.xml
a mai iesit si asta...
In HijackThis, da fix la urmatoarele (opreste BitDefender, pentru ca s-ar putea sa blocheze accesul la fisiere):
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4 832-A2BF-45AF82825583} - C:\WINDOWS\system32\hmaoxnis.dllO20 - AppInit_DLLs: C:\WINDOWS\system32\__c00DE5E B.datO23 - Service: DomainService - - C:\WINDOWS\system32\ujmuvahd.exe
Apoi da un restart la PC si mai fa o Scanare Profunda (Deep Scan, in engleza...nu stiu cum e in italiana) si mai posteaza un log HijackThis!
Daca BD mai detecteaza ceva, scrie unde anume (nu atasa log-uri de scanare, pentru ca nu am acces la ele...doar BD Virus Analysts au acces la atasamente pe aria asta).
P.s.: Inainte de a da fix in HJ, verifica daca fisierul C:\WINDOWS\system32\ujmuvahd.exe este detectat de BD. Daca nu, pune-l intr-o arhiva ZIP cu parola infected si atasaz-o la urmatorul tau post, pentru a putea fi analizat si sa i se adauge detectie
se pare ca nu mai da probleme...
din pacate, se pare ca mai am inca probleme...
din cand in cand se deschid ferestre de internet explorer cu url diferite.
une exemplu: ~ Link sters ~
Salut!
Data viitoarea, te rog scrie linkul intr-un fisier text pe care sa-l atasezi aici; linkurile directe pot fi accesate de oricine, si daca contin malware, pot deveni noi surse de infectie. La fisierele atasate pe aceasta arie avem acces doar noi moderatorii si analistii de virusi.
In ceea ce priveste problema ta este posibil ca sa mai ai ceva librarie incarcata sub ceva proces, care cauzeaza aceste rele. Ti-am pus pe PM un program care va crea un fisier text, c:\log.txt unde vor fi listate toate procesele care se executa si toate librariile incarcate. Sa imi trimiti acel fisier si ma voi uita peste el, sa incerc gasesc ce nu e in regula.
Toate cele bune!
/applications/core/interface/file/attachment.php?id=1127" data-fileid="1127" rel="">link.txt