Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

Amenintare Origine Necunoscuta

Optiuni
SorinK
editat septembrie 2008 în Discu355ii malware

Creaza fisiere de 45 KB cu extensiile exe pentru melodii si filme.


45107 e la size in TightVNC amenintarea, nu ma lasa sa trimit fisiere pe yahoo messenger, am incercat sa o trimit prin file transfer la TightVNC si tot nu ma lasa sa o i-au sa o adaug aici.


Nu permite downloadarea definitiilor pentru Bitdefender si inca un antivirus strain de pe site, in vederea scanarii online sau off-line.


Permite ca Bitdefender 10 sa se actualizeze dar ii corupe fisierele.


Bitdefender nu zice nimic cand vede fisiere .exe cu numele fisierelor de muzica si filme.


Cand dau la Bitdefender sa scaneze memoria nu scaneaza nimic si zice ca e curata, 0 procese in memorie scanate.


O versiune mai veche a acestei ciudatenii am eliminato cu Bitdefender online scan, dar acum e generatie mai noua, pare mai "desteapta".


Este calculatorul unui prieten, sper ca ma puteti ajuta, ca sa scape de reinstalarea Windows-ului..


Logfile of HijackThis v2.0.2


Scan saved at 17:08:03, on 9/3/2008


Platform: Windows XP SP3 (WinNT 5.01.2600)


MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)


Boot mode: Normal


Running processes:


C:\WINDOWS\System32\smss.exe


C:\WINDOWS\system32\winlogon.exe


C:\WINDOWS\system32\services.exe


C:\WINDOWS\system32\lsass.exe


C:\WINDOWS\system32\svchost.exe


C:\WINDOWS\System32\svchost.exe


C:\WINDOWS\Explorer.EXE


C:\WINDOWS\system32\spoolsv.exe


C:\WINDOWS\system32\RUNDLL32.EXE


C:\WINDOWS\RTHDCPL.EXE


C:\Program Files\ESET\ESET Smart Security\egui.exe


C:\Program Files\Winamp\winampa.exe


C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe


C:\Program Files\DAEMON Tools\daemon.exe


C:\Program Files\SweetIM\Messenger\SweetIM.exe


C:\WINDOWS\system32\ctfmon.exe


C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe


C:\Program Files\ESET\ESET Smart Security\ekrn.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


C:\WINDOWS\system32\nvsvc32.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe


C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe


C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe


C:\Program Files\PC Connectivity Solution\Transports\NclIrSrv.exe


C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe


C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe


C:\WINDOWS\system32\wuauclt.exe


C:\Program Files\TightVNC\WinVNC.exe


C:\Program Files\Java\jre1.6.0_06\bin\jucheck.exe


E:\Kit\Antivirusi\Trend Micro\HiJackThis.exe


R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com


R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll


O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll


O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll


O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll


O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup


O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit


O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE


O4 - HKLM\..\Run: [skyTel] SkyTel.EXE


O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE


O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice


O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe


O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"


O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"


O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"


O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033


O4 - HKLM\..\Run: [sweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe


O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe


O4 - HKCU\..\Run: [Yahoo! Pager] ~"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"


O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray


O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')


O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')


O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')


O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000


O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll


O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll


O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe


O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.ro/scan_ro/scan8/oscan8.cab


O17 - HKLM\System\CCS\Services\Tcpip\..\{A8FB4993-B731-4993-B383-6DBA517F0ACB}: NameServer = 213.154.124.1 193.231.252.1


O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe


O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe


O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe


O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe


O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe


O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe


O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe


O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe


O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe


--


End of file - 7695 bytes


Va multumesc anticipat.

Comentarii

  • Un antivirus prin metode euristice imi zice ca este posibila amenintare VB.


    Pare ca ar sterge-o, problema este de ce nu o vede Bitdefender.


    Si am mai scapat odata de versiunea mai veche a chestiei asteia si dupa cateva saptamani iar a aparut.


    Cand incerc sa o sterg manual zice Windows-ul "Cannot delete file: Cannot read from the source file or disk.".

  • Am uitat sa mentionez, este dubla extensie la aceasta amenintare, jpg.exe si avi.exe la fisierele create, toate au aceeasi dimensiune.

  • Te rog ataseaza cateva fisiere afectate, arhivate cu parola infected. Dupa ce ne uitam pe ele o sa putem sa va dam mai multe sfaturi.

  • Am reusit sa o sterg cu un alt program antivirus.


    Daca mai apare o sa mai incerc sa i-au un fisier desi ieri cand am incercat nu a mers.


    Va multumesc pentru raspuns.