Poslao: 01 Nov 2009 22:30
|
offline
- argonaut1
- Novi MyCity građanin
- Pridružio: 20 Jun 2008
- Poruke: 6
|
Pre dva tri dana ubacio sam skriptu u JDownloader koja menja IP adresu modemu radi skidanja programa sa rapida.
Priblizno u isto vreme sam ubacio i virtuagirlhd (ne znam da li se sme pisati za neke programe da su krekovani) u glavnom skinuo sam par peceva sa sumnjivih adresa.
Prvo su poceli da mi se otvaraju prozori u IE iako koristim mozilu.
Deinstalirao sam explorer kao komponentu windowsa ali su prozori iskakali ponovo.
Zatim su se culi zvuci sa nekih sajtova iako nista nije bilo pokrenuto na racunaru.(kao da su otvoreni prozori nevidljivi)
ZA Firewall me je par puta obavestio da program a.exe trazi pristup internetu posto sam proverio i video da zeli da pristupi adresi rutera dao sam mu dozvolu.
Ubrzo je avast poceo da prijavljuje da je a.exe inficiran ali ga nije mogao obrisati pronasao sam ga u c/doc end set/argonaut/loc. setings/temp
bilo je nekoliko istih a.exe fajlova ali se dva nisu mogla obrisati.
Zatim sam izlistao na netu o a. exe fajlu ,preporucivali su registry buster za njegov popravak.
Registry buster se nije mogao instalirati.
Daljim Googlanjem sam pronasao program dr.Web .
Ovaj program je registrovao backdoor.tdss.565
i jos gomilu drugih stetocina koje je obrisao ali je ovaj prvi samo neutralisao.
Pri svakom sledecem skeniranju ovaj nezeljeni program se nalazio na drugom mestu.
Pretragom na netu ustanovio sam da mnogo ljudi ima ovaj problem i da ga ne mogu resiti ni jednim alatom (vecina alata ga i ne prepoznaje) a on izgleda dozvoljava pristup svim ostalim stetocinama na netu.
Preporucen je program Spyhunter, on je pronasao oko 254 inficiranih fajlova uglavnom nose oznaku Zlob trojan u registri kljucevima.
Ovaj program naravno trazi uplatu da bi ocistio inficirane fajlove.
Takodje sam probao ciscenje sa Pareto antivirusem i Malwarebytes' Anti-Malware oni ga uopste ne pronalaze.
Prilazem fajlove koji su trazeni u uputstvu.
Koristim adsl telekom modem HUAWEI 520s realna brzina oko 800
pitanja :
Da li postoji neki efikasan besplatan alat za uklanjanje ovih smetnji.
U jednom Vasem odgovoru procitao sam da Vam za resavanje ovakvih problema treba i po nekoliko sati.
Ukoliko je proces uklanjanja mnogo komplikovan ili ako ce Vam oduzeti mnogo vremena njegovo resavanje, mogu reinstalirati sistem ako se ovaj nezeljeni program nece vratiti sa drugih particija.
Hvala i pozdrav
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
DDS (Ver_09-10-26.01) - NTFSx86
Run by ARGONAUT at 18:59:06,98 on ned 01.11.2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.290 [GMT 1:00]
AV: Doctor Web Anti-Virus *On-access scanning enabled* (Updated) {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
AV: avast! antivirus 4.8.1356 [VPS 091101-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\LckFldService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\DrWeb\spidernt.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\DrWeb\SpIDerAgent.exe
C:\Program Files\DrWeb\spiderml.exe
C:\Program Files\DrWeb\spidergate.exe
C:\PROGRA~1\DrWeb\spiderui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
c:\program files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\ARGONAUT\Desktop\dds.scr
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = panet.rs/
uSearch Page =
uSearch Bar =
mSearchAssistant =
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {eee6c35d-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live pomagac za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SweetIM Toolbar Helper: {eee6c35c-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: SweetIM Toolbar for Internet Explorer: {eee6c35b-6118-11dc-9c72-001320c79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: ZoneAlarm Spy Blocker Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: FireShot: {6e6e744e-4d20-4ce3-9a7a-26dfffe22f68} - c:\documents and settings\argonaut\application data\mozilla\firefox\profiles\r3sh46sz.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\library\fsaddin-0.80.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Acronis True Image Monitor] "c:\program files\acronis\trueimage\TrueImageMonitor.exe"
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [SpIDerAgent] "c:\program files\drweb\SpIDerAgent.exe"
mRun: [SpIDerMail] "c:\program files\drweb\spiderml.exe"
mRun: [SpIDerGate] "c:\program files\drweb\spidergate.exe" -autorun
mRun: [SpIDerNT] c:\progra~1\drweb\spiderui.exe /agent
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [ParetoLogic Anti-Virus PLUS] "c:\program files\paretologic\anti-virus plus\Pareto_AV.lnk" -NM -hidesplash
mRun: [SpyHunter Security Suite] c:\program files\enigma software group\spyhunter\SpyHunter3.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\program files\drweb\drwebsp.dll
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {41564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\argonaut\applic~1\mozilla\firefox\profiles\r3sh46sz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.panet.rs/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-flv&p=
FF - component: c:\documents and settings\argonaut\application data\mozilla\firefox\profiles\r3sh46sz.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
FF - plugin: c:\documents and settings\argonaut\application data\mozilla\firefox\profiles\r3sh46sz.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
============= SERVICES / DRIVERS ===============
R0 DwProt;DrWeb Protection;c:\windows\system32\drivers\dwprot.sys [2009-11-1 105080]
R0 stwlfbus;stwlfbus;c:\windows\system32\drivers\stwlfbus.sys [2003-4-27 8704]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-5-17 114768]
R2 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-6-17 464264]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-5-17 20560]
R2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);c:\program files\common files\doctor web\scanning engine\dwengine.exe [2009-9-22 869688]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-3-13 54752]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
R2 SPIDER;SpIDer Guard File System Monitor;c:\progra~1\drweb\spider.sys [2009-8-17 306464]
R2 SPIDERNT;SpIDer Guard for Windows;c:\progra~1\drweb\spidernt.exe [2009-8-17 231328]
S1 nltdi;nltdi;c:\windows\system32\drivers\nltdi.sys [2007-4-23 81688]
S2 ZeppelinService;plasservice;c:\program files\common files\paretologic\plas\plasservice.exe [2009-2-18 587216]
S3 fsssvc;Usluga Windows Live Porodicna bezbednost;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 MR97310_VGA_DUAL_CAMERA;MR97310 VGA Dual Mode Camera;c:\windows\system32\drivers\mr97310v.sys [2008-9-1 116078]
S3 PAC207;VideoCAM GE111;c:\windows\system32\drivers\PFC027.sys [2005-4-8 162176]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2008-5-24 35216]
S3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2008-5-24 35216]
S4 st3wolf;st3wolf;c:\windows\system32\drivers\st3wolf.sys [2003-4-27 99360]
=============== Created Last 30 ================
2009-11-01 16:11:33 646944 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-11-01 16:11:33 3872 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-11-01 16:11:33 32 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-11-01 16:11:33 32 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-11-01 16:10:29 0 -c--a-w- C:\rollback.ini
2009-11-01 15:37:23 0 d-----w- c:\program files\Enigma Software Group
2009-11-01 15:23:31 0 d-----w- c:\program files\NetLimiter 2 Monitor
2009-11-01 15:16:58 0 dc----w- c:\docume~1\alluse~1\applic~1\ParetoLogic Anti-Virus PLUS
2009-11-01 15:16:57 0 d-----w- c:\program files\ParetoLogic
2009-11-01 15:16:57 0 d-----w- c:\program files\common files\ParetoLogic
2009-11-01 10:57:15 105080 ----a-w- c:\windows\system32\drivers\dwprot.sys
2009-11-01 10:56:54 0 d-----w- c:\program files\common files\Doctor Web
2009-11-01 10:56:47 0 dc----w- c:\docume~1\alluse~1\applic~1\Doctor Web
2009-11-01 10:56:46 0 d-----w- c:\program files\DrWeb
2009-10-31 10:12:45 0 dc----w- C:\VundoFix Backups
2009-10-30 19:07:00 0 d-----w- c:\documents and settings\argonaut\DoctorWeb
2009-10-29 22:10:39 14 ----a-w- c:\windows\popcinfo.dat
2009-10-29 18:36:48 0 dc----w- C:\vghd
2009-10-29 17:33:10 0 d-----w- c:\program files\PowerQuest
2009-10-29 16:30:24 208640 ----a-w- c:\windows\system32\drivers\timntr.sys
2009-10-29 16:30:24 126976 ----a-w- c:\windows\system32\snapapi.dll
2009-10-27 20:23:11 0 d--h--w- c:\windows\PIF
2009-10-27 14:48:44 0 d-----w- c:\docume~1\argonaut\applic~1\FireShot
2009-10-26 19:32:52 7 ----a-w- c:\windows\sbacknt.bin
2009-10-17 18:43:59 20736 -c--a-w- c:\windows\system32\dllcache\ramdisk.sys
2009-10-17 18:42:55 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-10-17 18:41:55 369664 -c--a-w- c:\windows\system32\dllcache\asp51.dll
2009-10-17 18:39:30 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2009-10-17 18:39:22 749 ---ha-r- c:\windows\WindowsShell.Manifest
2009-10-17 18:39:22 749 ---ha-r- c:\windows\system32\wuaucpl.cpl.manifest
2009-10-17 18:39:22 749 ---ha-r- c:\windows\system32\sapi.cpl.manifest
2009-10-17 18:39:22 749 ---ha-r- c:\windows\system32\nwc.cpl.manifest
2009-10-17 18:39:22 749 ---ha-r- c:\windows\system32\ncpa.cpl.manifest
2009-10-17 18:36:27 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2009-10-17 18:36:27 28160 ----a-w- c:\windows\system32\irmon.dll
2009-10-17 18:36:27 151552 ----a-w- c:\windows\system32\irftp.exe
2009-10-17 18:36:26 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-10-17 18:33:04 27165 ----a-w- c:\windows\system32\drivers\fetnd5.sys
2009-10-17 18:31:18 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2009-10-17 18:29:23 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-17 18:29:23 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-10-17 18:29:23 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-17 18:29:23 13312 ----a-w- c:\windows\system32\irclass.dll
==================== Find3M ====================
2009-10-29 16:30:24 81088 ----a-w- c:\windows\system32\drivers\snapman.sys
2009-10-29 16:30:24 37888 ----a-w- c:\windows\system32\setupnt.dll
2009-10-29 16:30:24 28096 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2009-10-17 18:37:52 22748 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-10 13:54:06 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 13:53:50 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-16 00:31:34 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
============= FINISH: 19:03:18,43 ===============
|
|
|
|
|
|
|
Poslao: 02 Nov 2009 23:06
|
offline
- argonaut1
- Novi MyCity građanin
- Pridružio: 20 Jun 2008
- Poruke: 6
|
Dobro je da sam opet pogledao temu.
Tek sada sam izvrsio deinstalaciju, nadam se da nije prouzrokovalo neki problem posto sam koristio racunar skoro ceo dan.
Interesuje me za sta se jos moze koristiti combofix.
Hvala pozdrav
|
|
|
|
Poslao: 03 Nov 2009 14:55
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
argonaut1 ::
Interesuje me za sta se jos moze koristiti combofix.
Ti ga mozes koristiti samo kad ti neka strucna osoba koja je prosla obuku sa njim kaze sta da radis. U suprotnom mozes ostetiti sistem i izgubiti podatke.
|
|
|
|
Poslao: 03 Nov 2009 20:18
|
offline
- argonaut1
- Novi MyCity građanin
- Pridružio: 20 Jun 2008
- Poruke: 6
|
Da procunjao sam po netu ,
svuda napominju da combofix moze biti prilicno nezgodna alatka
za neupucene korisnike.
Onda mi je postalo jasno zasto prvo moraju da se urade snimci sistema,pa tek onda da se odabere potreban alat..
Na srecu sada znam kome mogu da se obratim ako zapnem ponovo.
|
|
|
|