@
tabu
Oprócz tytułowej infekcji widać także:
Cytat
SRV - [2006-11-02 10:46:03 | 000,171,520 | ---- | M] () [Auto | Running] -- C:\Windows\System32\tdctxte.exe -- (tdctxte)
SRV - [2006-11-02 10:46:03 | 000,046,592 | ---- | M] () [Auto | Running] -- C:\Windows\System32\mabidwe.exe -- (mabidwe)
SRV - [2006-11-02 10:46:03 | 000,046,080 | ---- | M] () [Auto | Running] -- C:\Windows\System32\soxpeca.exe -- (soxpeca)
SRV - [2006-11-02 10:46:03 | 000,045,568 | ---- | M] (module attribute) [Auto | Running] -- C:\Windows\System32\BtwSvc.dll -- (BtwSvc)
SRV - [2006-11-02 10:46:03 | 000,038,400 | ---- | M] () [Auto | Running] -- C:\Windows\System32\wsldoekd.exe -- (wsldoekd)
SRV - [2006-11-02 10:46:03 | 000,038,400 | ---- | M] () [Auto | Running] -- C:\Windows\System32\WServing.exe -- (WServing)
SRV - [2006-11-02 10:46:03 | 000,038,400 | ---- | M] () [Auto | Running] -- C:\Windows\System32\sotpeca.exe -- (sotpeca)
SRV - [2006-11-02 10:46:03 | 000,038,400 | ---- | M] () [Auto | Running] -- C:\Windows\System32\noxtcyr.exe -- (noxtcyr)
SRV - [2006-11-02 10:46:03 | 000,037,888 | ---- | M] () [Auto | Running] -- C:\Windows\System32\AFinding.exe -- (AFinding)
SRV - [2006-11-02 10:46:03 | 000,036,352 | ---- | M] (Netopsystems AG) [Auto | Running] -- C:\Windows\System32\sopidkc.exe -- (sopidkc)
SRV - [2006-11-02 10:46:03 | 000,034,816 | ---- | M] () [Auto | Running] -- C:\Windows\System32\tdxdowkc.exe -- (tdxdowkc)
SRV - [2006-11-02 10:46:03 | 000,034,816 | ---- | M] () [Auto | Running] -- C:\Windows\System32\macidwe.exe -- (macidwe)
SRV - [2006-11-02 10:46:03 | 000,034,304 | ---- | M] (Netopsystems AG) [Auto | Running] -- C:\Windows\System32\PereSvc.exe -- (peresvc)
SRV - [2006-11-02 10:46:03 | 000,034,304 | ---- | M] () [Auto | Running] -- C:\Windows\System32\routing.exe -- (Routing)
SRV - [2006-11-02 10:46:03 | 000,034,304 | ---- | M] () [Auto | Running] -- C:\Windows\System32\perfs.exe -- (perfmons)
Nie wiem, co to jest, ale wygląda jak kilkanaście Rootkitów i Backdoorów!
Sprawdź ich pliki na -->
JOTTI/ albo na
VIRUSTOTAL albo na
VIRSCAN
Podaj wyniki.
Uruchom
OTL i w oknie
Własne opcje skanowania/Script wklej to:
Cytat
:OTL
SRV - File not found [Auto | Stopped] -- -- (tdydowkc)
SRV - File not found [Auto | Stopped] -- -- (sobicyt)
SRV - File not found [Auto | Stopped] -- -- (roytctm)
SRV - File not found [Auto | Stopped] -- -- (roxtctm)
SRV - File not found [Auto | Stopped] -- -- (noytcyr)
SRV - File not found [Auto | Stopped] -- -- (NOBICYT)
SRV - File not found [Auto | Stopped] -- -- (afisicx)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKCU..\Run: [2EfUBgHgp38lN6] C:\ProgramData\2EfUBgHgp38lN6.exe (WISC)
O4 - HKCU..\Run: [MuXTvpYRmxcx.exe] C:\ProgramData\MuXTvpYRmxcx.exe (imgs)
[2011-02-08 20:55:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Disk
[2011-02-08 14:20:00 | 000,377,856 | ---- | C] (WISC) -- C:\ProgramData\2EfUBgHgp38lN6.exe
[2011-02-08 14:19:59 | 000,422,400 | ---- | C] (imgs) -- C:\ProgramData\jbfhsyTESfFw.dll
[2011-02-08 14:19:58 | 000,457,728 | ---- | C] (imgs) -- C:\ProgramData\MuXTvpYRmxcx.exe
[2011-02-08 20:58:53 | 000,000,264 | ---- | M] () -- C:\ProgramData\~2EfUBgHgp38lN6
[2011-02-08 20:58:53 | 000,000,144 | ---- | M] () -- C:\ProgramData\~2EfUBgHgp38lN6r
[2011-02-08 20:58:46 | 000,422,400 | ---- | M] (imgs) -- C:\ProgramData\jbfhsyTESfFw.dll
[2011-02-08 16:13:46 | 000,000,488 | ---- | M] () -- C:\ProgramData\2EfUBgHgp38lN6
[2011-02-08 14:20:00 | 000,377,856 | ---- | M] (WISC) -- C:\ProgramData\2EfUBgHgp38lN6.exe
[2011-02-08 14:19:55 | 000,457,728 | ---- | M] (imgs) -- C:\ProgramData\MuXTvpYRmxcx.exe
[2011-02-08 20:55:16 | 000,000,609 | ---- | C] () -- C:\Users\Admin\Desktop\Windows Disk.lnk
[2011-02-08 20:27:23 | 000,024,083 | ---- | C] () -- C:\UsbFix_Upload_Me_KSIEGOWA.zip
[2011-02-08 14:45:31 | 000,000,264 | ---- | C] () -- C:\ProgramData\~2EfUBgHgp38lN6
[2011-02-08 14:45:31 | 000,000,144 | ---- | C] () -- C:\ProgramData\~2EfUBgHgp38lN6r
[2011-02-08 14:45:17 | 000,000,488 | ---- | C] () -- C:\ProgramData\2EfUBgHgp38lN6
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.pl/"
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.pl/"
:Commands
[emptytemp]
[resethosts]
Kliknij w
Wykonaj Script. Zatwierdź restart komputera. Zapisz raport, który pokaże się po restarcie.
Następnie uruchom
OTL ponownie, tym razem kliknij
Skanuj.
Pokaż nowy log OTL.txt oraz raport z usuwania.
.
Użytkownik MORDA edytował ten post 09 luty 2011, 03:59