Nod hlasi trojan INJECTOR.CUA
Napsal: 24 zář 2010 11:05
Zasílám RSIT log z počítače, kde mi ESET Nod hlásí trojan INJECTOR.CUA, který se projevuje tím, že mi na jakémkoliv flash disku skryje složky, vytvoří složku 8585485, kam umístí progrmy exe s názvem každé složky, kterou najde na flash disku. V rootu vytvoří zástupce, kterým přiřadí v průzkumníkovi ikonku jako složka, takže dvojklikem dojde ke spuštění programu, kterým se trojan hezky rozmnoží... Fikaný... Ale nějak se ho nemůžu zbavit. Díky za pomoc.
LOG
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-09-24 11:43:46
Microsoft Windows 2000 Professional Service Pack 4
System drive C: has 26 GB (92%) free of 29 GB
Total RAM: 128 MB (32% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - @msdxmLC.dll,-1@1033,&Rádio - C:\WINNT\System32\msdxm.ocx [2003-09-18 848656]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=mobsync.exe /logon []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nezapomen"=C:\pamatuj\nezapomen.exe [2001-06-30 457216]
"ctfmon.exe"=C:\WINNT\system32\ctfmon.exe [2001-02-20 8192]
"C:\Program Files\NetMeter\NetMeter.exe"=C:\Program Files\NetMeter\NetMeter.exe [2007-08-11 331264]
"Windows USB Service"=C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe [2010-08-24 163840]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe"="C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe:*:Enabled:Windows USB Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-09-24 11:43:48 ----D---- C:\Program Files\trend micro
2010-09-24 11:43:46 ----D---- C:\rsit
2010-09-20 12:02:42 ----ASHD---- C:\Config.Msi
2010-08-26 10:45:26 ----RSHD---- C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747
======List of files/folders modified in the last 1 months======
2010-09-24 11:43:48 ----RAD---- C:\Program Files
2010-09-24 11:43:48 ----AD---- C:\WINNT\system32
2010-09-24 11:43:30 ----D---- C:\acces2000
2010-09-24 11:43:24 ----A---- C:\WINNT\wincmd.ini
2010-09-24 11:17:33 ----D---- C:\WINNT\system32\NtmsData
2010-09-24 07:17:20 ----AD---- C:\WINNT\security
2010-09-24 07:11:31 ----AD---- C:\WINNT\Debug
2010-09-23 15:00:27 ----A---- C:\WINNT\SchedLgU.Txt
2010-09-22 14:59:19 ----D---- C:\VELKOS
2010-09-22 11:19:11 ----A---- C:\WINNT\ODBC.INI
2010-09-20 12:03:25 ----SHD---- C:\WINNT\Installer
2010-09-20 12:02:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-09-20 12:02:56 ----AD---- C:\WINNT
2010-09-20 10:19:03 ----AD---- C:\WINNT\system32\CatRoot
2010-09-20 07:48:15 ----D---- C:\WINREDAP
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Intel AGP Bus Filter; C:\WINNT\System32\DRIVERS\agp440.sys [2003-06-19 21008]
R0 atapi;Standardní řadič disku IDE či ESDI; C:\WINNT\System32\DRIVERS\atapi.sys [2003-06-19 86672]
R0 Disk;Ovladač disku; C:\WINNT\System32\DRIVERS\disk.sys [2003-06-19 30768]
R0 Diskperf;Diskperf; C:\WINNT\system32\drivers\Diskperf.sys [2003-06-19 7728]
R0 dmio;Ovladač správce logických disků; C:\WINNT\System32\drivers\dmio.sys [2003-06-19 137936]
R0 dmload;dmload; C:\WINNT\System32\drivers\dmload.sys [2003-06-19 7312]
R0 Ftdisk;Ovladač správce svazků; C:\WINNT\System32\DRIVERS\ftdisk.sys [2003-06-19 115632]
R0 IntelIde;IntelIde; C:\WINNT\System32\DRIVERS\intelide.sys [2003-06-19 4624]
R0 isapnp;Řadič Plug and Play sběrnice ISA/EISA; C:\WINNT\System32\DRIVERS\isapnp.sys [2003-06-19 46992]
R0 KSecDD;KSecDD; C:\WINNT\system32\drivers\KSecDD.sys [2003-06-19 71888]
R0 MountMgr;MountMgr; C:\WINNT\system32\drivers\MountMgr.sys [2003-06-19 29264]
R0 Mup;Služba Multiple UNC Provider; C:\WINNT\system32\drivers\Mup.sys [2004-12-02 89328]
R0 NDIS;Systémový ovladač NDIS; C:\WINNT\system32\drivers\NDIS.sys [2003-06-19 170928]
R0 PartMgr;PartMgr; C:\WINNT\system32\drivers\PartMgr.sys [2003-06-19 11792]
R0 PCI;Řadič sběrnice PCI; C:\WINNT\System32\DRIVERS\pci.sys [2003-06-19 59888]
R2 Nbf;Protokol NetBEUI; C:\WINNT\System32\DRIVERS\nbf.sys [2002-08-26 102160]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINNT\System32\DRIVERS\nwlnkipx.sys [2003-06-19 91408]
R2 NwlnkNb;NWLink NetBIOS; C:\WINNT\System32\DRIVERS\nwlnknb.sys [2003-06-19 65520]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINNT\System32\DRIVERS\nwlnkspx.sys [2002-08-26 58480]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINNT\system32\drivers\es1371mp.sys [1999-11-06 44528]
R3 mga64;mga64; C:\WINNT\System32\DRIVERS\mga64m.sys [1999-11-30 150960]
R3 NtApm;Ovladač rozhraní služby NT Apm/Legacy; C:\WINNT\System32\DRIVERS\NtApm.sys [2000-03-08 9136]
R3 rtl8139;Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver; C:\WINNT\System32\DRIVERS\RTL8139.SYS [1999-09-25 18704]
R3 uhcd;Ovladač univerzálního hostitelského řadiče USB; C:\WINNT\System32\DRIVERS\uhcd.sys [2003-06-19 32848]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINNT\System32\DRIVERS\usbhub.sys [2003-06-19 40176]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINNT\System32\DRIVERS\USBSTOR.SYS [2003-06-19 21552]
S3 sermouse;Ovladač sériové myši; C:\WINNT\System32\DRIVERS\sermouse.sys [2000-03-08 17136]
S3 usbprint;Třída USB Printer; C:\WINNT\System32\DRIVERS\usbprint.sys [2003-06-19 21872]
S4 ACPI;ACPI; C:\WINNT\system32\drivers\ACPI.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------
LOG
Logfile of random's system information tool 1.08 (written by random/random)
Run by Administrator at 2010-09-24 11:43:46
Microsoft Windows 2000 Professional Service Pack 4
System drive C: has 26 GB (92%) free of 29 GB
Total RAM: 128 MB (32% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - @msdxmLC.dll,-1@1033,&Rádio - C:\WINNT\System32\msdxm.ocx [2003-09-18 848656]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=mobsync.exe /logon []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Nezapomen"=C:\pamatuj\nezapomen.exe [2001-06-30 457216]
"ctfmon.exe"=C:\WINNT\system32\ctfmon.exe [2001-02-20 8192]
"C:\Program Files\NetMeter\NetMeter.exe"=C:\Program Files\NetMeter\NetMeter.exe [2007-08-11 331264]
"Windows USB Service"=C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe [2010-08-24 163840]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe"="C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747\winusbmgr.exe:*:Enabled:Windows USB Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-09-24 11:43:48 ----D---- C:\Program Files\trend micro
2010-09-24 11:43:46 ----D---- C:\rsit
2010-09-20 12:02:42 ----ASHD---- C:\Config.Msi
2010-08-26 10:45:26 ----RSHD---- C:\Documents and Settings\Administrator\Data aplikací\U-2535-6853-8747
======List of files/folders modified in the last 1 months======
2010-09-24 11:43:48 ----RAD---- C:\Program Files
2010-09-24 11:43:48 ----AD---- C:\WINNT\system32
2010-09-24 11:43:30 ----D---- C:\acces2000
2010-09-24 11:43:24 ----A---- C:\WINNT\wincmd.ini
2010-09-24 11:17:33 ----D---- C:\WINNT\system32\NtmsData
2010-09-24 07:17:20 ----AD---- C:\WINNT\security
2010-09-24 07:11:31 ----AD---- C:\WINNT\Debug
2010-09-23 15:00:27 ----A---- C:\WINNT\SchedLgU.Txt
2010-09-22 14:59:19 ----D---- C:\VELKOS
2010-09-22 11:19:11 ----A---- C:\WINNT\ODBC.INI
2010-09-20 12:03:25 ----SHD---- C:\WINNT\Installer
2010-09-20 12:02:56 ----D---- C:\Documents and Settings\All Users\Data aplikací\Adobe
2010-09-20 12:02:56 ----AD---- C:\WINNT
2010-09-20 10:19:03 ----AD---- C:\WINNT\system32\CatRoot
2010-09-20 07:48:15 ----D---- C:\WINREDAP
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 agp440;Intel AGP Bus Filter; C:\WINNT\System32\DRIVERS\agp440.sys [2003-06-19 21008]
R0 atapi;Standardní řadič disku IDE či ESDI; C:\WINNT\System32\DRIVERS\atapi.sys [2003-06-19 86672]
R0 Disk;Ovladač disku; C:\WINNT\System32\DRIVERS\disk.sys [2003-06-19 30768]
R0 Diskperf;Diskperf; C:\WINNT\system32\drivers\Diskperf.sys [2003-06-19 7728]
R0 dmio;Ovladač správce logických disků; C:\WINNT\System32\drivers\dmio.sys [2003-06-19 137936]
R0 dmload;dmload; C:\WINNT\System32\drivers\dmload.sys [2003-06-19 7312]
R0 Ftdisk;Ovladač správce svazků; C:\WINNT\System32\DRIVERS\ftdisk.sys [2003-06-19 115632]
R0 IntelIde;IntelIde; C:\WINNT\System32\DRIVERS\intelide.sys [2003-06-19 4624]
R0 isapnp;Řadič Plug and Play sběrnice ISA/EISA; C:\WINNT\System32\DRIVERS\isapnp.sys [2003-06-19 46992]
R0 KSecDD;KSecDD; C:\WINNT\system32\drivers\KSecDD.sys [2003-06-19 71888]
R0 MountMgr;MountMgr; C:\WINNT\system32\drivers\MountMgr.sys [2003-06-19 29264]
R0 Mup;Služba Multiple UNC Provider; C:\WINNT\system32\drivers\Mup.sys [2004-12-02 89328]
R0 NDIS;Systémový ovladač NDIS; C:\WINNT\system32\drivers\NDIS.sys [2003-06-19 170928]
R0 PartMgr;PartMgr; C:\WINNT\system32\drivers\PartMgr.sys [2003-06-19 11792]
R0 PCI;Řadič sběrnice PCI; C:\WINNT\System32\DRIVERS\pci.sys [2003-06-19 59888]
R2 Nbf;Protokol NetBEUI; C:\WINNT\System32\DRIVERS\nbf.sys [2002-08-26 102160]
R2 NwlnkIpx;Transportní protokol kompatibilní s NWLink IPX/SPX/NetBIOS; C:\WINNT\System32\DRIVERS\nwlnkipx.sys [2003-06-19 91408]
R2 NwlnkNb;NWLink NetBIOS; C:\WINNT\System32\DRIVERS\nwlnknb.sys [2003-06-19 65520]
R2 NwlnkSpx;Protokol NWLink SPX/SPXII; C:\WINNT\System32\DRIVERS\nwlnkspx.sys [2002-08-26 58480]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINNT\system32\drivers\es1371mp.sys [1999-11-06 44528]
R3 mga64;mga64; C:\WINNT\System32\DRIVERS\mga64m.sys [1999-11-30 150960]
R3 NtApm;Ovladač rozhraní služby NT Apm/Legacy; C:\WINNT\System32\DRIVERS\NtApm.sys [2000-03-08 9136]
R3 rtl8139;Realtek RTL8139-based PCI Fast Ethernet Adapter NT Driver; C:\WINNT\System32\DRIVERS\RTL8139.SYS [1999-09-25 18704]
R3 uhcd;Ovladač univerzálního hostitelského řadiče USB; C:\WINNT\System32\DRIVERS\uhcd.sys [2003-06-19 32848]
R3 usbhub;Ovladač standardního rozbočovače USB; C:\WINNT\System32\DRIVERS\usbhub.sys [2003-06-19 40176]
R3 USBSTOR;Ovladač velkokapacitního paměťového zařízení USB; C:\WINNT\System32\DRIVERS\USBSTOR.SYS [2003-06-19 21552]
S3 sermouse;Ovladač sériové myši; C:\WINNT\System32\DRIVERS\sermouse.sys [2000-03-08 17136]
S3 usbprint;Třída USB Printer; C:\WINNT\System32\DRIVERS\usbprint.sys [2003-06-19 21872]
S4 ACPI;ACPI; C:\WINNT\system32\drivers\ACPI.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF-----------------