Stránka 1 z 1

Microsoft Security Essential Alert Trojan Windows 7

Napsal: 11 úno 2011 14:00
od Pulytr
Ahoj,

mam mensi problem tady stou haveti... Nechce me vubec nikam pustit porad to stejne okno, zrejme pokrocila faze. Mozna bude trochu problem s tim, ze je to Roaming profile na Win7.. At se ten uzivatel prihlasi na jinem PC bere si toho zmetka sebou.. to znamena ze je ulozen v lokalnich registrech toho uzivatele kde se mi ho nedari odstranit. PC a Win jako takove pod jinym uzivatelem funguje naprosto bez problemu.

Predem dekuji za radu


Logfile of random's system information tool 1.08 (written by random/random)
Run by p.neumann at 2011-02-11 13:28:25
Microsoft Windows 7 Enterprise
System drive C: has 11 GB (45%) free of 24 GB
Total RAM: 1024 MB (33% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:29:03, on 11.2.2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
\alcasalcer.centrala.local\userdata\i.rysava\Data aplikací\aytsae.exe
C:\Windows\system32\proquota.exe
C:\Windows\explorer.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Temp\RSIT.exe
C:\Program Files\trend micro\p.neumann.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [VMware Tools] "C:\Program Files\VMware\VMware Tools\VMwareTray.exe"
O4 - HKLM\..\Run: [VMware User Process] "C:\Program Files\VMware\VMware Tools\VMwareUser.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [Microsoft Forefront Client Security Antimalware Service] "c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKCU\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll
O15 - Trusted Zone: http://*.amadeus.com (HKLM)
O15 - Trusted Zone: http://*.amadeus.net (HKLM)
O15 - Trusted Zone: http://*.amadeusproweb.com (HKLM)
O15 - Trusted Zone: http://*.amadeusupdate.com (HKLM)
O15 - Trusted Zone: http://*.amadeusvista.com (HKLM)
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = centrala.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = centrala.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = centrala.local
O18 - Protocol: x-owacid - {0215258F-F0A8-49DE-BF1B-0FF02EDA8807} - C:\Program Files\Microsoft\Outlook Web Access SMIME Client\mimectl.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: TP AutoConnect Service (tpautoconnsvc) - ThinPrint AG - C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe
O23 - Service: TP VC Gateway Service (TPVCGateway) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPVCGateway.exe
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
O23 - Service: VMware Upgrade Helper (VMUpgradeHelper) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe

--
End of file - 5364 bytes

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile Device Center"=C:\Windows\WindowsMobile\wmdc.exe [2007-05-31 648072]
"VMware Tools"=C:\Program Files\VMware\VMware Tools\VMwareTray.exe [2010-05-09 186928]
"VMware User Process"=C:\Program Files\VMware\VMware Tools\VMwareUser.exe [2010-05-09 1038896]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-04-20 2064736]
"Microsoft Forefront Client Security Antimalware Service"=c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MSASCui.exe [2009-09-03 1033584]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-12-11 948672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\Sidebar.exe [2009-07-14 1173504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"mctadmin"=C:\Windows\System32\mctadmin.exe [2009-07-14 93696]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FCSAM]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\FCSAM]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2011-02-11 13:28:26 ----D---- C:\Program Files\trend micro
2011-02-11 13:28:25 ----D---- C:\rsit
2011-02-11 13:04:53 ----A---- C:\Windows\HPMProp.INI

======List of files/folders modified in the last 1 months======

2011-02-11 13:28:26 ----RD---- C:\Program Files
2011-02-11 13:28:00 ----D---- C:\Temp
2011-02-11 13:18:13 ----SHD---- C:\$Recycle.Bin
2011-02-11 13:15:51 ----RD---- C:\Users
2011-02-11 13:08:28 ----D---- C:\Windows\Prefetch
2011-02-11 13:06:49 ----D---- C:\Windows\Help
2011-02-11 13:05:08 ----D---- C:\Windows\Temp
2011-02-11 13:04:53 ----D---- C:\Windows
2011-02-11 13:04:50 ----SHD---- C:\Windows\Installer
2011-02-11 13:04:48 ----D---- C:\Windows\System32
2011-02-11 13:04:15 ----D---- C:\Windows\system32\spool
2011-02-11 13:04:14 ----D---- C:\Windows\system32\DriverStore
2011-02-11 13:04:14 ----D---- C:\Windows\inf
2011-02-11 12:32:44 ----D---- C:\Windows\system32\config
2011-02-06 15:12:11 ----SHD---- C:\System Volume Information

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AvgRkx86;avgrkx86.sys; C:\Windows\System32\Drivers\avgrkx86.sys [2010-03-05 52872]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2009-07-14 173648]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2010-03-05 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2010-03-05 29512]
R1 AvgTdiX;AVG Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2010-04-20 242896]
R1 vmrawdsk;VMware Vista Physical Disk Helper; \??\C:\Program Files\VMware\VMware Tools\vmrawdsk.sys [2010-05-09 36144]
R1 vpcnfltr;Virtual PC Network Filter Driver; C:\Windows\system32\DRIVERS\vpcnfltr.sys [2009-09-23 55040]
R1 vpcvmm;@%SystemRoot%\system32\drivers\vpcvmm.sys,-100; C:\Windows\system32\drivers\vpcvmm.sys [2009-09-23 294912]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 VMMEMCTL;Memory Control Driver; \??\C:\Program Files\VMware\VMware Tools\Drivers\memctl\vmmemctl.sys [2010-05-09 15024]
R3 E1G60;Intel(R) PRO/1000 NDIS 6 – ovladač adaptéru; C:\Windows\system32\DRIVERS\E1G60I32.sys [2009-07-13 118784]
R3 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2009-05-15 69616]
R3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2009-07-14 133120]
R3 vm3dmp;vm3dmp; C:\Windows\system32\DRIVERS\vm3dmp.sys [2010-05-09 82992]
R3 vmci;VMware VMCI Bus Driver; C:\Windows\system32\DRIVERS\vmci.sys [2010-05-09 61872]
R3 vmmouse;VMware Pointing Device; C:\Windows\system32\DRIVERS\vmmouse.sys [2010-05-09 11440]
R3 vpcbus;Služba hostitelské sběrnice programu Virtual PC; C:\Windows\system32\DRIVERS\vpchbus.sys [2009-09-23 165376]
R3 vpcusb;Služba konektoru virtualizace rozhraní USB; C:\Windows\system32\DRIVERS\vpcusb.sys [2009-09-23 78336]
S1 vmdebug;VMware Replay Debugging Helper; \??\C:\Windows\system32\Drivers\vmdebug.sys [2010-05-09 22064]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\DRIVERS\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-13 229888]
S3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2009-06-10 4756480]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-12-03 2664032]
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys [2009-07-14 12368]
S3 s3cap;s3cap; C:\Windows\system32\DRIVERS\vms3cap.sys [2009-07-14 5632]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\DRIVERS\sisagp.sys [2009-07-14 52304]
S3 storvsc;storvsc; C:\Windows\system32\DRIVERS\storvsc.sys [2009-07-14 28224]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\DRIVERS\viaagp.sys [2009-07-14 53328]
S3 ViaC7;Ovladač procesoru VIA C7; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\DRIVERS\vmbus.sys [2009-07-14 175824]
S3 VMBusHID;VMBusHID; C:\Windows\system32\DRIVERS\VMBusHID.sys [2009-07-14 17920]
S4 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2009-07-14 387584]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-03-05 308064]
R2 FCSAM;Microsoft Forefront Client Security Antimalware Service; c:\Program Files\Microsoft Forefront\Client Security\Client\Antimalware\MsMpEng.exe [2009-09-03 16880]
R2 FcsSas;Microsoft Forefront Client Security State Assessment Service; c:\Program Files\Microsoft Forefront\Client Security\Client\SSA\FcsSas.exe [2009-10-22 69512]
R2 MOM;MOM; c:\Program Files\Microsoft Forefront\Client Security\Client\Microsoft Operations Manager 2005\MOMService.exe [2005-07-21 134656]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R2 VMTools;VMware Tools Service; C:\Program Files\VMware\VMware Tools\vmtoolsd.exe [2010-05-09 64048]
R2 VMUpgradeHelper;VMware Upgrade Helper; C:\Program Files\VMware\VMware Tools\VMUpgradeHelper.exe [2010-05-09 154160]
R2 WcesComm;@%windir%\WindowsMobile\wcescomm.dll,-40079; C:\Windows\system32\svchost.exe [2009-07-14 20992]
R3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-03-05 916760]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2009-06-10 31064]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 tpautoconnsvc;TP AutoConnect Service; C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe [2010-05-09 255304]
S3 TPVCGateway;TP VC Gateway Service; C:\Program Files\VMware\VMware Tools\TPVCGateway.exe [2010-05-09 365856]
S3 vmvss;VMware Snapshot Provider; C:\Windows\system32\dllhost.exe [2009-07-14 7168]
S4 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]

-----------------EOF-----------------

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 11 úno 2011 15:07
od Pulytr
Tak už jsem ho našel byl to klasickej Shell v registru a soubor.. bohuzel migroval s cestovnim profilem tak jsem se na nej nemohl dostat dokud jsem si nepripojil registry toho konkretniho uzivatele.
Pokud chce nekdo tuhle havet na rozobor, mohu zaslat... Kazdopadne AVG ani Microsoft ho nedetekoval

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 11 úno 2011 19:53
od motji
Dobrý večer :)
nebyl to tento viník?
alcasalcer.centrala.local\userdata\i.rysava\Data aplikací\aytsae.exe

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 12 úno 2011 09:43
od Pulytr
jj ten a jeste jeden wcinns.exe

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 12 úno 2011 14:28
od motji
A jste si jistý, že je to už čisté?

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 14 úno 2011 09:55
od Pulytr
No tak to si jist samozřejmě nejsem, každopádně po odstranění z registrů a samzání souborů je zase vše v pořádku. Do systému jako takového uživatel nic nezapíše. Jediné kam může uživatel zapisovat je jeho roaming profile registr a jeho appdata.
Pokud mohu ještě něco udělat, otestovat.. tak udělám ?

Re: Microsoft Security Essential Alert Trojan Windows 7

Napsal: 14 úno 2011 10:26
od motji
:arrow: Stahněte MBAM z mého podpisu
-Nainstalujte,dejte úplný sken

NIC NEMAZAT :!:
-MBAM má občas falešné detekce,proto budeme mazat až po kontrole logu.
-Log zkopírujte sem.