Infected by Trojan-Dropper.Win32.Injector.knn
Napsal: 20 říj 2011 22:35
Zdravím, prosím o pomoc.
Svou hloupostí jsem si do počítače pustil trojského koně otevřením podezřelého souboru, který jsem pak oscanoval na virustotal a ten ho určil jako "Trojan-Dropper.Win32.Injector.knn". Vše se tváří v pořádku, jen při otevírání jakýchkoliv stránek občas naskočí jiná stránka, která se tváří jako nějaký vyhledávač a na pozadí má různé graficky vydařené obrázky na téma Pharmacy, Furniture, nějaká auta, apod. No a samozřejmě jsou blokovány všechny antiviry. MS Security Essentials tvrdí, že je služba vypnutá a nejde pustit. NOD32 Antivirus 4 hlásí chybu při komunikaci s jádrem. Mbam tvrdí, že nemám práva pro spuštění a už ani online scan Esetu nejde, píše že už byl spuštěn nebo chybu 101.. odolná potvora.
Po nakažení jsem pustil onlinescan od esetu (tehdy to ještě šlo) a ten naše následující:
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Bonjour\mDNSResponder.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\iPod\bin\iPodService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\OEM\OSD_1.16\OsdService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Spyware Terminator\sp_rsser.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Users\Maver!ck\AppData\Local\Opera\Opera\cache\g_0054\opr00XNX.tmp varianta infiltrace Win32/Kryptik.UEU trojský kůň vyléčen smazáním - uložen do karantény
Chtěl jsem spravovat karanténu toho online scanu, ale program vypsal pracuji.. a nic. Tak jsem pustil online scan Symantecu, ten našel následující soubor, který jsem pak vymazal:
C:\Windows\System32\IoctlSvc.exe is infected with Trojan.Paccyn!inf
V nouzovém režimu to nebylo o moc lepší, jen NOD pustil nějaký test v DOSu, ale když jsem se vrátil, okno bylo zavřené a žádný výsledek. To dělal třeba i mbam když jsem pustil test. Chvíli scanoval a pak se najednou zavřel, to samé Spyware Terminator. Chtěl jsem pustit test z live CD, ale Reatogo mi nenaběhlo, jen Knoppix, kde jsem sice pustil online test Esetu, ale ten nic nenašel. Ono asi testovat partition s Vistama z Linuxu není nic moc.
============================================================
RSIT se taky z ničehonic vypnul a log asi nebude kompletní:
============================================================
Logfile of random's system information tool 1.09 (written by random/random)
Run by Maver!ck at 2011-10-20 23:30:23
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 2 GB (2%) free of 94 GB
Total RAM: 3032 MB (40% free)
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2753588128-4106196835-699413311-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2753588128-4106196835-699413311-1000UA.job
C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-06 1961240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-06 187672]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-05-22 6139904]
"ECDeject"=C:\PROGRA~1\ECDeject\CDeject.exe [2008-07-01 371208]
"FSCRecovery"=c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe [2008-06-18 268096]
"OSD"=C:\Program Files\OEM\OSD_1.16\osd.exe [2008-06-18 376832]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2008-06-02 563984]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-06-02 2184464]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2008-02-29 76304]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2007-09-28 75136]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-11-06 2216960]
"C:\Program Files\Free Video Zilla\FVZilla.exe"= []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-07-05 421888]
"ASUS Ai Charger"=C:\Program Files\ASUS\ASUS Ai Charger\AiChargerAP.exe [2010-05-10 465536]
"NSU_agent"=C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe [2011-08-11 169264]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe [2009-04-02 203416]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-06 488728]
"Google Update"=C:\Users\Maver!ck\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-27 136176]
"HotSwap! Applet"=C:\Users\Maver!ck\AppData\Local\Temp\Rar$EX00.073\32bit\HotSwap!.EXE [2009-11-10 107520]
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2009-05-28 90624]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-06-15 15141768]
""= []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Users\Maver!ck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.ACDV"=ACDV.dll
"msacm.sl_anet"=sl_anet.acm
"msacm.divxa32"=divxa32.acm
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.l3codec"=l3codecp.acm
"vidc.dvsd"=pdvcodec.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-10-20 23:30:24 ----D---- C:\Program Files\trend micro
2011-10-20 23:30:23 ----D---- C:\rsit
2011-10-20 21:11:23 ----ASH---- C:\hiberfil.sys
2011-10-20 20:16:48 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-10-20 20:16:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-10-20 20:16:44 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-10-20 20:10:34 ----D---- C:\Program Files\Microsoft Security Client
2011-10-20 15:55:50 ----A---- C:\Windows\ntbtlog.txt
2011-10-20 15:38:04 ----A---- C:\Windows\system32\devil.dll
2011-10-20 15:38:04 ----A---- C:\Windows\system32\avisynth.dll
2011-10-20 13:55:42 ----A---- C:\Windows\umcat_01.db
2011-10-19 22:52:00 ----D---- C:\Program Files\WinPcap
2011-10-19 22:40:40 ----D---- C:\Program Files\WMR14
2011-10-19 12:49:41 ----D---- C:\Program Files\iPod
2011-10-19 12:49:35 ----D---- C:\Program Files\iTunes
2011-10-19 12:37:51 ----D---- C:\Program Files\Bonjour
2011-10-12 12:43:30 ----A---- C:\Windows\system32\wininet.dll
2011-10-12 12:43:30 ----A---- C:\Windows\system32\urlmon.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\url.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\jsproxy.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\iertutil.dll
2011-10-12 12:43:28 ----A---- C:\Windows\system32\mshtml.dll
2011-10-12 12:43:27 ----A---- C:\Windows\system32\ieframe.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\occache.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\mstime.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\msfeeds.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\iedkcs32.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\mshtmled.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\msfeedssync.exe
2011-10-12 12:43:25 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\licmgr10.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ieUnatt.exe
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ieui.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iesysprep.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iesetup.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iernonce.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iepeers.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ie4uinit.exe
2011-10-12 12:42:34 ----A---- C:\Windows\system32\psisdecd.dll
2011-10-12 12:42:32 ----A---- C:\Windows\system32\win32k.sys
2011-10-12 12:42:23 ----A---- C:\Windows\system32\UIAutomationCore.dll
2011-10-12 12:42:23 ----A---- C:\Windows\system32\oleacc.dll
2011-10-12 12:42:22 ----A---- C:\Windows\system32\oleaut32.dll
2011-10-12 12:42:22 ----A---- C:\Windows\system32\oleaccrc.dll
2011-10-10 22:30:38 ----D---- C:\Program Files\ICQ7.6
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbser6k.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbnmea.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbmdm6k.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\massfilter.sys
2011-10-08 20:40:24 ----D---- C:\Program Files\ZTE
2011-10-07 22:00:21 ----D---- C:\Program Files\Wireshark
2011-10-07 21:58:37 ----D---- C:\Users\Maver!ck\AppData\Roaming\Wireshark
2011-10-05 16:40:47 ----A---- C:\Windows\Replay Converter Setup Log.txt
2011-10-05 16:30:42 ----D---- C:\Windows\Replay AV
2011-10-05 16:29:49 ----D---- C:\Program Files\Replay AV 8
2011-09-29 14:30:11 ----D---- C:\Users\Maver!ck\AppData\Roaming\Canon
2011-09-29 14:08:39 ----A---- C:\Windows\system32\CNMLM88.DLL
======List of files/folders modified in the last 1 month======
2011-10-20 23:30:24 ----RD---- C:\Program Files
2011-10-20 23:29:27 ----D---- C:\Windows\inf
2011-10-20 22:51:05 ----D---- C:\Users\Maver!ck\AppData\Roaming\Skype
2011-10-20 22:22:35 ----D---- C:\Windows\Temp
2011-10-20 22:22:28 ----D---- C:\Program Files\Spyware Terminator
2011-10-20 22:19:19 ----D---- C:\Windows\system32\drivers
2011-10-20 21:16:57 ----D---- C:\Users\Maver!ck\AppData\Roaming\Spyware Terminator
2011-10-20 20:31:41 ----D---- C:\Windows\system32\catroot
2011-10-20 20:17:49 ----D---- C:\Windows\Prefetch
2011-10-20 20:11:08 ----SHD---- C:\Windows\Installer
2011-10-20 20:11:08 ----SHD---- C:\Config.Msi
2011-10-20 20:10:54 ----D---- C:\Windows\System32
2011-10-20 20:10:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-10-20 19:59:31 ----D---- C:\Windows
2011-10-20 15:32:24 ----D---- C:\Users\Maver!ck\AppData\Roaming\Media Player Classic
2011-10-20 15:32:09 ----D---- C:\Users\Maver!ck\AppData\Roaming\vlc
2011-10-20 15:29:33 ----D---- C:\Program Files\Opera
2011-10-20 14:26:02 ----SD---- C:\Windows\Downloaded Program Files
2011-10-20 12:19:15 ----SHD---- C:\System Volume Information
2011-10-20 12:11:00 ----D---- C:\Windows\system32\drivers\etc
2011-10-20 00:32:35 ----A---- C:\Windows\NeroDigital.ini
2011-10-19 23:53:41 ----D---- C:\Windows\Microsoft.NET
2011-10-19 23:45:14 ----D---- C:\Windows\twain_32
2011-10-19 23:45:14 ----D---- C:\Windows\system32\catroot2
2011-10-19 23:43:43 ----HD---- C:\ProgramData
2011-10-19 23:30:38 ----D---- C:\Program Files\ESET
2011-10-19 22:46:21 ----D---- C:\Program Files\WMR11
2011-10-19 22:20:56 ----RSD---- C:\Windows\assembly
2011-10-19 12:56:51 ----D---- C:\Users\Maver!ck\AppData\Roaming\Apple Computer
2011-10-19 12:53:11 ----D---- C:\Program Files\Common Files\Apple
2011-10-19 12:14:51 ----D---- C:\ProgramData\Spyware Terminator
2011-10-14 23:29:20 ----D---- C:\Users\Maver!ck\AppData\Roaming\ICQ
2011-10-14 23:24:51 ----D---- C:\Windows\rescache
2011-10-13 13:14:31 ----D---- C:\Windows\winsxs
2011-10-13 12:57:12 ----D---- C:\Program Files\Microsoft Silverlight
2011-10-13 12:56:02 ----D---- C:\Windows\system32\migration
2011-10-13 12:56:02 ----D---- C:\Program Files\Windows Mail
2011-10-13 12:56:02 ----D---- C:\Program Files\Internet Explorer
2011-10-13 12:56:01 ----D---- C:\Windows\system32\cs-CZ
2011-10-13 12:34:23 ----D---- C:\Program Files\ABBYY FineReader 10
2011-10-13 11:34:46 ----A---- C:\Windows\system32\mrt.exe
2011-10-13 11:33:22 ----D---- C:\ProgramData\Microsoft Help
2011-10-10 22:31:41 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-08 20:46:48 ----D---- C:\Windows\ModemLogs
2011-10-05 16:41:37 ----D---- C:\Windows\Downloaded Installations
2011-10-02 15:47:59 ----D---- C:\Users\Maver!ck\AppData\Roaming\uTorrent
2011-09-29 14:13:30 ----RSD---- C:\Windows\Media
2011-09-23 23:42:21 ----SD---- C:\Users\Maver!ck\AppData\Roaming\Microsoft
Svou hloupostí jsem si do počítače pustil trojského koně otevřením podezřelého souboru, který jsem pak oscanoval na virustotal a ten ho určil jako "Trojan-Dropper.Win32.Injector.knn". Vše se tváří v pořádku, jen při otevírání jakýchkoliv stránek občas naskočí jiná stránka, která se tváří jako nějaký vyhledávač a na pozadí má různé graficky vydařené obrázky na téma Pharmacy, Furniture, nějaká auta, apod. No a samozřejmě jsou blokovány všechny antiviry. MS Security Essentials tvrdí, že je služba vypnutá a nejde pustit. NOD32 Antivirus 4 hlásí chybu při komunikaci s jádrem. Mbam tvrdí, že nemám práva pro spuštění a už ani online scan Esetu nejde, píše že už byl spuštěn nebo chybu 101.. odolná potvora.
Po nakažení jsem pustil onlinescan od esetu (tehdy to ještě šlo) a ten naše následující:
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Bonjour\mDNSResponder.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Fujitsu Siemens Computers\SystemDiagnostics\OnlineDiagnostic\TestManager\TestHandler.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\iPod\bin\iPodService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\OEM\OSD_1.16\OsdService.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Spyware Terminator\sp_rsser.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe Win32/Patched.HN trojský kůň vyléčen - uložen do karantény
C:\Users\Maver!ck\AppData\Local\Opera\Opera\cache\g_0054\opr00XNX.tmp varianta infiltrace Win32/Kryptik.UEU trojský kůň vyléčen smazáním - uložen do karantény
Chtěl jsem spravovat karanténu toho online scanu, ale program vypsal pracuji.. a nic. Tak jsem pustil online scan Symantecu, ten našel následující soubor, který jsem pak vymazal:
C:\Windows\System32\IoctlSvc.exe is infected with Trojan.Paccyn!inf
V nouzovém režimu to nebylo o moc lepší, jen NOD pustil nějaký test v DOSu, ale když jsem se vrátil, okno bylo zavřené a žádný výsledek. To dělal třeba i mbam když jsem pustil test. Chvíli scanoval a pak se najednou zavřel, to samé Spyware Terminator. Chtěl jsem pustit test z live CD, ale Reatogo mi nenaběhlo, jen Knoppix, kde jsem sice pustil online test Esetu, ale ten nic nenašel. Ono asi testovat partition s Vistama z Linuxu není nic moc.
============================================================
RSIT se taky z ničehonic vypnul a log asi nebude kompletní:
============================================================
Logfile of random's system information tool 1.09 (written by random/random)
Run by Maver!ck at 2011-10-20 23:30:23
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 2 GB (2%) free of 94 GB
Total RAM: 3032 MB (40% free)
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2753588128-4106196835-699413311-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2753588128-4106196835-699413311-1000UA.job
C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06 63912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-05-04 42272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA837F48-5AD1-443E-AE34-FFE03CBF3099}]
Lištička - C:\Program Files\Seznam.cz\listicka.dll [2010-10-06 1961240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{1EA00BE1-6E54-4E2A-8099-680300BF23E1} - Nástroje Lištičky - C:\Program Files\Seznam.cz\toolbar\toolbar.dll [2010-10-06 187672]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-05-22 6139904]
"ECDeject"=C:\PROGRA~1\ECDeject\CDeject.exe [2008-07-01 371208]
"FSCRecovery"=c:\Program Files\Fujitsu Siemens Computers\Fujitsu Siemens Computers Recovery\FSCRecoveryReminder.exe [2008-06-18 268096]
"OSD"=C:\Program Files\OEM\OSD_1.16\osd.exe [2008-06-18 376832]
"LogitechCommunicationsManager"=C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [2008-06-02 563984]
"LogitechQuickCamRibbon"=C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-06-02 2184464]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-12-06 1029416]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2008-02-29 76304]
"ITSecMng"=C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe [2007-09-28 75136]
"SpywareTerminator"=C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2010-11-06 2216960]
"C:\Program Files\Free Video Zilla\FVZilla.exe"= []
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2011-02-11 137752]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2011-02-11 171032]
"Persistence"=C:\Windows\system32\igfxpers.exe [2011-02-11 172568]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2011-04-08 254696]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2011-06-06 937920]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2011-07-05 421888]
"ASUS Ai Charger"=C:\Program Files\ASUS\ASUS Ai Charger\AiChargerAP.exe [2010-05-10 465536]
"NSU_agent"=C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe [2011-08-11 169264]
"NokiaMServer"=C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer /watchfiles startup []
"APSDaemon"=C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [2011-09-27 59240]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2011-10-09 421736]
"egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2010-08-12 2215064]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2011-06-15 997920]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2011-08-31 449608]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe [2009-04-02 203416]
"Seznam Postak"=C:\Program Files\Seznam.cz\postak.exe [2010-10-06 488728]
"Google Update"=C:\Users\Maver!ck\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-27 136176]
"HotSwap! Applet"=C:\Users\Maver!ck\AppData\Local\Temp\Rar$EX00.073\32bit\HotSwap!.EXE [2009-11-10 107520]
"ShowBatteryBar"=C:\Program Files\BatteryBar\ShowBatteryBar.exe [2009-05-28 90624]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2011-06-15 15141768]
""= []
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Users\Maver!ck\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2011-02-11 228864]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=lvcodec2.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"vidc.cvid"=iccvid.dll
"MSVideo"=vfwwdm32.dll
"MSVideo8"=VfWWDM32.dll
"VIDC.ACDV"=ACDV.dll
"msacm.sl_anet"=sl_anet.acm
"msacm.divxa32"=divxa32.acm
"vidc.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.l3codec"=l3codecp.acm
"vidc.dvsd"=pdvcodec.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2011-10-20 23:30:24 ----D---- C:\Program Files\trend micro
2011-10-20 23:30:23 ----D---- C:\rsit
2011-10-20 21:11:23 ----ASH---- C:\hiberfil.sys
2011-10-20 20:16:48 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2011-10-20 20:16:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2011-10-20 20:16:44 ----A---- C:\Windows\system32\drivers\mbam.sys
2011-10-20 20:10:34 ----D---- C:\Program Files\Microsoft Security Client
2011-10-20 15:55:50 ----A---- C:\Windows\ntbtlog.txt
2011-10-20 15:38:04 ----A---- C:\Windows\system32\devil.dll
2011-10-20 15:38:04 ----A---- C:\Windows\system32\avisynth.dll
2011-10-20 13:55:42 ----A---- C:\Windows\umcat_01.db
2011-10-19 22:52:00 ----D---- C:\Program Files\WinPcap
2011-10-19 22:40:40 ----D---- C:\Program Files\WMR14
2011-10-19 12:49:41 ----D---- C:\Program Files\iPod
2011-10-19 12:49:35 ----D---- C:\Program Files\iTunes
2011-10-19 12:37:51 ----D---- C:\Program Files\Bonjour
2011-10-12 12:43:30 ----A---- C:\Windows\system32\wininet.dll
2011-10-12 12:43:30 ----A---- C:\Windows\system32\urlmon.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\url.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\jsproxy.dll
2011-10-12 12:43:29 ----A---- C:\Windows\system32\iertutil.dll
2011-10-12 12:43:28 ----A---- C:\Windows\system32\mshtml.dll
2011-10-12 12:43:27 ----A---- C:\Windows\system32\ieframe.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\occache.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\mstime.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\msfeeds.dll
2011-10-12 12:43:26 ----A---- C:\Windows\system32\iedkcs32.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\mshtmled.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\msfeedssync.exe
2011-10-12 12:43:25 ----A---- C:\Windows\system32\msfeedsbs.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\licmgr10.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ieUnatt.exe
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ieui.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iesysprep.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iesetup.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iernonce.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\iepeers.dll
2011-10-12 12:43:25 ----A---- C:\Windows\system32\ie4uinit.exe
2011-10-12 12:42:34 ----A---- C:\Windows\system32\psisdecd.dll
2011-10-12 12:42:32 ----A---- C:\Windows\system32\win32k.sys
2011-10-12 12:42:23 ----A---- C:\Windows\system32\UIAutomationCore.dll
2011-10-12 12:42:23 ----A---- C:\Windows\system32\oleacc.dll
2011-10-12 12:42:22 ----A---- C:\Windows\system32\oleaut32.dll
2011-10-12 12:42:22 ----A---- C:\Windows\system32\oleaccrc.dll
2011-10-10 22:30:38 ----D---- C:\Program Files\ICQ7.6
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbser6k.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbnmea.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\ZTEusbmdm6k.sys
2011-10-08 20:40:50 ----A---- C:\Windows\system32\drivers\massfilter.sys
2011-10-08 20:40:24 ----D---- C:\Program Files\ZTE
2011-10-07 22:00:21 ----D---- C:\Program Files\Wireshark
2011-10-07 21:58:37 ----D---- C:\Users\Maver!ck\AppData\Roaming\Wireshark
2011-10-05 16:40:47 ----A---- C:\Windows\Replay Converter Setup Log.txt
2011-10-05 16:30:42 ----D---- C:\Windows\Replay AV
2011-10-05 16:29:49 ----D---- C:\Program Files\Replay AV 8
2011-09-29 14:30:11 ----D---- C:\Users\Maver!ck\AppData\Roaming\Canon
2011-09-29 14:08:39 ----A---- C:\Windows\system32\CNMLM88.DLL
======List of files/folders modified in the last 1 month======
2011-10-20 23:30:24 ----RD---- C:\Program Files
2011-10-20 23:29:27 ----D---- C:\Windows\inf
2011-10-20 22:51:05 ----D---- C:\Users\Maver!ck\AppData\Roaming\Skype
2011-10-20 22:22:35 ----D---- C:\Windows\Temp
2011-10-20 22:22:28 ----D---- C:\Program Files\Spyware Terminator
2011-10-20 22:19:19 ----D---- C:\Windows\system32\drivers
2011-10-20 21:16:57 ----D---- C:\Users\Maver!ck\AppData\Roaming\Spyware Terminator
2011-10-20 20:31:41 ----D---- C:\Windows\system32\catroot
2011-10-20 20:17:49 ----D---- C:\Windows\Prefetch
2011-10-20 20:11:08 ----SHD---- C:\Windows\Installer
2011-10-20 20:11:08 ----SHD---- C:\Config.Msi
2011-10-20 20:10:54 ----D---- C:\Windows\System32
2011-10-20 20:10:54 ----A---- C:\Windows\system32\PerfStringBackup.INI
2011-10-20 19:59:31 ----D---- C:\Windows
2011-10-20 15:32:24 ----D---- C:\Users\Maver!ck\AppData\Roaming\Media Player Classic
2011-10-20 15:32:09 ----D---- C:\Users\Maver!ck\AppData\Roaming\vlc
2011-10-20 15:29:33 ----D---- C:\Program Files\Opera
2011-10-20 14:26:02 ----SD---- C:\Windows\Downloaded Program Files
2011-10-20 12:19:15 ----SHD---- C:\System Volume Information
2011-10-20 12:11:00 ----D---- C:\Windows\system32\drivers\etc
2011-10-20 00:32:35 ----A---- C:\Windows\NeroDigital.ini
2011-10-19 23:53:41 ----D---- C:\Windows\Microsoft.NET
2011-10-19 23:45:14 ----D---- C:\Windows\twain_32
2011-10-19 23:45:14 ----D---- C:\Windows\system32\catroot2
2011-10-19 23:43:43 ----HD---- C:\ProgramData
2011-10-19 23:30:38 ----D---- C:\Program Files\ESET
2011-10-19 22:46:21 ----D---- C:\Program Files\WMR11
2011-10-19 22:20:56 ----RSD---- C:\Windows\assembly
2011-10-19 12:56:51 ----D---- C:\Users\Maver!ck\AppData\Roaming\Apple Computer
2011-10-19 12:53:11 ----D---- C:\Program Files\Common Files\Apple
2011-10-19 12:14:51 ----D---- C:\ProgramData\Spyware Terminator
2011-10-14 23:29:20 ----D---- C:\Users\Maver!ck\AppData\Roaming\ICQ
2011-10-14 23:24:51 ----D---- C:\Windows\rescache
2011-10-13 13:14:31 ----D---- C:\Windows\winsxs
2011-10-13 12:57:12 ----D---- C:\Program Files\Microsoft Silverlight
2011-10-13 12:56:02 ----D---- C:\Windows\system32\migration
2011-10-13 12:56:02 ----D---- C:\Program Files\Windows Mail
2011-10-13 12:56:02 ----D---- C:\Program Files\Internet Explorer
2011-10-13 12:56:01 ----D---- C:\Windows\system32\cs-CZ
2011-10-13 12:34:23 ----D---- C:\Program Files\ABBYY FineReader 10
2011-10-13 11:34:46 ----A---- C:\Windows\system32\mrt.exe
2011-10-13 11:33:22 ----D---- C:\ProgramData\Microsoft Help
2011-10-10 22:31:41 ----HD---- C:\Program Files\InstallShield Installation Information
2011-10-08 20:46:48 ----D---- C:\Windows\ModemLogs
2011-10-05 16:41:37 ----D---- C:\Windows\Downloaded Installations
2011-10-02 15:47:59 ----D---- C:\Users\Maver!ck\AppData\Roaming\uTorrent
2011-09-29 14:13:30 ----RSD---- C:\Windows\Media
2011-09-23 23:42:21 ----SD---- C:\Users\Maver!ck\AppData\Roaming\Microsoft