-
Проблем с TR/Chydo.UX
ComboFix 09-12-21.04 - Administrator 22.12.2009 9:46.3.2 - x86 Microsoft Windows 2000 Professional 5.0.2195.4.1251.359.1033.18.503.384 [GMT 2:00] Running from: c:\documents and settings\Administrator\Desktop\Tool.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . -- Previous Run -- c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\comres.dll . . . is infected!! -- Previous Run -- c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\comres.dll . . . is infected!! -------- c:\winnt\system32\qmgr.dll . . . is infected!! -- Previous Run -- c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\comres.dll . . . is infected!! -------- c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\comres.dll . . . is infected!! -------- c:\winnt\system32\qmgr.dll . . . is infected!! c:\winnt\system32\comres.dll . . . is infected!! . ((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 ))))))))))))))))))))))))))))))) . 2009-12-16 12:35 . 2009-12-16 12:35 -------- d-----w- c:\documents and settings\operator\Application Data\.clamwin 2009-12-16 12:33 . 2009-12-16 12:33 -------- d-----w- c:\documents and settings\Administrator\Application Data\.clamwin 2009-12-16 12:32 . 2009-12-16 12:32 -------- d-----w- c:\program files\ClamWin 2009-12-16 12:32 . 2009-12-16 12:32 -------- d-----w- c:\documents and settings\All Users\.clamwin 2009-12-16 12:23 . 2009-12-16 12:23 -------- d-----w- c:\winnt\system32\Windows Media 2009-12-16 12:23 . 2009-12-16 12:23 -------- dc-h--w- c:\winnt\$NtUpdateRollupPackUninstall$ 2009-12-16 12:23 . 2009-12-16 12:29 -------- d-----w- c:\winnt\msiinst.tmp . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-16 12:34 . 2008-02-26 23:36 -------- d-----w- c:\program files\Common Files\InstallShield 2009-11-13 12:22 . 2009-11-13 12:22 0 ----a-w- c:\winnt\nsreg.dat 2008-02-26 23:30 . 2008-02-26 23:30 21952 ---h--w- c:\program files\folder.htt . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "internat.exe"="internat.exe" [2003-06-20 20752] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Synchronization Manager"="mobsync.exe" [2003-06-20 111376] "IgfxTray"="c:\winnt\system32\igfxtray.exe" [2006-10-05 98304] "HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2006-10-05 114688] "Persistence"="c:\winnt\system32\igfxpers.exe" [2006-10-05 94208] "SkyTel"="SkyTel.EXE" [2007-04-04 1822720] "RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464] "DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-23 81920] "WPMon"="c:\winnt\system32\wpmon.exe" [2005-05-13 1548800] "TrueImageMonitor.exe"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2005-12-27 988736] "Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2005-12-27 118784] "ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-11-03 86016] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "internat.exe"="internat.exe" [2003-06-20 20752] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "^SetupICWDesktop"="c:\program files\Internet Explorer\Connection Wizard\icwconn1.exe" [2003-06-20 186640] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360] Program Neighborhood Agent.lnk - c:\program files\Citrix\ICA Client\pnagent.exe [2005-11-29 233744] R0 d347bus;d347bus;c:\winnt\system32\drivers\d347bus.sys [26.2.2008 г. 15:47 155136] R0 d347prt;d347prt;c:\winnt\system32\drivers\d347prt.sys [26.2.2008 г. 15:47 5248] R3 usbhub20;USB 2.0 Root Hub Support;c:\winnt\system32\drivers\usbhub20.sys [26.2.2008 г. 17:21 49776] . ------- Supplementary Scan ------- . IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm LSP: %SystemRoot%\system32\msafd.dll TCP: {7FEB8B95-992F-4A1C-B728-3A621BE7BDCC} = 192.168.11.3 FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-12-22 09:49 Windows 5.0.2195 Service Pack 4 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net device: opened successfully user: MBR read successfully called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x81CF0E88]<< kernel: MBR read successfully detected MBR rootkit hooks: \Driver\Disk -> CLASSPNP.SYS @ 0xeb422ac3 \Driver\ACPI -> ACPI.sys @ 0xbffb8554 \Driver\atapi -> 0x81cf0e88 IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x804c4f34 ParseProcedure -> ntoskrnl.exe @ 0x804c3860 \Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x804c4f34 ParseProcedure -> ntoskrnl.exe @ 0x804c3860 Warning: possible MBR rootkit infection ! user & kernel MBR OK ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(324) c:\winnt\system32\wzcdlg.dll c:\winnt\system32\WZCSAPI.DLL - - - - - - - > 'lsass.exe'(364) c:\winnt\system32\relog_ap.dll - - - - - - - > 'explorer.exe'(1264) c:\winnt\AppPatch\AcLayers.DLL c:\winnt\system32\MSI.DLL . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Acronis\Schedule2\schedul2.exe c:\winnt\system32\hidserv.exe c:\winnt\system32\regsvc.exe c:\winnt\system32\MSTask.exe c:\winnt\System32\WBEM\WinMgmt.exe c:\winnt\RTHDCPL.EXE c:\winnt\system32\internat.exe c:\winnt\System32\SCardSvr.exe . ************************************************************************** . Completion time: 2009-12-22 09:50:18 - machine was rebooted ComboFix-quarantined-files.txt 2009-12-22 07:50 Pre-Run: 21 664 034 816 bytes free Post-Run: 21 647 278 080 bytes free - - End Of File - - 0C79CBBB34C6754E049D25F6CB7BDBC4 това е след скана.
-
Проблем с TR/Chydo.UX
Здравейте, Имам удоволствието да имам в системата си този хубав нов троянски кон. Става дума за няколко компютъра в домайн вси1ки са с опрационна система windows 2000 i 2000 server съответно. Кратко описание: създава фаилове във почти всички директории с разширение *.bat, *.exe, *.scr i *.pif. Стартира се при логване и прави сривове в системата. Обикновенно обивам процеса и майката с process explorer на sysinternals. Но естествено той пак се активира след време. Може ли да ми съдействате да го махна?
Разглеждащи това в момента 0
- Няма регистрирани потребители разглеждащи тази страница.