Apua! Win32 palasi taas.

Discussion in 'Virukset ja haittaohjelmat' started by Pattari, May 16, 2009.

  1. Pattari

    Pattari Member

    Joined:
    Aug 27, 2006
    Messages:
    9
    Likes Received:
    0
    Trophy Points:
    11
    Mitä ihmettä minun täytyy tF-secure herjaa koko ajan löytävännsä haitallista koodia Win32 kansioista?
    O1 - Hosts: 82.98.231.89 url.adtrgt.com Tämä tiedosto pitäisi poistaa mutta se ei onnistu Hijackthisin fixe files toiminnolla. Samoin kaikki muukin jonka se ilmoittaa vaaralliseksi. Näin F-secure sanoo parin minuutin välein:
    Haitallista koodia on löytynyt tiedostosta I:\WINDOWS\system32\repozuyi.dll.
    Tartunta: Packed.Win32.Krap.q
    Toiminto: Epäonnistui.

    Tässä vielä Hijackrhis logi:
    I:\WINDOWS\System32\smss.exe
    I:\WINDOWS\system32\winlogon.exe
    I:\WINDOWS\system32\services.exe
    I:\WINDOWS\system32\lsass.exe
    I:\WINDOWS\system32\Ati2evxx.exe
    I:\WINDOWS\system32\svchost.exe
    I:\WINDOWS\System32\svchost.exe
    I:\WINDOWS\system32\Ati2evxx.exe
    I:\WINDOWS\system32\spoolsv.exe
    I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    I:\Program Files\Bonjour\mDNSResponder.exe
    I:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    I:\Program Files\F-Secure\Common\FSMA32.EXE
    I:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
    I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    I:\Program Files\F-Secure\Common\FSMB32.EXE
    T:\Omat tiedostot\Alcohol120\Alcohol 120\StarWind\StarWindServiceAE.exe
    I:\WINDOWS\system32\svchost.exe
    I:\Program Files\F-Secure\Common\FCH32.EXE
    I:\Program Files\F-Secure\Common\FAMEH32.EXE
    I:\Program Files\F-Secure\Anti-Virus\fsqh.exe
    I:\Program Files\F-Secure\Common\FNRB32.EXE
    I:\Program Files\F-Secure\Anti-Virus\fssm32.exe
    I:\Program Files\F-Secure\Common\FIH32.EXE
    I:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    I:\Program Files\F-Secure\Anti-Virus\fsav32.exe
    I:\WINDOWS\Explorer.EXE
    I:\Program Files\F-Secure\Common\FSM32.EXE
    I:\WINDOWS\RTHDCPL.EXE
    I:\Program Files\F-Secure\FSGUI\fsguidll.exe
    I:\WINDOWS\system32\atwtusb.exe
    I:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    I:\WINDOWS\system32\LVCOMSX.EXE
    I:\Program Files\Logitech\Video\LogiTray.exe
    I:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    I:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
    I:\WINDOWS\V0230Mon.exe
    I:\Program Files\Creative\Shared Files\CTSched.exe
    I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    I:\WINDOWS\system32\ctfmon.exe
    I:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    I:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
    I:\Program Files\Logitech\Video\FxSvr2.exe
    I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    I:\Program Files\Logitech\SetPoint\SetPoint.exe
    I:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
    I:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    I:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    I:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bsplayer-search.com/startpage
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O2 - BHO: Adobe PDF Reader -linkkiavustaja - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - I:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {5f69512c-1778-4f9e-8094-04babdabf6d1} - I:\WINDOWS\system32\jewipaje.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - I:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - I:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - I:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [F-Secure Manager] "I:\Program Files\F-Secure\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] "I:\Program Files\F-Secure\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
    O4 - HKLM\..\Run: [HP Software Update] I:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [LVCOMSX] I:\WINDOWS\system32\LVCOMSX.EXE
    O4 - HKLM\..\Run: [LogitechVideoRepair] I:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] I:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [LVCOMS] I:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
    O4 - HKLM\..\Run: [AVFX Engine] I:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
    O4 - HKLM\..\Run: [V0230Mon.exe] I:\WINDOWS\V0230Mon.exe
    O4 - HKLM\..\Run: [CreativeTaskScheduler] "I:\Program Files\Creative\Shared Files\CTSched.exe" /logon
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "I:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [CloneCDTray] "I:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
    O4 - HKLM\..\Run: [ATICCC] "I:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [dubiwaniye] Rundll32.exe "I:\WINDOWS\system32\kapihiwo.dll",s
    O4 - HKLM\..\Run: [000000af] rundll32.exe "I:\WINDOWS\system32\lenosopo.dll",b
    O4 - HKLM\..\Run: [CPMabe29d56] Rundll32.exe "i:\windows\system32\repozuyi.dll",a
    O4 - HKCU\..\Run: [ctfmon.exe] I:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "T:\Omat tiedostot\Alcohol120\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "I:\Program Files\Logitech\Video\ManifestEngine.exe" boot
    O4 - HKCU\..\Run: [Advanced SystemCare 3] "I:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Paikallinen palve')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Verkkopalve')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] I:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: OneNote 2007 -näyttöleikkeet ja Launcher.lnk = I:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = I:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = I:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
    O4 - Global Startup: Logitech SetPoint.lnk = I:\Program Files\Logitech\SetPoint\SetPoint.exe
    O8 - Extra context menu item: V&ie Microsoft Exceliin - res://I:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - I:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Lähetä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: Läh&etä OneNoteen - {2670000A-7350-4f3c-8081-5663EE0C6C49} - I:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - I:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - I:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - I:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15107/CTPID.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - I:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - I:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - AppInit_DLLs: i:\windows\system32\repozuyi.dll,I:\WINDOWS\system32\bebuheku.dll
    O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - i:\windows\system32\repozuyi.dll
    O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - i:\windows\system32\repozuyi.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - I:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - I:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Bonjour-palvelu (Bonjour Service) - Apple Inc. - I:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - I:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - I:\Program Files\F-Secure\Common\FNRB32.EXE
    O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - I:\Program Files\F-Secure\FSAUA\program\fsaua.exe
    O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - I:\Program Files\F-Secure\Common\FSMA32.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - I:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - I:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod-palvelu (iPod Service) - Apple Inc. - I:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - I:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - I:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - I:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - I:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ServiceLayer - Nokia. - I:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O23 - Service: SonicStage Back-End Service - Sony Corporation - I:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - I:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - I:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - T:\Omat tiedostot\Alcohol120\Alcohol 120\StarWind\StarWindServiceAE.exe
     
  2. 79atanos

    79atanos Regular member

    Joined:
    May 19, 2008
    Messages:
    1,945
    Likes Received:
    15
    Trophy Points:
    48
    Tuosta logista löytyy useita muitakin merkkejä tartunnoista.

    http://www.virustorjunta.net/modules.php?name=Forums

    Rekisteröidy tuonne ja laita logisi sinne HjT-osioon tutkittavaksi, meillä ei ole täällä Afterdawnissa fiksaajia näkynyt pitkään aikaan, ja fiksaajia tässä tapauksissa tarvitaankin, nuo kun eivät ihan millä tahansa ohjelmilla lähde mihinkään.

    Btw, ei niitä hosts-tiedoston rivejä HjT:lla poistella, vaan sinun täytyy sieltä tiedostosta ne haluamasi rivit käydä poistamassa itse, fiksaaja opastaa kyllä tarvittaessa jos siinä ilmenee jotain ongelmia (esim. saat ilmoituksen puuttuvista oikeuksista yms).

    Ja laita sinne vt.nettiin myös ihan kokonainen logi, tuosta puuttuu yläosa, josta ilmenee käyttis ja sen päivitysversio yms.
     

Share This Page