Dziś po robocie zastałem niespodziankę w postacie kwarantanny w mbam z backdorem o nazwie Backdoor. Xyligan
DO objaw należą: brak polskich znaków (brak było polskiego języka, ale ani polski ani angielski nie mogą się załadować), wyłączenie usługi Pomoc i Obsługa Techniczna i blokada komputera (nie ukaszek) opis jest w poście http://searchengines.pl/topic/24311-windows-xp-zablokowanie-komputera/ hasła brak wiec mogę normalnie wchodzić, logowanie trochę przypomina logowanie w szkole na zasadzie domeny, ale bez hasła wic wchodzić można.
grzebałem w rejestrze i nie ma tego pliku dll, o którym mowa w temacie
Z logu ochronnego mbam wklejam listę infekcji/bogów z godzin 15:53:14 - 16:36:28
DETECTION C:\Program Files\Google\Update\1.3.22.5\GoogleCrashHandler.exe Backdoor.Xyligan QUARANTINE
DETECTION D:\Program Files\Malwarebytes Anti-Malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
DETECTION c:\program files\google\update\1.3.22.5\googlecrashhandler.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\mswsock.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: DeleteFile failed with error code 5
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\mstask.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION c:\windows\system32\mstask.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\mstask.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\dciman32.dll Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION c:\windows\system32\dciman32.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\dciman32.dll Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\wuaueng.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\mswsock.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: DeleteFile failed with error code 5
DETECTION c:\windows\system32\wuaueng.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\wuaueng.dll Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\logonui.exe Backdoor.Xyligan QUARANTINE
DETECTION c:\windows\system32\logonui.exe Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\logonui.exe Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\wscntfy.exe Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\cryptnet.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\es.dll Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: DeleteFile failed with error code 5
DETECTION c:\windows\system32\wscntfy.exe Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\wscntfy.exe Backdoor.Xyligan QUARANTINE
DETECTION c:\windows\system32\cryptnet.dll Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\dllcache\cryptnet.dll Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\rasapi32.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: DeleteFile failed with error code 5
ERROR Quarantine failed: SDKQuarantine failed with error code 2
DETECTION C:\WINDOWS\system32\kbdpl1.dll Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\kbdus.dll Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\kbdpl.dll Backdoor.Xyligan QUARANTINE
DETECTION d:\program files\malwarebytes anti-malware 1.75.0.1300\mbampt.exe Backdoor.Xyligan QUARANTINE
DETECTION C:\WINDOWS\system32\wuapi.dll Backdoor.Xyligan QUARANTINE
ERROR Quarantine failed: SDKQuarantine failed with error code 2
OTL
MBAM
//rano