TR/Spy.Goldu.FT.1.A: jak to usunac?

Moj kolega ma problem. Mianowicie wskoczyl mu trojan TR/Spy.Goldu.FT.1.A i nie mozna go wywalic. Kilka razy probowal ale trojan sie odtwarzal. prosze powiedzcie

Skan EWIDO po update :slight_smile:

Weź od niego log z HijackThis i wklej go na forum :slight_smile:

to jak będzie to napisz, post kosz

Oto on

Logfile of HijackThis v1.99.1

Scan saved at 20:28:32, on 2006-05-05

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)



Running processes:


C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\D-Tools\daemon.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\Program Files\Gadu-Gadu\gg.exe

C:\Program Files\Winamp\Winamp.exe

C:\WINDOWS\System32\svchost.exe

C:\Documents and Settings\Kuba\Pulpit\HijackThis.exe

C:\Documents and Settings\Kuba\Pulpit\HijackThis.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE

C:\WINDOWS\notepad.exe

C:\Program Files\AntiVir PersonalEdition Classic\GUARDGUI.EXE




R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łšcza

O1 - Hosts: 216.180.250.106 www.halifax-online.co.uk

O1 - Hosts: 216.180.250.106 ibank.barclays.co.uk

O1 - Hosts: 216.180.250.106 online.lloydstsb.co.uk

O1 - Hosts: 216.180.250.106 online-business.lloydstsb.co.uk

O1 - Hosts: 216.180.250.106 www.ukpersonal.hsbc.co.uk

O1 - Hosts: 216.180.250.106 banesnet.banesto.es

O1 - Hosts: 216.180.250.106 extranet.banesto.es

O1 - Hosts: 216.180.250.106 ebanking.bccbrescia.it

O1 - Hosts: 216.180.250.106 www.bankofscotlandhalifax-online.co.uk

O1 - Hosts: 216.180.250.106 oi.cajamadrid.es

O1 - Hosts: 216.180.250.106 bancae.caixapenedes.com

O1 - Hosts: 216.180.250.106 banking.postbank.de

O1 - Hosts: 216.180.250.106 meine.deutsche-bank.de

O1 - Hosts: 216.180.250.106 myonlineaccounts2.abbeynational.co.uk

O1 - Hosts: 216.180.250.106 ibank.cahoot.com

O1 - Hosts: 216.180.250.106 webbank.openplan.co.uk

O1 - Hosts: 216.180.250.106 bancopostaonline.poste.it

O1 - Hosts: 216.180.250.106 mybank.bybank.it

O1 - Hosts: 216.180.250.106 ibank.internationalbanking.barclays.com

O1 - Hosts: 216.180.250.106 welcome7.co-operativebank.co.uk

O1 - Hosts: 216.180.250.106 welcome11.co-operativebankonline.co.uk

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1045 -lock

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Microsoft IIS] C:\WINDOWS\System32]00xstmp.exe

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

O20 - Winlogon Notify: printpnp - C:\WINDOWS\SYSTEM32\printpnp.dll

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

=======================================

Log jest rozwalony, pozwoliłem sobie go poprawić

Pozdrawaim kuz5

W trybie awaryjnym z wyłącząnym przywracaniem systemu usuwasz (wpisy Hijackiem, pliki/foldery na czerwono ręcznie z dysku (w razie problemów z usuwaniem plików użyj narzędzia KillBox ):

Po zabiegach nowy log z Hijacka + log z Silent Runners