Trojan ASFWhide, jak usunąć?


(Mister Wojtek) #1

Witam!

Mam taki problem, że Avast znalazł trojana i nie może go usunąć ani nic z nim zrobić. Przeskanowałem jeszcze przy pomocy MKS Online i jest ta sama sytuacja. Natomiast Antivir nie widzi w ogóle tego trojana, a Skaner MKS wykrył jeszcze coś takiego jak: trojan killproc, o ile dobrze pamiętam.

Wklejam logi:

HijackThis:

Logfile of HijackThis v1.99.1

Scan saved at 18:10:41, on 2007-05-04

Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)

age = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [Ashampoo FireWall] "C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [AutoConnect] C:\Program Files\AutoConnect\AutoConnect.exe

O4 - HKCU\..\Run: [Gadu-Gadu] "C:\Program Files\Gadu-Gadu\gg.exe" /tray

O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O10 - Unknown file in Winsock LSP: c:\program files\ashampoo\ashampoo firewall\spi.dll

O11 - Options group: [INTERNATIONAL] International*

O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{0B14231D-EE9E-4FCB-B379-8299BF1A16E0}: NameServer = 194.204.159.1 217.98.63.164

O17 - HKLM\System\CS1\Services\Tcpip\..\{0B14231D-EE9E-4FCB-B379-8299BF1A16E0}: NameServer = 194.204.159.1 217.98.63.164

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing)

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Silent Runners:

"Silent Runners.vbs", revision R50, http://www.silentrunners.org/

Operating System: Windows XP SP2

Output limited to non-default values, except where indicated by "{++}"



Startup items buried in registry:

---------------------------------


HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"AutoConnect" = "C:\Program Files\AutoConnect\AutoConnect.exe" ["http://autoconnect.prv.pl"]

"Gadu-Gadu" = ""C:\Program Files\Gadu-Gadu\gg.exe" /tray" ["Gadu-Gadu S.A."]

"Steam" = "(empty string)" [file not found]

"BitComet" = ""C:\Program Files\BitComet\BitComet.exe"" ["www.BitComet.com"]

"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}

"CTHelper" = "CTHELPER.EXE" ["Creative Technology Ltd"]

"RegistryMechanic" = "(empty string)" [file not found]

"Ashampoo FireWall" = ""C:\Program Files\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY" [null data]

"avgnt" = ""C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min" ["Avira GmbH"]


HKLM\Software\Microsoft\Active Setup\Installed Components\

>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"

                                        \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]


HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)

  -> {HKLM...CLSID} = "SSVHelper Class"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll" ["Sun Microsystems, Inc."]


HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\

"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania wyświetlania"

  -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"

                   \InProcServer32\(Default) = "deskpan.dll" [file not found]

"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"

  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]

"{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"

  -> {HKLM...CLSID} = "Portable Media Devices Menu"

                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]

"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]

"{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"

  -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"

                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]

"{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"

  -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"

                   \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]

"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

"{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"

  -> {HKLM...CLSID} = "Haali Column Provider"

                   \InProcServer32\(Default) = "C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll" [null data]

"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"

  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"

                   \InProcServer32\(Default) = "C:\Program Files\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]


HKLM\Software\Classes\PROTOCOLS\Filter\

<> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"

  -> {HKLM...CLSID} = (no title provided)

                   \InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]


HKLM\Software\Classes\Folder\shellex\ColumnHandlers\

{0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"

  -> {HKLM...CLSID} = "Haali Column Provider"

                   \InProcServer32\(Default) = "C:\Program Files\Haali\MatroskaSplitter\mmfinfo.dll" [null data]

{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"

  -> {HKLM...CLSID} = "PDF Shell Extension"

                   \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]


HKLM\Software\Classes\*\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"

  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"

                   \InProcServer32\(Default) = "C:\Program Files\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\

avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"

  -> {HKLM...CLSID} = "avast"

                   \InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

FineReader8\(Default) = "{F7091C74-EBB1-49D7-94C7-FE4886CCC18D}"

  -> {HKLM...CLSID} = "FineReader8ExplorerContextMenuHandler"

                   \InProcServer32\(Default) = "C:\Program Files\ABBYY FineReader 8.0 Professional Edition\FECMenu.dll" ["ABBYY Software"]

Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"

  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"

                   \InProcServer32\(Default) = "C:\Program Files\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]

WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"

  -> {HKLM...CLSID} = "WinRAR"

                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]



Group Policies {GPedit.msc branch and setting}:

-----------------------------------------------


Note: detected settings may not have any effect.


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"NoWindowsUpdate" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Start Menu and Taskbar|

Remove links and access to Windows Update}


"NoRecentDocsMenu" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"NoFavoritesMenu" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Start Menu and Taskbar|

Remove Favorites menu from Start Menu}


"NoSMMyPictures" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Start Menu and Taskbar|

Remove My Pictures icon from Start Menu}


"NoStartMenuMyMusic" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoRecentDocsHistory" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"ClearRecentDocsOnExit" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"NoRecentDocsNetHood" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoRun" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoUserNameInStartMenu" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoInstrumentation" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoStartMenuPinnedList" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"ForceStartMenuLogoff" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoSMMyDocs" = (REG_DWORD) hex:0x00000001

{User Configuration|Administrative Templates|Start Menu and Taskbar|

Remove Documents menu from Start Menu}


"NoSharedDocuments" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Windows Components|Windows Explorer|

Remove Shared Documents from My Computer}


"NoSMHelp" = (REG_DWORD) hex:0x00000001

{User Configuration|Administrative Templates|Start Menu and Taskbar|

Remove Help menu from Start Menu}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\


"NoRecentDocsMenu" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"NoFavoritesMenu" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoSMMyPictures" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoStartMenuMyMusic" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoRecentDocsHistory" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"NoRecentDocsNetHood" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoRun" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoInstrumentation" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoSimpleStartMenu" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


"NoSMMyDocs" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


"NoSMHelp" = (REG_DWORD) hex:0x00000001

{unrecognized setting}


HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\WindowsUpdate\


"DisableWindowsUpdateAccess" = (REG_DWORD) hex:0x00000000

{User Configuration|Administrative Templates|Windows Components|Windows Update|

Remove access to use all Windows Update features}


HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\


"NoUpdateCheck" = (REG_DWORD) hex:0x00000000

{unrecognized setting}


HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\


"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Shutdown: Allow system to be shut down without having to log on}


"undockwithoutlogon" = (REG_DWORD) hex:0x00000001

{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|

Devices: Allow undock without having to log on}



Active Desktop and Wallpaper:

-----------------------------


Active Desktop may be disabled at this entry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState


Displayed if Active Desktop enabled and wallpaper not set by Group Policy:

HKCU\Software\Microsoft\Internet Explorer\Desktop\General\

"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"


Displayed if Active Desktop disabled and wallpaper not set by Group Policy:

HKCU\Control Panel\Desktop\

"Wallpaper" = "C:\Documents and Settings\wojtek\Ustawienia lokalne\Dane aplikacji\Microsoft\Wallpaper1.bmp"



Enabled Screen Saver:

---------------------


HKCU\Control Panel\Desktop\

"SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]



Winsock2 Service Provider DLLs:

-------------------------------


Namespace Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}

000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

000000000004\LibraryPath = "C:\Program Files\Bonjour\mdnsNSP.dll" ["Apple Computer, Inc."]


Transport Service Providers


HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}

0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:

C:\Program Files\Ashampoo\Ashampoo FireWall\spi.dll [null data], 01 - 05, 16

%SystemRoot%\system32\mswsock.dll [MS], 06 - 15, 17 - 19

%SystemRoot%\system32\rsvpsp.dll [MS], 20 - 21



Toolbars, Explorer Bars, Extensions:

------------------------------------


Explorer Bars


HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\


HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Badanie"

Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]

InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]


Extensions (Tools menu items, main toolbar menu buttons)


HKLM\Software\Microsoft\Internet Explorer\Extensions\

{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\

"MenuText" = "Sun Java Console"

"CLSIDExtension" = "{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}"

  -> {HKCU...CLSID} = "Java Plug-in 1.5.0_10"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll" ["Sun Microsystems, Inc."]

  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_10"

                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll" ["Sun Microsystems, Inc."]


{92780B25-18CC-41C8-B9BE-3C9C571A8263}\

"ButtonText" = "Badanie"



Running Services (Display Name, Service Name, Path {Service DLL}):

------------------------------------------------------------------


##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##, Bonjour Service, ""C:\Program Files\Bonjour\mDNSResponder.exe"" ["Apple Computer, Inc."]

AntiVir PersonalEdition Classic Guard, AntiVirService, ""C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe"" ["Avira GmbH"]

AntiVir PersonalEdition Classic Scheduler, AntiVirScheduler, ""C:\Program Files\AntiVir PersonalEdition Classic\sched.exe"" ["Avira GmbH"]

Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]



Print Monitors:

---------------


HKLM\System\CurrentControlSet\Control\Print\Monitors\

Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]



----------

<>: Suspicious data at a malware launch point.


+ This report excludes default entries except where indicated.

+ To see *everywhere* the script checks and *everything* it finds,

  launch it from a command prompt or a shortcut with the -all parameter.

+ The search for DESKTOP.INI DLL launch points on all local fixed drives

  took 101 seconds.

---------- (total run time: 178 seconds)

Proszę o pomoc w usunięciu trojanów. Z góry dzięki!


(Kubusiek71) #2

Wyłącz przywracanie systemu i uruchom kompa w trybie awaryjnym i spróbuj avastem wtedy usunąć.Jeżeli nie da rady,to zapisz ścieżkę dostępu tego trojana i może się go da ręcznie usunąć w trybie awaryjnym.Jeżeli chciałbyś to zrobić MKSem online to musisz kompa uruchomić w trybie awaryjnym z obsł. sieci.


(adam9870) #3

Oba logi czyste.

Dobrze, ale gdzie zostały wykryte te trojany, o których wspomniałeś? Proszę podać dokładne lokalizacje do znajdowanych zainfekowanych plików.

Przeskanuj system tym skanerem on-line:

i wklej raport plus log numer 1 z L2Mfix.


(Mister Wojtek) #4

Właśnie usunąłem ten plik ASFWhide w trybie awaryjnym.. ale znów powrócił w to samo miejsce.

Znajduje się on: C:\Documents and Settings\wojtek\Ustawienia lokalne\Temp\ASFWhide i na drugim koncie: C:\Documents and Settings\inni\Ustawienia lokalne\Temp\ASFWhide.

Już się zabieram za skanowanie tym linkiem co podałeś..


(Gutek) #5

Logi Ok, tylko ciasteczka :wink:


(Mister Wojtek) #6

C:...ckup\DOCUME~1\wojtek\USTAWI~1\Temp\ASFWHide

to niebezpieczny program (trojan) :

Trojan.Agent.En

Zaleca się skasowanie pliku

C:... Settings\wojtek\Ustawienia lokalne\Temp\ASFWHide

to niebezpieczny program (trojan) :

Trojan.Agent.En

Zaleca się skasowanie pliku

to znalazł MKS.. i

tu też znalazł

C:...uments and Settings\wojtek\Pulpit\l2mfix\restart.exe

to niebezpieczny program (trojan) :

Trojan.Shutdown

Zaleca się skasowanie pliku

:x :shock: ale dało się usunąć.

a ten ASFWhide dalej tam siedzi :frowning:


(Gutek) #7

a to usniesz zawsze - ATF-Cleaner - http://www.atribune.org/ccount/click.php?id=1

błąd to ok plik :wink:


(Mister Wojtek) #8

usunął.. ale to znowu wraca :?


(Gutek) #9

Daj log z Combofix - http://download.bleepingcomputer.com/sUBs/ComboFix.exe


(Mirfi2) #10

z

http://forum.avira.de/print.php?threadi ... 61bb148675

z

http://spywarefiles.prevx.com/RRFDAH245 ... Whide.html


(Mister Wojtek) #11

wklejam log z combofix:


(Gutek) #12

usuń pliki zaznaczone na czerwono

a po co usuwałeś antywirusowy soft???????


(Mirfi2) #13

jak masz jeszcze ten plik to sprawdż

http://www.virustotal.com/en/indexf.html

ale na forach uważają ,że błędny alarm .


(Mister Wojtek) #14

usunąłem avasta bo wkurzał z tymi komunikatami, i net nie działał przez to:shock: teraz mam Avira Antivir.. ale on nie widzi tam trojana...


(Gutek) #15

M_i_r nie mieszaj ATF-Cleaner poleciłem ogólnie ten plik ASFWHide wróci, ponieważ masz Ashampoo FireWall i avast. Avast blokuje Ashampoo. Tym się nie przejmuj :wink:


(Mister Wojtek) #16

Przeskanowałem:

Complete scanning result of "ASFWHide", received in VirusTotal at 05.05.2007, 11:33:52 (CET).


Antivirus Version Update Result 

AhnLab-V3 2007.5.4.0 05.04.2007 no virus found 

AntiVir 7.4.0.15 05.05.2007 no virus found 

Authentium 4.93.8 05.04.2007 no virus found 

Avast 4.7.997.0 05.05.2007 no virus found 

AVG 7.5.0.467 05.04.2007 Generic3.ABKK 

BitDefender 7.2 05.05.2007 no virus found 

CAT-QuickHeal 9.00 05.04.2007 no virus found 

ClamAV devel-20070416 05.05.2007 no virus found 

DrWeb 4.33 05.04.2007 no virus found 

eSafe 7.0.15.0 05.03.2007 no virus found 

eTrust-Vet 30.7.3614 05.04.2007 no virus found 

Ewido 4.0 05.05.2007 no virus found 

FileAdvisor 1 05.05.2007 no virus found 

Fortinet 2.85.0.0 05.05.2007 RKProc!tr 

F-Prot 4.3.2.48 05.04.2007 no virus found 

F-Secure 6.70.13030.0 05.05.2007 no virus found 

Ikarus T3.1.1.7 05.05.2007 no virus found 

Kaspersky 4.0.2.24 05.05.2007 no virus found 

McAfee 5024 05.04.2007 New Malware.z 

Microsoft 1.2503 05.05.2007 no virus found 

NOD32v2 2242 05.05.2007 no virus found 

Norman 5.80.02 05.04.2007 no virus found 

Panda 9.0.0.4 05.04.2007 no virus found 

Prevx1 V2 05.05.2007 no virus found 

Sophos 4.17.0 05.04.2007 Ashampoo Firewall Stealthing Component 

Sunbelt 2.2.907.0 05.05.2007 no virus found 

Symantec 10 05.05.2007 no virus found 

TheHacker 6.1.6.104 04.15.2007 no virus found 

VBA32 3.11.4 05.04.2007 no virus found 

VirusBuster 4.3.7:9 05.04.2007 no virus found 

Webwasher-Gateway 6.0.1 05.05.2007 no virus found 



Aditional Information 

File size: 4096 bytes 

MD5: f8c718dc4299002d495a9da30a7c6ef1 

SHA1: 019a49fad3d36132674fa7ad7ec9f0719c80b217

Sophos dał ciekawy wynik: Ashampoo Firewall Stealthing Component :shock:


(Gutek) #17

Przecież napisałem, że to od Ashampoo :wink:


(Mister Wojtek) #18

Czyli wszystko jest już OK, tak? :wink:


(Gutek) #19

Tak OK :mrgreen:


(Mister Wojtek) #20

Dzięki za pomoc!! :smiley: Avasta już nie będę używał bo kłamie :stuck_out_tongue: