Trojan guard.exe?


(MJ DwaTrzy) #1

Ok kilku dni sila procesora jest ciagle w 100%.Wydaje mi sie ze to trojan jest . W processorach jest podejrzany wpis guard.exe , jest to trojan ?

tu moj log :

Logfile of HijackThis v1.99.1

Scan saved at 18:44:40, on 28.07.2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Programme\Alwil Software\Avast4\aswUpdSv.exe

C:\Programme\Alwil Software\Avast4\ashServ.exe

C:\Programme\ewido anti-spyware 4.0\guard.exe

C:\Programme\Kerio\Personal Firewall 4\kpf4ss.exe

C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe

C:\WINDOWS\system32\lvhidsvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Programme\Kerio\Personal Firewall 4\kpf4gui.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Programme\Desktop Sidebar\dsidebar.exe

C:\Programme\Logitech\SetPoint\SetPoint.exe

C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe

C:\Programme\Gemeinsame Dateien\Logitech\KHAL\KHALMNPR.EXE

C:\Programme\Alwil Software\Avast4\ashMaiSv.exe

C:\Programme\Alwil Software\Avast4\ashWebSv.exe

C:\Programme\Kerio\Personal Firewall 4\kpf4gui.exe

C:\Programme\Netscape\Netscape\Netscp.exe

C:\WINDOWS\system32\taskmgr.exe

D:\Programy\HijackThis2\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ps2tools.de/

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 

O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} - C:\Programme\Desktop Sidebar\sbhelp.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKCU\..\Run: [SIDEBAR] "C:\Programme\Desktop Sidebar\dsidebar.exe"

O4 - Startup: tempweg.bat

O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Programme\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Mit WGet herunterladen - C:\Dokumente und Einstellungen\MJ DwaTrzy\Desktop\wgetgui_source\wgie.htm

O8 - Extra context menu item: Subscribe in Desktop Sidebar - res://C:\Programme\Desktop Sidebar\sbhelp.dll/menuhandler.html

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll

O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll

O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Programme\Desktop Sidebar\sbhelp.dll

O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{190C669B-8B1A-474C-BBAE-56C8F982BBC4}: NameServer = 217.237.150.225,217.237.151.225

O17 - HKLM\System\CS1\Services\Tcpip\..\{190C669B-8B1A-474C-BBAE-56C8F982BBC4}: NameServer = 217.237.150.225,217.237.151.225

O17 - HKLM\System\CS2\Services\Tcpip\..\{190C669B-8B1A-474C-BBAE-56C8F982BBC4}: NameServer = 217.237.150.225,217.237.151.225

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Programme\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programme\ewido anti-spyware 4.0\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Programme\Kerio\Personal Firewall 4\kpf4ss.exe

O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe

O23 - Service: Remote HID Service (LvHidSvc) - Animation Technologies Inc. - C:\WINDOWS\system32\lvhidsvc.exe

O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Programme\Sony\MD Simple Burner\NetMDSB.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\Pacsptisvr.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\Sptisrv.exe

Przez kilkoma dniami wlaczylem swojego PC i na dole obok zegara wyskoczyla tak chmurka ze jest nowe polaczenie D-link Router (moj router ). Wchodze w polaczenia sieciowe a tam jakies nowe polaczenie tu jest screen : http://img123.imageshack.us/img123/7861 ... me1ph7.jpg . predkosd polaczenia byla 10 Mbit/s czyli ma to cos z WIfi wspolnego . NIe dalo sie tego wylaczyc . Sprawdzilem logi z routera i tekie cos znalazlem :

Jul/23/2006 13:50:44

 SMTP: sending mail fail   

Jul/23/2006 13:50:43

 Sending one E-mail Subject: Manual

Jul/23/2006 13:20:54

 DHCP release IP 192.168.0.2 00-04-1F-16-85-2E

Jul/23/2006 13:20:32

 PPPoE line connected   

Jul/23/2006 13:20:31

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:217.18.19.23:10070 

Jul/23/2006 13:20:28

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:87.248.83.233:6435 

Jul/23/2006 13:20:27

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:26

 PPPoE line connected   

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:46021 dst:217.18.18.73:10078 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:87.248.83.233:6435 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.31.217.136:6846 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.144.114.246:62911 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.200.50.215:6946 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.164.106.209:6859 

Jul/23/2006 13:20:25

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:62.226.242.161:6443 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:80.134.185.27:63299 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:87.122.153.174:64039 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.11.64.243:10356 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.31.217.136:6215 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.153.27.252:6482 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:212.41.86.130:24774 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.159.88.195:6739 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:213.39.176.2:33276 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:217.83.137.157:64189 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:62.47.45.201:61292 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:81.36.91.134:6986 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:24

 PPPoE: opening connection ... src:192.168.0.108:1036 dst:217.237.150.225:53 

Jul/23/2006 13:20:24

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:23

 PPPoE line connected   

Jul/23/2006 13:20:22

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.156.95.209:57818 

Jul/23/2006 13:20:21

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:19

 PPPoE line connected   

Jul/23/2006 13:20:18

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:18

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:17

 PPPoE line connected   

Jul/23/2006 13:20:16

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:16

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.156.95.209:57818 

Jul/23/2006 13:20:15

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:217.18.19.23:10070 

Jul/23/2006 13:20:15

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:14

 PPPoE line connected   

Jul/23/2006 13:20:13

 PPPoE: opening connection ... src:192.168.0.2:46021 dst:217.18.18.73:10078 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.31.217.136:6846 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.144.114.246:62911 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.200.50.215:6946 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.164.106.209:6859 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:62.226.242.161:6443 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:87.248.83.233:6435 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:80.134.185.27:63299 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:87.122.153.174:64039 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.11.64.243:10356 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:83.31.217.136:6215 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.153.27.252:6482 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:212.41.86.130:24774 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.159.88.195:6739 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:213.39.176.2:33276 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:217.83.137.157:64189 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:62.47.45.201:61292 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:81.36.91.134:6986 

Jul/23/2006 13:20:12

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:12

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:11

 PPPoE line connected   

Jul/23/2006 13:20:10

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.156.95.209:57818 

Jul/23/2006 13:20:09

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:07

 PPPoE line connected   

Jul/23/2006 13:20:06

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:06

 PPPoE: Receive PADT TAG Disconnect PPPoE line

Jul/23/2006 13:20:05

 PPPoE line connected   

Jul/23/2006 13:20:04

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.179.227.30:59353 

Jul/23/2006 13:20:04

 PPPoE: opening connection ... src:192.168.0.2:6011 dst:84.156.95.209:57818 

Jul/23/2006 13:20:03

 PPPoE: opening connection ... src:192.168.0.108:1296 dst:66.212.229.233:80 

Jul/23/2006 13:17:50

 DHCP lease IP 192.168.0.2 to 00-04-1F-16-85-2E

Jul/23/2006 12:59:44

 SMTP: sending mail fail   

Jul/23/2006 12:59:43

 TearDrop Attack Detect src:84.189.223.112:4667 dst:217.225.162.241:60590 Packet Dropped

Jul/23/2006 12:36:38

 DHCP lease IP 192.168.0.123 to SIEKACZ 00-0D-87-75-6C-83

Jul/23/2006 12:35:53

 PPPoE line connected   

Jul/23/2006 12:35:46

 PPPoE: opening connection ... src:192.168.0.108:8 dst:217.70.246.248:0 

Jul/23/2006 12:35:41

 System started

Jul/23/2006 12:59:43

 Jul/23/2006 12:59:43

 TearDrop Attack Detect src:84.189.223.112:4667 dst:217.225.162.241:60590 Packet Dropped

powiedzcie co te jest ?

Teraz tak ustawilem dostaje logo na maila i dostaja tak gdzies z 10 dzienie jak nie wiecej z tytulem Log AttackLog(from: 217.225.143.153) .


(Vilargo Pl) #2

To nie jest trojan, ma to samo pozainstalowaniu EWIDO ANTY-SPYWARE , wyszukaj to sobie start/wyszukaj i wpisz guard.exe jest w folderze EWIDO :wink: pozdrowienia :slight_smile:


(MJ DwaTrzy) #3

no tak myslalem ale nie bylem w 100% pewny. Co do tego polaczenia to dalej nie wiem jak mi sie moglo jakies polaczenie samo wpiepszyc .

Przyczyna obciazenia processora byl odpowiedzialny plik lvhidsvc.exe. Usunolem go i juz wszystko chodzi normalnie . Ale prosze zeby ktos sprawdzil te loga co podalem wyzej .


(Gblade) #4

jeśli znasz i sam to ustawiałeś to ok.

My tutaj nie korzystamy i nie polecamy takich automatów, ponieważ wprowadzają ludzi w błąd...wiele razy było na forum.

to było coś związane z tunerem...


(Kuz5) #5

Dlatego post kosz

A dla niedowiarków co to automatu mogę wysłać komplet wpisów które udowodnią iż automat to bagno