Amandill
(Kacper Kucharski)
16 Maj 2006 18:16
#1
witam!
Mam problem taki:
mój brat na kompie otworzył linka z gg od nieznanej osoby i zainfekowal kompa. Zrobilem loga i prosilbym o sprawdzenie oraz porade. Pozdrawiam, a ponizej podaje log z hjackthis:
Logfile of HijackThis v1.99.1 Scan saved at 07:57:44, on 2006-05-16 Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\explorer.exe C:\WINDOWS\inet20001\winlogon.exe C:\Program Files\MKS\Bin\mks_menu.exe C:\Program Files\AutoPartner\autobackup.exe C:\WINDOWS\system32\kernels8.exe C:\WINDOWS\system32\brmfrsmq.exe C:\Windows\xpupdate.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\taskdir.exe D:\Corel\Graphics8\programs\MFIndexer.exe C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe C:\Program Files\MKS\Bin\NetMonSV.exe C:\WINDOWS\system32\aspi154065.exe C:\Program Files\MKS\Bin\mksmonsv.exe C:\Program Files\Microsoft SQL Server\MSSQL$INTEGRA\Binn\sqlservr.exe C:\Program Files\MKS\Bin\mks_scan.exe C:\WINDOWS\system32\dlh9jkdq6.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\User1\Pulpit\kasper\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.neostrada.pl/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Neostrada Plus wita Cie w Internecie R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza F2 - REG:system.ini: Shell=explorer.exe “C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe” F3 - REG:win.ini: run=C:\WINDOWS\inet20001\winlogon.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20001\3.03.00.dll (file missing) O2 - BHO: (no name) - {78364D99-A640-4ddf-B91A-67EFF8373045} - C:\WINDOWS\system32\ipv6mons.dll O4 - HKLM…\Run: [MKS_MENU] C:\Program Files\MKS\Bin\mks_menu.exe O4 - HKLM…\Run: [ABREGMON] C:\Program Files\MKS\Bin\ABregmon.exe O4 - HKLM…\Run: [ObjectLoader] C:\WINDOWS\system32\30.tmp O4 - HKLM…\Run: [AutoBackup] C:\Program Files\AutoPartner\autobackup.exe O4 - HKLM…\Run: [system] C:\WINDOWS\system32\kernels8.exe O4 - HKLM…\Run: [brmfrsmq] C:\WINDOWS\system32\brmfrsmq.exe O4 - HKLM…\Run: [msmsn] c:\windows\system32\msmsn.exe O4 - HKLM…\Run: [ZPoint] C:\WINDOWS\system32\winmuse.exe O4 - HKLM…\RunServices: [brmfrsmq] C:\WINDOWS\system32\brmfrsmq.exe O4 - HKLM…\RunServices: [systemTools] C:\WINDOWS\system32\kernels8.exe O4 - HKCU…\Run: [Windows update loader] C:\Windows\xpupdate.exe O4 - HKCU…\Run: [xp_system] C:\WINDOWS\inet20001\winlogon.exe O4 - HKCU…\Run: [taskdir] C:\WINDOWS\system32\taskdir.exe O4 - HKCU…\Run: [WinMedia] C:\WINDOWS\system32\vx O4 - HKCU…\Run: [Windows installer] C:\winstall.exe O4 - HKCU…\Run: [brmfrsmq] C:\WINDOWS\system32\brmfrsmq.exe O4 - HKCU…\Run: [shell] “C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe” O4 - Global Startup: Corel MEDIA FOLDERS INDEXER 8.LNK = D:\Corel\Graphics8\programs\MFIndexer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O17 - HKLM\System\CCS\Services\Tcpip…{09F8064E-8E79-43CF-B14B-5BEB9F198BB6}: NameServer = 194.204.152.34 O17 - HKLM\System\CS1\Services\Tcpip…{09F8064E-8E79-43CF-B14B-5BEB9F198BB6}: NameServer = 194.204.152.34 O20 - Winlogon Notify: gdwxp3 - gdwxp3.dll (file missing) O20 - Winlogon Notify: SensSrv - senssrv.dll (file missing) O23 - Service: ArcaBit NetMonitor (ABNetMon) - ArcaBit sp. z o.o. - C:\Program Files\MKS\Bin\NetMonSV.exe O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\system32\aspi154065.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: ELSA HostConn Server (HostConn) - Unknown owner - d:\ELSA\bin\HostConn.exe (file missing) O23 - Service: ELSA Administration Service (LcSvrAdm) - Unknown owner - d:\ELSA\bin\LcSvrAdm.exe (file missing) O23 - Service: ELSA Auftragsverwaltungs Service (LcSvrAuf) - Unknown owner - d:\ELSA\bin\LcSvrAuf.exe (file missing) O23 - Service: ELSA DBA Server (LcSvrDba) - Unknown owner - d:\ELSA\bin\LcSvrDba.exe (file missing) O23 - Service: ELSA Historie Server (LcSvrHis) - Unknown owner - d:\ELSA\bin\LcSvrHis.exe (file missing) O23 - Service: ELSA KD-Nummern Server (LcSvrKds) - Unknown owner - d:\ELSA\bin\LcSvrKdS.exe (file missing) O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: MkSUpdateInt - MkS Sp. z o. o. - C:\Program Files\MKS\bin\MkSUpdateInt.exe O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS\Bin\mksmonsv.exe O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS\Bin\mks_scan.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
Bieniol
(Bbieniol)
16 Maj 2006 18:23
#2
Użyj Windows Worms Doors Cleanera zmień znaczki z disable na enable. Po użyciu tego narzędzia wymagany jest reset sysa.
Start --> uruchom --> services.msc --> zatrzymaj i wyłącz usługe Microsoft ASPI Manager
W trybie awaryjnym z wyłączonym przywracaniem systemu usuwasz (wpisy Hijackiem, pliki/foldery na czerwono ręcznie z dysku (w razie problemów z usuwaniem plików użyj narzędzia KillBox ):
Skan EWIDO po update
Po zabiegach nowy log z Hijacka + log z Silent Runners