Win32/trojanProxy.Dlena trojan

Tykis

Użytkownik
Dołączył
Luty 27, 2007
Posty
32
Witam wszystkich. mam problem trojanem podanym w temacie. co chwile nod32 wykrywa mi zarazenie jakiegos pliku w folderze system32:

Czas Moduł Obiekt Nazwa Wirus Czynność Użytkownik Informacje
2007-03-06 17:55:44 AMON zbiór C:WINDOWSsystem3255368902ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 17:35:41 AMON zbiór C:WINDOWSsystem3235184842ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 17:15:18 AMON zbiór C:WINDOWSsystem3214592032ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 16:45:46 AMON zbiór C:WINDOWSsystem324202812ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 14:42:42 AMON zbiór C:WINDOWSsystem3242376092ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 14:32:23 AMON zbiór C:WINDOWSsystem3232189062ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
2007-03-06 14:22:07 AMON zbiór C:WINDOWSsystem322207182ld.exe odmiana Win32/TrojanProxy.Dlena trojan Kwarantanna - usunięty ZARZĄDZANIE NTSYSTEM Zdarzenie miało miejsce podczas próby tworzenia nowego zbioru przez program: C:WINDOWSsystem32svchost.exe. Zbiór został przeniesiony do kwarantanny.
z tego co wiem to ten proces svchost.exe jest waznym procesem systemowym. poza tym chyba z innego powodu wywala mi neta(po prostu znika okno) gdy wychodze na strone typu konto bankowe, konto w orane-tam gdzie podaje hasla.problem jest gdy robie to za pomoca internet explorer, opery zas nie wywala byc moze to przez programy ktoych ostanio zaczalem uzywac: zonealarm i nod32. Wiem ktos moze jak to naprawic? no i prosze o pomoc w sprawie trojana. oto log z gmera:

---- System - GMER 1.0.12 ----

SSDT a347bus.sys ZwClose
SSDT SystemRootSystem32vsdatant.sys ZwConnectPort
SSDT a347bus.sys ZwCreateKey
SSDT a347bus.sys ZwCreatePagingFile
SSDT SystemRootSystem32vsdatant.sys ZwDeleteKey
SSDT SystemRootSystem32vsdatant.sys ZwDeleteValueKey
SSDT a347bus.sys ZwEnumerateKey
SSDT a347bus.sys ZwEnumerateValueKey
SSDT SystemRootSystem32vsdatant.sys ZwLoadKey
SSDT a347bus.sys ZwOpenFile
SSDT a347bus.sys ZwOpenKey
SSDT SystemRootSystem32vsdatant.sys ZwOpenProcess
SSDT a347bus.sys ZwQueryKey
SSDT a347bus.sys ZwQueryValueKey
SSDT SystemRootSystem32vsdatant.sys ZwReplaceKey
SSDT SystemRootSystem32vsdatant.sys ZwRestoreKey
SSDT a347bus.sys ZwSetSystemPowerState
SSDT SystemRootSystem32vsdatant.sys ZwSetValueKey

---- User code sections - GMER 1.0.12 ----

.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 00C7288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 00C7270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 00C72808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 00C72769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 00C7279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 00C726DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 00C7273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!connect 71A5406A 5 Bytes JMP 00C7226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!send 71A5428A 5 Bytes JMP 00C7231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 00C72548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!recv 71A5615A 5 Bytes JMP 00C723BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 00C72451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesM-Audio Audiophile USBDmnma003dmn.exe[300] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 00C72640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 00A5288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 00A5270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 00A52808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 00A52769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 00A5279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 00A526DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 00A5273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!connect 71A5406A 5 Bytes JMP 00A5226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!send 71A5428A 5 Bytes JMP 00A5231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 00A52548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!recv 71A5615A 5 Bytes JMP 00A523BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 00A52451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[408] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 00A52640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 00AA288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 00AA270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 00AA2808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 00AA2769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 00AA279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 00AA26DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 00AA273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!connect 71A5406A 5 Bytes JMP 00AA226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!send 71A5428A 5 Bytes JMP 00AA231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 00AA2548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!recv 71A5615A 5 Bytes JMP 00AA23BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 00AA2451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32rundll32.exe[480] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 00AA2640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 1000288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 1000270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 10002808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 10002769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 1000279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 100026DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 1000273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!connect 71A5406A 5 Bytes JMP 1000226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!send 71A5428A 5 Bytes JMP 1000231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 10002548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!recv 71A5615A 5 Bytes JMP 100023BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 10002451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32kui.exe[632] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 10002640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 1000288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 1000270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 10002808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 10002769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 1000279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 100026DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 1000273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!connect 71A5406A 5 Bytes JMP 1000226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!send 71A5428A 5 Bytes JMP 1000231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 10002548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!recv 71A5615A 5 Bytes JMP 100023BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 10002451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32ctfmon.exe[676] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 10002640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 023D288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 023D270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 023D2808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 023D2769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 023D279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 023D26DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 023D273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!connect 71A5406A 5 Bytes JMP 023D226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!send 71A5428A 5 Bytes JMP 023D231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 023D2548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!recv 71A5615A 5 Bytes JMP 023D23BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 023D2451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe[720] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 023D2640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptDestroyKey 77DDA544 3 Bytes JMP 00E6288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptDestroyKey + 4 77DDA548 3 Bytes [ 89, CC, CC ]
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 00E6270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 00E62808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 00E62769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 00E6279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 00E626DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 00E6273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!connect 71A5406A 5 Bytes JMP 00E6226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!send 71A5428A 5 Bytes JMP 00E6231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 00E62548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!recv 71A5615A 5 Bytes JMP 00E623BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 00E62451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32svchost.exe[1836] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 00E62640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 1000288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 1000270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 10002808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 10002769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 1000279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 100026DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 1000273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!connect 71A5406A 5 Bytes JMP 1000226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!send 71A5428A 5 Bytes JMP 1000231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 10002548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!recv 71A5615A 5 Bytes JMP 100023BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 10002451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:program FilesESETnod32krn.exe[1864] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 10002640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptDestroyKey 77DDA544 7 Bytes JMP 1000288E c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptDeriveKey 77DDA685 7 Bytes JMP 1000270C c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptDecrypt 77DDA7B1 7 Bytes JMP 10002808 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptImportKey 77DDA879 7 Bytes JMP 10002769 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptEncrypt 77DE1558 7 Bytes JMP 1000279D c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptGenKey 77E014B1 7 Bytes JMP 100026DC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] ADVAPI32.dll!CryptGetUserKey 77E01789 7 Bytes JMP 1000273F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!connect 71A5406A 5 Bytes JMP 1000226A c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!send 71A5428A 5 Bytes JMP 1000231F c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!WSARecv 71A54318 5 Bytes JMP 10002548 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!recv 71A5615A 5 Bytes JMP 100023BC c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!WSASend 71A56233 5 Bytes JMP 10002451 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
.text C:WINDOWSsystem32wscntfy.exe[3760] WS2_32.dll!closesocket 71A59639 5 Bytes JMP 10002640 c:program filescommon filesmicrosoft sharedweb foldersibm00002.dll
A to z Hijack this

Logfile of HijackThis v1.99.1
Scan saved at 18:10:05, on 2007-03-06
Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSSystem32svchost.exe
C:program FilesEsetnod32krn.exe
C:WINDOWSSystem32nvsvc32.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32ZoneLabsvsmon.exe
C:WINDOWSsystem32RUNDLL32.EXE
C:WINDOWSsystem32RunDll32.exe
C:program FilesEsetnod32kui.exe
C:program FilesZoneAlarmzlclient.exe
C:WINDOWSsystem32ctfmon.exe
C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe
C:program FilesM-Audio Audiophile USBDmnma003dmn.exe
C:WINDOWSsystem32wscntfy.exe
C:program FilesGadu-Gadugg.exe
C:program FilesMicrosoft OfficeOffice10WINWORD.EXE
C:program FilesOperaOpera.exe
C:program FilesInternet Exploreriexplore.exe
C:WINDOWSsystem32wuauclt.exe
C:Documents and SettingsTykisPulpitkill em all - Johnny RambohijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.pl/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Łącza
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:pROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSSystem32NvMcTray.dll,NvTaskbarInit
O4 - HKLM..Run: [Network Bridge] C:WINDOWSsystem32netadp.exe
O4 - HKLM..Run: [C-Media Speaker Configuration] C:Documents and SettingsTykisPulpitdrvSetup.exe /SPEAKER
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [nod32kui] "C:program FilesEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [Zone Labs Client] "C:program FilesZoneAlarmzlclient.exe"
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:program FilesCommon FilesAheadlibNMBgMonitor.exe"
O4 - HKCU..Run: [swg] C:program FilesGoogleGoogleToolbarNotifier1.0.720.3640GoogleToolbarNotifier.exe
O4 - Global Startup: BlueSoleil.lnk = C:program FilesIVT CorporationBlueSoleilBlueSoleil.exe
O4 - Global Startup: MA003DMN.LNK = C:program FilesM-Audio Audiophile USBDmnma003dmn.exe
O4 - Global Startup: Microsoft Office.lnk = C:program FilesMicrosoft OfficeOffice10OSA.EXE
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 - Extra context menu item: E&ksport do programu Microsoft Excel - res://C:pROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:pROGRA~1SkypePhoneIEPluginSKYPEI~1.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:program FilesMessengermsmsgs.exe (file missing)
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.117.128.162/activex/AxisCamControl.cab
O16 - DPF: {92ECE6FA-AC2E-4042-BFAE-0C8608E52A43} (SignActivX Control) - https://www.bph.pl/pi/components/SignActivX.cab
O17 - HKLMSystemCCSServicesTcpip..{503C1AC6-DC48-45B9-A530-C5C1A4C39EB9}: NameServer = 217.144.192.2,217.144.192.33
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:pROGRA~1COMMON~1SkypeSKYPE4~1.DLL
O20 - AppInit_DLLs:
O20 - Winlogon Notify: rpcc - C:WINDOWSsystem32rpcc.dll
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:WINDOWSSystem32urdvxc.exe" /service (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:program FilesEsetnod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSSystem32nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:WINDOWSsystem32ZoneLabsvsmon.exe

Czekam cierpliwie na odopowiedz
 

fl3a

Użytkownik
Dołączył
Marzec 12, 2005
Posty
538
O4 - HKLM..Run: [Network Bridge] C:WINDOWSsystem32netadp.exe
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:WINDOWSSystem32urdvxc.exe" /service (file missing)
O20 - Winlogon Notify: rpcc - C:WINDOWSsystem32rpcc.dll[/b]
Te wpisy nalezy usunac w HJT oraz recznie usunac pliki za pomoca gmer'a:
gmer -del file C:WINDOWSsystem32netadp.exe
gmer -del file C:WINDOWSsystem32urdvxc.exe
gmer -del file C:WINDOWSsystem32rpcc.dll[/b]

Jesli w katalogu system32 znajduja sie jakies pliki o losowych nazwach podobnych do tych blokowanych przez nod'a - "55368902ld.exe" nalezy je skasowac w podobny sposob!
 

Tykis

Użytkownik
Dołączył
Luty 27, 2007
Posty
32
Wielkie dzieki. Teraz jest gitara :faja: Usunalem te pliki w troche inny sposob niz za pomoca gmer'a (uruchamiajac system z dysku kumpla ktory mam podpiety) ale to juz nie wazne. Pa =]
 
Do góry Bottom