Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Problem sa virusom! INF\\Autorun.gen trojan

[es] :: Zaštita :: Problem sa virusom! INF\\Autorun.gen trojan

[ Pregleda: 2908 | Odgovora: 3 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

Kuzmo
RS

Član broj: 171268
Poruke: 18
213.196.71.*



Profil

icon Problem sa virusom! INF\\Autorun.gen trojan29.11.2008. u 12:26 - pre 188 meseci
Prije nego sto sam otvorio ovu temu i zatrazio pomoc od vas koji ste spremni pomoci pokusao sam na vise nacina rijesiti svoj problem, koji je prisutan vec nekoliko dana. Citao sam dosta savjeta sa ovog foruma, ali za sad nisam uspio rijesiti ovaj problem. Naime, radi se o slecem.
Koristio sam Symantec Antivirus 10.1 (uredan update), XP Pro SP3 i firewall od XP-a.
Nakon odredjenih problema, a nisam ih imao za tri godine koristeci ovaj antivirus, odlucim ga promijeniti i instaliram ESET NOD32 Antivirus, koji sam takodje uredno update-ovao.
NOD32 mi svakih 10 sekundi izbacuje po dva prozora upozorenja u donjem desnom uglu, gdje pise ovako:

Object:
C\autorun.inf
Threat:
INF/Autorun.gen trojan
Information:
cleaned by deleting - quarantined

U drugom je jedina razlika sto umjesto C, pise da je na D particiji "D\autorun.inf".
Pokusao sam rijesiti problem i sa sledecim programima: Spyboot Search and Destroy, SpyHunter, Malwarebytes' Anti-Malware, RogueRemover FREE (svi uredan update) i nista. Stalno NOD32 prijavljuje isto, a pri skeniranju nista ne pronalazi.
Instalirao sam i HijackThis i napravio log koji prilazem uz ovu poruku, pa molim vas da pogleate ima li sta vama sumnjivo.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:08:50, on 29.11.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpyHunter Security Suite] "C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Program Files\Free Download Manager\FUM\fumoei.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Preuzmi odabrano Free Download Manager-om - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Preuzmi sa Free Download Managerom - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Preuzmi sve sa Free Download Manager-om - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Program Files\Free Download Manager\FUM\fumiebtn.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{59CC0569-10C3-4AB8-9CBD-18CA3673E790}: NameServer = 87.250.97.250,87.250.98.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE04772A-DA7D-4023-8161-50D492D1E922}: NameServer = 87.250.98.250 208.67.222.222
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 6465 bytes
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Problem sa virusom! INF\\\\\\\\Autorun.gen trojan29.11.2008. u 17:34 - pre 188 meseci
amvo..a jooj...


restartuj komp...drzi f8 i izaberi safe mode

pokreni HjT pa Fix ovu liniju

O1 - Hosts: 66.98.148.65 auto.search.msn.es


ondak...odradi sledece:

isprati uputstvo sa linka:
http://www.bleepingcomputer.com/tutorials/tutorial62.html

pa
start >> run pa kucaj regedit

nadji sledeci reg. kljuc

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

sa desne strane ces naci amva ..to obrisi

sad zatvori regedit ( X)
onda nadji i obrisi rucno sledeci file ( shift + delete pa enter )

C:\WINDOWS\system32\amvo.exe

restartuj komp
......................................

ondak..skini i pokreni ovaj program
http://www.ccleaner.com/download
skeniraj registry i cokie

ovo je putanja HjT programa
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

promeni naziv Foldera (Trend Micro i HijackThis folder ) i HijackThis.exe program u nesto drugo (bilo sta) pa postavi svez logfile



 
Odgovor na temu

Kuzmo
RS

Član broj: 171268
Poruke: 18
213.196.71.*



Profil

icon Re: Problem sa virusom! INF\Autorun.gen trojan29.11.2008. u 22:00 - pre 188 meseci
Zahvaljujem na detaljnom uputstvu!
Moja greska je sto sam zaboravio, a mislio sam, upisati odmah u prvom komentaru da imam problem sa aktiviranjem nevidljivih fajlova i foldera. Ta mi opcija ne funkcionise. Odaberem ja da se vide skriveni i ono kao prihvati, ali nema rezultata. Posle se opet vratim na isti prozor i vidim da su postavke nepromijenjene.
Dakle, zapeo sam vec na drugom koraku. Ocekujem daljnje upute...
 
Odgovor na temu

Kuzmo
RS

Član broj: 171268
Poruke: 18
213.196.71.*



Profil

icon Re: Problem sa virusom! INF\Autorun.gen trojan30.11.2008. u 10:46 - pre 188 meseci
Problem rijesen uz pomoc Combofix-a bez dodatnih skripti, hvala svima!
 
Odgovor na temu

[es] :: Zaštita :: Problem sa virusom! INF\\Autorun.gen trojan

[ Pregleda: 2908 | Odgovora: 3 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.