Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

TR/Crypt.ZPACK.Gen Trojan

[es] :: Zaštita :: TR/Crypt.ZPACK.Gen Trojan

[ Pregleda: 2937 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 21:41 - pre 166 meseci
Pozdrav

Avira 9 mi je pronasla ovaj trojanac i to u C:\WINDOWS\system32\drivers\iffgv.sys

Pokušao sam da ga uklonim sa Malwarebytes ali ga on ne detektuje.

Internet mi je malo usporen , a koliko vidim i kad mi ništa nije pokrenuto na računaru stalno ima nakog saobraćaja kroz mrežu.

Može li mi neko pomoći .


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:21 PM, on 05/08/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sbb.co.yu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2311E123-1CF1-11D8-85DE-E8A6F2801631} (CryptoBlob Class) - https://secure.24x7.co.yu/Meta...S/DigitrustApiNetSetPlugIn.cab
O16 - DPF: {60B128A0-9343-4521-B525-6856543ED8F4} (CustomMediaManager Class) - https://secure.24x7.co.yu/Meta...BS/DigitrustApiPeximPlugin.cab
O16 - DPF: {7136C6F0-DE59-4AD5-B4A3-CA8B779D035E} (SetPinManager Class) - https://secure.24x7.co.yu/Meta...S/DigitrustApiSetPinPlugin.cab
O16 - DPF: {DC01983E-2FD5-4200-9C3A-755E86413172} (PINManager Class) - https://secure.24x7.co.yu/Meta...S/DigitrustApiPKCS11Plugin.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6718 bytes

 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 21:48 - pre 166 meseci
Log je cist...Avira pronadje tog trojanca i ne moze da ga ukloni??? Zasto nisi presao na Aviru 10?
Nebitno...skini Avenger odavde http://www.geekstogo.com/forum.../393-the-avenger-by-swandog46/ , raspakuj ga, pokreni, odgovori sa OK i u polje kopiraj sledece:

File to delete:
C:/WINDOWS/system32/drivers/iffgv.sys

Klikni na Execute, verovatno ce zahtevati restart nakon toga...posle restarta mi kopiraj log koji ce ti izbaciti ili ako ne izbaci nalazi se u C:/Avenger.txt...



[Ovu poruku je menjao Aleksandar Maletic dana 05.08.2010. u 23:06 GMT+1]
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:04 - pre 166 meseci
Avira i jeste 10 (od pre jedno mesec dva) , pogrešno sam napisao.

Moraš mi još malo pomoći jer nisam baš iskusan sa ovim, naime kad u polje (skinuo i otpakovao Avenger) upišem
File to delete:
C:/WINDOWS/system32/drivers/iffgv.sys

i idem na execute

javi ... Inavlid script. A valid script must begin with a command directive

Hvala
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:23 - pre 166 meseci
Pardon, moja greska...pokreni Avenger, klikni OK, zatim prekopiraj sledeci tekst:

Drivers to delete:
C:/WINDOWS/system32/drivers/iffgv.sys

Klikni na Execute...restartuj komp, zatim mi posalji log file...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:29 - pre 166 meseci
Evo ga

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\C:/WINDOWS/system32/drivers/iffgv.sys" not found!
Deletion of driver "C:/WINDOWS/system32/drivers/iffgv.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:33 - pre 166 meseci
@Aleksandar Maletic
Sta ti to mislis da radis?
ti bas resio coveku da "malo" zeznes sistem...

@zbelca

--> Postavi mi screen shot od toga sto ti AntiVirus detektuje

--> Skini Malwarebytes program (freeware je ) i odradi Quick Scan...javi rezultate
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:36 - pre 166 meseci
Da li si siguran da Avira nije obrisala tog trojanca?
Skini Malwarebytes' Anti-Malware http://download.cnet.com/Malwa...8022_4-10804572.html?tag=mncol, instaliraj, update-uj i odradi Quick scan, ukoliko nesto pronadje idi na "Remove selected"...posle toga mi log kopiraj ovde...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan05.08.2010. u 23:50 - pre 166 meseci
Još nešto da dodam
kada kod pogledam folder Windows\system32\drivers
file iffgv.sys uvek ima trenutno vreme.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Verzija baze: 4395

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

06/08/2010 12:41:39 AM
mbam-log-2010-08-06 (00-41-39).txt

Naèin skeniranja: Brzo skeniranje
Skeniranih objekata 143548
Proteklo vreme 5 minuta(e), 39 sekundi

Inficirani procesi u memoriji: 0
Inficirani moduli u memoriji: 0
Inficirani kljuèevi u registru: 0
Inficirane vrednosti u registru: 0
Inficirani podaci u registru: 0
Inficirane fascikle: 0
Inficirane datoteke: 0

Inficirani procesi u memoriji:
(Maliciozne stavke nisu pronaðene)

Inficirani moduli u memoriji:
(Maliciozne stavke nisu pronaðene)

Inficirani kljuèevi u registru:
(Maliciozne stavke nisu pronaðene)

Inficirane vrednosti u registru:
(Maliciozne stavke nisu pronaðene)

Inficirani podaci u registru:
(Maliciozne stavke nisu pronaðene)

Inficirane fascikle:
(Maliciozne stavke nisu pronaðene)

Inficirane datoteke:
(Maliciozne stavke nisu pronaðene)



a evo sta javi Avira kad skenira folder C:\WINDOWS\system32\drivers

Avira AntiVir Personal
Report file date: Friday, 06 August, 2010 00:45

Scanning for 2679945 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : Zoran
Computer name : KORISNIK

Version information:
BUILD.DAT : 10.0.0.567 32097 Bytes 19/04/2010 15:07:00
AVSCAN.EXE : 10.0.3.0 433832 Bytes 01/04/2010 11:37:38
AVSCAN.DLL : 10.0.3.0 46440 Bytes 01/04/2010 11:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 07/03/2010 17:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 22:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 08:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 18:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 16:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 15:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 10:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 16:02:12
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 16:02:14
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 16:02:20
VBASE008.VDF : 7.10.9.166 2048 Bytes 23/07/2010 16:02:20
VBASE009.VDF : 7.10.9.167 2048 Bytes 23/07/2010 16:02:20
VBASE010.VDF : 7.10.9.168 2048 Bytes 23/07/2010 16:02:20
VBASE011.VDF : 7.10.9.169 2048 Bytes 23/07/2010 16:02:20
VBASE012.VDF : 7.10.9.170 2048 Bytes 23/07/2010 16:02:20
VBASE013.VDF : 7.10.9.198 157696 Bytes 26/07/2010 16:02:21
VBASE014.VDF : 7.10.9.255 997888 Bytes 29/07/2010 16:02:22
VBASE015.VDF : 7.10.10.28 139264 Bytes 02/08/2010 16:02:22
VBASE016.VDF : 7.10.10.52 127488 Bytes 03/08/2010 16:02:22
VBASE017.VDF : 7.10.10.53 1536 Bytes 03/08/2010 16:02:22
VBASE018.VDF : 7.10.10.54 1536 Bytes 03/08/2010 16:02:22
VBASE019.VDF : 7.10.10.55 1536 Bytes 03/08/2010 16:02:22
VBASE020.VDF : 7.10.10.56 1536 Bytes 03/08/2010 16:02:22
VBASE021.VDF : 7.10.10.57 1536 Bytes 03/08/2010 16:02:22
VBASE022.VDF : 7.10.10.58 1536 Bytes 03/08/2010 16:02:23
VBASE023.VDF : 7.10.10.59 1536 Bytes 03/08/2010 16:02:23
VBASE024.VDF : 7.10.10.60 1536 Bytes 03/08/2010 16:02:23
VBASE025.VDF : 7.10.10.61 1536 Bytes 03/08/2010 16:02:23
VBASE026.VDF : 7.10.10.62 1536 Bytes 03/08/2010 16:02:23
VBASE027.VDF : 7.10.10.63 1536 Bytes 03/08/2010 16:02:23
VBASE028.VDF : 7.10.10.64 1536 Bytes 03/08/2010 16:02:23
VBASE029.VDF : 7.10.10.65 1536 Bytes 03/08/2010 16:02:23
VBASE030.VDF : 7.10.10.66 1536 Bytes 03/08/2010 16:02:23
VBASE031.VDF : 7.10.10.81 110080 Bytes 05/08/2010 16:02:23
Engineversion : 8.2.4.32
AEVDF.DLL : 8.1.2.1 106868 Bytes 05/08/2010 16:02:28
AESCRIPT.DLL : 8.1.3.42 1364347 Bytes 05/08/2010 16:02:28
AESCN.DLL : 8.1.6.1 127347 Bytes 05/08/2010 16:02:27
AESBX.DLL : 8.1.3.1 254324 Bytes 05/08/2010 16:02:28
AERDL.DLL : 8.1.8.2 614772 Bytes 05/08/2010 16:02:27
AEPACK.DLL : 8.2.3.3 471414 Bytes 05/08/2010 16:02:27
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 05/08/2010 16:02:26
AEHEUR.DLL : 8.1.2.10 2830711 Bytes 05/08/2010 16:02:26
AEHELP.DLL : 8.1.13.2 242039 Bytes 05/08/2010 16:02:25
AEGEN.DLL : 8.1.3.18 393589 Bytes 05/08/2010 16:02:24
AEEMU.DLL : 8.1.2.0 393588 Bytes 05/08/2010 16:02:24
AECORE.DLL : 8.1.16.2 192887 Bytes 05/08/2010 16:02:24
AEBB.DLL : 8.1.1.0 53618 Bytes 05/08/2010 16:02:24
AVWINLL.DLL : 10.0.0.0 19304 Bytes 14/01/2010 11:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 14/01/2010 11:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 18/02/2010 15:47:40
AVREG.DLL : 10.0.3.0 53096 Bytes 01/04/2010 11:35:46
AVSCPLR.DLL : 10.0.3.0 83816 Bytes 01/04/2010 11:39:51
AVARKT.DLL : 10.0.0.14 227176 Bytes 01/04/2010 11:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26/01/2010 08:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 28/01/2010 11:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 16/03/2010 14:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 19/02/2010 13:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28/01/2010 12:10:20
RCTEXT.DLL : 10.0.53.0 97128 Bytes 09/04/2010 13:14:29

Configuration settings for the scan:
Jobname.............................: ShlExt
Configuration file..................: C:\DOCUME~1\Zoran\LOCALS~1\Temp\24235372.avp
Logging.............................: low
Primary action......................: repair
Secondary action....................: delete
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: off
Scan registry.......................: off
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Friday, 06 August, 2010 00:45

Starting the file scan:

Begin scan in 'C:\WINDOWS\system32\drivers'
C:\WINDOWS\system32\drivers\iffgv.sys
[DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
[NOTE] A backup was created as '4f5c94eb.qua' ( QUARANTINE )


End of the scan: Friday, 06 August, 2010 00:46
Used time: 00:16 Minute(s)

The scan has been done completely.

4 Scanned directories
245 Files were scanned
1 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
1 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
244 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes


Prikačeni fajlovi
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan06.08.2010. u 00:09 - pre 166 meseci
Skeniraj opet taj folder Avirom...da li opet nakon stavljanja fajla u Quarantine Avira prijavljuje isto?
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan06.08.2010. u 05:26 - pre 166 meseci
Citat:
Aleksandar Maletic: Skeniraj opet taj folder Avirom...da li opet nakon stavljanja fajla u Quarantine Avira prijavljuje isto?


Da , svaki put
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan06.08.2010. u 12:06 - pre 166 meseci
Skini Avira Rescue System (CD) odavde http://www.avira.com/en/support/support_downloads.html , to je image koji ces narezati na disk i pomocu njega boot-ovati Windows...kada narezes disk, ubaci ga, restartuj komp i pri boot-ovanju izaberi skeniranje...kada sve ocistis, javi mi rezlutate i da li se isto ponavlja opet...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

zbelca

Član broj: 45921
Poruke: 9
*.dynamic.sbb.rs.



+1 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan06.08.2010. u 20:09 - pre 166 meseci
Yeeesssssssssss

Hvala puno, uspelo je .

Avira Rescue System je prvo skenirao oko sat vremena i samo javio sta je pronašao.
Onda sam postavio setovanje na "remove" i ponovo ga pokrenuo .

Kad sam posle toga opet pokrenuo windows video sam da onog fajla više nema .
Pustio sam Aviru da skenirao ceo PC i ništa nije našla .

Još jednom veliko hvala na pomoći.


Avira AntiVir Personal
Report file date: Friday, August 06, 2010 19:49

Scanning for 2679945 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : KORISNIK

Version information:
BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 11:37:38
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 11:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 17:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 22:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 08:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 18:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 16:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 15:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 10:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 16:02:12
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 16:02:14
VBASE007.VDF : 7.10.9.165 4840960 Bytes 7/23/2010 16:02:20
VBASE008.VDF : 7.10.9.166 2048 Bytes 7/23/2010 16:02:20
VBASE009.VDF : 7.10.9.167 2048 Bytes 7/23/2010 16:02:20
VBASE010.VDF : 7.10.9.168 2048 Bytes 7/23/2010 16:02:20
VBASE011.VDF : 7.10.9.169 2048 Bytes 7/23/2010 16:02:20
VBASE012.VDF : 7.10.9.170 2048 Bytes 7/23/2010 16:02:20
VBASE013.VDF : 7.10.9.198 157696 Bytes 7/26/2010 16:02:21
VBASE014.VDF : 7.10.9.255 997888 Bytes 7/29/2010 16:02:22
VBASE015.VDF : 7.10.10.28 139264 Bytes 8/2/2010 16:02:22
VBASE016.VDF : 7.10.10.52 127488 Bytes 8/3/2010 16:02:22
VBASE017.VDF : 7.10.10.53 1536 Bytes 8/3/2010 16:02:22
VBASE018.VDF : 7.10.10.54 1536 Bytes 8/3/2010 16:02:22
VBASE019.VDF : 7.10.10.55 1536 Bytes 8/3/2010 16:02:22
VBASE020.VDF : 7.10.10.56 1536 Bytes 8/3/2010 16:02:22
VBASE021.VDF : 7.10.10.57 1536 Bytes 8/3/2010 16:02:22
VBASE022.VDF : 7.10.10.58 1536 Bytes 8/3/2010 16:02:23
VBASE023.VDF : 7.10.10.59 1536 Bytes 8/3/2010 16:02:23
VBASE024.VDF : 7.10.10.60 1536 Bytes 8/3/2010 16:02:23
VBASE025.VDF : 7.10.10.61 1536 Bytes 8/3/2010 16:02:23
VBASE026.VDF : 7.10.10.62 1536 Bytes 8/3/2010 16:02:23
VBASE027.VDF : 7.10.10.63 1536 Bytes 8/3/2010 16:02:23
VBASE028.VDF : 7.10.10.64 1536 Bytes 8/3/2010 16:02:23
VBASE029.VDF : 7.10.10.65 1536 Bytes 8/3/2010 16:02:23
VBASE030.VDF : 7.10.10.66 1536 Bytes 8/3/2010 16:02:23
VBASE031.VDF : 7.10.10.81 110080 Bytes 8/5/2010 16:02:23
Engineversion : 8.2.4.32
AEVDF.DLL : 8.1.2.1 106868 Bytes 8/5/2010 16:02:28
AESCRIPT.DLL : 8.1.3.42 1364347 Bytes 8/5/2010 16:02:28
AESCN.DLL : 8.1.6.1 127347 Bytes 8/5/2010 16:02:27
AESBX.DLL : 8.1.3.1 254324 Bytes 8/5/2010 16:02:28
AERDL.DLL : 8.1.8.2 614772 Bytes 8/5/2010 16:02:27
AEPACK.DLL : 8.2.3.3 471414 Bytes 8/5/2010 16:02:27
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 8/5/2010 16:02:26
AEHEUR.DLL : 8.1.2.10 2830711 Bytes 8/5/2010 16:02:26
AEHELP.DLL : 8.1.13.2 242039 Bytes 8/5/2010 16:02:25
AEGEN.DLL : 8.1.3.18 393589 Bytes 8/5/2010 16:02:24
AEEMU.DLL : 8.1.2.0 393588 Bytes 8/5/2010 16:02:24
AECORE.DLL : 8.1.16.2 192887 Bytes 8/5/2010 16:02:24
AEBB.DLL : 8.1.1.0 53618 Bytes 8/5/2010 16:02:24
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 11:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 11:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 15:47:40
AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 11:35:46
AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 11:39:51
AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 11:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 08:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 11:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 14:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 13:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 12:10:20
RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 13:14:29

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: repair
Secondary action....................: delete
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Friday, August 06, 2010 19:49

Starting search for hidden objects.
HKEY_USERS\S-1-5-21-602162358-1844823847-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1CA78E3C-D1F9-E495-A41E-2DECA038C0E6}\oakfnolobcddkpphenngehdkefbjle
[NOTE] The registry entry is invisible.
HKEY_USERS\S-1-5-21-602162358-1844823847-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1CA78E3C-D1F9-E495-A41E-2DECA038C0E6}\oaggemojghgefaonknddbjijaaebka
[NOTE] The registry entry is invisible.
HKEY_USERS\S-1-5-21-602162358-1844823847-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1CA78E3C-D1F9-E495-A41E-2DECA038C0E6}\naagkbfmmpkigbdgnecekcdfapie
[NOTE] The registry entry is invisible.
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\parseautoexec
[NOTE] The registry entry is invisible.

The scan of running processes will be started
Scan process 'vssvc.exe' - '34' Module(s) have been scanned
Scan process 'avscan.exe' - '64' Module(s) have been scanned
Scan process 'avcenter.exe' - '59' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'PsiService_2.exe' - '14' Module(s) have been scanned
Scan process 'avshadow.exe' - '24' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '31' Module(s) have been scanned
Scan process 'MDM.EXE' - '19' Module(s) have been scanned
Scan process 'jqs.exe' - '31' Module(s) have been scanned
Scan process 'avguard.exe' - '51' Module(s) have been scanned
Scan process 'rapimgr.exe' - '41' Module(s) have been scanned
Scan process 'ctfmon.exe' - '23' Module(s) have been scanned
Scan process 'Wcescomm.exe' - '41' Module(s) have been scanned
Scan process 'avgnt.exe' - '48' Module(s) have been scanned
Scan process 'zlclient.exe' - '58' Module(s) have been scanned
Scan process 'RTHDCPL.EXE' - '33' Module(s) have been scanned
Scan process 'Explorer.EXE' - '101' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '32' Module(s) have been scanned
Scan process 'sched.exe' - '42' Module(s) have been scanned
Scan process 'spoolsv.exe' - '58' Module(s) have been scanned
Scan process 'vsmon.exe' - '88' Module(s) have been scanned
Scan process 'svchost.exe' - '42' Module(s) have been scanned
Scan process 'svchost.exe' - '29' Module(s) have been scanned
Scan process 'svchost.exe' - '29' Module(s) have been scanned
Scan process 'svchost.exe' - '134' Module(s) have been scanned
Scan process 'svchost.exe' - '37' Module(s) have been scanned
Scan process 'svchost.exe' - '49' Module(s) have been scanned
Scan process 'lsass.exe' - '57' Module(s) have been scanned
Scan process 'services.exe' - '26' Module(s) have been scanned
Scan process 'winlogon.exe' - '64' Module(s) have been scanned
Scan process 'csrss.exe' - '11' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '1119' files ).


Starting the file scan:

Begin scan in 'C:\'
Begin scan in 'D:\' <New Volume>


End of the scan: Friday, August 06, 2010 20:48
Used time: 58:58 Minute(s)

The scan has been done completely.

8740 Scanned directories
735487 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
735487 Files not concerned
9377 Archives were scanned
0 Warnings
0 Notes
561576 Objects were scanned with rootkit scan
4 Hidden objects were found
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: TR/Crypt.ZPACK.Gen Trojan06.08.2010. u 20:15 - pre 166 meseci
Naravno da je uspelo...
Rescue Disk moze da ocisti ono sto antivirus u aktivnom Windows-u ne moze...
Ukoliko budes nekad imao slicnih problema skini svez Avira Rescue Disk i odradi sve isto...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

[es] :: Zaštita :: TR/Crypt.ZPACK.Gen Trojan

[ Pregleda: 2937 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.