Dodaj do ulubionych

Bloodhound.Packed

IP: *.internetdsl.tpnet.pl 07.10.04, 22:52
Norton wykryl tego wirusa i nie mogl go usunac wiem ze byly podobne tematy
ale w logu mam inaczej, nie wiem ktore pliki trzeba usunac
prosze o sprawdzenie i pomoc

Logfile of HijackThis v1.98.2
Scan saved at 21:21:21, on 2004-10-07
Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
D:\Program Files\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
D:\PROGRA~1\SERV-U\ServUDaemon.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\ntvdm.exe
D:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
D:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\WINDOWS\System32\ctfmon.exe
D:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
D:\Program Files\Netropa\Onscreen Display\OSD.exe
D:\WINDOWS\System32\winit.exe
D:\Program Files\Messenger\msmsgs.exe
F:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
www.google.pl/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
F3 - REG:win.ini: load=D:\YDPDict\watch.exe
O1 - Hosts: 200.199.201.81:80 www.tronix.brturbo.com # ADDED WITH BRTurboTool
by BADMoJO
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1
\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
D:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program
Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-
90002030B8EE} - D:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - D:\PROGRA~1
\STARDO~1\SDIEInt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
D:\PROGRA~1\FLASHGET\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
D:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32
\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -
atboottime
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] D:\Program Files\Netropa\Multimedia
Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_05
\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec
Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec
Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [DemonStarter] C:\Program
Files\PWN\Definicje\Bin\Starter.exe
O4 - HKLM\..\Run: [upddateit] winit.exe
O4 - HKLM\..\RunServices: [upddateit] winit.exe
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Action Manager 32.lnk = D:\Program
Files\ScannerU\AM32.exe
O8 - Extra context menu item: Download with Star Downloader - D:\Program
Files\Star Downloader\sdie.htm
O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Pobierz używając Download &Express'a -
G:\download flash\Add_Url.htm
O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - D:\Program
Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a -
D:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
D:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - D:\WINDOWS\System32\msjava.dll
O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
D:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094941550409
O17 - HKLM\System\CCS\Services\Tcpip\..\{661D9113-BAA7-4C0B-8550-
075FA3D99986}: NameServer = 217.17.34.50,194.204.152.34

Obserwuj wątek
    • netsec Re: Bloodhound.Packed 08.10.04, 09:35
      Gość portalu: spy x napisał(a):

      > Norton wykryl tego wirusa i nie mogl go usunac wiem ze byly podobne tematy
      > ale w logu mam inaczej, nie wiem ktore pliki trzeba usunac
      > prosze o sprawdzenie i pomoc
      >
      > Logfile of HijackThis v1.98.2
      > Scan saved at 21:21:21, on 2004-10-07
      > Platform: Windows XP Dodatek SP. 1 (WinNT 5.01.2600)
      > MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
      >
      > Running processes:
      > D:\WINDOWS\System32\smss.exe
      > D:\WINDOWS\system32\winlogon.exe
      > D:\WINDOWS\system32\services.exe
      > D:\WINDOWS\system32\lsass.exe
      > D:\WINDOWS\system32\svchost.exe
      > D:\WINDOWS\System32\svchost.exe
      > D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      > D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      > D:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      > D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      > D:\WINDOWS\system32\spoolsv.exe
      > D:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
      > D:\Program Files\Norton AntiVirus\navapsvc.exe
      > D:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      > D:\PROGRA~1\SERV-U\ServUDaemon.exe
      > D:\WINDOWS\System32\svchost.exe
      > D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      > D:\WINDOWS\Explorer.EXE
      > D:\WINDOWS\system32\ntvdm.exe
      > D:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
      > D:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
      > D:\Program Files\Common Files\Symantec Shared\ccApp.exe
      > D:\WINDOWS\System32\ctfmon.exe
      > D:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
      > D:\Program Files\Netropa\Onscreen Display\OSD.exe
      > D:\WINDOWS\System32\winit.exe
      > D:\Program Files\Messenger\msmsgs.exe
      > F:\hijackthis\HijackThis.exe
      >
      > R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      > www.google.pl/
      > R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
      > F3 - REG:win.ini: load=D:\YDPDict\watch.exe
      > O1 - Hosts: 200.199.201.81:80 www.tronix.brturbo.com # ADDED WITH BRTurboTool
      > by BADMoJO
      > O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
      > D:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      > O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1
      > \SPYBOT~1\SDHelper.dll
      > O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} -
      > D:\PROGRA~1\FLASHGET\jccatch.dll
      > O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program
      > Files\Norton AntiVirus\NavShExt.dll
      > O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-
      > 90002030B8EE} - D:\PROGRA~1\FlashFXP\IEFlash.dll
      > O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - D:\PROGRA~1
      > \STARDO~1\SDIEInt.dll
      > O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
      > D:\PROGRA~1\FLASHGET\fgiebar.dll
      > O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
      > D:\WINDOWS\System32\msdxm.ocx
      > O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
      > D:\Program Files\Norton AntiVirus\NavShExt.dll
      > O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\System32
      > \spool\drivers\w32x86\3\hpztsb07.exe
      > O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -
      > atboottime
      > O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] D:\Program Files\Netropa\Multimedia
      > Keyboard\MMKeybd.exe
      > O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_05
      > \bin\jusched.exe
      > O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec
      > Shared\ccApp.exe"
      > O4 - HKLM\..\Run: [SSC_UserPrompt] D:\Program Files\Common Files\Symantec
      > Shared\Security Center\UsrPrmpt.exe
      > O4 - HKLM\..\Run: [DemonStarter] C:\Program
      > Files\PWN\Definicje\Bin\Starter.exe
      > O4 - HKLM\..\Run: [upddateit] winit.exe
      > O4 - HKLM\..\RunServices: [upddateit] winit.exe
      > O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\ctfmon.exe
      > O4 - Global Startup: Action Manager 32.lnk = D:\Program
      > Files\ScannerU\AM32.exe
      > O8 - Extra context menu item: Download with Star Downloader - D:\Program
      > Files\Star Downloader\sdie.htm
      > O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
      > res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      > O8 - Extra context menu item: Pobierz używając Download &Express'a -
      > G:\download flash\Add_Url.htm
      > O8 - Extra context menu item: Ściągnij przy pomocy FlashGet'a - D:\Program
      > Files\FlashGet\jc_link.htm
      > O8 - Extra context menu item: Ściągnij wszystko przy pomocy FlashGet'a -
      > D:\Program Files\FlashGet\jc_all.htm
      > O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
      > D:\WINDOWS\System32\msjava.dll
      > O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
      > 00401C608501} - D:\WINDOWS\System32\msjava.dll
      > O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
      > D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      > O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
      > D:\PROGRA~1\FLASHGET\flashget.exe
      > O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
      > 0050BA6940E3} - D:\PROGRA~1\FLASHGET\flashget.exe
      > O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
      > <a
      href="v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094941550409"
      target="_blank">v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1094941550409</a>
      > O17 - HKLM\System\CCS\Services\Tcpip\..\{661D9113-BAA7-4C0B-8550-
      > 075FA3D99986}: NameServer = 217.17.34.50,194.204.152.34

      Tu masz opis podobnego przypadku.
      W Twoim wypadku należy usunąc w HiJackThis te wpisy:

      O1 - Hosts: 200.199.201.81:80 www.tronix.brturbo.com # ADDED WITH BRTurboTool
      by BADMoJO
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1
      \SPYBOT~1\SDHelper.dll
      O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - D:\PROGRA~1
      \STARDO~1\SDIEInt.dll
      O4 - HKLM\..\Run: [upddateit] winit.exe
      O4 - HKLM\..\RunServices: [upddateit] winit.exe

      Pozostałe działania jak w podanym przykładzie ;)
    • netsec Re: Bloodhound.Packed podobny przypadek 08.10.04, 09:37
      forum.gazeta.pl/forum/72,2.html?f=430&w=13236242&a=14989084

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka