IP: *.eu.org 16.04.06, 00:15
Jak usunąć plik senssrv.dll z c:\WINN\system32 ?
Już nie wiem jak mam tego trojana usunąć
Obserwuj wątek
    • kolobos Re: trojan 16.04.06, 02:02
      Wklej log z hijackthis.
    • v0lrath Re: trojan 16.04.06, 09:48
      Ja bym wszedł w tryb awaryjny i spróbował usunąć.
      Najlepiej w trybie samej linii poleceń, jeśli w danej wersji windy jest dostępny.
      A jak nie da rady to podłączyć jako drugi dysk z dyskiem z zainstalowanym
      systemem (u siebie lub u znajomego) i usuń (startując z jego systemu i jego dysku).
      Chyba że masz FAT32 a nie np. NTFS - to można wystartować z dyskietki startowej
      i spróbować usunąć.
      • Gość: monika Re: trojan IP: *.eu.org 16.04.06, 15:04
        Cześć! Wklejam loga:
        Logfile of HijackThis v1.99.1
        Scan saved at 14:58:26, on 2006-04-16
        Platform: Windows 2000 Dodatek SP. 2 (WinNT 5.00.2195)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINN\System32\smss.exe
        C:\WINN\system32\winlogon.exe
        C:\WINN\system32\services.exe
        C:\WINN\system32\lsass.exe
        C:\WINN\system32\svchost.exe
        C:\WINN\system32\spoolsv.exe
        C:\WINN\System32\svchost.exe
        C:\WINN\system32\regsvc.exe
        C:\WINN\system32\MSTask.exe
        C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
        C:\WINN\explorer.exe
        C:\WINN\System32\WBEM\WinMgmt.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
        C:\WINN\System32\eventwvr.exe
        C:\WINN\System32\internat.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
        C:\WINN\TEMP\ECB7.tmp
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\a\Pulpit\hijackthis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
        F2 - REG:system.ini: Shell=explorer.exe
        "C:\Program
        Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
        O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} -
        C:\WINN\system32\winbrume.dll
        O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program
        Files\iMeshBar\bar\2.bin\IMESHBAR.DLL
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
        c:\program files\google\googletoolbar.dll
        O3 - Toolbar: @msdxmLC.dll,-1@1045,&Radio -
        {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINN\System32\msdxm.ocx
        O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program
        Files\iMeshBar\bar\2.bin\IMESHBAR.DLL
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
        files\google\googletoolbar.dll
        O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINN\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
        Files\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
        O4 - HKLM\..\Run: [eventwvr] C:\WINN\System32\eventwvr.exe
        O4 - HKLM\..\Run: [KAVPersonal50] "D:\Program Files\Kaspersky Anti-Virus
        Personal\kav.exe" /minimize
        O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy
        Sweeper\SpySweeper.exe" /startintray
        O4 - HKLM\..\RunServices: [eventwvr] C:\WINN\System32\eventwvr.exe
        O4 - HKCU\..\Run: [internat.exe] internat.exe
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash
        /minimized
        O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
        O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
        Folders\ibm00001.exe"
        O4 - HKCU\..\Run: [eventwvr] C:\WINN\System32\eventwvr.exe
        O4 - Startup: Morpheus.lnk = D:\Program Files\Morpheus\Morpheus.exe
        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
        Office\Office\OSA9.EXE
        O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL
        Server\80\Tools\Binn\sqlmangr.exe
        O8 - Extra context menu item: &Google Search - res://C:\Program
        Files\Google\googletoolbar.dll/cmsearch.html
        O8 - Extra context menu item: Backward &Links - res://C:\Program
        Files\Google\googletoolbar.dll/cmbacklinks.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program
        Files\Google\googletoolbar.dll/cmcache.html
        O8 - Extra context menu item: Si&milar Pages - res://C:\Program
        Files\Google\googletoolbar.dll/cmsimilar.html
        O8 - Extra context menu item: Translate into English - res://C:\Program
        Files\Google\googletoolbar.dll/cmtrans.html
        O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
        C:\WINN\web\related.htm
        O9 - Extra 'Tools' menuitem: Show &Related Links -
        {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINN\web\related.htm
        O16 - DPF: ING Bank Online - ssl.bsk.com.pl/bskonlreg/component/INGOnl.cab
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
        www.kaspersky.pl/resources/virusscanner/kavwebscan_unicode.cab
        O16 - DPF: {52B52056-649E-420F-8C05-F424B3606D21} (StdVideoCtl Class) -
        www.multivision.com.hk/StdVideo.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
        software-dl.real.com/213a13883023a8f58e19/netzip/RdxIE601.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class)
        - security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
        acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {A6916797-7ABD-4F07-93AE-098B6F543129} (CO2Player Class) -
        www.lemontv.pl/lmctrlp.cab
        O16 - DPF: {E7544C6C-CFD6-43EA-B4E9-360CEE20BDF7} (MainControl Class) -
        skaner.mks.com.pl/SkanerOnline.cab
        O20 - Winlogon Notify: SensSrv - C:\WINN\SYSTEM32\senssrv.dll
        O20 - Winlogon Notify: WRNotifier - C:\WINN\SYSTEM32\WRLogonNTF.dll
        O23 - Service: Usługa administracyjna Menedżera dysków logicznych (dmadmin) -
        VERITAS Software Corp. - C:\WINN\System32\dmadmin.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation
        - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: kavsvc - Kaspersky Lab - D:\Program Files\Kaspersky Anti-Virus
        Personal\kavsvc.exe
        O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc.
        - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

        • kolobos Re: trojan 16.04.06, 15:25
          Platform: Windows 2000 Dodatek SP. 2 (WinNT 5.00.2195) <- dlaczego masz SP2
          zamiast SP4?! Jak juz wszystko usuniesz to zainstaluj aktualizacje z
          www.windowsupdate.com

          Zakoncz:
          C:\WINN\System32\eventwvr.exe
          C:\WINN\TEMP\ECB7.tmp <- usun wszystko z temp.

          W hijackthis:
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no
          file)
          F2 - REG:system.ini: Shell=explorer.exe
          "C:\Program
          Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
          O2 - BHO: (no name) - {196B9CB5-4C83-46F7-9B06-9672ECD9D99B} -
          C:\WINN\system32\winbrume.dll <- usun plik z dysku
          O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program
          Files\iMeshBar\bar\2.bin\IMESHBAR.DLL
          O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program
          Files\iMeshBar\bar\2.bin\IMESHBAR.DLL <- usun i najlepiej odinstaluj imesh
          O4 - HKLM\..\Run: [eventwvr] C:\WINN\System32\eventwvr.exe
          O4 - HKLM\..\RunServices: [eventwvr] C:\WINN\System32\eventwvr.exe
          O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web
          Folders\ibm00001.exe" <- usun plik ibm z dysku.
          O4 - HKCU\..\Run: [eventwvr] C:\WINN\System32\eventwvr.exe <- usun plik z dysku
          O4 - Startup: Morpheus.lnk = D:\Program Files\Morpheus\Morpheus.exe <-
          najlepiej odinstaluj i nie uzywaj tego smiecia.
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
          Office\Office\OSA9.EXE <- usun z autostartu
          O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
          C:\WINN\web\related.htm
          O9 - Extra 'Tools' menuitem: Show &Related Links -
          {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINN\web\related.htm
          O16 - DPF: {52B52056-649E-420F-8C05-F424B3606D21} (StdVideoCtl Class) -
          www.multivision.com.hk/StdVideo.cab
          O16 - DPF: {A6916797-7ABD-4F07-93AE-098B6F543129} (CO2Player Class) -
          www.lemontv.pl/lmctrlp.cab
          O20 - Winlogon Notify: SensSrv - C:\WINN\SYSTEM32\senssrv.dll <- usun plik z
          dysku

          W razie problemow z usuwaniem plikow uzyj killbox'a.

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka