Dodaj do ulubionych

Wirus w Windows\Temp

IP: *.e-wro.net.pl 12.03.07, 22:32
Norton AntiVirus pokazuje mi komunikat "High Risk":
Object Name: C:\WINDOWS\TEMP\temp10.tmp
Wirus Name: Downloader
Action Taken: Unable to repair this file

Jak klikam OK, to plik ten znika ze wskazanej ścieżki, ale za to pojawia się
natychmiast następny, w tym samym folderze \TEMP tylko numerek w nazwie jest
inny. Jak klikam znów to pojawia się ten sam komunikat, jednak dotyczący
pliku z folderu kwarantanna Nortona AntiVirusa. I tak w kółko

Czy ktoś wie jak mam to zwalczyć?!

Z góry dzięki za pomoc
Obserwuj wątek
    • Gość: Kolobos Re: Wirus w Windows\Temp IP: *.escom.net.pl 12.03.07, 22:47
      Uzyj: siri.urz.free.fr/Fix/SmitfraudFix_En.php zrob to co masz
      opisane pod "Clean" po uzyciu utworzy sie log, ktory wklej na forum.

      Scan tym:
      www.pandasoftware.com/activescan/pol/activescan_principal.htm
      www.spywareinfo.com/xscan.php
      www.bitdefender.com/scan8/ie.html
      Kasacja smieci z temp itd przy pomocy:
      www.atribune.org/content/view/25/2/
      Na koniec wklej log z hijackthis.
      • Gość: KK Re: Wirus w Windows\Temp IP: *.e-wro.net.pl 12.03.07, 23:30
        SmitFraudFix v2.148

        Scan done at 23:23:50,70, 2007-03-12
        Run from C:\Documents and Settings\Mushir\Pulpit\SmitfraudFix
        OS: Microsoft Windows XP [Wersja 5.1.2600] - Windows_NT
        The filesystem type is NTFS
        Fix run in normal mode

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Killing process


        »»»»»»»»»»»»»»»»»»»»»»»» hosts


        127.0.0.1 localhost

        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

        GenericRenosFix by S!Ri


        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""


        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

        Registry Cleaning done.

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll


        »»»»»»»»»»»»»»»»»»»»»»»» End

        • kolobos Re: Wirus w Windows\Temp 12.03.07, 23:50
          Nie zakladaj nowych watkow!
          Wklej log z hijackthis.
          • Gość: KK Re: Wirus w Windows\Temp IP: *.e-wro.net.pl 13.03.07, 00:04
            A co to jest hijackthis?
            • Gość: KK Re: Wirus w Windows\Temp IP: *.e-wro.net.pl 13.03.07, 00:19
              Logfile of HijackThis v1.99.1
              Scan saved at 00:18:20, on 2007-03-13
              Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\Program Files\Eset\nod32krn.exe
              C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
              C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
              C:\Program Files\Eset\nod32kui.exe
              C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
              C:\Program Files\Norton AntiVirus\navapsvc.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Documents and Settings\Mushir\Pulpit\hijackthis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
              www.google.pl/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
              C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1
              \FlashGet\jccatch.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
              Files\Java\jre1.5.0_11\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
              c:\program files\google\googletoolbar2.dll
              O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program
              Files\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} -
              C:\Program Files\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
              files\google\googletoolbar2.dll
              O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} -
              C:\PROGRA~1\FlashGet\fgiebar.dll
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec
              Shared\ccApp.exe"
              O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1
              \SNDMon.exe /Consumer
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11
              \bin\jusched.exe"
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common
              Files\Ahead\Lib\NeroCheck.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [Skype] "C:\Program
              Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-
              88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
              O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common
              Files\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
              Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
              Office\Office\OSA9.EXE
              O8 - Extra context menu item: &Google Search - res://c:\program
              files\google\GoogleToolbar2.dll/cmsearch.html
              O8 - Extra context menu item: &Translate English Word - res://c:\program
              files\google\GoogleToolbar2.dll/cmwordtrans.html
              O8 - Extra context menu item: Backward Links - res://c:\program
              files\google\GoogleToolbar2.dll/cmbacklinks.html
              O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program
              files\google\GoogleToolbar2.dll/cmcache.html
              O8 - Extra context menu item: Download All by FlashGet - C:\PROGRA~1
              \FlashGet\jc_all.htm
              O8 - Extra context menu item: Download using FlashGet - C:\PROGRA~1
              \FlashGet\jc_link.htm
              O8 - Extra context menu item: Similar Pages - res://c:\program
              files\google\GoogleToolbar2.dll/cmsimilar.html
              O8 - Extra context menu item: Translate Page into English - res://c:\program
              files\google\GoogleToolbar2.dll/cmtrans.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
              C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-
              00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} -
              C:\PROGRA~1\FlashGet\flashget.exe
              O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-
              0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
              C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-
              00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {A9ED6AA2-D9D4-4D71-9586-E293E2E3580B} (GameDesire
              Marbles&Diamonds&Runes) - 67.15.101.3/g_bin/pl/marbles_2_0_0_27.cab
              O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common
              Files\Adobe Systems Shared\Service\Adobelmsvc.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation -
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation -
              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation -
              C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation -
              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1
              \LUCOMS~1.EXE
              O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec
              Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero
              BackItUp\NBService.exe
              O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program
              Files\Eset\nod32krn.exe
              O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec
              Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
              O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton
              AntiVirus\SAVScan.exe
              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation -
              C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec
              Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
              O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program
              Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program
              Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

              • kolobos Re: Wirus w Windows\Temp 13.03.07, 00:21
                Log jest ok, ale nie instaluj wiecej nie jedenego antywirusa. Odinstaluj nortona i zostaw tylko nod.

                • Gość: KK Re: Wirus w Windows\Temp IP: *.e-wro.net.pl 13.03.07, 00:22
                  OK. Tak też zrobię
                  Dzięki serdeczne

Nie masz jeszcze konta? Zarejestruj się


Nakarm Pajacyka