2008-09-02, 18:32
#1
Tjenare, Laddade precis ner ett fusk till ett spel innan ja läste vad andra personer hade skrivit om det, det var visst ett virus
En av sakerna som hände var att firefox slutade fungera om och om igen, Även fast jag itne hade det på. Kom upp en sån där "firefox har slutat fungera windows söker efter en lösning" så jag raderade firefox å datorn fungerade okej igen, men tror knappast att viruset försvann så lätt så skulle vilja ha lite hjälp av nån snäll människa att fixa detta, När jag gjorde en hijacklogga att klistra in här så kom det här medelandet upp:
"For some reason your system denied write access to the hosts file. If any hijacked domains are in this file, HijackThis may not be able to fix this", vad betyder detta?
Tack på förhand!
Skulle visst vara nått av dom här virusena
File: archer.rar
Status:
INFECTED/MALWARE
MD5: 4bebb594b794616f47fd1bbe7fbce9f0
Packers detected:
-
Bit9 reports: File not found
Scanner results
Scan taken on 22 Jan 2008 19:38:59 (GMT)
A-Squared
Found Backdoor.Win32.Agent.rk
AntiVir
Found BDS/Bifrose.Gen
ArcaVir
Found Trojan.Agent.Rk
Avast
Found Win32:Agent-DDN
AVG Antivirus
Found BackDoor.Agent.YE
BitDefender
Found Backdoor.Agent.RK
ClamAV
Found Trojan.Delf-117
CPsecure
Found BackDoor.W32.Agent.rk
Dr.Web
Found BackDoor.Bifrost.522
F-Prot Antivirus
Found W32/Agent.AGL
F-Secure Anti-Virus
Found Backdoor.Win32.Agent.bac
Fortinet
Found W32/Agent.RK!tr.bdr
Ikarus
Found Backdoor.Win32.Agent.RK
Kaspersky Anti-Virus
Found Backdoor.Win32.Agent.bac
NOD32
Found Win32/Agent.NAK
Norman Virus Control
Found W32/Agent.AYPA
Panda Antivirus
Found nothing
Rising Antivirus
Found Backdoor.Agent.ful
Sophos Antivirus
Found Mal/Behav-053
VirusBuster
Found Backdoor.Agent.EOI
VBA32
Found nothing
Hijack loggan fixades sig ändå
En av sakerna som hände var att firefox slutade fungera om och om igen, Även fast jag itne hade det på. Kom upp en sån där "firefox har slutat fungera windows söker efter en lösning" så jag raderade firefox å datorn fungerade okej igen, men tror knappast att viruset försvann så lätt så skulle vilja ha lite hjälp av nån snäll människa att fixa detta, När jag gjorde en hijacklogga att klistra in här så kom det här medelandet upp:"For some reason your system denied write access to the hosts file. If any hijacked domains are in this file, HijackThis may not be able to fix this", vad betyder detta?
Tack på förhand!
Skulle visst vara nått av dom här virusena
File: archer.rar
Status:
INFECTED/MALWARE
MD5: 4bebb594b794616f47fd1bbe7fbce9f0
Packers detected:
-
Bit9 reports: File not found
Scanner results
Scan taken on 22 Jan 2008 19:38:59 (GMT)
A-Squared
Found Backdoor.Win32.Agent.rk
AntiVir
Found BDS/Bifrose.Gen
ArcaVir
Found Trojan.Agent.Rk
Avast
Found Win32:Agent-DDN
AVG Antivirus
Found BackDoor.Agent.YE
BitDefender
Found Backdoor.Agent.RK
ClamAV
Found Trojan.Delf-117
CPsecure
Found BackDoor.W32.Agent.rk
Dr.Web
Found BackDoor.Bifrost.522
F-Prot Antivirus
Found W32/Agent.AGL
F-Secure Anti-Virus
Found Backdoor.Win32.Agent.bac
Fortinet
Found W32/Agent.RK!tr.bdr
Ikarus
Found Backdoor.Win32.Agent.RK
Kaspersky Anti-Virus
Found Backdoor.Win32.Agent.bac
NOD32
Found Win32/Agent.NAK
Norman Virus Control
Found W32/Agent.AYPA
Panda Antivirus
Found nothing
Rising Antivirus
Found Backdoor.Agent.ful
Sophos Antivirus
Found Mal/Behav-053
VirusBuster
Found Backdoor.Agent.EOI
VBA32
Found nothing
HTML-kod:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:41:37, on 2008-09-02
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Razer\Diamondback 3G\razerhid.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Eraser\Eraser.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Razer\Diamondback 3G\razertra.exe
C:\Program Files\Razer\Diamondback 3G\razerofa.exe
C:\Program Files\VentriloMIX\Ventrilo 2.1.4.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\notepad.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\helppane.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\DllHost.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.daemon-search.com/startpage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Diamondback] C:\Program Files\Razer\Diamondback 3G\razerhid.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe -hide
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [{20AC6A5E-E932-7E5A-03BC-802E1232E070}] C:\Users\EazY\AppData\Roaming\Win32.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
--
End of file - 4082 bytes
Hijack loggan fixades sig ändå