2009-08-21, 18:26
#1
Hej!
Wow har blivit hackat och efter det har vi kört lite datorstädning med Norton, Adaware. Men det verkar vara nåt skit kvar, vad är det och hur ska man få bort?
Malware:
Malwarebytes' Anti-Malware 1.40
Databasversion: 2670
Windows 5.1.2600 Service Pack 3
2009-08-21 16:31:37
mbam-log-2009-08-21 (16-31-37).txt
Skanningstyp: Snabb skanning
Antal skannade objekt: 96888
Förfluten tid: 10 minute(s), 13 second(s)
Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 7
Infekterade registervärden: 1
Infekterade registerdataposter: 2
Infekterade mappar: 0
Infekterade filer: 1
Infekterade minnesprocesser:
(Inga illasinnade poster hittades)
Infekterade minnesmoduler:
(Inga illasinnade poster hittades)
Infekterade registernycklar:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransp orterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransp orterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
Infekterade registervärden:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\SharedDLLs\C:\Program\Delade filer\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
Infekterade registerdataposter:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infekterade mappar:
(Inga illasinnade poster hittades)
Infekterade filer:
C:\Program\Delade filer\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
Hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:51:42, on 2009-08-21
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program\CyberLink\PowerCinema\PCMService.exe
C:\Program\HP\HP Software Update\HPwuSchd2.exe
C:\Program\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\VM_STI.EXE
C:\Program\QuickTime\qttask.exe
C:\Program\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program\Delade filer\Teleca Shared\CapabilityManager.exe
C:\Program\MarkAny\ContentSafer\MAAgent.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\Program\Windows Live\Messenger\msnmsgr.exe
C:\Program\MySpace\IM\MySpaceIM.exe
C:\Program\Google\GoogleToolbarNotifier\GoogleTool barNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\Program\Personal\bin\Personal.exe
C:\Program\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program\Panasonic\LUMIXSimpleViewer\PhLeAutoRun .exe
C:\Program\Philips\SPC 300NC PC Camera\TrayMin300.exe
C:\Program\DELADE~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program\CyberLink\PowerCinema\Kernel\TV\CLCapSv c.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program\CyberLink\PowerCinema\Kernel\CLML_NTSer vice\CLMLServer.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\LightScribe\LSSrvc.exe
C:\Program\Delade filer\Teleca Shared\Generic.exe
C:\Program\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\CyberLink\PowerCinema\Kernel\TV\CLSched .exe
C:\Program\MySpace\IM\MySpaceIM.exe
C:\Program\Delade filer\PCSuite\Services\ServiceLayer.exe
C:\HP\KBD\KBD.EXE
C:\Program\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\WINDOWS\system32\WgaTray.exe
c:\windows\system\hpsysdrv.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
C:\Program\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Wow har blivit hackat och efter det har vi kört lite datorstädning med Norton, Adaware. Men det verkar vara nåt skit kvar, vad är det och hur ska man få bort?
Malware:
Malwarebytes' Anti-Malware 1.40
Databasversion: 2670
Windows 5.1.2600 Service Pack 3
2009-08-21 16:31:37
mbam-log-2009-08-21 (16-31-37).txt
Skanningstyp: Snabb skanning
Antal skannade objekt: 96888
Förfluten tid: 10 minute(s), 13 second(s)
Infekterade minnesprocesser: 0
Infekterade minnesmoduler: 0
Infekterade registernycklar: 7
Infekterade registervärden: 1
Infekterade registerdataposter: 2
Infekterade mappar: 0
Infekterade filer: 1
Infekterade minnesprocesser:
(Inga illasinnade poster hittades)
Infekterade minnesmoduler:
(Inga illasinnade poster hittades)
Infekterade registernycklar:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransp orterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransp orterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntiVirus) -> Quarantined and deleted successfully.
Infekterade registervärden:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\SharedDLLs\C:\Program\Delade filer\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
Infekterade registerdataposter:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infekterade mappar:
(Inga illasinnade poster hittades)
Infekterade filer:
C:\Program\Delade filer\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
Hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:51:42, on 2009-08-21
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\CTXFIHLP.EXE
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program\CyberLink\PowerCinema\PCMService.exe
C:\Program\HP\HP Software Update\HPwuSchd2.exe
C:\Program\Hewlett-Packard\OrderReminder\OrderReminder.exe
C:\WINDOWS\VM_STI.EXE
C:\Program\QuickTime\qttask.exe
C:\Program\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program\Delade filer\Teleca Shared\CapabilityManager.exe
C:\Program\MarkAny\ContentSafer\MAAgent.exe
C:\Program\Java\jre6\bin\jusched.exe
C:\Program\Windows Live\Messenger\msnmsgr.exe
C:\Program\MySpace\IM\MySpaceIM.exe
C:\Program\Google\GoogleToolbarNotifier\GoogleTool barNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program\Spybot - Search & Destroy\TeaTimer.exe
C:\Program\Personal\bin\Personal.exe
C:\Program\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program\Panasonic\LUMIXSimpleViewer\PhLeAutoRun .exe
C:\Program\Philips\SPC 300NC PC Camera\TrayMin300.exe
C:\Program\DELADE~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program\CyberLink\PowerCinema\Kernel\TV\CLCapSv c.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program\CyberLink\PowerCinema\Kernel\CLML_NTSer vice\CLMLServer.exe
C:\Program\Java\jre6\bin\jqs.exe
C:\Program\Delade filer\LightScribe\LSSrvc.exe
C:\Program\Delade filer\Teleca Shared\Generic.exe
C:\Program\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program\CyberLink\PowerCinema\Kernel\TV\CLSched .exe
C:\Program\MySpace\IM\MySpaceIM.exe
C:\Program\Delade filer\PCSuite\Services\ServiceLayer.exe
C:\HP\KBD\KBD.EXE
C:\Program\Norton 360\Engine\3.0.0.134\ccSvcHst.exe
C:\WINDOWS\system32\WgaTray.exe
c:\windows\system\hpsysdrv.exe
C:\Program\iTunes\iTunesHelper.exe
C:\Program\iPod\bin\iPodService.exe
C:\Program\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
C:\Program\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe