Jump to content

SUBIECTE NOI
« 1 / 5 »
RSS
Caut medic chirurg

Substante de baza la pastile de r...

Taiere meri gradina

Inginer PNA / CNS ROMATSA
 "DIY" UPS 12V - Scoate cu...

Grafic in excel

Extensie de browser care sa reduc...

Priza smart monitorizare consum e...
 Unde reclam spamul electoral?

Putem avea incredere in Victor Or...

Inel de logodna

Certificat de deces pentru un cet...
 Programare weekend

Profit News scos din grila RCS...

Piulite rare

Sistem rezidential Sigenergy
 

IM-Worm.Win32.Qucan.a / Sohanad.E

- - - - -
  • Please log in to reply
44 replies to this topic

#37
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,229
  • Înscris: 10.02.2006
ionut2, instalezi SP3 pentru Windows XP si de asemenea toate upadte-urile pentru Windows mai apoi.

#38
Eduard15

Eduard15

    New Member

  • Grup: Members
  • Posts: 4
  • Înscris: 14.11.2010
buna .
am urmat pasii tai dar la HiJackThis nu mi-a gasit ce trebuia.
nici svhost nu am gasit
prin urmare nu am rezolvat nici problema .
cred ca am si eu un astfel de virus.
nu mi se mai deschide task managerul si ruleaza destul de greu
imi poti da un sfat despre ce ar trebui sa fac in cazul meu? :worthy:

#39
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
De unde ai ajuns tu la concluzia ca e acelasi virus ?!

#40
Eduard15

Eduard15

    New Member

  • Grup: Members
  • Posts: 4
  • Înscris: 14.11.2010
pai , dupa cum ai spus, m-am uitat la simptome si am constatat ca ask managerul nu mi se deschide, pagina web mi s-a schimbat insa run-ul a ramas


sau la ce a spus daisuke m-am uitat

#41
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Multi malware lasa in urma aceste simtome.

Descarca

Malwarebytes Anti-Malware 1.50.1.1100

si salveaza-l pe Desktop.

Instaleaza-l si la sfarsit asigura-te ca ai bifat urmatoarele: Update Malwarebytes' Anti-Malware si Launch Malwarebytes' Anti-Malware. Apoi apasa Finish.

[ http://i53.tinypic.com/13za8f8.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i54.tinypic.com/2dtq001.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i53.tinypic.com/qrerzm.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i54.tinypic.com/2wnpfr6.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i54.tinypic.com/15i7tea.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i55.tinypic.com/1ikapc.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i51.tinypic.com/2efpyfl.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i56.tinypic.com/5xo5g8.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i53.tinypic.com/2e2dnkn.png - Pentru incarcare in pagina (embed) Click aici ]

Dupa lansarea programului, click pe tab-ul Update si apasa butonul Check for Updates pentru a verifica daca definitiile descarcate sunt ultimele.

Database version: 5XXX

[ http://i52.tinypic.com/9fyxjr.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i52.tinypic.com/5ytef5.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i51.tinypic.com/2gw53z7.png - Pentru incarcare in pagina (embed) Click aici ]

Click pe tab-ul Scanner, selecteaza Perform full scan si apoi apasa pe Scan.

[ http://i54.tinypic.com/23h3pj7.png - Pentru incarcare in pagina (embed) Click aici ]

La terminarea scanarii apasa OK si apoi Show Results.

[ http://i55.tinypic.com/1z1yavt.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i55.tinypic.com/2cygmc5.png - Pentru incarcare in pagina (embed) Click aici ]

Asigura-te ca e totul bifat si apoi apasa Remove Selected.

[ http://i53.tinypic.com/2rrqi2q.png - Pentru incarcare in pagina (embed) Click aici ]

La final se va deschide un fisier in Notepad cu rezultatele scanarii. Posteaza continutul lui aici.

[ http://i53.tinypic.com/1zxazrk.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i56.tinypic.com/2enrbwj.png - Pentru incarcare in pagina (embed) Click aici ]

Daca ai dat restart pentru indepartare malware din PC, log-ul il gasesti in fereastra principala in cadrul tab-ului Logs. Verifica sa fie ultimul(dupa data din numele fisierului .txt.)

[ http://i51.tinypic.com/2yllhk5.png - Pentru incarcare in pagina (embed) Click aici ]

[ http://i53.tinypic.com/1zxazrk.png - Pentru incarcare in pagina (embed) Click aici ]

#42
Eduard15

Eduard15

    New Member

  • Grup: Members
  • Posts: 4
  • Înscris: 14.11.2010
iti multumesc mult cristi.
stiu ca nu este asta topicul bun dar care antivirus mi-l recomanzi? :worthy:

#43
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
http://forum.softped...howtopic=437728

#44
Eduard15

Eduard15

    New Member

  • Grup: Members
  • Posts: 4
  • Înscris: 14.11.2010
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Versiunea bazei de date: 5786

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2/17/2011 9:39:37 PM
mbam-log-2011-02-17 (21-39-37).txt

Modul de scanare: Scanare completa (C:\|D:\|)
Obiecte scanate: 38031
Timp trecut: 22 minute, 19 secunde

Procese din Memorie Infectate: 2
Module de Memorie Infectate: 0
Chei de Registru Infectate: 29
Valori de Registru Infectate: 2
Date din Registru Infectate: 0
Foldere Infectate: 0
Fisiere Infectate: 3

Procese din Memorie Infectate:
c:\program files\common files\microsoft shared\web components\jkss.exe (Malware.Gen) -> 1720 -> Unloaded process successfully.
c:\program files\common files\microsoft shared\web components\jkss.exe (Malware.Gen) -> 1860 -> Unloaded process successfully.

Module de Memorie Infectate:
(Nu au fost detectate obiecte malicioase)

Chei de Registru Infectate:
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1602F07D-8BF3-4c08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C55CA95C-324B-451C-B2D2-6E895AA75FEC} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ClickPotatoLiteAX.Info.1 (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ClickPotatoLiteAX.Info (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1602F07D-8BF3-4C08-BDD6-DDDB1C48AEDC} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ClickPotatoLiteAX.UserProfiles.1 (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ClickPotatoLiteAX.UserProfiles (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{AC6D819E-AA8F-4418-A3BB-D165C1B18BB5} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{814BAA91-DC22-4350-87D6-0C86E93F7F08} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{419EDA30-6DFF-432C-B534-E15D899ABEE4} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B58926D6-CFB0-45D2-9C28-4B5A0F0368AE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-CD68-4f36-8D02-8C43722EE5DA} (Adware.Hotbar) -> Quarantined and deleted successfully.

Valori de Registru Infectate:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jkss.exe (Malware.Gen) -> Value: jkss.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jkss.exe (Malware.Gen) -> Value: jkss.exe -> Quarantined and deleted successfully.

Date din Registru Infectate:
(Nu au fost detectate obiecte malicioase)

Foldere Infectate:
(Nu au fost detectate obiecte malicioase)

Fisiere Infectate:
c:\program files\common files\microsoft shared\web components\jkss.exe (Malware.Gen) -> Quarantined and deleted successfully.
c:\program files\clickpotatolite\bin\10.0.630.0\clickpotatolitesaax.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
c:\documents and settings\all users\documents\19792079 (Spyware.Passwords.XGen) -> Quarantined and deleted successfully.
:huh:

#45
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Restart. Instaleaza un antivirus.

Anunturi

Chirurgia spinală minim invazivă Chirurgia spinală minim invazivă

Chirurgia spinală minim invazivă oferă pacienților oportunitatea unui tratament eficient, permițându-le o recuperare ultra rapidă și nu în ultimul rând minimizând leziunile induse chirurgical.

Echipa noastră utilizează un spectru larg de tehnici minim invazive, din care enumerăm câteva: endoscopia cu variantele ei (transnazală, transtoracică, transmusculară, etc), microscopul operator, abordurile trans tubulare și nu în ultimul rând infiltrațiile la toate nivelurile coloanei vertebrale.

www.neurohope.ro

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Forumul Softpedia foloseste "cookies" pentru a imbunatati experienta utilizatorilor Accept
Pentru detalii si optiuni legate de cookies si datele personale, consultati Politica de utilizare cookies si Politica de confidentialitate