
Coś mnie dziś zaatakowało, zaczęły się samoistnie tworzyć m.in. pliki:
c:\2.cmd c:\Autorun.inf
Po ich ręcznym usunięciu za chwilę były z powrotem.
Puściłem ComboFix, poniżej podaję log, ale nie mam 100% pewności, czy już wszystko będzie działać.
Wie ktoś jak się można tym robactwem zarazić (przeglądarka, poczta)?
Bo rozprzestrzenia się nieźle - podłączyłem dysk do drugiego kompa (przed ComboFix), żeby usunąć jakimś zwykłym antywirem i od razu załatwił mi ten zdrowy!
Log z ComboFix:
- Kod: Zaznacz wszystko
ComboFix 08-08-18.05 - ja 2008-08-20 11:25:51.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows 2000 Professional 5.0.2195.4.1250.1.1045.18.253 [GMT 2:00]
Running from: C:\1\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\2.cmd
C:\autorun.inf
C:\Documents and Settings\ja\UserData
C:\Documents and Settings\ja\UserData\index.dat
C:\WINNT\system32\btfunc.dll
C:\WINNT\system32\Cfx32.lic
C:\WINNT\system32\cfx32.ocx
C:\WINNT\system32\ckvo.exe
C:\WINNT\system32\ckvo0.dll
C:\WINNT\system32\ckvo1.dll
C:\WINNT\Web\default.htt
D:\2.cmd
D:\Autorun.inf
E:\2.cmd
E:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-07-20 to 2008-08-20 )))))))))))))))))))))))))))))))
.
2008-08-20 11:16 . 08-08-20 11:16 <DIR> d-------- C:\1
2008-08-20 10:24 . 08-08-20 10:24 <DIR> d-------- C:\fsaua.data
2008-08-20 10:14 . 08-08-20 10:14 84,992 --a------ C:\WINNT\system32\ckvo0-.dll
2008-08-20 10:12 . 08-08-20 10:12 <DIR> d-------- C:\FOUND.000
2008-08-20 10:12 . 08-08-20 10:12 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_278.dat
2008-08-20 06:17 . 01-03-02 20:51 368,710 --a------ C:\WINNT\system32\msisam11.dll
2008-08-20 06:17 . 01-10-01 19:47 335,360 --a------ C:\WINNT\system32\wmstream.dll
2008-08-20 06:17 . 01-03-02 20:51 241,725 --a------ C:\WINNT\system32\msuni11.dll
2008-08-20 06:17 . 01-10-01 19:50 163,840 --a------ C:\WINNT\system32\mindex.dll
2008-08-20 06:17 . 01-10-01 19:47 118,784 --a------ C:\WINNT\system32\wmsdmoe.dll
2008-08-20 06:17 . 01-10-01 19:49 89,088 --a------ C:\WINNT\system32\wmidx.ocx
2008-08-20 06:13 . 07-07-30 19:19 38,232 --a------ C:\WINNT\system32\wucltui.dll.mui
2008-08-20 06:13 . 07-07-30 19:20 30,040 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2008-08-20 06:13 . 07-07-30 19:20 30,040 --a------ C:\WINNT\system32\wuapi.dll.mui
2008-08-20 06:13 . 07-07-30 19:18 21,336 --a------ C:\WINNT\system32\wuaueng.dll.mui
2008-08-20 05:59 . 08-08-20 05:59 16,384 --a------ C:\WINNT\system32\Perflib_Perfdata_274.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 09:33 --------- d-----w C:\Program Files\Gnokii
2008-07-11 09:46 --------- d-----w C:\Documents and Settings\ja\Dane aplikacji\AdobeUM
2008-07-10 10:10 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-09 08:14 --------- d-----w C:\Program Files\Sun
2008-06-10 09:10 256 ----a-w C:\Documents and Settings\ja\pool.bin
2007-03-21 16:58 271 ---h--w C:\Program Files\desktop.ini
2007-03-21 16:58 22,039 ---h--w C:\Program Files\folder.htt
2000-03-20 22:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
2007-05-22 17:14 8,784 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-05-22 17:17 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [06-09-11 04:40 218032]
"internat.exe"="internat.exe" [00-03-21 00:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINNT\System32\igfxtray.exe" [05-09-20 10:35 94208]
"igfxhkcmd"="C:\WINNT\System32\hkcmd.exe" [05-09-20 10:32 77824]
"igfxpers"="C:\WINNT\System32\igfxpers.exe" [05-09-20 10:36 114688]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [04-10-14 09:11 1388544]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [08-06-10 04:27 144784]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [08-07-19 16:38 78008]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [04-08-22 17:05 81920]
"NeroFilterCheck"="C:\WINNT\system32\NeroCheck.exe" [01-07-09 10:50 155648]
"PCSuiteTrayApplication"="C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [06-06-15 12:36 229376]
"LogMeIn GUI"="C:\Program Files\LogMeIn\LogMeInSystray.exe" [06-10-06 19:55 303864]
"RemoteControl"="C:\WINNT\system32\rmctrl.exe" [05-01-25 06:03 32768]
"Client Access Service"="C:\Program Files\IBM\Client Access\cwbsvstr.exe" [05-10-19 05:40 20531]
"Client Access Check Version"="C:\Program Files\IBM\Client Access\cwbckver.exe" [05-10-19 05:40 53299]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [05-10-26 16:17 159744]
"Synchronization Manager"="mobsync.exe" [03-06-19 12:05 111888 C:\WINNT\system32\mobsync.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"internat.exe"="internat.exe" [00-03-21 00:00 20752 C:\WINNT\system32\internat.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-06-19 12:05 188688]
C:\Documents and Settings\ja\Menu Start\Programy\Autostart\
PopTray.lnk - C:\Program Files\PopTray\PopTray.exe [2006-09-16 15:01:16 1666048]
C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 07:05:26 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll
R1 aswSP;avast! Self Protection;C:\WINNT\system32\drivers\aswSP.sys [08-07-19 16:35 ]
R2 aswFsBlk;aswFsBlk;C:\WINNT\system32\DRIVERS\aswFsBlk.sys [08-07-19 16:37 ]
R2 aswMon;avast! Standard Shield Support;C:\WINNT\system32\drivers\aswMon.sys [08-01-17 17:34 ]
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\RaInfo.sys [06-10-06 19:56 ]
R2 nedrv;nedrv;C:\WINNT\system32\drivers\nedrv.sys [03-10-23 12:57 ]
R2 npdrv;npdrv;C:\WINNT\system32\drivers\npdrv.sys [07-02-03 20:23 ]
R3 usbhub20;Obsługa głównego koncentratora USB 2.0;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 12:05 ]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINNT\system32\DRIVERS\k510bus.sys [08-03-19 13:55 ]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINNT\system32\DRIVERS\k510mdfl.sys [08-03-19 13:55 ]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINNT\system32\DRIVERS\k510mdm.sys [08-03-19 13:55 ]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);C:\WINNT\system32\DRIVERS\k510mgmt.sys [08-03-19 13:55 ]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINNT\system32\DRIVERS\k510obex.sys [08-03-19 13:55 ]
S3 KS-959;Kingsun KS-959 USB Infrared Adapter;C:\WINNT\system32\DRIVERS\KS-959.sys [05-09-05 02:59 ]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kamsoft - C:\WINNT\system32\ckvo.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\ja\Dane aplikacji\Mozilla\Firefox\Profiles\att87w4j.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-20 11:26:50
Windows 5.0.2195 Service Pack 4 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-20 11:27:10
ComboFix-quarantined-files.txt 2008-08-20 09:27:08
Pre-Run: 2,952,499,200 bajtów wolnych
Post-Run: 3,051,466,752 bajtów wolnych
127
Czy coś jeszcze trzeba zrobić?
PS. Jeżeli coś zrobiłem nie tak jak zwyczaje tego forum - to sorki, jestem tu 1-szy raz....