Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112

Deprecated: preg_replace(): The /e modifier is deprecated, use preg_replace_callback instead in /home/mati/domains/forum.programosy.pl/public_html/includes/bbcode.php on line 112
Wirus wincft.exe oraz dużo działających procesów • programosy.pl

  • Ogłoszenie:

Wirus wincft.exe oraz dużo działających procesów

Bezpieczeństwo systemów, usuwanie wirusów, dobieranie programów antywirusowych. Obowiązkowe logi w tym dziale: trzy z FRST + Gmer.

Wirus wincft.exe oraz dużo działających procesów

Postprzez tomi798 15 Wrz 2011, 15:35

reklama
Witam,otóż niedawno pożyczyłem sobie od znajomego netbooka i chciałem go trochę oczyścić ze zbędnych programów.Zainstalowałem avire,zeskanowałem i przeczyściłem cleanerem.Po jakimś czasie wykrywa mi tego właśnie wirusa wincft.exe ale nie można go usunąć.Drugą sprawą jest to że jest dość dużo działających procesów(w tej chwili 53)których nie znam.Proszę o pomoc w sprawie wirusa i możliwość wyłączenia zbędnych procesów.Tak jak napisałem jest to netbook,system windows xp SP3.

Kod: Zaznacz wszystko
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-09-15 15:14:07
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.01.0
Running: 5omk9q4i.exe; Driver: C:\DOCUME~1\MONIA\USTAWI~1\Temp\pxldypod.sys


---- System - GMER 1.0.15 ----

SSDT            A5B33A6E                                                                                                                      ZwCreateKey
SSDT            A5B33A64                                                                                                                      ZwCreateThread
SSDT            A5B33A73                                                                                                                      ZwDeleteKey
SSDT            A5B33A7D                                                                                                                      ZwDeleteValueKey
SSDT            A5B33A82                                                                                                                      ZwLoadKey
SSDT            A5B33A50                                                                                                                      ZwOpenProcess
SSDT            A5B33A55                                                                                                                      ZwOpenThread
SSDT            A5B33A8C                                                                                                                      ZwReplaceKey
SSDT            A5B33A87                                                                                                                      ZwRestoreKey
SSDT            A5B33A78                                                                                                                      ZwSetValueKey
SSDT            A5B33A5F                                                                                                                      ZwTerminateProcess

---- User code sections - GMER 1.0.15 ----

.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Program Files\Google\Chrome\Application\chrome.exe[3808] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\Google\Chrome\Application\chrome.exe[1976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002C0010
IAT             C:\Program Files\Google\Chrome\Application\chrome.exe[3808] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002C0010

---- Devices - GMER 1.0.15 ----

AttachedDevice  \FileSystem\Fastfat \Fat                                                                                                      fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001583bbb005                                                   
Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001583bbb005 (not active ControlSet)                               

---- EOF - GMER 1.0.15 ----



Nie działa mi skanowanie OTL,proszę napisać jakim innym programem mam to zeskanować.
tomi798
~user
 
Posty: 20
Dołączenie: 17 Maj 2011, 15:02



Wirus wincft.exe oraz dużo działających procesów

Postprzez wojtas 15 Wrz 2011, 17:14

jak nie działa ? spróbowałeś w awaryjnym ?? ( w temacie o OTL są różne rozszerzenia tej aplikacji zobacz ) ,jeśli nie uda się OTL to daj loga z DDS :

otl-dds-combofix-vt117885.html
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656



Wirus wincft.exe oraz dużo działających procesów

Postprzez tomi798 15 Wrz 2011, 17:30

otl
http://wklej.org/id/594423/

extras
http://wklej.org/id/594424/

Ok już działa
tomi798
~user
 
Posty: 20
Dołączenie: 17 Maj 2011, 15:02



Wirus wincft.exe oraz dużo działających procesów

Postprzez wojtas 15 Wrz 2011, 18:07

Uruchom OTL i w sekcji własne opcje skanowania / skrypt wklej:

:OTL
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query="
FF - prefs.js..browser.search.order.1: "Ask.com"
[2011-06-01 19:13:45 | 000,002,574 | ---- | M] () -- C:\Documents and Settings\MONIA\Dane aplikacji\Mozilla\Firefox\Profiles\2yfwhlei.default\searchplugins\askcom.xml
[2011-02-08 19:03:57 | 000,001,244 | ---- | M] () -- C:\Documents and Settings\MONIA\Dane aplikacji\Mozilla\Firefox\Profiles\2yfwhlei.default\searchplugins\winamp-search.xml
O3: - HKU\S-1-5-21-439199626-1318987518-222395546-1006\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\S-1-5-21-439199626-1318987518-222395546-1006\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3: - HKU\S-1-5-21-439199626-1318987518-222395546-1006\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\S-1-5-21-439199626-1318987518-222395546-1006\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [S6000Mnt] Rundll32.exe S6000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKLM..\Run: [WinDefender] C:\WINDOWS\Wincft.exe ()
O4 - HKLM..\RunOnce: [] File not found
O20 - Winlogon\Notify\RelevantKnowledge: DllName - (C:\Program Files\RelevantKnowledge\rlls.dll) - File not found
@Alternate Data Stream - 231 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:6BE50C2B
@Alternate Data Stream - 150 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:5D7E5A8F
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:CDFF58FE
@Alternate Data Stream - 149 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:93EB7685
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:4D066AD2
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E36F5B57
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:1A60DE96
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E1F04E8D
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:0B9176C0
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:E3C56885
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Dane aplikacji\TEMP:798A3728
[2011-08-06 21:08:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MONIA\Dane aplikacji\Search Settings
[2011-05-31 18:25:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\MONIA\Dane aplikacji\Dealio

:Files
C:\WINDOWS\Wincft.exe

:Reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"c:\program files\relevantknowledge\rlvknlg.exe"=-

:Commands
[emptytemp]
[emptyflash]


Kliknij wykonaj skrypt. I potwierdź reset komputera .

Następnie uruchamiasz OTL z opcją skanuj. Pokazujesz nowy log OTL.txt oraz raport z czyszczenia (zawartość notatnika, która otworzy się po restarcie).
Image
Awatar użytkownika
wojtas
*mod
 
Posty: 18165
Dołączenie: 13 Sty 2006, 16:00
Miejscowość: Krzeszyce
Pochwały: 1656




Powróć do Bezpieczeństwo

Kto jest na forum

Użytkownicy przeglądający to forum: Brak zarejestrowanych użytkowników oraz 7 gości