Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!
Showing posts with label trojan horses. Show all posts
Showing posts with label trojan horses. Show all posts

Thursday, August 1, 2013

lnk:runner-n

http://www.zonavirus.com/descargas/utilidades-satinfo.asp
password de descarga:  zonavirus
http://www.precisesecurity.com/tools-resources/adware-tools

Adware Tools


Avast! Browser Cleanup – Download and Usage

Avast! Browser Cleanup – Download and Usage

http://www.avast.com/store

Recent threats for computer user these days are not just limited to viruses, Trojans, spyware, or malware. Adware , toolbars and search redirects are now becoming problems for people. Antivirus program is not sufficient in blocking these kinds of threats due to the fact that it may arrive with some legitimate programs. Almost every free software that is made available for download contains adware that integrates toolbar and search engine into the browser without seeking for user’s approval. More
MalwareBytes Flash Scanner

MalwareBytes Flash Scanner

Malwarebytes’ Anti-Malware added new flash scanning option which searches for malicious objects in memory and load point locations. Worms and other kinds of flash drive viruses will utilize autorun functions of Windows to spread the infection to other drives connected on target PC. More
Flash Disinfector

Flash Disinfector

Flash Disinfector is a tool that will automatically remove unwanted files on removable USB drives, flash drives and memory sticks. Typically, computer Worms can enter the computer either when user download compromised files from insecure locations. Worms also spreads on spam email messages that come as attachment or links. More

SmitFraudFix

SmitFraudFix


SmitFraudFix is a tool created to remove various desktop hijackers, adware and malware installed by Zlob family of Trojans.
Note: This is the legitimate SmiFraudFix Removal Created by SiRi. The rogue program was called SmitFraud Fix Tool created to confuse computer users. More
Logs to assist in cleaning malware
===================
SPECIFIC INFECTIONS LOGS

If you have the hard drive infection and are no longer able to see your files/folders/start menu then do not run any temporary file cleaners but download and run the following programme:

  • Download RogueKiller  and save it on your desktop.

    NOTE: If using IE8 or better Smartscreen Filter will need to be disabled
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ... 
  •     Click on Scan
 

  • Wait for the end of the scan. 
  • The report has been created on the desktop. 
  • Click on the Delete button.
   
  • The report has been created on the desktop.
  • Next click on the ShortcutsFix 
  • The report has been created on the desktop.
Please attach:    All RKreport.txt text files located on your desktop.

If you cannot  Boot the computer

Please print these instruction out so that you know what you are doing

  • Download OTLPENet.exe to your desktop
  • Download Farbar Recovery Scan Tool and save it to a flash drive.
  • Ensure that you have a blank CD in the drive
  • Double click OTLPENet.exe and this will then open imgburn  to burn the file to CD
  • Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads  :)
  • Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
  • Insert the flash drive with FRST on it
  • Locate the flash drive and run FSRT
  • The tool will start to run.

  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.
===================
Combofix and Rkill are just for one off use - nothing gets installed. MBAM remains on the system but is not resident i.e it doesn't start at boot up time with Windows.
lnk:runner-b 
forum.avast.com/index.php?topic=85151.0
Download aswMBR.exe ( 1.8mb ) to your desktop.
 Double click the aswMBR.exe to run it  Click the "Scan" button to start scan 
http://forum.avast.com/index.php?topic=85151.0
TDSSKiller put out by Kaspersky:
http://forum.avast.com/index.php?topic=83140.15

http://www.virus-delete.com/es/guides/removal-tips/how-to-remove-lnkrunner-btrj-virus.html 
Guía eficaz para eliminar LNK: Runner-B [Trj] Virus
Paso 1: Vaya al Administrador de tareas con Ctrl + Alt + Delete y detener el proceso.
Paso 2.Trojan Remover LNK: Runner-B [Trj], buscar los archivos relacionados
. %AllUsersProfile% \ Application Data \ %AllUsersProfile% \ Datos de programa \ exe %UserProfile% \ Start Menu \ Programs \ LNK: Runner-B [Trj]
Paso 3.Retire LNK: Runner-B [Trj] registros de Troya:
Software \ Microsoft \ Windows \ CurrentVersion \ Run ". Exe" HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ System "DisableTaskMgr" = '1 ' HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ policies \ system "DisableTaskMgr "= '1 ' HKEY_CURRENT_USER \ Software \ Microsoft \ Internet Explorer \ Download" CheckExeSignatures "=" no "
http://blog.teesupport.com/manual-guide-to-remove-lnkrunner-btrj-virus/http://forum.avast.com/index.php?topic=66667.0

http://es.kioskea.net/forum/affich-483276-virus-con-extension-lnk
Archivos Con Extensión LNK Solucionado 1 son solo accesos directos los archivos y carpetas están ocultos deshabilitar en Herramientas/opciones de carpeta
Ocultar archivos Protegidos del sistema operativo
Ocultar las Extensiones de archivo para tipo sde archivo conocido
allí podrán ver los accesos directos y las carpetas ocultas luego eliminan los accesos directos encontraran los virus allí mismo les recomiendo que tengan instalado el antivirus algunos virus se eliminaran tendrán y los que no tendrán que eliminarlos manualmente las aplicaciones o virus luego las carpetas apareceran ocultas no se pueden cambiar sus atributos en este caso tendrán que utilizar el FPC File Propeties Changer lo pueden descargar de esta dirección y listo archivos recuperados.
Si desean Ayuda mi correo es clientmsn@hotmail.es
descarga el fpc de esta dirección
www.download25.com/install/file-properties-changer.html
--------------
1.- Primero borre todos los archivos contenidos en las siguientes carpetas...
Carpeta Temp
Carpeta Archivos Temporales de Internet
Carpeta Cookies
Carpeta Temp que esta contenida en Carpeta Win
Carpeta Prefetch que tambien esta contenida en Carpeta Win
Quizá algunos archivos no te dejará borrarlos y te dira que estan utilizandose... los podras borrar al llegar al paso 6...
2.- luego hice un escanneo completo con Dr. Web portable desde un USB y elimine lo que encontro.
3.- Luego instale Ad-Aware y lo corrí realizando un análisis completo del sistema activando incluso la casillas que dice buscar entradas de riesgo insignificante y de amenazas poco arriesgadas.... al concluir seleccionas lo que encontro y lo mandas a cuarentena...posteriormente entras a cuarentena y las elemine...
4 este paso casi va de la mano con el anterior porque al correr el Ad-Aware... aparecen virus que curiosamente el Antivirus no habia detectado por si solo.... y en mi caso tengo instalado el NOD32 pero haciendo el mismo procediemiento en otro equipo con Kaspersky resulto en lo mismo... aparecerán virus que tendras que ir eliminando o mandando a cuarentena para luego eliminar manualmente.....
5 Desactive Restaurar Sistema y reinicie para luego entrar a modo a prueba de fallos pulsando la tecla F8 repetidamente despues de que aparecen los textos de inicio...
6.- Repetí los pasos 1,2, 3 (obvio sin la instalación) y nuevamente elimine lo encontrado
7.- Reinicie el equipo y entre en modo normal
8.- Instale el CCleaner y le di una limpieza al registro
9.- Reinicie el equipo e instale el RegUnlocker.... este es la clave para arreglar lo que te sucede...pero no podiamos llegar a este paso sin eliminar todo aquello que hace los cambios fastidiosos...
en Reparar activas Repara la visualización de extensiones de archivo...y le das aplicar...
RegUnlocker es una aplicación que elimina las restricciones de los sistemas Windows serie NT, y repara los daños comunmente provocados por malwares. Pero hay que tener cuidado al usarlo...
Reinicias y listo.
lnk:runner-n
http://foros.zonavirus.com/viewtopic.php?f=6&t=33786 
parece tratarse de este RAMNIT:
http://www.precisesecurity.com/files-process/2010/11/16/watermark-exe/
WaterMark.exe
Executable file "WaterMark.exe" was identified as a threats.
Overall Risk Level:
Submitted on: 16 November 2010
Related to: W32.Ramnit.B
Classification: Trojan
File Directory:
%ProgramFiles%\Microsoft\
Startup Type:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\”Userinit” = “%system%\userinit.exe,,c%ProgramFiles%\microsoft\watermark.exe”

Help protect your computer from fake "WaterMark.exe" pop-up alert:
- Make firewall active.
- Always update operating system, internet browser and anti-virus programs.
- Install a separate anti-malware program aside from present anti-virus application if it is not included.
- Be cautious when clicking links. It can point your browser to download threats or visit malicious web site.

Tuesday, August 23, 2011

Backdoor.Tidserv TR.win32.TDDS

Quelle
generell werden versteckte dateien angelegt, um die erkennung/entfernung
des jeweiligen programms zu erschweren.
daemon tools arbeitet z.b. damit, aber wohl in erster linie malware, in dem punkt ist von adware bis zur backdoor alles drin.
es ist bzgl. tdss die frage, welche funktionen die module, die installiert werden, im einzelnen erfüllen.
das müßte man bei jedem betroffenen rechner individuell (es gibt nicht das tdss-rootkit oder den tdss-trojaner)
im detail untersuchen, siehe z.b. hier:
http://virscan.org/report/cd3ded7ae2...a0ae6b487.html
http://virscan.org/report/f99bda1df7...7e4a75950.html
http://virscan.org/report/bb12093b20...7bf9b0171.html
http://virscan.org/report/3d061614e7...46a11e2e7.html
bei einer "ursprünglichen" datei schlagen die scanner (mittlerweile)
sowohl bzgl. der komponente dns-changer als auch backdoor an:
http://www.virustotal.com/de/analisi...400bcd2daa403d
ein umbenennen der tdss-dateien, wie wohl beim letzten virscan-report vorgenommen,
kann eine möglichkeit sein, die dateien zu analysieren bzw. zu löschen.
auch blacklight bietet diese option an.
der einsatz von catchme bei versteckten einträgen ist ebenfalls denkbar.
mit diesem programm können kopien der dateien erzeugt werden,
die bei virustotal ausgewertet oder an av-labs gesendet werden können etc.
ob rootkit-tests(da kann man sicher noch mehr nennen) bzw. welche von tdss-varianten geblockt werden, sei dahingestellt.

Source
Download removal tool
Discovered: September 18, 2008
Updated: September 18, 2008 4:01:39 PM
Also Known As:
Backdoor:W32/TDSS [F-Secure], BKDR_TDSS [Trend], Win32/Alureon [Microsoft], Trojan-Dropper.Win32.TDSS [Kaspersky], Packed.Win32.TDSS [Kaspersky],
Type: Trojan
Systems Affected:
Windows XP, Windows Vista, Windows NT, Windows Server 2003, Windows 2000
1. Prevention and avoidance
1.1 User behavior and precautions
1.2 Patch operating system and software
Users are advised to ensure that their operating systems and any installed software are fully patched, and that antivirus and firewall software is up to date and operational. Users should turn on automatic updates if available, so that their computers can receive the latest patches and updates when they are made available.
1.3 Address blocking
Block access to the following addresses using a firewall, router, or add entries to the local hosts file to redirect the following addresses to 127.0.0.1:
  • 1il1il1il.com
  • 69b69b6b96b.com
  • b00882244.cn
  • b11335599.cn
  • countri1l.com
  • d45648675.cn
  • d92378523.cn
  • gnarenyawr.com
  • ikaturi11.com
  • jukdoout0.com
  • lkaturl71.com
  • m3131313.cn
  • ranmjyuke.com
  • rinderwayr.com
  • stableclick.com
  • stableclick2.com
  • swltcho0.com
  • updatemic0.com
  • updatemic1.cn
  • updatepanel.us
Note: The domains used by this threat change frequently.
2. Infection method
2.1 Forums and blogs
2.2 Hacked websites
2.3 File sharing, cracks, and warez
2.4 Affiliate schemes
3. Functionality
3.1. System modifications
 The following side effects may be observed on computers compromised by this Trojan. It should be noted that the threat uses a rootkit and other advanced stealth techniques to hide itself and its side effects. Upon successful installation and execution, any changes may not be visible on the compromised computer except where specialist tools are used to reveal them.
File creation
The following file(s) may be seen on the compromised computer.
  • %System%\spool\prtprocs\[TEMPORARY FILE NAME].tmp (Initial executable file)
  • %System%\drivers\TDSServ.sys
  • %System%\TDSS[RANDOM VALUE].log
  • %System%\TDSS[RANDOM VALUE].dat
  • %System%\TDSS[RANDOM VALUE].dll
  • %System%\drivers\H8SRTd.sys
File deletion
The following file(s) may be deleted from the compromised computer.
%System%\spool\prtprocs\[TEMPORARY FILE NAME].tmp (Initial executable file)
The following file(s) may be modified on the compromised computer.
  • atapi.sys (file infection)
  • advapi32.dll (file infection)
  • iastor.sys (file infection)
  • idechndr.sys (file infection)
  • ndis.sys (file infection)
  • nvata.sys (file infection)
  • vmscsi.sys (file infection)
The infection of system drivers and low level system files may cause instability in the operating system. It has been observed that certain computers infected by Backdoor.Tidserv may experience a Blue Screen of Death (BSOD) error after applying the Microsoft patches from February 9th, 2010.

Installation
During installation, the threat will cause spoolsv.exe (print spooler) to load the code for the threat. The code loaded into memory may hold one or more of the following logical files:
  • tdlwsp.dll (for hooking search queries)
  • tdlcmd.dll (main back door functionality)
  • config.ini (configuration details)
More information on the functionality of these files is as follows:
tdlcmd.dll
This file contains code to perform the following activities:
  • Download, decrypt, and execute files.
  • Update the configuration file.
tdlwsp.dll
The file contains code to perform the following activities (the latest variants have the functionality of tdlwsp.dll incorporated into tdlcmd.dll):
  • Hook Winsock routines to allow it to examine network traffic.
  • Log search engine strings and send them to a remote computer.
  • Inject or build HTTP responses so that it may modify or replace Web content returned by a Web server during a browsing session.
config.ini
This is a configuration file detailing bot identifiers, version information and other parameters.
Here is a sample config.ini file:
[main]
quote=Tomorrow will be the most beautiful day of Raymond K. Hessel's life
version=3.241
botid=xxxxx
affid=20273
subid=0
installdate=7.2.2010 16:8:33
builddate=7.2.2010 15:1:5
[injector]
*=tdlcmd.dll
[tdlcmd]
servers=https://d45648675.cn/;https://d92378523.cn/;https://91.212.226.62/
wspservers=http://b11335599.cn/;http://b00882244.cn/
popupservers=http://m3131313.cn/
clkservers=http://clkmfd001.ws/
version=3.64
delay=7200
[tasks]
tdlcmd.dll=https://91.212.226.64/pOxhFds1itxq
Once the code for the threat is installed, it deletes the original executable file that was executed and by doing this removes any obvious traces of its presence on the file system. Next, it infects one of the lowest level of drivers (atapi.sys) and manipulates it to load the threat when the computer is started.
It then creates an RC4-encrypted file system (the key used is "tdl") on the last sectors of the hard disk and stores the logical files (tdlwsp.dll, tdlcmd.dll, config.ini, and the original portion of the infected driver file) from the memory in the newly created file system. Once these actions are completed, there will be no visible traces of the threat when examining the file system of the computer except, eventually, for a change in the size of the infected driver file.
After the computer is restarted, the infected driver file (atapi.sys) will load the threat from the end sectors of the hard disk. It will create the hooks for the rootkit to do its job as well as injecting the code from tdlcmd.dll into all processes or into specific processes as defined in the config.ini file.
Manipulation of the Master Boot Record
More recent variants of Tidserv such as variant Backdoor.Tidserv.L (since August 2010) and Backdoor.Tidserv.M (January 2011) have adopted a technique pioneered by another sophisticated threat, Trojan.Mebroot. The technique involves replacing the existing MBR with another copy that enables the threat to get loaded first during the boot up process. The original MBR and components used by the threat is then copied to sectors of the hard disk that are unknown to the operating system, usually located in slack space after the end of the main partitions.

The MBR technique enables the threat to gain full control over the computer as it will be loaded even before the operating system. It takes advantage of the early loading to manipulate the boot up process to bypass security measures and ensure that it is executed each time the operating system is started.
Registry subkeys and entries created
  • HKEY_CURRENT_USER\Software\Mozilla\affid=
  • HKEY_CURRENT_USER\Software\Mozilla\subid=
  • HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT\injectors
  • HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT
  • HKEY_LOCAL_MACHINE\SOFTWARE\TDSS
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\H8SRTd.sys
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSServ
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSServ.sys
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDSServ.sys
Registry subkeys/entries deleted
No registry keys or entries are deleted.
Registry subkeys/entries modified (final values given)
No registry keys or entries are modified.
3.2. Network activity
3.3. Rootkit functionality

The threat uses an advanced rootkit and stealth techniques that provide highly effective cover from detection. It achieves this by:
  • Hiding its own files in the end sectors of the hard disk, bypassing the traditional file system.
  • Hiding the end sectors of the hard disk; the threat returns a 0-byte buffer when any other applications attempt to access or query the protected sectors.
  • Removing itself from the list of loaded drivers.
  • Infecting the lowest level of drivers and then returning the clean areas of the file when it is read by other processes.
4. Additional information

Friday, August 19, 2011

lpdd.exe

Source
The unsafe files using this name are associated with the malware group:
  • System Back Door
File Name Aliases LPDD.EXE can also use the following file names:
  • SMSC.EXE
  • TYF[1].JPG
  • UPDATE.EXE
  • UI41.EXE
  • 33131893.DAT
  • 54966891.DAT
  • 77109486.DAT
  • 22343863.EXE
=========     ==========
Fuente
Descarga, Instala y/o Actualiza estas herramientas, pero no las ejecutes aùn:
CCleaner
Malwarebytes' Anti-Malware
Ahora ejecuta de una por una y respetando estrictamente el orden:
a) CCleaner como indica su Manual en la opcion de Limpiador y Registro.
  • Se recomienda hacer una copia de seguridad en la ejecución de la opción Registro
b) Malwarebytes' Anti-Malware como indica su Manual
  • En la opción de Análisis Completo, al finalizar pulsas Mostrar resultados
  • Verificas que todo este seleccionado y pulsas Eliminar seleccionados
  • Si te lo solicita debes aceptar el Reinicio del sistema.
c) Realiza un examen en linea con ESET Online Scanner como indica su Manual
  • Al finalizar el examen no olvides Guardar el Reporte en el escritorio u otra locación
Pega los siguientes reportes:
  • Malwarebytes' Anti-Malware
  • ESET Online Scanner
si no.. en modo seguro
-------------------------
Desactiva Restaurar Sistema
Descarga y ejecuta USBFix como indica su Manual
  • Eliges la opcion de Supresion
Con Internet Explorer ingresa a la pagina de Panda ActiveScan 2.0
  • Realiza un examen como indica su Manual
Pega los reporte de panda ActiveScan y USBFix en la siguiente respuesta.
=========     ==========
http://forum.html.it/forum/showthread.php?s=3c793d2429231e0378ad7abe12d7d482&threadid=1471340&perpage=15&highlight=&pagenumber=1

URL: file://C:\WINDOWS\system32\lpdd.exe
Process: file://C:\WINDOWS\System32\svchost.exe
Infection: win32:Trojan-gen
----------------
scarica Hijackthis
http://www.trendsecure.com/portal/e...hijackthis.php#
1) crea una cartella dedicata e scompattalo al suo interno
Ricordati di mettere HIJACKTHIS in una cartella a lui dedicata (in Programmi o Documenti), l'importante è che non si trovi sul desktop o in cartelle temporanee è importante se vuoi salvare i backup

2) lancia il programma
3) nel menu' di destra clicca su "do a system scan and save a log file"
4) il programma ti rilascerà un file di report in formato txt, salvalo e postalo sul forum

------------
ci sono delle voci poco convincenti vediamo di controlare ill pc piu' a fondo
scarica combofix sul desktop
alla richiesta se vuoi installare la recovery console clicca su NO
esegui ComboFix.exe
segui le instruzioni
finita la scansione portati in C:\ e allega nella tua prossima risposta, il contenuto del file di testo Combofix.txt
come usare correttamente combofix
--------------


se ancora non lo hai fatto rimuovilo con OTC by OldTimer
eseguilo
Clicca su CleanUp.
Alla richiesta di riavvio clicca SI
prova a scaricarlo nuovamente e rinominalo durante il download
devi rinominare il file prima di salvarlo sul desktop in abc.exe
(per rinominare il file, quando lo scarichi ti chiede dove salvarlo e ti compare la casella "nome file" ,basta che cambi il nome che ti appare in abc.exe)
Fatto questo, clicca su start>esegui, nel box bianco copia e incolla questo comando, virgolette comprese:
"%userprofile%\desktop\abc.exe" /killall
Premi OK, se tutto va bene parte il programma che potrebbe impiegare molto (non fare altre manovre durante la scansione),una volta terminata, se tutto è andato bene, in C:\ dovresti trovare il file combofix.txt , riavvia in modalità normale e posta il contenuto del file
allegalo su wikisend
-----------------
Scarica e installa malwarebytes.
http://www.malwarebytes.org/
Aggiornalo: clicca sulla scheda "aggiornamenti" => "controlla aggiornamenti"
Esegui una "scansione completa" (seleziona l'opzione)
A scansione completa, fai clic su OK => Mostra i Risultati.
Assicurarti che tutto sia selezionato e clicca clic su Rimuovi selezionati.
Se ti chiede di riavviare, riavvia per completare il processo di pulizia.
Posta il rapporto .

dopo riprova a scaricare combofix e vedi se da lo stesso errore
-----------------
vai qui e amalizza il file che avsst continua a segnalarti
c:\windows\system32\lpdd.exe
salva la pagina e posta il link per il controllo
-------------
scarica CKScanner sul desktop
doppio clic sull'icona CKScanner.exe per lanciare il programma e quindi clic sul pulsante Search For Files.
Quando la scansione è terminata (- il cursore clessidra scompare quando la scansione è completata), clicca sulla lista pulsante Save to File. verrà creata sul desktop --- > ckfiles.txt
-------------
prima di finire e prima delle pulizie fammi questa scansione dovrebbe togliere qualcosa
Scarica sulk desktop questo programma clicca sulla sua icona e nella finestra dos che si aprirà scrivi 2 e premi Invio. Attendi il termine della scansione e posta qui il log che trovi in C:\FindyKill.txt
-------------
controlla il sistema con questo se dovesse uscire ancora quell'errore fai un controllo con dds
Doppio clic per avviare il file dds.scr, si apre una finestra dos, a fine scansione si apriranno 2 report,salvali con il nome che hanno e inseiscili su wikisend
------------
i due file che avenger non ha eliminato in quanto assenti io li vedo
c:\windows\system32\lpdd.exe
c:\windows\system32\ui41.exe
prevx li considera una Back Door e non finisce qui....il lpdd.exe si porta con se una bella famigliola tra cui anche ui41.exe
http://www.prevx.com/filenames/2236...1/LPDD.EXE.html
ora fai in questo modo
disattiva il ripristino e lascialo disattivato
rimuovi avast e java da pannello di controllo
ripeti la pulizia del registro e dei file temp come ti ho indicato prima
scarica avenger sul desktop
http://swandog46.geekstogo.com/avenger.zip
Decomprimi l'archivio
Avvia il file avenger.exe
Copi e incolli nella finestra: "Imput script here" questo testoCitazione:
Files to delete:
c:\windows\system32\lpdd.exe
c:\windows\system32\ui41.exe
Togli il segno di spunta dalla voce Scan for Rootkits
Premi il pulsante Execute
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà.
----------------
quel messaggio generic host processo for win32 servidces è stato chiuso e' generico bisognerebbe vedere cosa o chi lo provoca proviamo a controllare meglio il sistema ma ti anticipo che non e' assicurato il successo, solo una controllatina a qualcosa fuori posto soprattutto quella cartella della quale non mi fido (anche se tu non la vedi) voglio fare una verifica
Scarica systemscan
aprilo ed assicurati che tutte le opzioni siano spuntate, clicca su "Scan Now" al termine della scansione verranno rilasciati (sempre sul desktop all'interno della cartella suspectfile) due file. Allega il file con estensione .zip nella tua prossima risposta.
---------------
ecco
file zip su megaupload http://www.megaupload.com/?d=EAVWJMDC
report.txt su wikisend report.txt
----------------
controllando il rapporto abbastanza velocemente mi sono soffermato su queste cartelle
C:\WINDOWS\system32\1040
C:\WINDOWS\system32\1033
se non le conosci, eliminale
-----------------
non capisco da dove si generano queste infezioni ma forse ne abbiamo gia' parlato....
se hai ancora combofix rimuovilo con OTC by OldTimer
eseguilo
Clicca su CleanUp.
Alla richiesta di riavvio clicca SI
scaricalo nuovamente da qui e mettilo sul desktop
(non installare la recovery console)
Lascia lavorare il programma senza interferire
Allega il rapporto C:\ComboFix.txt nella tua risposta.
non usare il pc durante la scansione, nemmeno il mouse!
===================
scusatemi se intervengo.
Si tratta di un'infezione dovuta ad un net-worm.
Il pc è in una LAN?
Scarica ed installa un firewall, oltre al traffico in http (TCP 80) verifica i dati in-out verso le porte
21 - 22 - 42 - 69 - 135 - 443 - 445 - 1433
http://personalfirewall.comodo.com/free-download.html
===================
elimina la cartella qoobox se dovesse darti accesso negato o altro usa Inherit
mettilo nella stessa directory della cartella BackEnv e poi trascina la stessa cartella sull'icona di inherinit.Aspetta la scritta OK.
Poi potrai eliminare la cartella qoobox.
fai pulizia con ccleaner ( eseguilo due volte)
poi vai in provvisoria e scansiona il sistema con avira, vediamo cosa esce
----------------
andando un po a spulciare cosa sono quei trojan, ho trovato questa discussione che dice che non c'è nessun modo per eliminarlo
http://it.answers.yahoo.com/questio...20084842AAvhvYT
-----------------
Pensi d'avere un file infetto?
Invialo a
SuspectFile

http://amvinfe.myblog.it

-----------------
ho installato comodo : come faccio per far scansionare o bloccare quelle porte?
vai nella sezione "Firewall", apri "Eventi Firewall" e verifichi quali porte vengono utilizzate e da quali processi.
Se devi bloccare un'applicazione, portati nella scheda "Definire una nuova applicazione bloccata".
-----------------
l'unica cosa e' che ora hai due antivirus quello di comodo e avira
fixa queste righe
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
se non le conosci fixa anche queste
O17 - HKLM\System\CCS\Services\Tcpip\..\{C17DE59B-0A60-453E-99D6-F665C548C347}: NameServer = 156.154.70.25,156.154.71.25
O17 - HKLM\System\CS1\Services\Tcpip\..\{C17DE59B-0A60-453E-99D6-F665C548C347}: NameServer = 156.154.70.25,156.154.71.25




Wednesday, May 4, 2011

winlogon.exe troyano usa dispositivos USB

Inicio/ejecutar/regedit
alli te aparecera una ventana a la izquierda tienes que abrir el arbol:
HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/CurrentVersion/Run
Entonces a la izquierda te apareceran varios registros o archivos debes eliminarlos todos exepto el (Predeterminado)
Luego reinicias el sistema
En este punto debes buscar el archivo winlogon.exe, generalmente esta en la particion del sistema y en las otras particiones, ademas te recomiendo que busques el memorias USB, MP3, MP4, iPOD, o cualquier unidad suele copiarse automaticamente.
Cuando lo encuentres eliminalo y listo tu maquina esta curada.
J . "No borres el archivo winlogon que esta en el c:/windows/sistem32" es un archivo del sistema.
Fuente
Fichero/archivo: winlogon.exe
Nombre del proceso/tarea: Microsoft Windows Logon Process
1. winlogon.exe es el proceso de nombre Microsoft Windows Logon Process típico de los sistemas Windows NT, 2000 y XP.
Winlogon.exe se encarga de validar la identidad de un usuario en el sistema. Es un proceso esencial y no debería ser terminado.
Este fichero suele ubicarse en:
C:\WINDOWS\system32\winlogon.exe
2. Existen programas malignos que emplean este nombre o similar para pasar desapercibidos. Es el caso del virus W32.Netsky.D y del W32/Backdoor-CFB.
Dude de este archivo si se ubica en:
C:\winlogon.exe (gusano W32/Archiles.worm)
C:\WINDOWS\system32\dllcache\winlogon.exe (troyano Trojan.Win32.Patched.i)
C:\WINDOWS\system32\winlogon.exe (troyano Trojan.Win32.Patched.i)


C:\WINDOWS\ServicePackFiles\i386\winlogon.exe (troyano Trojan.Win32.Patched.i)

Algunos virus / malwares, utilizan el nombre de winlogon.exe (o similares) para infectar tu computadora de virus. Existen pruebas de que los virus W32.Netsky.D / Backdoor-CFB, se esconden con este nombre para pasar desapercibidos. Recomendamos, en cualquier caso, de manera inmediata, revisar tu computadora con el mejor antivirus gratis (Avira AntiVir), y descartar, de esa forma, presencia de bichos informáticos que puedan alterar el funcionamiento del sistema. 
Una nueva variante de AUTORUN.VB.ML con singulares características, ha hecho su aparición:
Se lanza desde un AUTORUN.ONF con mucha pala, desde una ruta bastante larga ...y con nombre de fichero
shell\open\command=h3wjKiH9lvqErmFO0mG6HlXplgLV3LeYuVHdaRjetLhEN80
DYiEPQXQY2sziakx2axTnS4SApIY8ELg3lSPkbMnv9Qm\S-3-7-01-3639077401-4404491267-704113574-
1143\EmrVQMar0BHh9hKKJ9vG6gt5zm2slhPo.exe
Queda residente.
Detiene Procesos y ventanas de propiedades.
Oculta ficheros del sistema y extensiones.
(Continuamente esta accediendo a la Disketera y al Pendrive)
Si existen Carpetas en la Disketera o en el Pendrive les pone attributos
(+s+h+r) y genera un link con el mismo nombre apuntando al malware:
"%SystemRoot%\system32\rundll32.exe
url.dll,FileProtocolHandler h3wjKiH9lvqErmFO0mG6HlXplgLV3LeYuVHdaRjetLhEN80DYiEPQXQY2sziakx2axTn
S4SApIY8ELg3lSPkbMnv9Qm\EmrVQMar0BHh9hKKJ9vG6gt5zm2slhPo.exe"
y modifica claves del registro de sistema para ser lanzado en cada reinicio, desde C:\Documents and Settings\Administrador\Administrador1\winlogon.exe"
y desactiva la posibilidad de lanzar una restauracion de sistema a un punto anterior al problema.
Se distingue facilmente por la modificación de la página de inicio a "Default_Page_URL"="http://www.nuevaq.fm"
Una vez eliminado el troyano con el ElistarA, se deben restablecer los cambios efectuados por el malware en el sistema, eliminando los links de llamada al troyano (en lugar de las carpetas) y quitando los atributos S, H y R a las carpetas ocultadas
Recuerdo que alguna vez nos han preguntado si esta web es maliciosa: "http://www.nuevaq.fm" , sin necesidad de que lo sea, ahora sabemos que la instala como pagina de inicio del I.E. este troyano, lo cual se indica para quien pueda estar interesado.
Lo pasamos a controlar a partir del ElistarA 21.42 de hoy como AUTORUN.VB.ML
 21-7-2010