Zarazen svchost.exe

*P*A*B*L*O*

Aktivan član
Poruka
1.686
Znaci situacija je sledeca: drugar koji ima PC vec 4 godine, zarazio je PC virusom: Trojan program Trojan-Downloader.Win32.Agent.bwx koji se ushtekao u file svchost.exe.... Kaspersky sa najnovijim definicijama ne moze da ga desinfikuje a pored ovog virusa je nashao josh oko 35 koje je bez problema obrisao.... SpyBoot je nashao josh nekoliko virusa a sve je bez problema obrisao ali nije nashao ovaj shto je nashao Kaspersky..... Probao sam i na Safe Mode ali tu ne Kaspersky ne moze da skenira startup objekte pa ne nalazi ovaj virus.....
OS je Win XP + SP2 + update-i do februara07...

Kako da mu reshim taj problem a da ne zahteva reinstal windows-a ?
 
Kako misliš uštekao u svchost.exe?
Hoćeš da kažeš da se pokreće kroz njega? Ili ga je možda patchovao?
Bilo bi dobro imati malo više detalja, ako bude trebalo ''ručno'' da se uklanja.
Za početak probaj nekim drugim skenerom iz Safe Moda, npr. ftp://ftp.drweb.com/pub/drweb/cureit/cureit.exe ( kada ga pokreneš on odradi početno skeniranje, pa tek onda mu ti obeležiš diskove i pokreneš scan ).
Nabaci ovde i HijackThis log. Verovatno se malware pokreće kao servis pa mu zato KAV ništa ne može.
Takođe izvrti Spybot u Safe Modu.
 
Pa lepo se ushtekao u njega i pokrece se prilikom start-up-a sa windowsom.......
Znachi file svchost.exe je infektiran virusom a KAV ne moze da ga desinfektira....
Znam da je svchost.exe sistemski proces ( i da ih ima jedno 5 komada ) pa nisam hteo da ga obrishem ruchno ( normalno najpre ubijem onaj shto koristi 99 % CPU )....
Ovo za Spyboot se nisam setio da ga izvrtim u Safe Mode.....
Ovo sve cu moci probati samo sutra poshto sam sad kuci a tom drugaru da dam neshto da uradi nece uraditi kako valja... :)
 
Problem reshen.... I to reshio ga je sam drugar a ne ja, posle kad sam ga izribao da ima PC 5 godina a nema pojma da instalira win i otarasi se virusa..... Otishao je na Safe Mode i preko Spy Boot-a obrisao taj virus i kaze da je sad sve ok.....
 
Ipak problem nije bio reshen kao shto mi je to drugar preneo....
Pokrenuo sam CureIt.exe iz safe mode-a i kaze da je nashao virus u file-u svchost.exe i pita me da ga izlechi i ja odgovorim potvrdno i pishe da je deleted ali kad se ponovo loguje na normal mode virus je opet tu....
Evo shta kaze Hijack This log file:
Logfile of HijackThis v1.99.1
Scan saved at 19:43:15, on 12.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files\HijackThis\HijackThis.exe
C:\Program Files\Opera\Opera.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {8BF884A4-CF81-4E00-B7C1-076FCE6CFDD7} - (no file)
O2 - BHO: (no name) - {98C6247B-C38D-40EB-880B-B8FAFF36257B} - (no file)
O2 - BHO: Mario Forever Toolbar Helper - {A20854FD-DDB5-4931-8F76-D11EA2364D94} - C:\Program Files\Mario Forever Toolbar\v3.2.0.0\MarioForever_Toolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Mario Forever Toolbar - {71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7} - C:\Program Files\Mario Forever Toolbar\v3.2.0.0\MarioForever_Toolbar.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: qomnoon - qomnoon.dll (file missing)
O20 - Winlogon Notify: sstts - C:\WINDOWS\
O20 - Winlogon Notify: winemx32 - winemx32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
 
*P*A*B*L*O*:
O2 - BHO: (no name) - {8BF884A4-CF81-4E00-B7C1-076FCE6CFDD7} - (no file)
O2 - BHO: (no name) - {98C6247B-C38D-40EB-880B-B8FAFF36257B} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O20 - Winlogon Notify: qomnoon - qomnoon.dll (file missing)
O20 - Winlogon Notify: sstts - C:\WINDOWS\
O20 - Winlogon Notify: winemx32 - winemx32.dll (file missing)


O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\msvcrtd.exe
Svetlo crveno su neispravne stavke.
Tamno crveno, boldovano je ''zlikovac'' - Trojan/Flooder.

Znači... Iz safe moda: pobrisati sve spomenute stavke. Preimenuj c:\windows\system32\msvcrtd.exe u bilo šta ( za sada ga nemoj brisati! ).
Pronađi ovaj ključ u registru: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters . U njemu bi trebala da bude stavka: "DisableRawSecurity"=DWORD:00000001 - obriši je ( samo tu stavku, ne ceo ključ! ).

Izvrti najnoviji DrWeb CureIt!, restartuj pc u Normal Mode. Nakon toga možeš obrisati onaj preimenovani fajl.
Odradi još jedan HT sken i postavi log.

Čisto da spomenem... ima tu još nekih sitnica u logu, ali ništa bitno sada. Kasnije ću objasniti...
 
DEFINITION OF: MSVCRTD.EXE
Safety Rating: Known Malware, do not run
Malware Family: Part of Malware group - Dropper Payload
Determination: Automatically determined using Prevx centralized heuristics
Malware Form: EXPLOIT
Protection: Prevx is a very powerful PC security product, it will protect, disinfect, cleanup and remove MSVCRTD.EXE and safeguard your PC against viruses, trojans, worms, spyware, rootkits and adware
New Users: You can download the full Prevx product and use it to cleanup and remove MSVCRTD.EXE and other infections free of charge, then leave it to monitor your PC for other infections
http://info.prevx.com/downloadprevx2.asp
 
Jesi li nekada koristio taj program?
Vrlo je zanimljivo da na tom sajtu bukvalno za svaki fajl piše isto: njihov softver to rutinski rešava.
Takođe kažu: First seen: Feb 3 2007 (GMT).
A pogledaj ovaj link: http://www.castlecops.com/t193508-msvcrtd_exe.html
Znači, 28. juna 2007. praktično nijedan AV ga ne prepoznaje u ovoj varijanti, sem dva koji to rade pogrešno - po njima je to generic malware... a ovo je daleko od toga - trojanac zamišljen za DoS flooding ( po McAfee-ovoj analizi starije varijante početkom juna )... :wink:
 
Mozda je najbolje dr_Bora da prvo raruje ili zipuje, svejedno, ovaj fajl, a onda da ga uploaduje na www.file-wire.net i da nam posalje link uploadovanog fajla na PP, meni, tebi, jos nekome ko ima iskustva, a ko zeli da se igra sa malwareima, da ga analiziramo i da vidimo od cega je napravljen. Mozemo da ga posaljemo i na analizu raznim proizvodjacima antivirusa.
 
Pa, u principu, nije loša ideja. Mogao bi to da uradi.
Usput, dobra prilika i da se isproba softver koji je snejks spomenuo ( bar za mene, pošto ga nisam pre koristio ).
Ne kažem da PrevX nije regularan softver, ali zvuči previše dobro i lagano. To me brine... :)
 
PrevX je odlican program, samo nije besplatan. Koliko se secam, a odavno nisam imao priliku da nesto procitam o njemu, nedostatak vremena na zalost, radi se o programu koji ima sasvim drugaciji koncept detekcije i rada od klasicnih zastitnih programa.
 

Back
Top