Vaag terugkerend virus

Pagina: 1
Acties:

  • Carel
  • Registratie: Juni 2000
  • Laatst online: 31-08 15:35
Vraag me niet hoe ik het voor elkaar krijg, maar ik heb een vage dialer in mijn systeem. Deze wordt wel gevonden door zowel norton als panda en wordt zogenaamd verwijderd ( in mn geheuegen zit ie en in temp i-net files). Na een nieuwe install had ik hem ook weer heel snel ( zit dus volgens mij ergens in een exe van me)

Echter nu komt het vage... hij komt altijd terug !.. na ee tijdje zie ik dat er iets gedownload wordt en staat dit virus er weer in ?.. Ook zorgt het virus ervoor dat de verbinding soms weg valt en kan ik er verder weinig van vinden. Soms start ie een nieuwe IE en op komt met een 0900 dial screen.

IK weet dat dit achter program files/Carpe Diem staat.
Ook heb geprobeerd deze exe's in die dir corrupt te maken/ deleten etc etc. Elke keer kom er gewoon weer deze dir bij bij de parisvoyeur.exe en cdupdate.exe.


Ook in het register/startup kan ik geen link vinden vinden hier naartoe.. het zal dus via een omweg gaan.

  • Denker
  • Registratie: Maart 2003
  • Laatst online: 19-08 11:51
Je moet ook geen twee virusscanners tegelijk draaien.
Heb je al met Ad-aware en Spybot gecheckt op spyware?

  • Mike Jarod
  • Registratie: Januari 2002
  • Niet online
HijackThis: http://www.siena.edu/antivirus/software/HijackThis.exe

Post je log maar tussen [ code ] tags :)

  • Carel
  • Registratie: Juni 2000
  • Laatst online: 31-08 15:35
Denker schreef op 14 februari 2004 @ 19:06:
Je moet ook geen twee virusscanners tegelijk draaien.
Heb je al met Ad-aware en Spybot gecheckt op spyware?
Nee ik doe ze ook niet tegelijk... en ad aware krijgt hem ook niet weg.

code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
Logfile of HijackThis v1.97.3
Scan saved at 7:21:44 PM, on 2/14/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\NoAds\NoAds.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\Pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\AVENGINE.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\nutsrv4.exe
C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\WebProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://awebfind.biz/sp.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCpl28Deamon] ndriver.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Titanium Antivirus 2004\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner\RivaTuner.exe" /S
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NuTCSetupEnviron] C:\Program Files\Rational\Rational Test\nutcroot\bin\ncoeenv.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\webcheck.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Onderzoek (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37986.4044560185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O19 - User stylesheet: C:\WINDOWS\hh.htt (file missing) (HKLM)


http://awebfind.biz/ ... dat spoort idd ook niet
quicktime van apple heb ik trouwen ook nooit installed, die kwam er ook opeens bij.

[ Voor 97% gewijzigd door Carel op 14-02-2004 19:27 ]


Verwijderd

Al aangepast door TS :)

[ Voor 100% gewijzigd door Verwijderd op 14-02-2004 19:36 ]


  • Mike Jarod
  • Registratie: Januari 2002
  • Niet online
Richting ronde archief:
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://awebfind.biz/sp.htm
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O19 - User stylesheet: C:\WINDOWS\hh.htt (file missing) (HKLM)


Vind ik niks over, zou weghalen:
code:
1
O4 - HKLM\..\Run: [NvCpl28Deamon] ndriver.exe
Potentieel Bugbear virus :? Nee maar wel een trojan, weg ermee :) bron
code:
1
O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\webcheck.exe


BTW wil je die ndriver.exe zippen en mailen naar Schouw? ( submitvirus [at] yahoo [dot] com ). Omdat Google de file niet herkent is het misschien iets nieuws.

Edit2: kijk even hier: http://www.sophos.com/virusinfo/analyses/w32spybotad.html
W32/Spybot-AD is a worm that spreads through network shares and has backdoor capabilities.

Upon execution, the worm drops copies of itself into the Windows system folder as mdosft.exe and winx32.exe and sets the following registry entries so that it is run on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NvCpl28Deamon
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\NvCpl28Deamon

W32/Spybot-AD drops itself to the startup folder of shared network drives as xddl32.exe, adds an entry in win.ini of the remote computer and also schedules a remote job to run the copy of the worm.

W32/Spybot-AD monitors running processes and terminates regedit.exe, taskmgr.exe, msconfig.exe, netstat.exe vshwin32.exe, avgnt.exe and persfw.exe if found running.

The worm logs on to a predefined IRC server to wait for backdoor commands.
Kortom scan nog even al je netwerkdrives/shares met een andere virusscanner die dit ding herkent.

[ Voor 30% gewijzigd door Mike Jarod op 14-02-2004 19:43 ]


  • Carel
  • Registratie: Juni 2000
  • Laatst online: 31-08 15:35
OK, alvast bedankt voor de reacties... hier thuis zijn 8 pc's dus ik ga ff alles doorzoeken, want ik wordt helemaal gek van dit gekloot..

Die ndriver kan ik momenteel niet vinden.... ik w8 ff af, ik heb alles wat inderdaad verd8 is eraf gesmeten nu.. echter is het meestal weer over 2 dagen raak ofzo en ga ik idd dus nu alle 8 pc's op het netwerk hierzo afscannen, want het zou idd een hoop verklaren.

Verwijderd

Carel schreef op 14 februari 2004 @ 19:52:
OK, alvast bedankt voor de reacties... hier thuis zijn 8 pc's dus ik ga ff alles doorzoeken, want ik wordt helemaal gek van dit gekloot..

Die ndriver kan ik momenteel niet vinden.... ik w8 ff af, ik heb alles wat inderdaad verd8 is eraf gesmeten nu.. echter is het meestal weer over 2 dagen raak ofzo en ga ik idd dus nu alle 8 pc's op het netwerk hierzo afscannen, want het zou idd een hoop verklaren.
Voor de zekerheid:
Als je een pc gecleand hebt, laat hem dan ff los van je netwerk, zodat er niet alsnog een besmetting via het netwerk kan plaatsvinden.
Het lijkt iets onbekends, dus je weet niet wat het kan.

Denk hierbij aan het Blastervirus, waar je niks voor hoeft te doen, maar wat je krijgt als je onbeschermd aan het net hangt ;)
Pagina: 1