Richting ronde archief:
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
| R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://awebfind.biz/sp.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://awebfind.biz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://awebfind.biz/sp.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://awebfind.biz/sp.htm
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\panda software\panda titanium antivirus 2004\pavlsp.dll
O19 - User stylesheet: C:\WINDOWS\hh.htt (file missing) (HKLM) |
Vind ik niks over, zou weghalen:
code:
1
| O4 - HKLM\..\Run: [NvCpl28Deamon] ndriver.exe |
Potentieel Bugbear virus 
Nee maar wel een trojan, weg ermee
bron
code:
1
| O4 - HKCU\..\Run: [System Update] C:\WINDOWS\System\webcheck.exe |
BTW wil je die ndriver.exe zippen en mailen naar Schouw? ( submitvirus [at] yahoo [dot] com ). Omdat Google de file niet herkent is het misschien iets nieuws.
Edit2: kijk even hier:
http://www.sophos.com/virusinfo/analyses/w32spybotad.htmlW32/Spybot-AD is a worm that spreads through network shares and has backdoor capabilities.
Upon execution, the worm drops copies of itself into the Windows system folder as mdosft.exe and winx32.exe and sets the following registry entries so that it is run on startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\NvCpl28Deamon
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\NvCpl28Deamon
W32/Spybot-AD drops itself to the startup folder of shared network drives as xddl32.exe, adds an entry in win.ini of the remote computer and also schedules a remote job to run the copy of the worm.
W32/Spybot-AD monitors running processes and terminates regedit.exe, taskmgr.exe, msconfig.exe, netstat.exe vshwin32.exe, avgnt.exe and persfw.exe if found running.
The worm logs on to a predefined IRC server to wait for backdoor commands.
Kortom scan nog even al je netwerkdrives/shares met een andere virusscanner die dit ding herkent.
[
Voor 30% gewijzigd door
Mike Jarod op 14-02-2004 19:43
]