PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Softverski problemi (https://forum.pcekspert.com/forumdisplay.php?f=42)
-   -   (riješeno) Uklanjanje gamadi win32.tdss.rtk, virtumonde.dll, fraud.virusremover2009 (https://forum.pcekspert.com/showthread.php?t=156544)

Barny 19.08.2009. 11:20

(riješeno) Uklanjanje gamadi win32.tdss.rtk, virtumonde.dll, fraud.virusremover2009
 
Napalo me win32.tdss.rtk, virtumonde.dll, te fraud.virusremover2009.

Bit nenalazi ništa, ad-aware isto no spybot nalazi ali nemože očistiti.

Naime kao on to popravi ali se uvijek vrate kod ponovnog skena.

Molim pomoć

hvala

Doink the Clown 19.08.2009. 11:27

Malwarebytes' Anti-Malware provrti u safe modu, quick! Pobij štetočine :fuming:

Dizel 19.08.2009. 12:42

Meni na poslu netko nasrao nekakav PC Antispyware 2010...pas mater, nemos se rijesit gada SpyBotom da se ubijes...jel postoji sto ucinkovito bez mrljanja po registrima?

Campeonato 19.08.2009. 12:48

Format C...
ja sam se samo tako rijesio tog djubreta, ili slicnog neceg... Meni nije nista pomoglo... nece se uninstalirat, nabija prostor na hardu... nikoji program mu nece nista...

Barny 19.08.2009. 12:52

ovo je vrlo obeshrabrujuće, nadam se još uvijek da ima neko ko je uspio

Doink the Clown 19.08.2009. 12:58

Imao sam nešto slično, moraš mu pronaći autorun datoteku i manualno ju izbrisati da se ne može dizati ponovo, ako ni sa Malwares'-om nisi uspio najsigurnije ti je napravit backup format C: i :amen:

Barny 19.08.2009. 13:04

kako se traži autorun datoteka???

EDIT:

imam samo ove info. i to nikako nemogu očistiti i uvjek se vračaju. kad tražim nevidim ih

Memory Modules Infected:
\\?\globalroot\systemroot\system32\geyekrxnxuhrhh.dll (Trojan.TDSS) -> No action taken.

Files Infected:
\\?\globalroot\systemroot\system32\geyekrxnxuhrhh.dll (Trojan.TDSS) -> No action taken.

Doink the Clown 19.08.2009. 13:08

E toliko potkovan znanjem nisam, znam da mi je frend to riješio kopajući po command promptu, virus se sakrio negdje u rootu a autorun datoteka je bila vidjiva odmah čim otvoriš C particiju i stalno se obnavljala dok ju nije onemogućio u command promptu i onda sve izbrisao Malwarebyte's-om. Sad, ako sam nešto krivo skužio kod njegove metode već će me stručnjaci ispraviti bez brige ;) Što pronalazi Malwarebytes'? Jesi izvrtio scan s njim uopće?
EDIT: Pokušaj skenirat s Avirom još...

Barny 19.08.2009. 13:11

to i je njegov rezultat. našao je on još ponešto no samo to neće.

EDIT:

našao sam neki "wininit" ini. i unutra zapis :

[rename]
c:\tempjunk1956.tmp=C:\WINDOWS\system32\drivers\geyekrmpjwpkka.sys
nul=c:\tempjunk6375.tmp
c:\tempjunk9540.tmp=C:\WINDOWS\system32\geyekrwykmpskb.dll
c:\tempjunk9914.tmp=C:\WINDOWS\system32\geyekrxnxuhrhh.dll
c:\tempjunk3937.tmp=C:\WINDOWS\system32\geyekraqgrqodg.dat
c:\tempjunk662.tmp=C:\WINDOWS\system32\geyekrealqyxmt.dat
c:\tempjunk739.tmp=C:\WINDOWS\system32\lowsec\local.ds
c:\tempjunk9450.tmp=C:\WINDOWS\system32\lowsec\user.ds
c:\tempjunk5889.tmp=C:\WINDOWS\system32\drivers\geyekrmpjwpkka.sys
c:\tempjunk6927.tmp=C:\WINDOWS\system32\geyekrwykmpskb.dll
c:\tempjunk2367.tmp=C:\WINDOWS\system32\geyekrxnxuhrhh.dll
c:\tempjunk5031.tmp=C:\WINDOWS\system32\geyekraqgrqodg.dat
c:\tempjunk5218.tmp=C:\WINDOWS\system32\geyekrealqyxmt.dat
c:\tempjunk1664.tmp=C:\WINDOWS\system32\drivers\geyekrmpjwpkka.sys
c:\tempjunk4787.tmp=C:\WINDOWS\system32\geyekrwykmpskb.dll
c:\tempjunk5075.tmp=C:\WINDOWS\system32\geyekrxnxuhrhh.dll
c:\tempjunk917.tmp=C:\WINDOWS\system32\geyekraqgrqodg.dat
c:\tempjunk3806.tmp=C:\WINDOWS\system32\geyekrealqyxmt.dat
c:\tempjunk5749.tmp=C:\WINDOWS\system32\zipfldr.dll
c:\tempjunk5161.tmp=C:\WINDOWS\system32\drivers\geyekrmpjwpkka.sys
c:\tempjunk2570.tmp=C:\WINDOWS\system32\geyekrwykmpskb.dll
c:\tempjunk785.tmp=C:\WINDOWS\system32\geyekrxnxuhrhh.dll
c:\tempjunk2474.tmp=C:\WINDOWS\system32\geyekraqgrqodg.dat
c:\tempjunk4629.tmp=C:\WINDOWS\system32\geyekrealqyxmt.dat
c:\tempjunk9664.tmp=C:\WINDOWS\system32\drivers\geyekrmpjwpkka.sys
c:\tempjunk8386.tmp=C:\WINDOWS\system32\geyekrwykmpskb.dll
c:\tempjunk3244.tmp=C:\WINDOWS\system32\geyekrxnxuhrhh.dll
c:\tempjunk6717.tmp=C:\WINDOWS\system32\geyekraqgrqodg.dat
c:\tempjunk6375.tmp=C:\WINDOWS\system32\geyekrealqyxmt.dat


ako to što pomaže

Doink the Clown 19.08.2009. 13:48

Citiraj:

Autor Doink the Clown (Post 1410441)
EDIT: Pokušaj skenirat s Avirom još...

:rtfm: Jesi?

Barny 19.08.2009. 13:55

ne tražim odgovore po netu

hello! 19.08.2009. 14:02

Probaj s hajackom pokidati tu gamad...pa onda s malvareom očisti ponovno..

Barny 19.08.2009. 14:08




Logfile of HijackThis v1.99.1
Scan saved at 14:06:48, on 19.8.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/yco...search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/yco.../www.yahoo.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2C7056E-B9DB-4AF7-9A88-3DED6F6B753F}: NameServer = 194.146.109.223 194.146.109.224
O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Update Service (gupdate1c9891249ebc698) (gupdate1c9891249ebc698) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe" /service (file missing)


smijem li izbrisati ručno ovaj wininit ini.

nino 19.08.2009. 14:28

Ovako. Posto svaki dan sredjujem ovakve stvari, moj savjet vam je da:

1. Skinuti hard i proskenirat na drugom kompu sa vec navedenim programima.
2. Usput rucno obrisati raznorazne foldere koji je gamad napravila
3. Vratit disk i u safe modu pogasit nepotrebne i sumnjive startup programe
4. Dignut win normalno i jos jednom proskenirat

Ne sjecam se kad sam zadnji put morao formatirat disk. Sve ocistim na ovaj nacin manje vise.

Joke 19.08.2009. 15:27

Citiraj:

Autor Doink the Clown (Post 1410441)
E toliko potkovan znanjem nisam, znam da mi je frend to riješio kopajući po command promptu, virus se sakrio negdje u rootu a autorun datoteka je bila vidjiva odmah čim otvoriš C particiju i stalno se obnavljala dok ju nije onemogućio u command promptu i onda sve izbrisao Malwarebyte's-om. Sad, ako sam nešto krivo skužio kod njegove metode već će me stručnjaci ispraviti bez brige ;) Što pronalazi Malwarebytes'? Jesi izvrtio scan s njim uopće?
EDIT: Pokušaj skenirat s Avirom još...

U vezi autorun-a.. :)
http://forum.pcekspert.com/showthread.php?t=134499#13
Citiraj:

Autor Barny (Post 1410534)
smijem li izbrisati ručno ovaj wininit ini.

http://www.spywareremove.com/removewininitini.html
http://support.microsoft.com/kb/140570

Barny 19.08.2009. 18:41

evo svima koji imaju isti ili će imati isti problem.Izgleda da je sve riješeno.

Nakon svega gore navedenog i napravljenog:

1. prvo spybot (zadnji update)
2. Malwarebytes' Anti-Malware ( hvala Doink the Clown-u) te potom
3. ComboFix ( riješio sve, i zadnje tragove )

strogo se pridržavati uputa i sve će biti ok.

pozdrav!

ps. čuvajte se ovog što sam ja pokupio doista je opako. pogotovo oni koji plačaju račune i prebacuju sredstva.

Dizel 20.08.2009. 07:13

Krasno, ovaj PC Antispyware 2010 ne mogu maknit da ga ubies, racunalo na poslu ima 3 accounta i nemam pojma gdje se sve nasrao. Odustajem. Imam u firmi i placene ljude koji se time trebau zajebavati, a ne ja cistac nuklearnog reaktora :D

Joke 20.08.2009. 12:09

Citiraj:

Autor Dizel (Post 1411134)
Krasno, ovaj PC Antispyware 2010 ne mogu maknit da ga ubies, racunalo na poslu ima 3 accounta i nemam pojma gdje se sve nasrao. Odustajem. Imam u firmi i placene ljude koji se time trebau zajebavati, a ne ja cistac nuklearnog reaktora :D

A sta ne ide sa Malwarebytes? http://www.bleepingcomputer.com/viru...ware-2010#keys

Dizel 20.08.2009. 12:20

Nula bodova. I dalje javlja da ima kao nekog spywarea i pokusava se to djubre instalirati...

Joke 20.08.2009. 12:22

A dobro onda jbg kad si rekao da ne smijes drkeljat po registryma i to.. :D
Citiraj:

Odustajem. Imam u firmi i placene ljude koji se time trebau zajebavati, a ne ja cistac nuklearnog reaktora
EDIT:Nisam rekao da ne znas :) nego da ne smijes! Kao sta si naveo u postu gore (odnosno bez diranja registrya)..

Dizel 20.08.2009. 12:59

Smijem i znam, ali nemam zivaca i strpljenja, konacno nije mi to u opisu radnog mjesta :)

EDIT: Uspio ocistiti s ovim Malwarebytes' Anti-Malware-om...ali nakon jedno 3-4 skeniranja u safe modu i to full scana, ona brza provjera nije dala rezultate, stalno se vracao neki braviax.exe u system32 direktoriju windoza...


Sva vremena su GMT +2. Sada je 13:55.

Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger