PC Ekspert Forum

PC Ekspert Forum (https://forum.pcekspert.com/index.php)
-   Softverski problemi (https://forum.pcekspert.com/forumdisplay.php?f=42)
-   -   ctfmon trojan (https://forum.pcekspert.com/showthread.php?t=77869)

archangel264 23.08.2007. 11:42

ctfmon trojan
 
imam problema sa ctfmon.exe datotekom, nod32 mi je cijelo vrijeme prijavljuje kao trojanca, a kad sam ga obrisao (ručno) onda mi se pri ulasku u disk d ili e pojavljuje poruka da je mjesto nedostupno, da ne može pristupiti disku, nego se mora ići desni klik pa na open. u autorun datoteci na diskovima ima sljedeći tekst, neznam jel to treba tako biti il ne, pa bi vas molio za pomoć jer me izluđuje.

[autorun]
shellexecute=Recycled\ctfmon.exe
shell\Open(&0)\command=Recycled\ctfmon.exe
shell=Open(&0)

ange 13.09.2007. 18:19

Ja imam isti problem i neznam ga kako rješiti, dajte pomagajte:care:

domy_os 13.09.2007. 19:35

Arrival and Installation

This worm usually arrives on a system as a dropped file of other malware, or as a downloaded file from the Internet by an unsuspecting user when visiting malicious Web sites.

Upon execution, it opens the root folder, which is usually C:\, and creates a folder named RECYCLED inside it.

It then drops a copy of itself as CTFMON.EXE in the following folders:

* C:\Recycled\Recycled
* %User Startup%

Note that a legitimate file also named CTFMON.EXE exists in the Windows system folder.

It also creates its own AUTORUN.INF file in the root folder. The said file contains the following strings:

Citiraj:

[AutoRun]
shellexecute=Recycled\Recycled\ctfmon.exe
shell\Open(O)\command=Recycled\Recycled\ctfmon.exe
shell=Open(0).
It adds the option Open(o) to the normal Context Menu. Once a user chooses the said option, the worm is automatically executed.

It also drops the following non-malicious files in the created RECYCLED folder:

* desktop.ini
* INFO2

DESKTOP.INI contains the following strings:

Citiraj:

[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
The said CLSID refers to the Recycle Bin. Once this file is present in a specific folder, the said folder uses the default icon of the Recycle Bin. This technique is a stealth mechanism done to trick users into thinking that the said folder is the legitimate Recycle Bin folder.

When DESKTOP.INI is deleted, the fake folder's icon changes back to the standard folder icon.

The file INFO2 is a harmless data file.

Propagation via Removable and Mapped Drives

This worm drops copies of itself in removable drives and mapped drives as CTFMON.EXE. It also drops the same AUTORUN.INF file described above to automatically execute the mentioned dropped copies when the drives are accessed.

Other Details

On Windows XP systems, this worm creates the following registry keys and entries, which ensure the execution of the Context Menu Open(o):

Citiraj:

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\{random CLSID}
\Shell\Open(O)\command
(Default) = "C:\Recycled\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\{random CLSID}
\Shell\AutoRun\command
(Default) = "RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\
##%Server name%#%Share name%\Shell\Open(O)\command
(Default) = "%Drive letter%\Recycled\ctfmon.exe"

HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Explorer\MountPoints2\
##%Server name%#%Share name%\Shell\AutoRun\command
(Default) = "%Drive letter%\Recycled\ctfmon.exe"
(Note: %Server name% is the name of the server where the mapped folder is located. %Share name% is the name of the mapped folder.)

This worm runs on Windows 98, ME, NT, 2000, XP, and Server 2003.

ange 15.09.2007. 19:05

Hvala Domy_os, ali da li netko može ukratko objasniti šta i kako da napravim ne kužim baš engleski.
Hvala.

Codiac 15.09.2007. 22:04

:D:D:D:D:DD

ange uzmi nekoga tko zna engleski i dofuraj ga i reci da radi po uputama...

ange 16.09.2007. 16:36

Citiraj:

Autor Codiac (Post 814519)
:D:D:D:D:DD

ange uzmi nekoga tko zna engleski i dofuraj ga i reci da radi po uputama...

Ja sam u problemima i nije mi potreban još jedan "pametan savjet" od tebe, ako možeš pomogni ako ne rađe nemoj odogovarati.:offtopic:


Sva vremena su GMT +2. Sada je 23:46.

Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger