Win32/Autoit.FL ...worm?

2

Win32/Autoit.FL ...worm?

offline
  • maqdam 
  • Novi MyCity građanin
  • Pridružio: 08 Jun 2009
  • Poruke: 12

Napisano: 08 Jun 2009 18:10

ComboFix 09-06-07.07 - Marija 08.06.2009 18:04.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.1116 [GMT 2:00]
Running from: c:\documents and settings\Marija\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Marija\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.

2009-06-08 15:33 . 2009-06-08 15:42 -------- d-----w- C:\USBNoRisk
2009-06-08 13:05 . 2009-06-08 13:05 -------- d-sh--r- C:\Win
2009-06-06 17:55 . 2009-06-06 17:55 -------- d-----w- c:\program files\TGTSoft
2009-06-06 17:46 . 2009-06-06 17:46 -------- d-----w- c:\program files\Recnik20

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 13:07 . 2008-10-14 02:41 -------- d-----w- c:\documents and settings\Marija\Application Data\Kingston
2009-06-08 09:57 . 2008-04-14 08:35 -------- d-----w- c:\documents and settings\Marija\Application Data\stickies
2009-06-06 17:58 . 2008-05-30 20:07 -------- d-----w- c:\documents and settings\Marija\Application Data\Yahoo!
2009-06-06 17:58 . 2008-05-30 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-11 11:40 . 2008-10-11 22:14 -------- d-----w- c:\documents and settings\Marija\Application Data\ZoomBrowser EX
2008-02-04 19:03 . 2008-01-14 22:09 56 --sh--r- c:\windows\system32\4AA3B47549.sys
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Win ----



((((((((((((((((((((((((((((( SnapShot@2009-06-08_14.24.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-14 19:19 . 2009-06-08 14:33 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-01-14 19:19 . 2009-03-12 10:26 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-04-03 949376]
"Acrobat Assistant 7.0"="d:\adobe\Acrobat 7\Distillr\Acrotray.exe" [2008-04-23 483328]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-06-10 55296]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Marija\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\Stickies\stickies.exe [2008-1-16 757760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-1-14 25214]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [3.4.2008 22:39 15424]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\MSN Messenger\usnsvc.exe [19.1.2007 12:54 97136]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Marija\Application Data\Mozilla\Firefox\Profiles\n1fwqsg7.default\
FF - prefs.js: browser.startup.homepage - hxxp://mail.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: d:\adobe\Acrobat 7\Acrobat\browser\nppdf32.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-06-08 18:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(708-)
c:\windows\system32\imon.dll

- - - - - - - > 'explorer.exe'(2868-)
c:\windows\system32\msi.dll
.
Completion time: 2009-06-08 18:07
ComboFix-quarantined-files.txt 2009-06-08 16:07
ComboFix2.txt 2009-06-08 15:53
ComboFix3.txt 2009-06-08 14:26

Pre-Run: 3.796.103.168 bytes free
Post-Run: 3.786.031.104 bytes free

117

Dopuna: 08 Jun 2009 18:25

Je li to "to"?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Napisano: 08 Jun 2009 18:26

Nije to to, sacekaces koji minut.

Dopuna: 08 Jun 2009 18:49

Idemo korak po korak:

Otvoriti Notepad i iskopirati sledeci tekst:

Folder::
C:\Win


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • maqdam 
  • Novi MyCity građanin
  • Pridružio: 08 Jun 2009
  • Poruke: 12

Sve sam to uradila, ali nakon restarta, na moje zaprepascenje:
prvo, rezolucija se skroz poremetila, svedena na 600x800,
drugo, komp mi je skroooz usporen... Sad
... inace, nisam imala problema sa tim
trece, izbrisala mi se konekcija za net, sto mi ama bas nikako nije jasno na koji nacein... zapravo, nista od ovoga mi nema logike, samo sam restartovala komp....
... tako da... imam onaj log sacuvan na C:\
ali sta sad da radimmm? Sad

...

Ulazila sam u bios, LAN je na Enable...

Ne znam sta cu... i kako se sve to desilo...?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ne znam kako se to desilo, obrisali smo prazan folder.

Ako mozes nadji taj poslednji log, da vidimo da CF nije nesto obrisao, mada, da je hteo da obrise, obrisao bi prvi put.

offline
  • maqdam 
  • Novi MyCity građanin
  • Pridružio: 08 Jun 2009
  • Poruke: 12

ComboFix 09-06-07.07 - Marija 08.06.2009 19:58.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1535.1204 [GMT 2:00]
Running from: c:\documents and settings\Marija\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Marija\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Win

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DumaNT
-------\Legacy_nod32drv
-------\Legacy_NVSvc
-------\Legacy_WinTabService
-------\Service_ALCXSENS
-------\Service_DumaNT
-------\Service_FETNDIS
-------\Service_GT680x
-------\Service_NCHSSVAD
-------\Service_nod32drv
-------\Service_NVSvc
-------\Service_TClass2k
-------\Service_uagp35
-------\Service_UCTblHid
-------\Service_WinTabService


((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.

2009-06-08 15:33 . 2009-06-08 15:42 -------- d-----w- C:\USBNoRisk
2009-06-06 17:55 . 2009-06-06 17:55 -------- d-----w- c:\program files\TGTSoft
2009-06-06 17:46 . 2009-06-06 17:46 -------- d-----w- c:\program files\Recnik20

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 17:05 . 2008-04-14 08:35 -------- d-----w- c:\documents and settings\Marija\Application Data\stickies
2009-06-08 13:07 . 2008-10-14 02:41 -------- d-----w- c:\documents and settings\Marija\Application Data\Kingston
2009-06-06 17:58 . 2008-05-30 20:07 -------- d-----w- c:\documents and settings\Marija\Application Data\Yahoo!
2009-06-06 17:58 . 2008-05-30 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-05-11 11:40 . 2008-10-11 22:14 -------- d-----w- c:\documents and settings\Marija\Application Data\ZoomBrowser EX
2008-02-04 19:03 . 2008-01-14 22:09 56 --sh--r- c:\windows\system32\4AA3B47549.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-06-08_14.24.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-14 19:19 . 2009-06-08 14:33 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
- 2008-01-14 19:19 . 2009-03-12 10:26 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 240544 c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-02-03 02:15 . 2009-02-03 02:15 3771296 c:\windows\system32\Macromed\Flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-04-03 949376]
"Acrobat Assistant 7.0"="d:\adobe\Acrobat 7\Distillr\Acrotray.exe" [2008-04-23 483328]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-06-10 55296]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Marija\Start Menu\Programs\Startup\
Stickies.lnk - c:\program files\Stickies\stickies.exe [2008-1-16 757760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-1-14 25214]
AutoCAD Startup Accelerator.lnk - c:\program files\Common Files\Autodesk Shared\acstart17.exe [2006-3-5 11000]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=

S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\MSN Messenger\usnsvc.exe [19.1.2007 12:54 97136]
.
.
------- Supplementary Scan -------
.
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Convert link target to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - d:\adobe\Acrobat 7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
FF - ProfilePath - c:\documents and settings\Marija\Application Data\Mozilla\Firefox\Profiles\n1fwqsg7.default\
FF - prefs.js: browser.startup.homepage - hxxp://mail.yahoo.com/
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: d:\adobe\Acrobat 7\Acrobat\browser\nppdf32.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-06-08 20:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(536)
c:\windows\system32\imon.dll

- - - - - - - > 'explorer.exe'(1160)
c:\windows\system32\msi.dll
.
Completion time: 2009-06-08 20:02
ComboFix-quarantined-files.txt 2009-06-08 18:02
ComboFix2.txt 2009-06-08 16:07
ComboFix3.txt 2009-06-08 15:53
ComboFix4.txt 2009-06-08 14:26

Pre-Run: 5.341.675.520 bytes free
Post-Run: 5.331.402.752 bytes free

137

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Zipuj/raruj mi sledeci folder:

c:\qoobox i posalji mi ga preko sledeceg linka:

http://www.mycity.rs/ambulanta-upload.php

offline
  • maqdam 
  • Novi MyCity građanin
  • Pridružio: 08 Jun 2009
  • Poruke: 12

Poslala....

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Iz nepoznatih razloga, CF je izgleda obrisao razne drajvere. Ne diraj nista, moracu da vidim sta cemo.

offline
  • maqdam 
  • Novi MyCity građanin
  • Pridružio: 08 Jun 2009
  • Poruke: 12

OK... Ne diram.

Hvala ti sto si tu...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Evo me.

Da li znas da koristis System Restore, i da li si pokusavala nesto sama da sredis?

Ko je trenutno na forumu
 

Ukupno su 885 korisnika na forumu :: 46 registrovanih, 6 sakrivenih i 833 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, Apok, Bobrock1, bokisha253, Brana01, cavatina, darkangel, Denaya, Dorcolac, drimer, Kubovac, kybonacci, ladro, Magistar78, Maschinekalibar, mercedesamg, Milometer, Misirac, Mixelotti, mkukoleca, mnn2, nemkea71, nikoladim, pein, procesor, rovac, royst33, samsung, Shinobi, Sir Budimir, Sićko, slonic_tonic, Smiljke, Srle993, stegonosa, suton, theNedjeljko, tubular, vathra, vrag81, wizzardone, yrraf, YugoSlav, zdrebac, zeo, Zoca