Hej Team Spywarefri
Jeg kører NIS 2008 i en fuld opdateret vers, og denne sagde pludselig: Warning rootkit/trojan, for derefter at lukke ned.
Det var ikke muligt at genstarte NIS eller geninstallere.
CCleaner vil heller ikke starte op. Jeg havde så hørt om jeres forum,
og kom til at tænke på om i kunne hjælpe mig.
På jeres side fandt jeg Norman virus skanner, og her er dens rapport:
Norman Malware Cleaner
Copyright © 1990 - 2008, Norman ASA. Built 2008/08/27 13:08:08
Norman Scanner Engine Version: 5.93.01
Nvcbin.def Version: 5.93.00, Date: 2008/08/27 13:08:08, Variants: 2049413
Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Home 5.1.2600 Service Pack 3
Logged on user: KONTOR\jj
Scan started: 28/08/2008 12:53:44
Scanning running processes and process memory…
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
Too many infections/an unexpected error (Please contact support)
Number of processes/threads found: 2054
Number of processes/threads scanned: 2054
Number of processes/threads not scanned: 0
Number of infected processes/threads terminated: 0
Total scanning time: 2m 21s
Scanning file system…
Scanning: C:\*.*
C:\Documents and Settings\jj\Application Data\m\flec006.exe (Infected with W32/Bagle.BCO)
File marked for defered cleaning (reboot required)
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\05QVQBGX\b64_1[1].jpg (Infected with W32/Spybot.CYZP)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\CBP7QI7D\b64_1[1].jpg (Infected with W32/Spybot.CYZP)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\CZFBMW55\b64[1].jpg (Infected with W32/Bagle.BCO)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\CZFBMW55\b64_1[1].jpg (Infected with W32/Spybot.CYZP)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\FJLRFDWW\b64_1[1].jpg (Infected with W32/Spybot.CYZP)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\WVZ3AWLX\b64[1].jpg (Infected with W32/Bagle.BCO)
Deleted file
C:\Documents and Settings\jj\Lokale indstillinger\Temporary Internet Files\Content.IE5\YXB4TG7Q\b64_1[1].jpg (Infected with W32/Spybot.CYZP)
Deleted file
C:\Programmer\EA GAMES\The Sims 2 Glamour Life Xtra Pakke\TSBin\Keygen.exe (Infected with Suspicious_F.gen)
Deleted file
C:\Programmer\Nero\Nero8\Nero BackItUp\BackItUp_ImageTool\root.img/unknown0 (Error whilst scanning file: I/O Error (0x0022000A))
C:\Programmer\Nero\Nero8\Nero BackItUp\BackItUp_ImageTool\root.img (Possible archive bomb)
C:\Programmer\Windows Media Player\wmpnscfg.exe (Infected with W32/Malware.DNDS)
Removed registry value: HKCU\Software\Microsoft\Windows\CurrentVersion\Run -> WMPNSCFG = “C:\Programmer\Windows Media Player\WMPNSCFG.exe”
Deleted file
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe (Error opening file: Not found)
C:\WINDOWS\system32\mdelk.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\mdelk.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\mdelk.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\mdelk.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\mdelk.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
Too many infections/an unexpected error (Please contact support)
C:\WINDOWS\system32\wintems.exe (Infected with W32/Bagle.BCY)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\hldrrr.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\mdelk.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\mdelk.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\mdelk.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\mdelk.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\mdelk.exe (Infected with W32/Malware.DNDS)
File marked for defered cleaning (reboot required)
Too many infections/an unexpected error (Please contact support)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
C:\WINDOWS\system32\drivers\srosa.sys (Infected with W32/Rootkit.gen7)
File marked for defered cleaning (reboot required)
Too many infections/an unexpected error (Please contact support)
C:\WINDOWS\system32\drivers\downld\1343453.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\1392015.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\1394625.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\155781.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\156531.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\15960625.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\15961859.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\169953.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\172953.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\185812.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\186656.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\195125.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\207125.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\23045250.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\23076609.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\23078062.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\37627656.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\37657000.exe (Infected with W32/Bagle.BCZ)
Deleted file
C:\WINDOWS\system32\drivers\downld\52162687.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\52175828.exe (Infected with W32/Bagle.BCY)
Deleted file
C:\WINDOWS\system32\drivers\downld\52178031.exe (Infected with W32/Bagle.BCO)
Deleted file
C:\WINDOWS\system32\drivers\downld\66674890.exe (Infected with W32/Spybot.CYZP)
Deleted file
C:\WINDOWS\system32\drivers\downld\66687156.exe (Infected with W32/Bagle.BCO)
Deleted file
Scanning: c:\System Volume Information\*.*
Running post-scan cleanup routine:
Number of files found: 1213625
Number of archives unpacked: 8273
Number of files scanned: 1213554
Number of files not scanned: 71
Number of files skipped due to exclude list: 0
Number of infected files found: 41
Number of infected files repaired/deleted: 34
Number of infections removed: 34
Total scanning time: 9h 40m 3s
Det hjalp ikke rigtigt, for hvis den køres igen efter en restart
kommer nøjagtigt det samme resultat, også de filer den siger den har slettet. Hvad gør en klog (måske mindre klog) nu.
Jan
