Vraag & Antwoord

Beveiliging & privacy

arun.exe / install.exe /autorun.inf in gedeelde mappen

5 antwoorden
  • Hai Allemaal, Ik heb een probleempje waar ik maar niet van af lijk te komen, een programma, waarschijnlijk virusje, plaatst continu 3 bestanden in alle gedeelde mappen die mijn server rijk is. Deze 3 bestanden (arun.exe (4kB), install.exe(36kB) en autorun.inf(die arun.exe wil opstarten), zijn gewoon te verwijderen. Ik heb verder geen enkel probleem, geen corrupte data, geen netwerkverkeer etc etc etc. Toch wil ik graag van dit probleem af. Norton + het complete pakket in hitmanpro vinden niets, iemand hier misschien een idee? Bij voorbaat dank, Janssen
  • Kan je een hijackthislog maken en deze posten?
  • Natuurlijk: Logfile of HijackThis v1.99.1 Scan saved at 18:06:55, on 6-3-2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\logonui.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Apache Group\Apache2\bin\Apache.exe C:\WINDOWS\system32\cisvc.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\Program Files\Apache Group\Apache2\bin\Apache.exe C:\mysql\bin\mysqld-nt.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\Program Files\Norton AntiVirus\SAVScan.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\logon.scr C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\rdpclip.exe C:\WINDOWS\Explorer.EXE C:\Program Files\D-Tools\daemon.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe C:\mysql\bin\winmysqladmin.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\Bas\LOCALS~1\Temp\Rar$EX00.766\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.symantec.com/techsupp/servlet/ProductMessages?product=LU&version=2.5&language=English&module=LU&error=1899&build=Symantec R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT" O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: WinMySQLadmin.lnk = C:\mysql\bin\winmysqladmin.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {003FADA5-8FEE-11D6-AFB7-0004768F6183} (CryptoRSA Control) - https://www.p3.postbank.nl/sesam/CAX.cab O23 - Service: Apache2 - Unknown owner - C:\Program Files\Apache Group\Apache2\bin\Apache.exe" -k runservice (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: MySql - Unknown owner - C:/mysql/bin/mysqld-nt.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • Ik zie niks verdacht. Heb je de bewuste bestanden al eens laten scannen bij Jotti: http://virusscan.jotti.org/ Heb je onlangs last gehad van virussen?
  • [code:1:9d2f2f5925] File: install.exe Status: INFECTED/MALWARE Packers detected: YODA, UPX AntiVir Worm/Robobot (0.37 seconds taken) Avast No viruses found (1.52 seconds taken) AVG Antivirus No viruses found (0.48 seconds taken) BitDefender Backdoor.Robobot.P (0.52 seconds taken) ClamAV No viruses found (0.59 seconds taken) Dr.Web BackDoor.IRC.Robobot (0.87 seconds taken) F-Prot Antivirus W32/Robobot.gen (0.40 seconds taken) Fortinet No viruses found (0.44 seconds taken) Kaspersky Anti-Virus Backdoor.Win32.Robobot.p (1.03 seconds taken) mks_vir Win32.4 (probable variant) (0.25 seconds taken) NOD32 probably modified Win32/Yodup-based (NewHeur_PE) (probable variant) (0.54 seconds taken) Norman Virus Control Robobot.M (0.20 seconds taken) [/code:1:9d2f2f5925] [code:1:9d2f2f5925] Service load: 0% 100% File: arun.exe Status: INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) Packers detected: None AntiVir No viruses found (0.37 seconds taken) Avast No viruses found (1.53 seconds taken) AVG Antivirus No viruses found (0.46 seconds taken) BitDefender No viruses found (0.50 seconds taken) ClamAV No viruses found (0.58 seconds taken) Dr.Web No viruses found (1.83 seconds taken) F-Prot Antivirus No viruses found (0.21 seconds taken) Fortinet No viruses found (0.79 seconds taken) Kaspersky Anti-Virus No viruses found (0.99 seconds taken) mks_vir Trojan.Arun (0.22 seconds taken) NOD32 Win32/Dedler.gen (0.47 seconds taken) Norman Virus Control No viruses found (0.53 seconds taken) [/code:1:9d2f2f5925] Dat ze niet zuiver waren wist ik al, deze service kende ik nog niet, maar ik ga is proberen te kijken of de genoemde virusscanners een patch verspreiden. Ik laat het nog ff weten. Bedankt alvast :)

Beantwoord deze vraag

Weet jij het antwoord op deze vraag? Registreer of meld je aan met je account

Dit is een gearchiveerde pagina. Antwoorden is niet meer mogelijk.