Goede dag!
Vandaag heb ik voor de 2de keer deze trojan te pakken...
Hij zit dus nogal diep heb ik het idee.
Kan hem wel herstellen, via veiligemodus maar wil weten als hij daarna ook schoon is.
Link die ik zelf gevonden op het internet is deze: http://www.pcwebplus.nl/phpbb/viewto...p?f=222&t=6651
EDIT:
Lukte niet met veilige modus dus heb via Hitman de kickstarter via USB gedaan.
Deze heeft gewerkt en gaf deze log:
Vandaag heb ik voor de 2de keer deze trojan te pakken...
Hij zit dus nogal diep heb ik het idee.
Kan hem wel herstellen, via veiligemodus maar wil weten als hij daarna ook schoon is.
Link die ik zelf gevonden op het internet is deze: http://www.pcwebplus.nl/phpbb/viewto...p?f=222&t=6651
EDIT:
Lukte niet met veilige modus dus heb via Hitman de kickstarter via USB gedaan.
Deze heeft gewerkt en gaf deze log:
Code:
HitmanPro 3.7.6.201 www.hitmanpro.com Computer name . . . . : *************** Windows . . . . . . . : 6.1.1.7601.X64/2 User name . . . . . . : NT AUTHORITY\SYSTEM UAC . . . . . . . . . : Disabled License . . . . . . . : Trial (30 days left) Scan date . . . . . . : 2013-06-18 16:43:42 Scan mode . . . . . . : Normal Scan duration . . . . : 3m 29s Disk access mode . . : Direct disk access (SRB) Cloud . . . . . . . . : Internet Reboot . . . . . . . : Yes Threats . . . . . . . : 5 Traces . . . . . . . : 508 Objects scanned . . . : 1.177.687 Files scanned . . . . : 21.546 Remnants scanned . . : 234.864 files / 921.277 keys Malware _____________________________________________________________________ C:\Users\-\AppData\Roaming\skype.dat -> Quarantined Size . . . . . . . : 70.656 bytes Age . . . . . . . : 0.0 days (2013-06-18 15:43:02) Entropy . . . . . : 7.4 SHA-256 . . . . . : 441DD17ED7A21F25081998303ABD873B4048CE0932311561183B4F00E48101C4 > HitmanPro . . . . : Win32/Ransomware.Urausy Fuzzy . . . . . . : 58.0 Substitutes Explorer.exe as the default shell. Malware tends to start this way. This file was most recently added as automatic startup. The file name extension of this program is not common. Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs. Authors name is missing in version info. This is not common to most programs. Version control is missing. This file is probably created by an individual. This is not typical for most programs. Program starts automatically without user intervention. Time indicates that the file appeared recently on this computer. Startup HKU\S-1-5-21-3242989975-279657017-1924616003-1000\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell References C:\Users\-\AppData\Local\Temp\a-squared.jpg C:\Users\-\AppData\Local\Temp\a-squared.png C:\Users\-\AppData\Local\Temp\adaware.jpg C:\Users\-\AppData\Local\Temp\arcavir.jpg C:\Users\-\AppData\Local\Temp\av_noav.jpg C:\Users\-\AppData\Local\Temp\avast.jpg C:\Users\-\AppData\Local\Temp\avg.jpg C:\Users\-\AppData\Local\Temp\avira.jpg C:\Users\-\AppData\Local\Temp\bitdefender.jpg C:\Users\-\AppData\Local\Temp\clamwin.jpg C:\Users\-\AppData\Local\Temp\comodo.jpg C:\Users\-\AppData\Local\Temp\drweb.jpg C:\Users\-\AppData\Local\Temp\ewido.jpg C:\Users\-\AppData\Local\Temp\f-prot.jpg C:\Users\-\AppData\Local\Temp\f-secure.jpg C:\Users\-\AppData\Local\Temp\gdata.jpg C:\Users\-\AppData\Local\Temp\header.jpg C:\Users\-\AppData\Local\Temp\ic_0.jpg C:\Users\-\AppData\Local\Temp\ic_0_1.png C:\Users\-\AppData\Local\Temp\ic_0_2.png C:\Users\-\AppData\Local\Temp\ic_0_3.png C:\Users\-\AppData\Local\Temp\ic_0_4.png C:\Users\-\AppData\Local\Temp\ic_0_5.png C:\Users\-\AppData\Local\Temp\ic_1.jpg C:\Users\-\AppData\Local\Temp\ic_5_1.jpg C:\Users\-\AppData\Local\Temp\ikarus.jpg C:\Users\-\AppData\Local\Temp\kaspersky.jpg C:\Users\-\AppData\Local\Temp\mcafee.jpg C:\Users\-\AppData\Local\Temp\me_error.jpg C:\Users\-\AppData\Local\Temp\me_notice.jpg C:\Users\-\AppData\Local\Temp\mse.jpg C:\Users\-\AppData\Local\Temp\nod32.jpg C:\Users\-\AppData\Local\Temp\norton.jpg C:\Users\-\AppData\Local\Temp\nosignal.jpg C:\Users\-\AppData\Local\Temp\onecare.jpg C:\Users\-\AppData\Local\Temp\outpost.jpg C:\Users\-\AppData\Local\Temp\p_AKO-Bookstore.jpg C:\Users\-\AppData\Local\Temp\p_argos.jpg C:\Users\-\AppData\Local\Temp\p_avia.jpg C:\Users\-\AppData\Local\Temp\p_bp.jpg C:\Users\-\AppData\Local\Temp\p_coop-compact.jpg C:\Users\-\AppData\Local\Temp\p_coop.jpg C:\Users\-\AppData\Local\Temp\p_esso.jpg C:\Users\-\AppData\Local\Temp\p_ev-primera.jpg C:\Users\-\AppData\Local\Temp\p_ev-totaal-gemak.jpg C:\Users\-\AppData\Local\Temp\p_free-record-shop.jpg C:\Users\-\AppData\Local\Temp\p_gulf.jpg C:\Users\-\AppData\Local\Temp\p_hema.jpg C:\Users\-\AppData\Local\Temp\p_kijkshop-bv.jpg C:\Users\-\AppData\Local\Temp\p_kruidvat.jpg C:\Users\-\AppData\Local\Temp\p_narvesen.jpg C:\Users\-\AppData\Local\Temp\p_postkantoor.jpg C:\Users\-\AppData\Local\Temp\p_Q8.jpg C:\Users\-\AppData\Local\Temp\p_shell_01.jpg C:\Users\-\AppData\Local\Temp\p_spar_01.jpg C:\Users\-\AppData\Local\Temp\p_supercoop.jpg C:\Users\-\AppData\Local\Temp\p_t-mobile.jpg C:\Users\-\AppData\Local\Temp\p_tamoil.jpg C:\Users\-\AppData\Local\Temp\p_texaco.jpg C:\Users\-\AppData\Local\Temp\p_total.jpg C:\Users\-\AppData\Local\Temp\p_trekpleister.jpg C:\Users\-\AppData\Local\Temp\p_videoland.jpg C:\Users\-\AppData\Local\Temp\panda.jpg C:\Users\-\AppData\Local\Temp\sophos.jpg C:\Users\-\AppData\Local\Temp\style.css C:\Users\-\AppData\Local\Temp\trendmicro.jpg C:\Users\-\AppData\Local\Temp\vba.jpg C:\Users\-\AppData\Local\Temp\vexira.jpg C:\Users\-\AppData\Local\Temp\zonealarm.jpg Potential Unwanted Programs _________________________________________________ C:\ProgramData\Babylon\ (Babylon) C:\Users\-\AppData\Roaming\Babylon\ (Babylon) C:\Users\-\AppData\Roaming\Babylon\log_file.txt (Babylon) HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon) HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\ (Funmoods) HKLM\SOFTWARE\Classes\Prod.cap\ (Claro) HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}\ (Babylon) HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}\ (Funmoods) HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}\ (Yontoo) HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}\ (Yontoo) HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}\ (Yontoo) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B2468513CA2D6943A1A233CD3F88CE7\ (Claro) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E\ (AskBar) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar\ (Babylon) HKLM\SOFTWARE\Wow6432Node\Babylon\ (Babylon) HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\ (Babylon) HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\ (Yontoo)
Comment