» »

napadi preko interneta

napadi preko interneta

jekson ::

zadnje čase prejem stalne informacija preko kaspersky internet security o sledečih napadih:

01/11/2006 11:21:22 PM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.228.249. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:21:22 PM.
01/11/2006 11:21:22 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.228.249. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:21:22 PM.
01/11/2006 11:27:23 PM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.253.105. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:27:23 PM.
01/11/2006 11:27:23 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.253.105. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:27:23 PM.
01/11/2006 11:29:11 PM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.243.202. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:29:11 PM.
01/11/2006 11:29:11 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.243.202. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:29:11 PM.
01/11/2006 11:38:18 PM Intrusion.Win.NETAPI.buffer-overflow.exploit! Attacker's IP: 213.172.254.156. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:38:18 PM.
01/11/2006 11:46:08 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.232.19. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:46:08 PM.
01/11/2006 11:48:21 PM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.255.109. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:48:21 PM.
01/11/2006 11:48:22 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.255.109. Protocol/service: TCP on local port 445. Time: 01/11/2006 11:48:22 PM.
01/11/2006 11:52:50 PM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.252.45. Protocol/service: TCP on local port 139. Time: 01/11/2006 11:52:50 PM.
01/11/2006 11:52:50 PM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.252.45. Protocol/service: TCP on local port 139. Time: 01/11/2006 11:52:50 PM.
02/11/2006 12:00:34 AM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.243.93. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:00:34 AM.
02/11/2006 12:00:34 AM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.243.93. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:00:34 AM.
02/11/2006 12:02:47 AM Intrusion.Win.DCOM.exploit! Attacker's IP: 213.172.252.132. Protocol/service: TCP on local port 135. Time: 02/11/2006 12:02:47 AM.
02/11/2006 12:03:04 AM Intrusion.Win.DCOM.exploit! Attacker's IP: 213.172.245.51. Protocol/service: TCP on local port 135. Time: 02/11/2006 12:03:04 AM.
02/11/2006 12:03:22 AM Intrusion.Win.DCOM.exploit! Attacker's IP: 213.172.255.80. Protocol/service: TCP on local port 135. Time: 02/11/2006 12:03:22 AM.
02/11/2006 12:03:40 AM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.242.11. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:03:40 AM.
02/11/2006 12:03:40 AM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.242.11. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:03:40 AM.
02/11/2006 12:15:26 AM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.244.78. Protocol/service: TCP on local port 139. Time: 02/11/2006 12:15:26 AM.
02/11/2006 12:15:26 AM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.244.78. Protocol/service: TCP on local port 139. Time: 02/11/2006 12:15:26 AM.
02/11/2006 12:22:55 AM Intrusion.Win.LSASS.exploit! Attacker's IP: 213.172.254.16. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:22:55 AM.
02/11/2006 12:22:55 AM Intrusion.Win.LSASS.ASN1-kill-bill.exploit! Attacker's IP: 213.172.254.16. Protocol/service: TCP on local port 445. Time: 02/11/2006 12:22:55 AM.

Napadi se pojavljajo zelo pogosto seveda KAV jih ustavi vendar napadi se nadaljujejo res nevem kaj bi lahko naredu ker opažam da mi opačsni tudi celoten internet ter emule in utorrent mi delata zelo počasi zaradi tega mam 1mbit linijo in ne gre čez oba skupaj ne gresta čez 50kB/s. Spodaj vam postam če hijackthis log če se kdo kej razume pa lahko pomaga

Logfile of HijackThis v1.97.7
Scan saved at 12:28:21 AM, on 02/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\StatBar.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
F:\Programi\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: StatBar.lnk = C:\StatBar.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Web Anti-Virus (HKLM)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 (HKLM)
O9 - Extra button: Research (HKLM)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc...
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So...
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACD9E807-E852-4AF1-A5BF-F85F6A5AC87D}: NameServer = 217.72.64.10 217.72.64.11

#000000 ::

Startup: StatBar.lnk = C:\StatBar.exe

za tole pokaže www.hijackthis.de da je nasty

jekson ::

žal napadi e popustijo se redno pojavljajo čez noč sem prejel skupno 160 attackov istega tipa kot zgoraj


Vredno ogleda ...

TemaSporočilaOglediZadnje sporočilo
TemaSporočilaOglediZadnje sporočilo
»

problem z odpiranjem strani v IE

Oddelek: Omrežja in internet
251961 (1776) bbf
»

PC se ob startu ne odziva 10 min ?Disk melje?Virus?

Oddelek: Pomoč in nasveti
202442 (2048) Racunalnik
»

Trojan big problem:(

Oddelek: Strojna oprema
133781 (3574) mini-moris
»

Proxy trojanski konj

Oddelek: Pomoč in nasveti
142544 (2263) jan01
»

zajedalski spyware

Oddelek: Operacijski sistemi
212596 (2263) hunter01

Več podobnih tem