IE otvara nove tabove - usb otkazao

1

IE otvara nove tabove - usb otkazao

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

Ne znam da li postoji povezanost izmedju toga sto usb vise ne radi i toga sto IE sam otvara blank stranice, ali dovoljno je alarmantna situacija za novu temu.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:48:27 AM, on 11/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\zerocool\Desktop\ambulantni folder\hiki1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe, explorer.exe
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Barsaka] explorer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Startup: Nikon Monitor.lnk = ?
O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/ji.....586-jc.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: ebk - {1E411CE8-FE8B-4973-B8E0-6EA2CC3C6B06} - C:\WINDOWS\system32\ebkp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 6357 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Pogledacemo:

* Klikni desnim tasterom na Norton Antivirus ikonicu () u donjem, desnom uglu ekrana i izaberi Disable Auto Protect.
* Zatim izaberi željeno trajanje (npr. 5 sati) i klikni OK.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.

----------------------------------


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

ComboFix 08-11-13.01 - zerocool 2008-11-15 13:34:05.11 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.259 [GMT 1:00]
Running from: c:\documents and settings\zerocool\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\zerocool\Cookies\cukaxoqoca.bat
c:\documents and settings\zerocool\Cookies\dapaxozet._dl
c:\documents and settings\zerocool\Cookies\eneteval.scr
c:\documents and settings\zerocool\Cookies\exeluxuka.inf
c:\documents and settings\zerocool\Cookies\hako.dll
c:\documents and settings\zerocool\Cookies\hiqy.lib
c:\documents and settings\zerocool\Cookies\mocixi.bat
c:\documents and settings\zerocool\Cookies\onacaho.dl
c:\documents and settings\zerocool\Cookies\tejumefuva.bat
c:\documents and settings\zerocool\Cookies\ujity.dat
c:\documents and settings\zerocool\Cookies\umap._sy
c:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.

2008-11-15 00:41 . 2004-08-03 23:08 25,600 --a------ c:\windows\system32\drivers\usbser.sys
2008-11-15 00:41 . 2004-08-03 23:08 25,600 --a--c--- c:\windows\system32\dllcache\usbser.sys
2008-11-15 00:41 . 2008-11-15 00:41 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-15 00:41 . 2008-11-15 00:41 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-11-15 00:29 . 2008-11-15 00:53 <DIR> d-------- c:\documents and settings\zerocool\Application Data\PC Suite
2008-11-15 00:29 . 2008-11-15 00:52 <DIR> d-------- c:\documents and settings\zerocool\Application Data\Nokia
2008-11-15 00:29 . 2008-11-15 00:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite
2008-11-15 00:27 . 2008-11-15 00:27 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-11-15 00:26 . 2008-11-15 00:26 <DIR> d-------- c:\program files\PC Connectivity Solution
2008-11-15 00:26 . 2007-09-17 15:53 21,632 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2008-11-15 00:25 . 2008-05-07 07:39 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-11-15 00:25 . 2008-05-07 07:38 659,968 --a------ c:\windows\system32\nmwcdcocls.dll
2008-11-15 00:25 . 2008-05-07 07:38 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-11-15 00:25 . 2008-05-07 07:38 20,864 --a------ c:\windows\system32\drivers\ccdcmbo.sys
2008-11-15 00:25 . 2008-05-07 07:38 17,536 --a------ c:\windows\system32\drivers\ccdcmb.sys
2008-11-15 00:25 . 2008-05-07 07:38 8,064 --a------ c:\windows\system32\drivers\usbser_lowerfltj.sys
2008-11-15 00:25 . 2008-06-06 09:24 8,064 --a------ c:\windows\system32\drivers\usbser_lowerflt.sys
2008-11-15 00:23 . 2008-11-15 00:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
2008-11-06 19:15 . 2008-11-06 19:15 <DIR> d-------- C:\PSFONTS
2008-11-06 19:15 . 2008-11-06 19:15 <DIR> d-------- c:\program files\Adobe Type Manager
2008-11-06 19:15 . 1997-06-17 04:00 212,352 --a------ c:\windows\system32\ATMDRVR.DLL
2008-11-06 19:15 . 1997-06-17 04:00 4,064 --a------ c:\windows\system32\drivers\ATMHELPR.SYS
2008-11-06 19:14 . 2008-11-06 19:14 <DIR> d-------- C:\Acrobat3
2008-11-06 19:14 . 2008-11-14 22:54 2,615 --a------ c:\windows\ACROREAD.INI
2008-11-06 19:11 . 2008-11-06 19:13 <DIR> d-------- c:\program files\PhotoDeluxe HE 3.1
2008-11-06 19:11 . 2008-11-06 19:11 <DIR> d-------- c:\program files\ImageServer
2008-11-06 19:11 . 2008-11-06 19:11 <DIR> d-------- c:\program files\Common Files\Kodak
2008-11-06 18:54 . 1999-04-28 01:01 659,456 --a------ c:\windows\system32\ipeistor12.dll
2008-11-06 18:53 . 2008-11-06 18:53 <DIR> d-------- c:\program files\Hewlett-Packard
2008-10-23 15:11 . 2008-10-23 15:11 <DIR> d-------- c:\program files\YouTube Downloader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 11:55 --------- d-----w c:\documents and settings\zerocool\Application Data\uTorrent
2008-11-15 10:40 --------- d-----w c:\documents and settings\zerocool\Application Data\Skype
2008-11-15 09:13 --------- d-----w c:\documents and settings\zerocool\Application Data\skypePM
2008-11-14 23:27 --------- d-----w c:\program files\Nokia
2008-11-14 23:27 --------- d-----w c:\program files\Common Files\Nokia
2008-11-14 17:19 --------- d-----w c:\documents and settings\zerocool\Application Data\mIRC
2008-11-14 16:39 --------- d-----w c:\program files\mIRC
2008-11-10 19:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 19:17 --------- d-----w c:\documents and settings\zerocool\Application Data\Samsung
2008-10-23 13:48 --------- d-----w c:\documents and settings\zerocool\Application Data\LimeWire
2008-10-07 18:48 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-10-07 16:28 --------- d-----w c:\program files\Samsung
2008-10-06 11:12 --------- d-----w c:\program files\Java
2008-10-06 09:49 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-10-04 13:04 --------- d-----w c:\program files\Skype
2008-10-04 13:04 --------- d-----w c:\program files\Common Files\Skype
2008-10-04 13:04 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-02 19:52 --------- d-----w c:\documents and settings\zerocool\Application Data\X3mE Yamb
2008-10-02 19:52 --------- d-----w c:\documents and settings\All Users\Application Data\X3mE Yamb
2008-10-02 13:50 --------- d-----w c:\program files\Allok MP3 to AMR Converter
2008-10-02 13:48 2,368 ----a-w c:\windows\system32\SVKP.sys
2008-09-22 15:20 --------- d-----w c:\program files\X3mE Yamb
2008-09-22 15:16 --------- d-----w c:\program files\MSBuild
2008-09-22 15:15 --------- d-----w c:\program files\Reference Assemblies
2008-09-22 15:11 --------- d-----w c:\program files\MSXML 6.0
2008-09-20 10:37 --------- d-----w c:\program files\Valve
2008-09-15 21:20 --------- d-----w c:\documents and settings\zerocool\Application Data\PlayFirst
2008-09-03 17:43 25,088 ----a-w c:\windows\system32\ebkp.dll
2008-01-24 10:12 374 ----a-w c:\documents and settings\zerocool\Application Data\internaldb6334.dat
2008-01-24 10:11 555 ----a-w c:\documents and settings\zerocool\Application Data\internaldb8467.dat
2008-01-24 10:11 18,432 ----a-w c:\documents and settings\zerocool\Application Data\internaldb41.dat
2006-11-25 10:11 2,560 --sh--r c:\windows\system32\fooool.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="c:\progra~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-21 50256]
"WFXSwtch"="c:\progra~1\NORTON~1\WinFax\WFXSWTCH.exe" [2001-07-19 26624]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-11-22 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-07-19 c:\windows\system32\WFXSNT40.EXE]
"Barsaka"="explorer.exe" [2004-08-03 c:\windows\explorer.exe]

c:\documents and settings\zerocool\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-05-15 479232]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
CleanSweep Smart Sweep-Internet Sweep.lnk - c:\program files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe [2007-11-01 221184]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVF"= DivX412.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMhelpr.sys [1997-06-17 4064]
R2 SVKP;SVKP;c:\windows\system32\SVKP.sys [2008-10-02 2368]
R3 KCIRDA;%KCIRDA.ServiceDesc%;c:\windows\system32\DRIVERS\KCIrNet.sys [2001-10-04 11856]
R3 QDFSDRV;QDFSDRV;c:\windows\system32\drivers\qdfsdrv.sys [2001-07-26 13792]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2001-10-11 61312]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2669e613-8bc8-11dc-8f43-0007951fccfb}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nircmd.exe execmd CALL batexe\progstart.bat
.
Contents of the 'Scheduled Tasks' folder

2008-11-14 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NORTON~1\NAVW32.exe [2001-07-21 09:14]

2008-11-14 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Common Files\Symantec Shared\NMAIN.EXE [2001-07-24 16:35]

2008-11-15 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2001-07-26 12:23]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\zerocool\Application Data\Mozilla\Firefox\Profiles\gx5wm0rj.default\
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-15 13:36:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-11-15 13:37:43
ComboFix-quarantined-files.txt 2008-11-15 12:37:38
ComboFix2.txt 2008-08-09 16:18:19

Pre-Run: 9,819,754,496 bytes free
Post-Run: 10,203,095,040 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

182

Dopuna: 16 Nov 2008 11:18

I dalje je sve isto.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Izvini sto se ne javljam slava mi je danas pa nisam bas u prilici, a juce su bile pripreme.

Evo, nesto za pocetak, a dalje cemo sutra.

Vazi?


Pokreni HJT i skeniraj ponovo, potom nadji sledece linije:


O4 - HKLM\..\Run: [Barsaka] explorer.exe
O18 - Protocol: ebk - {1E411CE8-FE8B-4973-B8E0-6EA2CC3C6B06} - C:\WINDOWS\system32\ebkp.dll


cekiraj ih i klikni FIX CHECKED pa mi potom postavi novi HJT log.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:09:40 PM, on 11/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\zerocool\Desktop\ambulantni folder\hiki1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [WFXSwtch] C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Startup: Nikon Monitor.lnk = ?
O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.lnk = C:\Program Files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/ji.....586-jc.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: ebk - {1E411CE8-FE8B-4973-B8E0-6EA2CC3C6B06} - C:\WINDOWS\system32\ebkp.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 6098 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ponovo ugasi Norton antivirus i uradi sledece:


Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\system32\fooool.exe
c:\windows\system32\ebkp.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Barsaka"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2669e613-8bc8-11dc-8f43-0007951fccfb}]



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.



Skini sledeci program - http://amf.mycity.rs/personal/bobby/USB_blocker/usb_blocker.exe
- startuj ga i odaberi opciju Auto block
- ubaci USB stick u komp i sacekaj koji sekund (recimo 5-10 sekundi)
- program je sada uradio analizu sticka (vidi se u donjem delu programa, u logu)
- gore levo klikni duplo na slovo koje oznacava particiju, tj. tvoj USB stick
- dole kraj sata ce se pojaviti poruka da smes da izvadis USB stick iz kompa
- ne gasi program, vec ubaci sledeci USB stick i za njega isto sacekaj par sekundi, i tako redom za sve stickove, MP3 plejere, mobilni
- zapamti kojim redom su ubacivani stickovi

Kada sve to zavrsis, log u donjem delu programa ce sadrzati sve podatke koji su meni potrebni da bih video koji stick je zarazen.
Klikni desnim dugmetom misa na log/izvestaj i odaberi Save log.
Automatski ce se otvoriti Notepad i u njemu izvestaj.
Iskopiraj mi taj izvestaj ovde na forum.

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

ComboFix 08-11-16.05 - zerocool 2008-11-17 12:33:43.12 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255 [GMT 1:00]
Running from: c:\documents and settings\zerocool\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\zerocool\Desktop\CFScript.txt
* Created a new restore point

FILE ::
c:\windows\system32\ebkp.dll
c:\windows\system32\fooool.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\ebkp.dll
c:\windows\system32\fooool.exe

.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.

2008-11-15 00:41 . 2004-08-03 23:08 25,600 --a------ c:\windows\system32\drivers\usbser.sys
2008-11-15 00:41 . 2004-08-03 23:08 25,600 --a--c--- c:\windows\system32\dllcache\usbser.sys
2008-11-15 00:41 . 2008-11-15 00:41 0 --ah----- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-11-15 00:41 . 2008-11-15 00:41 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01005.Wdf
2008-11-15 00:29 . 2008-11-15 00:53 <DIR> d-------- c:\documents and settings\zerocool\Application Data\PC Suite
2008-11-15 00:29 . 2008-11-15 00:52 <DIR> d-------- c:\documents and settings\zerocool\Application Data\Nokia
2008-11-15 00:29 . 2008-11-15 00:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Suite
2008-11-15 00:27 . 2008-11-15 00:27 <DIR> d-------- c:\program files\Common Files\PCSuite
2008-11-15 00:26 . 2008-11-15 00:26 <DIR> d-------- c:\program files\PC Connectivity Solution
2008-11-15 00:26 . 2007-09-17 15:53 21,632 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2008-11-15 00:25 . 2008-05-07 07:39 1,419,232 --a------ c:\windows\system32\wdfcoinstaller01005.dll
2008-11-15 00:25 . 2008-05-07 07:38 659,968 --a------ c:\windows\system32\nmwcdcocls.dll
2008-11-15 00:25 . 2008-05-07 07:38 90,624 --a------ c:\windows\system32\nmwcdcls.dll
2008-11-15 00:25 . 2008-05-07 07:38 20,864 --a------ c:\windows\system32\drivers\ccdcmbo.sys
2008-11-15 00:25 . 2008-05-07 07:38 17,536 --a------ c:\windows\system32\drivers\ccdcmb.sys
2008-11-15 00:25 . 2008-05-07 07:38 8,064 --a------ c:\windows\system32\drivers\usbser_lowerfltj.sys
2008-11-15 00:25 . 2008-06-06 09:24 8,064 --a------ c:\windows\system32\drivers\usbser_lowerflt.sys
2008-11-15 00:23 . 2008-11-15 00:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Installations
2008-11-06 19:15 . 2008-11-06 19:15 <DIR> d-------- C:\PSFONTS
2008-11-06 19:15 . 2008-11-06 19:15 <DIR> d-------- c:\program files\Adobe Type Manager
2008-11-06 19:15 . 1997-06-17 04:00 212,352 --a------ c:\windows\system32\ATMDRVR.DLL
2008-11-06 19:15 . 1997-06-17 04:00 4,064 --a------ c:\windows\system32\drivers\ATMHELPR.SYS
2008-11-06 19:14 . 2008-11-06 19:14 <DIR> d-------- C:\Acrobat3
2008-11-06 19:14 . 2008-11-15 22:52 2,616 --a------ c:\windows\ACROREAD.INI
2008-11-06 19:11 . 2008-11-06 19:13 <DIR> d-------- c:\program files\PhotoDeluxe HE 3.1
2008-11-06 19:11 . 2008-11-06 19:11 <DIR> d-------- c:\program files\ImageServer
2008-11-06 19:11 . 2008-11-06 19:11 <DIR> d-------- c:\program files\Common Files\Kodak
2008-11-06 18:54 . 1999-04-28 01:01 659,456 --a------ c:\windows\system32\ipeistor12.dll
2008-11-06 18:53 . 2008-11-06 18:53 <DIR> d-------- c:\program files\Hewlett-Packard
2008-10-23 15:11 . 2008-10-23 15:11 <DIR> d-------- c:\program files\YouTube Downloader

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-16 23:00 --------- d-----w c:\documents and settings\zerocool\Application Data\Skype
2008-11-16 18:55 --------- d-----w c:\documents and settings\zerocool\Application Data\uTorrent
2008-11-16 15:55 --------- d-----w c:\documents and settings\zerocool\Application Data\skypePM
2008-11-14 23:27 --------- d-----w c:\program files\Nokia
2008-11-14 23:27 --------- d-----w c:\program files\Common Files\Nokia
2008-11-14 17:19 --------- d-----w c:\documents and settings\zerocool\Application Data\mIRC
2008-11-14 16:39 --------- d-----w c:\program files\mIRC
2008-11-10 19:17 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-10 19:17 --------- d-----w c:\documents and settings\zerocool\Application Data\Samsung
2008-10-23 13:48 --------- d-----w c:\documents and settings\zerocool\Application Data\LimeWire
2008-10-07 18:48 5,632 ----a-w c:\windows\system32\drivers\StarOpen.sys
2008-10-07 16:28 --------- d-----w c:\program files\Samsung
2008-10-06 11:12 --------- d-----w c:\program files\Java
2008-10-06 09:49 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2008-10-04 13:04 --------- d-----w c:\program files\Skype
2008-10-04 13:04 --------- d-----w c:\program files\Common Files\Skype
2008-10-04 13:04 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-02 19:52 --------- d-----w c:\documents and settings\zerocool\Application Data\X3mE Yamb
2008-10-02 19:52 --------- d-----w c:\documents and settings\All Users\Application Data\X3mE Yamb
2008-10-02 13:50 --------- d-----w c:\program files\Allok MP3 to AMR Converter
2008-10-02 13:48 2,368 ----a-w c:\windows\system32\SVKP.sys
2008-09-22 15:20 --------- d-----w c:\program files\X3mE Yamb
2008-09-22 15:16 --------- d-----w c:\program files\MSBuild
2008-09-22 15:15 --------- d-----w c:\program files\Reference Assemblies
2008-09-22 15:11 --------- d-----w c:\program files\MSXML 6.0
2008-09-20 10:37 --------- d-----w c:\program files\Valve
2008-01-24 10:12 374 ----a-w c:\documents and settings\zerocool\Application Data\internaldb6334.dat
2008-01-24 10:11 555 ----a-w c:\documents and settings\zerocool\Application Data\internaldb8467.dat
2008-01-24 10:11 18,432 ----a-w c:\documents and settings\zerocool\Application Data\internaldb41.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-10-02 1124352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NAV Agent"="c:\progra~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-21 50256]
"WFXSwtch"="c:\progra~1\NORTON~1\WinFax\WFXSWTCH.exe" [2001-07-19 26624]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-11-22 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-07-19 c:\windows\system32\WFXSNT40.EXE]

c:\documents and settings\zerocool\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-05-15 479232]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
CleanSweep Smart Sweep-Internet Sweep.lnk - c:\program files\Norton SystemWorks\Norton CleanSweep\csinsmnt.exe [2007-11-01 221184]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIVF"= DivX412.dll
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 ATMhelpr;ATMhelpr;c:\windows\system32\drivers\ATMhelpr.sys [2008-11-06 4064]
R2 SVKP;SVKP;\??\c:\windows\system32\SVKP.sys [2008-10-02 2368]
R3 KCIRDA;%KCIRDA.ServiceDesc%;c:\windows\system32\DRIVERS\KCIrNet.sys [2007-11-15 11856]
R3 QDFSDRV;QDFSDRV;\??\c:\windows\system32\drivers\qdfsdrv.sys [2007-11-01 13792]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);c:\windows\system32\drivers\sis7012.sys [2007-10-15 61312]
.
Contents of the 'Scheduled Tasks' folder

2008-11-14 c:\windows\Tasks\Norton AntiVirus - Scan my computer.job
- c:\progra~1\NORTON~1\NORTON~1\NAVW32.exe [2001-07-21 09:14]

2008-11-14 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Common Files\Symantec Shared\NMAIN.EXE [2001-07-24 16:35]

2008-11-17 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2001-07-26 12:23]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-17 12:36:18
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-11-17 12:37:24
ComboFix-quarantined-files.txt 2008-11-17 11:37:09
ComboFix2.txt 2008-11-15 12:37:44
ComboFix3.txt 2008-08-09 16:18:19

Pre-Run: 10,008,186,880 bytes free
Post-Run: 10,074,644,480 bytes free

154

Dopuna: 17 Nov 2008 16:29

USB_blocker by bobby

Started at 11/17/2008 4:23:47 PM

Scanning for connected USB Mass storage...
========================================
========================================
Scanning for other storage...
========================================
C: d5604073-7b4f-11dc-b7fd-806d6172696f
D: d5604074-7b4f-11dc-b7fd-806d6172696f
========================================

Scanning fixed storage for autorun.inf files...
========================================
========================================



New device connected at 11/17/2008 4:24:24 PM

Scanning for connected USB Mass storage...
========================================
I: d82c9e87-ec50-11dc-8ff8-0007951fccfb
========================================

Scanning USB mass storage for autorun.inf and desktop.ini files...
========================================

desktop.ini found on I:
Sanitizing Shell Menu...
No key for GUID: d82c9e87-ec50-11dc-8ff8-0007951fccfb
========================================

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Kakvo je sad stanje, proradili flash?

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

Nije flash prestao da radi nego usb na racunaru. Ali, izgleda da to nema nikakve veze sa malicioznim fajlovima.
Izgleda mi da sad sve ok funkcionise. Hvala!

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Log je cist. Nema vise znakova malwera.

Uradi jos ovo:


Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 860 korisnika na forumu :: 17 registrovanih, 3 sakrivenih i 840 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: avijacija, bojcistv, branko7, darioc969, darkojbn, FileFinder, HrcAk47, indja, JOntra, Kubovac, ladro, nikoladim, Parker, pein, raketaš, simazr, zdrebac