Imam virusa, spyware. Komp se ledi

1

Imam virusa, spyware. Komp se ledi

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Reinstalirao sam sistem prije par dana, i neki dan ostavio sam komp da skidam nesto i otisao u skolu, kad sam se vratio komp je bio zarazen. Niko nije koristio komp tada. Na desktopu mi se promjenio wall na njemu pise da imam spyware.
evo loga:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:22 AM, on 3/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608-)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\DOCUME~1\Bojan\LOCALS~1\Temp\IMAdvertiser.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IMprocess] C:\DOCUME~1\Bojan\LOCALS~1\Temp\IMAdvertiser.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7603 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Zdravo,

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ovako je izgledao wall, a poslije skeniranja sa ComboFix je nestao.

Evo log:

ComboFix 08-03-27.3 - Bojan 2008-03-29 11:47:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.454 [GMT 1:00]
Running from: C:\Documents and Settings\Bojan\My Documents\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_npf


((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.

2008-03-29 11:51 . 2008-03-29 11:54 <DIR> d-------- C:\Program Files\seekmo
2008-03-29 11:07 . 2008-03-29 11:07 <DIR> d-------- C:\VundoFix Backups
2008-03-29 11:04 . 2008-03-29 11:04 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-28 15:27 . 2008-03-28 15:27 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-03-28 06:56 . 2008-03-28 06:56 <DIR> d-------- C:\Program Files\180searchassistant
2008-03-28 06:56 . 2008-03-28 06:56 <DIR> d-------- C:\Program Files\180search assistant
2008-03-27 16:38 . 2008-03-27 16:38 <DIR> d-------- C:\Program Files\180solutions
2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Program Files\Web Page Maker V2
2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Web Page Maker V2
2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-27 16:23 . 2008-03-27 16:23 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-26 23:27 . 2008-03-26 23:27 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-26 23:26 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-26 23:25 . 2008-03-26 23:25 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-26 23:25 . 2008-03-26 23:25 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-03-26 23:22 . 2008-03-26 23:22 <DIR> dr-h----- C:\MSOCache
2008-03-26 15:33 . 2008-03-26 15:33 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\IM-Names
2008-03-26 11:40 . 2008-03-26 11:40 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Grisoft
2008-03-26 11:40 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-26 11:34 . 2008-03-26 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\zango
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\Sysmnt
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\stc
2008-03-26 07:01 . 2008-03-26 07:01 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Syntrillium
2008-03-26 06:59 . 2008-03-26 06:59 90,537 --a------ C:\WINDOWS\system32\sbwltbxa.exe
2008-03-23 23:38 . 2008-03-23 23:38 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-03-23 23:38 . 2008-03-23 23:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-03-23 23:37 . 2008-03-23 23:40 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-23 23:29 . 2008-03-28 16:17 482 --a------ C:\WINDOWS\wcx_ftp.ini
2008-03-23 22:53 . 2008-03-28 23:55 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-23 22:51 . 2008-03-23 22:51 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-03-23 22:49 . 2008-03-23 22:54 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Ahead
2008-03-23 22:43 . 2008-03-23 22:43 <DIR> d-------- C:\Program Files\Nero
2008-03-23 22:43 . 2008-03-23 22:50 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-23 22:43 . 2008-03-23 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-22 17:17 . 2008-03-22 17:17 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-03-22 15:55 . 2008-03-22 17:17 <DIR> d-------- C:\Program Files\Macromedia
2008-03-22 15:55 . 2008-03-22 16:41 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-03-22 15:54 . 2008-03-22 17:15 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-03-22 15:52 . 2008-03-22 15:52 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Media Player Classic
2008-03-22 15:44 . 2008-03-22 15:44 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-22 12:18 . 2008-03-22 12:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-22 10:40 . 2007-12-07 03:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-22 10:40 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-22 10:40 . 2007-07-01 04:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-22 10:40 . 2007-12-07 03:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-22 10:40 . 2007-12-07 03:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-22 10:40 . 2007-12-07 03:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-22 10:40 . 2007-12-07 03:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-22 10:40 . 2007-12-07 03:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-22 10:40 . 2007-12-06 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-22 03:05 . 2004-09-01 09:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-03-21 18:05 . 2008-03-22 12:12 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-21 18:05 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-21 14:40 . 2008-03-21 14:40 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-21 14:40 . 2008-03-29 08:00 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\AVG7
2008-03-21 14:40 . 2008-03-21 14:40 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-03-21 14:39 . 2008-03-26 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-21 14:39 . 2008-03-21 14:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-21 14:30 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-21 14:30 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-21 13:29 . 2008-03-21 13:29 <DIR> d-------- C:\Program Files\uTorrent
2008-03-21 13:29 . 2008-03-29 10:56 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\uTorrent
2008-03-21 13:04 . 2008-03-21 13:04 12,736 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-03-20 22:42 . 2008-03-20 22:42 38 --a------ C:\WINDOWS\avisplitter.INI
2008-03-20 22:14 . 2008-03-20 22:32 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\vlc
2008-03-20 20:22 . 2008-03-28 17:19 2,535 --a------ C:\WINDOWS\WINCMD.INI
2008-03-20 20:20 . 2008-03-20 20:22 <DIR> d-------- C:\Program Files\TotalCmd
2008-03-20 20:20 . 2008-03-28 21:07 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\skypePM
2008-03-20 20:20 . 2008-03-20 20:20 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-20 20:19 . 2008-03-28 21:12 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Skype
2008-03-20 20:18 . 2008-03-20 20:19 <DIR> d-------- C:\Program Files\Skype
2008-03-20 20:18 . 2008-03-20 20:18 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-03-20 20:18 . 2008-03-20 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-03-20 20:13 . 2008-03-20 20:13 <DIR> d-------- C:\Program Files\Notepad++
2008-03-20 20:13 . 2008-03-20 22:41 <DIR> d-------- C:\Program Files\Mv2Player
2008-03-20 20:13 . 2008-03-21 13:04 <DIR> d-------- C:\Program Files\mIRC
2008-03-20 20:13 . 2008-03-24 00:05 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Notepad++
2008-03-20 20:13 . 2008-03-21 13:07 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\mIRC
2008-03-20 19:59 . 2008-03-20 19:59 304 --ah----- C:\sqmdata03.sqm
2008-03-20 19:59 . 2008-03-20 19:59 244 --ah----- C:\sqmnoopt03.sqm
2008-03-20 19:57 . 2008-03-20 19:57 268 --ah----- C:\sqmdata02.sqm
2008-03-20 19:57 . 2008-03-20 19:57 244 --ah----- C:\sqmnoopt02.sqm
2008-03-20 19:29 . 2008-03-20 19:29 268 --ah----- C:\sqmdata01.sqm
2008-03-20 19:29 . 2008-03-20 19:29 244 --ah----- C:\sqmnoopt01.sqm
2008-03-20 18:46 . 2008-03-20 18:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-20 18:46 . 2008-03-20 18:46 <DIR> d-------- C:\Program Files\MSN Messenger
2008-03-20 18:46 . 2008-03-26 21:44 <DIR> d-------- C:\Documents and Settings\Bojan\Contacts
2008-03-20 18:46 . 2008-03-20 18:46 268 --ah----- C:\sqmdata00.sqm
2008-03-20 18:46 . 2008-03-20 18:46 244 --ah----- C:\sqmnoopt00.sqm
2008-03-20 18:01 . 2008-03-20 18:01 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-03-20 18:01 . 2003-06-27 14:11 491,520 --a------ C:\WINDOWS\Au51Fun.exe
2008-03-20 18:01 . 2000-05-18 14:43 108,978 --a------ C:\WINDOWS\TTTest.wav
2008-03-20 16:46 . 2008-03-20 16:46 16 --a------ C:\WINDOWS\wininit.ini
2008-03-20 16:44 . 2008-03-20 16:44 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-20 16:44 . 2008-03-20 16:44 <DIR> d-------- C:\Program Files\CCleaner
2008-03-20 16:09 . 2006-06-14 09:47 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-03-20 16:09 . 2006-06-14 09:47 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-03-20 16:07 . 2000-10-20 18:28 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-26 06:14 8,960 ----a-w C:\WINDOWS\shdocpl.dll
2008-03-22 14:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-20 14:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-20 14:31 --------- d-----w C:\Program Files\Opera
2008-03-20 14:31 --------- d-----w C:\Program Files\Foxit Software
2008-03-20 14:31 --------- d-----w C:\Program Files\Ares
2008-03-20 14:30 --------- d-----w C:\Program Files\Winamp
2008-03-20 14:30 --------- d-----w C:\Program Files\VideoLAN
2008-03-20 14:30 --------- d-----w C:\Documents and Settings\Bojan\Application Data\Winamp
2008-03-20 14:28 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-03-20 14:27 --------- d-----w C:\Program Files\Java
2008-03-20 14:27 --------- d-----w C:\Program Files\Common Files\Java
2008-03-20 14:19 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-16 22:54 961536]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-01 09:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 16:50 4620288]
"nwiz"="nwiz.exe" [2004-10-29 16:50 921600 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 16:50 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-21 14:39 411648]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-21 14:39 145920]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-29 11:54:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-29 11:58:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 10:58:15
Pre-Run: 16,304,640,000 bytes free
Post-Run: 16,249,679,872 bytes free
.
2008-03-27 15:48:32 --- E O F ---

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Vidim da si koristio i Vundo Fix,mozes li log da postavis,da vidimo da li je on nesto uklonio?

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

On nije nista nasao...

Dopuna: 29 Mar 2008 12:17

A sta je ovo za recovery console? Jel moram imati instaliranu? I ako da, kako se instalira?

Dopuna: 29 Mar 2008 12:18

Sad mi komp ok radi. Jel bi trebao provjeriti jos nesto? Ili sam cist? =)

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Nismo jos zavrsili. U toku dana cu ti napisati skriptu koja ce da ukloni ostatak.

kuckamo se kasnije... :-D

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ok, hvala puno! Do javljanja...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Skini Ewido micro (8Mb) :
http://downloads.ewido.net/ewido_micro.exe

Kako se radi sa Ewido micro:
- na prvom ekranu odaberi sve particije (štikliraj polja ispred njih)
- klikni na dugme Start Scan
- nakon završenog skeniranja klikni na Save Report i snimi log fajl na sigurno mesto
- klikni na Remove Infections
- iskopiraj nam ovde sadržaj log fajla koji je malopre snimljen

Nakon skeniranja sa Ewidom i postavljanja log fajla, postavi nam i svez log programa HijackThis.

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ewido nije nista nasao, kaze nema infekcija... A evo log za hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:08 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608-)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6166 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ajmo jos jednom CF:


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

Ko je trenutno na forumu
 

Ukupno su 1070 korisnika na forumu :: 35 registrovanih, 8 sakrivenih i 1027 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., AleksSE, Alibaba1981, avijacija, babaroga, Bobrock1, Boris90, Bubimir, djuradj, Excalibur13, Fisherman, hyla, kokodakalo, Krusarac, Kubovac, kubura91, mercedesamg, Mi lao shu, milenko crazy north, Milija.00, mkukoleca, mnn2, MrNo, nemkea71, panzerwaffe, procesor, sombrero, Srle993, suton, Viktor Petrenko, W123, wolverined4, x9, yrraf, šumar bk2