Ower keylogger

1

Ower keylogger

offline
  • Pridružio: 20 Jul 2008
  • Poruke: 197

Uzas, instalirao sam ower keylogger i saznao sam sto mi je trebalo, a on moze da se vidi samo ako ukucam tajnu sifru bilo gde.
Problem je sto nece, a kad hocu opet da ga instaliram kaze da je instalirano.
Molim za pomoc...

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 20 Jul 2008
  • Poruke: 197

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:31:46, on 28.2.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Comodo\Firewall\cfp.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\713xRMTMon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
D:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\713xRMT.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
D:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe
D:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\honestech\honestech TVR\scheduleTV.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\Program Files\WinRAR\WinRAR.exe
c:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Program Files\BitTorrent\bittorrent.exe
C:\Documents and Settings\Gundy & Johny\My Documents\Firefox\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = travian.rs/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\real\IEeREAD.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "D:\Program Files\Comodo\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMTMon.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Program Files\Comodo\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [WorkFlowTray] "D:\Program Files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe"
O4 - HKLM\..\Run: [Opware14] "D:\Program Files\ScanSoft\OmniPagePro14.0\Opware14.exe"
O4 - HKLM\..\Run: [OpScheduler] "D:\Program Files\ScanSoft\OmniPagePro14.0\OpScheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HTV Agent] d:\Program Files\HTV\HTV.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Free Download Manager] "d:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Scheduler for OEM.lnk = C:\Program Files\honestech\honestech TVR\scheduleTV.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - D:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - d:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - d:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 9048 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 20 Jul 2008
  • Poruke: 197

ComboFix 09-02-27.02 - Gundy & Johny 2009-02-28 18:40:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1331 [GMT 1:00]
Running from: c:\documents and settings\Gundy & Johny\My Documents\Firefox\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090227-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
Error: Cfiles.dat
ADS - svchost.exe: deleted 88 bytes in 2 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Gundy & Johny\Application Data\.#

.
((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 15:16 . 2009-02-28 15:16 <DIR> d-------- c:\program files\Trojan Remover
2009-02-28 15:16 . 2009-02-28 15:16 <DIR> d-------- c:\documents and settings\Gundy & Johny\Application Data\Simply Super Software
2009-02-28 15:16 . 2009-02-28 15:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-02-28 15:16 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-28 15:16 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-28 15:16 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-28 15:16 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-28 15:07 . 2009-02-28 15:07 268 --ah----- C:\sqmdata10.sqm
2009-02-28 15:07 . 2009-02-28 15:07 244 --ah----- C:\sqmnoopt10.sqm
2009-02-28 15:00 . 2009-02-28 15:00 <DIR> d-------- c:\documents and settings\Administrator
2009-02-28 14:51 . 2009-02-28 14:51 268 --ah----- C:\sqmdata09.sqm
2009-02-28 14:51 . 2009-02-28 14:51 244 --ah----- C:\sqmnoopt09.sqm
2009-02-28 12:33 . 2009-02-28 12:33 268 --ah----- C:\sqmdata08.sqm
2009-02-28 12:33 . 2009-02-28 12:33 244 --ah----- C:\sqmnoopt08.sqm
2009-02-28 12:06 . 2009-02-28 12:06 268 --ah----- C:\sqmdata07.sqm
2009-02-28 12:06 . 2009-02-28 12:06 244 --ah----- C:\sqmnoopt07.sqm
2009-02-28 11:21 . 2009-02-28 11:21 268 --ah----- C:\sqmdata06.sqm
2009-02-28 11:21 . 2009-02-28 11:21 244 --ah----- C:\sqmnoopt06.sqm
2009-02-28 10:53 . 2009-02-28 10:53 268 --ah----- C:\sqmdata05.sqm
2009-02-28 10:53 . 2009-02-28 10:53 244 --ah----- C:\sqmnoopt05.sqm
2009-02-28 10:47 . 2009-02-28 10:47 268 --ah----- C:\sqmdata04.sqm
2009-02-28 10:47 . 2009-02-28 10:47 244 --ah----- C:\sqmnoopt04.sqm
2009-02-28 10:20 . 2009-02-28 10:20 268 --ah----- C:\sqmdata03.sqm
2009-02-28 10:20 . 2009-02-28 10:20 244 --ah----- C:\sqmnoopt03.sqm
2009-02-28 00:22 . 2009-02-28 00:22 268 --ah----- C:\sqmdata02.sqm
2009-02-28 00:22 . 2009-02-28 00:22 244 --ah----- C:\sqmnoopt02.sqm
2009-02-28 00:09 . 2009-02-28 00:09 268 --ah----- C:\sqmdata01.sqm
2009-02-28 00:09 . 2009-02-28 00:09 244 --ah----- C:\sqmnoopt01.sqm
2009-02-27 12:47 . 2009-02-27 12:47 268 --ah----- C:\sqmdata00.sqm
2009-02-27 12:47 . 2009-02-27 12:47 244 --ah----- C:\sqmnoopt00.sqm
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\program files\iTunes
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\program files\iPod
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\documents and settings\Gundy & Johny\Application Data\Apple Computer
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-02-25 17:13 . 2009-02-25 17:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-02-25 17:13 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2009-02-25 17:13 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2009-02-25 17:12 . 2009-02-25 17:13 <DIR> d-------- c:\program files\Common Files\Apple
2009-02-25 17:12 . 2009-02-25 17:12 <DIR> d-------- c:\program files\Apple Software Update
2009-02-25 17:12 . 2009-02-25 17:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2009-02-23 12:36 . 2009-02-25 17:13 <DIR> d-------- c:\program files\QuickTime
2009-02-21 17:41 . 2009-02-21 17:41 116,714 --a------ C:\Oaza
2009-02-21 12:27 . 2009-02-21 12:27 <DIR> d-------- c:\documents and settings\Gundy & Johny\Application Data\GlobalSCAPE
2009-02-21 12:27 . 2009-02-21 12:27 <DIR> d-------- c:\documents and settings\All Users\Application Data\GlobalSCAPE
2009-02-20 17:42 . 2009-02-21 18:48 10 --a------ c:\windows\popcinfo.dat
2009-02-20 16:24 . 2009-02-20 16:51 <DIR> d-------- c:\program files\Zuma Deluxe
2009-02-16 11:37 . 2009-02-16 11:37 230 --a------ c:\windows\system32\spupdsvc.inf
2009-02-16 10:20 . 2008-12-21 00:15 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-02-16 10:20 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-02-16 10:20 . 2007-03-08 06:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-16 10:20 . 2008-12-21 00:15 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-02-16 10:20 . 2008-12-21 00:15 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-16 10:20 . 2008-12-21 00:15 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-02-16 10:20 . 2008-12-21 00:15 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-02-16 10:20 . 2008-12-21 00:15 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-16 10:20 . 2008-12-19 10:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-02-16 00:45 . 2009-02-16 00:46 <DIR> d-------- C:\travianroman
2009-02-16 00:12 . 2009-02-16 00:12 <DIR> d--hs---- c:\documents and settings\Gundy & Johny\IECompatCache
2009-02-16 00:11 . 2009-02-16 00:11 <DIR> d--hs---- c:\documents and settings\Gundy & Johny\PrivacIE
2009-02-16 00:11 . 2009-02-16 00:11 <DIR> d--hs---- c:\documents and settings\Gundy & Johny\IETldCache
2009-02-16 00:06 . 2009-02-16 09:34 <DIR> d-------- c:\windows\ie8updates
2009-02-16 00:06 . 2008-04-14 04:41 81,920 --a------ c:\windows\system32\ieencode.dll
2009-02-16 00:06 . 2008-04-14 04:41 81,920 --a------ c:\windows\system32\dllcache\ieencode.dll
2009-02-16 00:05 . 2009-01-11 06:00 79,360 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-02-15 23:20 . 2009-02-15 23:20 <DIR> d-------- C:\travian
2009-02-15 21:27 . 2009-02-15 21:27 <DIR> d-------- c:\documents and settings\Gundy & Johny\temp
2009-02-15 21:27 . 2009-02-15 21:27 <DIR> d-------- c:\documents and settings\Gundy & Johny\Application Data\TeamViewer
2009-02-13 19:29 . 2009-02-13 19:29 32 --a------ c:\documents and settings\All Users\Application Data\ezsid.dat
2009-02-08 14:50 . 2009-02-08 14:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\MSScanAppDataDir
2009-02-08 14:22 . 2009-02-08 14:22 <DIR> d---s---- c:\documents and settings\Gundy & Johny\UserData
2009-02-08 14:05 . 2009-02-08 14:05 <DIR> d-------- c:\documents and settings\Gundy & Johny\Application Data\ScanSoft
2009-02-08 14:05 . 2009-02-08 14:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-02-08 14:05 . 2009-02-08 14:05 430 --a------ c:\windows\MAXLINK.INI
2009-02-08 14:04 . 2009-02-08 14:04 <DIR> d-------- c:\program files\Common Files\Scansoft Shared
2009-02-08 14:04 . 2009-02-08 14:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\ScanSoft
2009-02-06 22:09 . 2009-02-06 22:09 <DIR> d-------- c:\program files\ACD Systems
2009-02-06 22:09 . 2009-02-06 22:09 10,368 --a------ c:\windows\system32\drivers\pfc.sys
2009-01-31 13:53 . 2009-01-31 13:53 137,344 --a------ c:\windows\system32\drivers\hwpsgt.sys
2009-01-31 13:53 . 2009-01-31 13:53 9,472 --a------ c:\windows\system32\drivers\lemsgt.sys
2009-01-29 15:16 . 2009-01-29 15:18 <DIR> d-------- c:\program files\Remote Desktop Control 2
2009-01-29 15:16 . 2009-01-29 15:16 <DIR> d-------- c:\documents and settings\All Users\Remote Desktop Control 2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-28 17:42 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\BitTorrent
2009-02-28 17:36 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\DNA
2009-02-28 14:07 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Skype
2009-02-28 14:07 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Free Download Manager
2009-02-28 14:06 196,608 ----a-w c:\windows\system32\drivers\nStandard.bin
2009-02-28 14:06 --------- d-----w c:\program files\DNA
2009-02-28 10:21 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-28 09:13 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\skypePM
2009-02-21 11:27 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-16 10:31 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\mIRC
2009-02-08 13:04 --------- d-----w c:\program files\Common Files\InstallShield
2009-02-06 21:09 --------- d-----w c:\program files\Common Files\ACD Systems
2009-02-05 16:39 --------- d-----w c:\program files\YouTube Downloader
2009-01-25 17:52 --------- d-----w c:\program files\Microsoft
2009-01-25 14:40 53,248 ----a-w c:\windows\system32\suppdll.dll
2009-01-25 14:40 35,363 ----a-w c:\windows\system32\windrvNT.sys
2009-01-25 12:52 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Thinstall
2009-01-25 12:51 --------- d-----w c:\program files\Skype
2009-01-25 12:51 --------- d-----w c:\program files\Common Files\Skype
2009-01-25 12:51 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-01-25 12:37 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Nero
2009-01-25 12:36 --------- d-----w c:\program files\Nero
2009-01-25 02:04 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\ACD Systems
2009-01-25 02:03 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-01-25 02:02 --------- d-----w c:\program files\real
2009-01-25 01:53 --------- d-----w c:\program files\HP
2009-01-25 01:22 --------- d-----w c:\program files\Microsoft IntelliPoint
2009-01-25 00:55 --------- d-----w c:\documents and settings\All Users\Application Data\DriverScanner
2009-01-25 00:51 --------- dc-h--w c:\documents and settings\All Users\Application Data\{D5ABFFAD-D592-4F98-B02B-587125B4801F}
2009-01-25 00:51 --------- d-----w c:\program files\Uniblue
2009-01-25 00:51 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Uniblue
2009-01-24 15:40 --------- d-----w c:\program files\Common Files\Macromedia
2009-01-22 17:13 --------- d-----w c:\program files\Cheat Engine
2009-01-21 13:31 --------- d-----w c:\program files\Google
2009-01-20 17:20 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-01-20 17:20 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-01-20 11:41 --------- d-----w c:\program files\Nokia
2009-01-20 11:41 --------- d-----w c:\program files\Common Files\PCSuite
2009-01-20 11:41 --------- d-----w c:\program files\Common Files\Nokia
2009-01-20 11:40 --------- d-----w c:\program files\PC Connectivity Solution
2009-01-20 11:38 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-01-18 14:50 --------- d-----w c:\program files\Opera
2009-01-18 14:47 --------- d-----w c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-01-17 02:00 --------- d-----w c:\program files\MSXML 4.0
2009-01-16 07:48 --------- d-----w c:\program files\Hewlett-Packard
2009-01-16 07:48 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2009-01-16 07:48 --------- d-----w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-01-15 12:49 --------- d-----w c:\program files\Microsoft.NET
2009-01-15 12:49 --------- d-----w c:\program files\Microsoft ActiveSync
2009-01-15 12:49 --------- d-----w c:\program files\Common Files\L&H
2009-01-15 12:48 --------- d-----w c:\program files\Microsoft Works
2009-01-15 12:39 --------- d-----w c:\program files\Common Files\Adobe
2009-01-15 06:15 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Nokia
2009-01-15 06:14 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\PC Suite
2009-01-14 20:02 --------- d-----w c:\program files\MSN Messenger
2009-01-14 12:32 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-01-14 12:31 --------- d-----w c:\program files\DIFX
2009-01-13 23:56 31,504 ----a-w c:\windows\system32\drivers\cmdhlp.sys
2009-01-13 23:56 147,192 ----a-w c:\windows\system32\guard32.dll
2009-01-13 23:56 101,776 ----a-w c:\windows\system32\drivers\cmdguard.sys
2009-01-13 22:59 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Ringtone
2009-01-13 21:45 14,336 ----a-w c:\windows\system32\svchost.exe
2009-01-13 20:06 --------- d-----w c:\program files\honestech
2009-01-13 12:03 --------- d-----w c:\documents and settings\All Users\Application Data\comodo
2009-01-13 11:45 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Comodo
2009-01-13 10:13 --------- d-----w c:\program files\ASUS
2009-01-12 23:16 --------- d-----w c:\documents and settings\All Users\Application Data\Bluetooth
2009-01-12 23:00 155,995 ----a-w c:\windows\java\Packages\0LVDJ3VN.ZIP
2009-01-12 23:00 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\PC Tools
2009-01-12 22:23 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-12 22:23 --------- d-----w c:\program files\Java
2009-01-12 21:58 --------- d-----w c:\program files\ThreatFire
2009-01-12 21:34 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\PCToolsFirewallPlus
2009-01-12 15:55 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\GetRightToGo
2009-01-12 15:33 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\Yahoo!
2009-01-12 15:33 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-12 15:29 --------- d-----w c:\program files\Yahoo!
2009-01-12 15:15 --------- d-----w c:\program files\Alwil Software
2009-01-12 14:16 --------- d-----w c:\program files\My Company Name
2009-01-12 14:05 --------- d-----w c:\program files\AMD
2009-01-12 14:03 315,392 ----a-w c:\windows\HideWin.exe
2009-01-12 14:03 --------- d-----w c:\program files\Realtek
2009-01-12 13:54 --------- d-----w c:\program files\NVIDIA Corporation
2009-01-12 13:52 --------- d-----w c:\documents and settings\Gundy & Johny\Application Data\InstallShield
2009-01-12 13:51 --------- d-----w c:\program files\E-Color
2009-01-12 13:15 --------- d-----w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-01-12 342848]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"Free Download Manager"="d:\program files\Free Download Manager\fdm.exe" [2009-01-02 3399727]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-16 8491008]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-16 81920]
"ASUSGamerOSD"="c:\program files\ASUS\GamerOSD\GamerOSD.exe" [2007-09-13 380928]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-12 136600]
"COMODO Firewall Pro"="d:\program files\Comodo\Firewall\cfp.exe" [2009-01-14 1797880]
"TV Card Remote Control Device Monitor"="c:\windows\713xRMTMon.exe" [2005-07-20 352256]
"COMODO Internet Security"="d:\program files\Comodo\Firewall\cfp.exe" [2009-01-14 1797880]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2008-06-10 1406024]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"WorkFlowTray"="d:\program files\ScanSoft\OmniPagePro14.0\WorkFlowTray.exe" [2004-03-08 155747]
"Opware14"="d:\program files\ScanSoft\OmniPagePro14.0\Opware14.exe" [2004-03-08 57344]
"OpScheduler"="d:\program files\ScanSoft\OmniPagePro14.0\OpScheduler.exe" [2004-03-08 114688]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-23 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"TrojanScanner"="c:\program files\Trojan Remover\Trjscan.exe" [2009-02-15 1214856]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2007-08-03 c:\windows\SkyTel.exe]
"nwiz"="nwiz.exe" [2007-09-16 c:\windows\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Scheduler for OEM.lnk - c:\program files\honestech\honestech TVR\scheduleTV.exe [2009-01-13 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"vidc.ffds"= d:\progra~1\ffdshow\ffdshow.ax
"VIDC.ACDV"= ACDV.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"d:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"d:\\Program Files\\mIRC\\mirc.exe"=
"d:\\Program Files\\Free Download Manager\\fdm.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Documents and Settings\\Gundy & Johny\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 BtHidBus;Bluetooth HID Bus Service;c:\windows\system32\drivers\BtHidBus.sys [2008-07-31 20616]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-12 114768]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-01-13 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-01-13 31504]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2009-01-13 289280]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-12 20560]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2009-01-13 26880]
S3 IvtBtBUs;IVT Bluetooth Bus Service;c:\windows\system32\drivers\IvtBtBus.sys [2008-07-02 26248]
S3 sdAuxService;PC Tools Auxiliary Service;d:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-13 356920]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a9c2a42-e0b1-11dd-b309-806d6172696f}]
\Shell\AutoRun\command - e:\bin\assetup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-25 c:\windows\Tasks\Microsoft_Hardware_Launch_IPoint_exe.job
- c:\program files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 12:56]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-HTV Agent - d:\program files\HTV\HTV.exe
HKU-Default-Run-Nokia.PCSync - d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://travian.rs/
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Gundy & Johny\Application Data\Mozilla\Firefox\Profiles\mdworhse.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.rs/
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - component: d:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - plugin: d:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: d:\program files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\program files\DivX\DivX Web Player\npdivx32.dll

---- FIREFOX POLICIES ----
FF - user.js: capability.policy.policynames - localfilelinks
FF - user.js: capability.policy.localfilelinks.sites - hxxp://www.travian.org rs2.travian.com travian.at welt1.travian.de welt2.travian.de welt3.travian.de welt4.travian.de welt5.travian.de welt6.travian.de welt7.travian.de welt8.travian.de welt9.travian.de welt10.travian.de speed.travian.de
FF - user.js: capability.policy.localfilelinks.checkloaduri.enabled - allAccess.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-28 18:42:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Device Monitor = c:\windows\713xRMTMon.exe???????????????T?a??r5?m?a?????????????????????????????????????????x?5?????8n5?????????????????x?5??????r5?????????T?a?x?5?m?a????????????????|?r5?????????????????????????????????????????????????????x?5?????T?a?h?o?m?a???????????A????

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\hbddc]
"ImagePath"="system32\drivers\hbddc.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(744)
c:\windows\system32\guard32.dll

- - - - - - - > 'lsass.exe'(800)
c:\windows\system32\guard32.dll
.
Completion time: 2009-02-28 18:43:47
ComboFix-quarantined-files.txt 2009-02-28 17:43:43

Pre-Run: 34.808.684.544 bytes free
Post-Run: 36,439,130,112 bytes free

318 --- E O F --- 2009-02-25 12:39:04


Dopuna: 28 Feb 2009 18:56

Sta dalje?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Daj mi sledece fajlove na proveru:
C:\Windows\system32\drivers\hbddc.sys
C:\Oaza

Upload uradi preko sledece forme:
http://www.mycity.rs/ambulanta-upload.php

offline
  • Pridružio: 20 Jul 2008
  • Poruke: 197

Uradio sam to. Što se tiče oaze, skoro sam ga sam dodao, ne sećam se zašto, bilo je to prošle nedelje. Mislim da sam to skinuo sa svog sajta...

Primetio sam da kada upalim komp, meni se pojavi neka greška za windows explorer... U smislu close...

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Obrisi sledeci fajl:
C:\Windows\system32\drivers\hbddc.sys

To ti je bio ostatak tog keylogera.

C:\Oaza je legitiman, i to ti je u stvari ZIP fajl sa nekim templateom za sajt.


Javi ako si uspeo rucno da obrises onaj fajl, pa da ti onda napisem kako da deinstaliras ComboFix.

offline
  • Pridružio: 20 Jul 2008
  • Poruke: 197

Hwala. Sa lakocom sam ga obrisao, nije pravio nikakve probleme.
Hajde sad da deinstaliram combofix.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 1078 korisnika na forumu :: 29 registrovanih, 6 sakrivenih i 1043 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, airsuba, bestguarder, bladesu, bojank, bokisha253, Brana01, bufanje, cemix, Djokislav, dolinalima, DPera, draganl, HrcAk47, jukeboxer, Koridor, lcc, LeGrandCharles, Miki01, Misirac, pein, powSrb, shone34, SR-3m, Tvrtko I, Vlada1389, Vzor50, wolverined4, zlaya011