Poslao: 07 Sep 2008 18:23
|
offline
- Pridružio: 07 Sep 2008
- Poruke: 49
|
Imam problem sa multiquoting na nekim forumima (tj. ne dozvoljava mi da citiram vishe poruka, vec samo jednu), ne radi mi Nokia PC Suite, i ne znam sta jos...
Nije mi radio ni language bar, al sam to resila kad sam u RUN ukucala ctfmon.exe.
Skenirala sam ga pomocu Malwarebytes i nasao je 13 inficiranih fajlova, sto je prikaceno uz poruku. Obrisala sam ih sve, ali i dalje imam iste probleme
mycity.rs/must-login.png
Moze neko da mi pomogne?
Irena
Dopuna: 07 Sep 2008 18:23
A evo ga i log racunara...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:18:12 PM, on 9/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\PROGRA~1\AVG\AVG8\avgscanx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.75\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 3.75\MediaManager\grab.html
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 2882 bytes
|
|
|
|
|
Poslao: 07 Sep 2008 20:40
|
offline
- Pridružio: 07 Sep 2008
- Poruke: 49
|
Nema potrebe za novu proveru...
Mozda bitna informacija je da sam instalirala novu graficku pre neka tri dana, i od tada mi sve to i ne radi. Ja sam mislila da treba samo to sve negde da se ukljuci (mozda neki addon za Mozilu i sl.) kao sto sam ukljucila language bar. Al su mi na drugom forumu rekli da mi je komp verovatno zarazen i da se ovde obratim za pomoc.
Evo ga log...
ComboFix 08-09-05.03 - IRENA 2008-09-07 20:28:17.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1563 [GMT 2:00]
Running from: C:\Documents and Settings\IRENA\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-08-07 to 2008-09-07 )))))))))))))))))))))))))))))))
.
2008-09-07 18:30 . 2008-09-07 18:30 <DIR> d-------- C:\Documents and Settings\IRENA\Application Data\Uniblue
2008-09-07 18:17 . 2008-09-07 18:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-07 17:11 . 2008-09-07 17:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-07 17:11 . 2008-09-07 17:11 <DIR> d-------- C:\Documents and Settings\IRENA\Application Data\Malwarebytes
2008-09-07 17:11 . 2008-09-07 17:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-07 17:11 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-07 17:11 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-06 12:39 . 2008-09-06 12:39 <DIR> d-------- C:\Program Files\Microsoft
2008-09-03 20:14 . 2008-09-03 20:02 41,076 --a------ C:\mediamp3.dat
2008-09-03 13:28 . 2008-09-03 13:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ATI
2008-09-03 13:28 . 2008-09-03 13:28 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-09-03 13:20 . 2007-11-14 21:48 84,992 -ra------ C:\WINDOWS\system32\drivers\AtiHdmi.sys
2008-09-03 13:19 . 2008-05-12 17:22 3,107,788 -ra------ C:\WINDOWS\system32\ativva5x.dat
2008-09-03 13:19 . 2008-05-12 17:22 887,724 -ra------ C:\WINDOWS\system32\ativva6x.dat
2008-09-03 13:19 . 2008-05-12 10:49 593,920 --------- C:\WINDOWS\system32\ati2sgag.exe
2008-09-03 13:19 . 2008-05-12 17:56 397,312 -ra------ C:\WINDOWS\system32\ATIDEMGX.dll
2008-09-03 13:19 . 2008-05-12 17:53 307,200 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2008-09-03 13:19 . 2007-08-31 15:20 7,167 -ra------ C:\WINDOWS\system32\atifglpf.xml
2008-09-03 13:18 . 2008-09-03 13:23 <DIR> d-------- C:\Program Files\ATI Technologies
2008-09-03 13:18 . 2008-05-12 17:22 3,107,788 -ra------ C:\WINDOWS\system32\ativvaxx.dat
2008-09-03 13:18 . 2008-03-06 16:24 168,883 -ra------ C:\WINDOWS\system32\atiicdxx.dat
2008-08-31 16:44 . 2008-08-31 16:44 <DIR> d-------- C:\Program Files\MP3 Player Utilities 3.75
2008-08-30 19:19 . 2008-08-30 19:19 25 --a------ C:\WINDOWS\cdplayer.ini
2008-08-30 19:17 . 2008-08-30 19:17 <DIR> d-------- C:\Program Files\Real
2008-08-30 19:17 . 2008-08-30 19:17 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-30 13:14 . 2008-08-30 13:14 <DIR> d-------- C:\Documents and Settings\IRENA\Application Data\Apple Computer
2008-08-30 13:13 . 2008-08-31 16:57 72 --a------ C:\WINDOWS\MediaManager.INI
2008-08-30 13:06 . 2008-08-30 13:06 <DIR> d-------- C:\Program Files\QuickTime
2008-08-30 13:06 . 2008-08-30 13:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-30 13:05 . 2008-08-30 13:05 <DIR> d-------- C:\Program Files\Apple Software Update
2008-08-30 13:05 . 2008-08-30 13:05 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-08-29 00:26 . 2008-08-29 00:26 268 --ah----- C:\sqmdata00.sqm
2008-08-29 00:26 . 2008-08-29 00:26 244 --ah----- C:\sqmnoopt00.sqm
2008-08-28 09:13 . 2008-08-28 09:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-08-28 09:11 . 2007-08-15 00:34 <DIR> d-------- C:\WINDOWS\nview
2008-08-25 15:51 . 2008-05-02 22:46 181,895 --a------ C:\WINDOWS\system32\nvdsp.chm
2008-08-25 15:51 . 2008-05-02 22:46 121,529 --a------ C:\WINDOWS\system32\nvcpl.chm
2008-08-25 15:51 . 2008-05-02 22:46 116,384 --a------ C:\WINDOWS\system32\nv3d.chm
2008-08-25 15:51 . 2008-05-02 22:46 54,988 --a------ C:\WINDOWS\system32\nvmob.chm
2008-08-25 12:44 . 2008-08-25 12:44 <DIR> d-------- C:\WINDOWS\system32\WinFast
2008-08-25 10:22 . 2008-08-28 09:08 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-08-23 12:16 . 2008-08-23 12:16 0 --a------ C:\WINDOWS\msicpl.ini
2008-08-23 11:10 . 2008-08-23 11:10 <DIR> d-------- C:\Program Files\Total Commander XP
2008-08-22 14:46 . 2008-08-22 14:48 <DIR> d-------- C:\WINDOWS\NV31403144.TMP
2008-08-20 15:28 . 2005-03-25 18:24 9,600 --a------ C:\WINDOWS\system32\drivers\winfoxiobackup.sys
2008-08-20 15:19 . 2008-08-20 15:32 <DIR> d-------- C:\WINDOWS\system32\WinFox
2008-08-20 15:19 . 2005-03-25 18:24 9,600 --------- C:\WINDOWS\system32\drivers\WINFOXIO.sys
2008-08-18 11:01 . 2008-08-18 11:04 <DIR> d-------- C:\WINDOWS\NV36043608.TMP
2008-08-15 19:08 . 2008-09-05 05:15 <DIR> d-------- C:\Documents and Settings\IRENA\Application Data\gtk-2.0
2008-08-15 19:08 . 2008-08-15 19:08 <DIR> d-------- C:\Documents and Settings\IRENA\.thumbnails
2008-08-15 19:06 . 2008-09-05 06:43 <DIR> d-------- C:\Documents and Settings\IRENA\.gimp-2.4
2008-08-15 19:05 . 2008-08-15 19:05 <DIR> d-------- C:\Program Files\GIMP-2.0
2008-08-07 22:46 . 2008-08-07 22:46 0 --a------ C:\WINDOWS\system32\MSWINSCK.OCX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-07 17:04 --------- d-----w C:\Program Files\eMule
2008-09-07 15:10 --------- d-----w C:\Documents and Settings\IRENA\Application Data\uTorrent
2008-09-06 10:20 --------- d-----w C:\Documents and Settings\IRENA\Application Data\OpenOffice.org2
2008-09-05 18:14 --------- d-----w C:\Documents and Settings\IRENA\Application Data\dvdcss
2008-09-03 11:28 --------- d-----w C:\Documents and Settings\IRENA\Application Data\ATI
2008-09-03 11:07 --------- d-----w C:\Program Files\Common Files\ATI Technologies
2008-08-30 17:17 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-30 17:17 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-08-30 17:17 --------- d-----w C:\Program Files\Common Files\Real
2008-08-29 14:47 --------- d-----w C:\Program Files\Common Files\Adobe
2008-08-29 12:02 --------- d-----w C:\Program Files\Opera
2008-08-29 06:11 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-28 22:25 --------- d-----w C:\Program Files\Windows Live
2008-08-28 22:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-21 22:53 --------- d-----w C:\Program Files\Winamp
2008-08-21 22:53 --------- d-----w C:\Documents and Settings\IRENA\Application Data\Winamp
2008-08-05 12:15 --------- d-----w C:\Program Files\Java
2008-07-27 22:42 --------- d-----w C:\Program Files\DominateGame
2008-07-23 00:06 230,432 ----a-w C:\StiImg.dat
2008-07-04 10:46 2,560 ----a-w C:\WINDOWS\_MSRSTRT.EXE
2008-07-04 10:36 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-06-14 01:16 348,160 ----a-w C:\WINDOWS\eSellerateEngine.dll
2008-03-06 18:08 32 ----a-r C:\Documents and Settings\All Users\hash.dat
2007-12-07 21:37 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-30 15:26 81,920 ----a-w C:\Documents and Settings\IRENA\Application Data\ezpinst.exe
2007-11-30 15:26 47,360 ----a-w C:\Documents and Settings\IRENA\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 8491008]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 81920]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 385024]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-30 185896]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"nwiz"="nwiz.exe" [2007-10-04 C:\WINDOWS\system32\nwiz.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 19:46 87352 C:\WINDOWS\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.l3codec"= l3codecp.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-10-04 18:14 8491008 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-10-04 18:14 81920 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-10-04 18:14 1626112 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NVSvc"=2 (0x2)
"Nvrfocunm"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Miranda IM\\miranda32.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-08-03 46112]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;C:\WINDOWS\system32\drivers\AtiHdmi.sys [2007-11-14 84992]
R3 PAC207;VideoCAM GE111;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [ ]
S3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-06-14 12416]
S3 snpstd2;Trek 310;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [ ]
S3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02cfffc8-7048-11dd-9dab-0019664c88d3}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL portableav16b.exe
\Shell\Scan_Virus_First!!!\command - F:\portableav16b.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c08da5e-9c2e-11dc-9a66-001485849a8d}]
\Shell\Auto\command - F:\Cn911.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Cn911.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7e7cc71e-3e5e-11dd-9d72-0019664c88d3}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f75cf7a3-ba10-11dc-9a74-001485849a8d}]
\Shell\Auto\command - F:\auto.exe
\Shell\AutoRun\command - F:\auto.exe
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\IRENA\Application Data\Mozilla\Firefox\Profiles\hp5ybq0o.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.yahoo.com/
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npqtplugin8.dll
FF -: plugin - C:\Program Files\QuickTime\Plugins\npqtplugin8.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-09-07 20:30:15
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-07 20:32:53
ComboFix-quarantined-files.txt 2008-09-07 18:31:50
Pre-Run: 35,249,274,880 bytes free
Post-Run: 35,257,733,120 bytes free
183 --- E O F --- 2008-02-14 02:04:04
|
|
|
|
|
Poslao: 07 Sep 2008 21:28
|
offline
- Pridružio: 07 Sep 2008
- Poruke: 49
|
Ovo prvo je proslo ok, al ovaj drugi link... idem na run, al ne otvara Notepad, kaze da ne moze da ga nadje.
|
|
|
|
Poslao: 07 Sep 2008 22:38
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
OK...
Znači, ovo je čist kompjuter.
Ako neki program ne radi, pokušaj da ga reinstaliraš.
Što se tiče ovog pisanja poruka po forumima, to je najbolje da preupitaš na forumima na kojima ti se taj problem ispoljava.
Za eventualna dodatno pitanja, otvori temu u za to odgovarajućem forumu (Windows ili Aplikacije).
To je sve što u Ambulanti možemo da uradimo.
|
|
|
|
Poslao: 07 Sep 2008 22:42
|
offline
- Pridružio: 07 Sep 2008
- Poruke: 49
|
Vec sam pitala... I nisu ni oni mogli da mi pomognu.
Hvala ti za ovoliko mucenje! U svakom slucaju sam se uplasila da mi je zarazen, a ovako znam da je ok... ovo ostalo ce se srediti vec.
HVALA!!!!!
|
|
|
|