Provera

Provera

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 557

juce mi je od jedanput usporio komp u tom trenutku sam imao instaliran nod32 i on nista nije naso pa sam ga izbrisao pa instaliro kaspersky koji je nasao dosta nekih packet trojan pa zelim da proverim da li ima jos neki
https://www.mycity.rs/must-login.png



Logfile of HijackThis v1.99.1
Scan saved at 15:32:35, on 25.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\(HijackThis)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gg-game.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Postavljeni logfile ne pokazuje znakove malware-a.

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 557

ok znaci nema vise virusa ali ne znam sta mi tako koci komp

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Iz tvog prvog posta stekoh utisak da je sada stanje bolje...

No, dobro. Proverićemo još nešto.


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 557

pre nego sto sam poceo da skeniram sa ComboFix kaspersky je nasao trojan download i izbrisao ga ja mislim da je sad sve u redu sa kompom ali evo ti log od ComboFix

ComboFix 08-01-23.1C - wizard 2008-01-26 9:09:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.642 [GMT 1:00]
Running from: C:\Documents and Settings\wizard\Desktop\ComboFix(3).exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\0_exception.nls
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\kdlre.exe
C:\WINDOWS\system32\systeminfo.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_RUNTIME
-------\runtime


((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.

2008-01-26 09:08 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-01-26 09:08 . 2001-08-23 13:00 375,808 --a------ C:\WINDOWS\system32\cmd.exe
2008-01-26 09:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-25 15:47 . 2008-01-25 15:47 <DIR> d-------- C:\VundoFix Backups
2008-01-25 15:27 . 2008-01-25 15:27 88,205 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-25 15:27 . 2008-01-25 15:27 84,621 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-25 15:26 . 2008-01-26 09:12 3,788,320 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-25 15:26 . 2008-01-26 09:11 54,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-25 15:26 . 2008-01-26 09:13 4,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-25 15:26 . 2008-01-26 09:11 2,456 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-25 15:20 . 2008-01-25 15:20 <DIR> d-------- C:\kav
2008-01-21 20:20 . 2008-01-21 20:20 65,862 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-01-21 20:19 . 2008-01-21 20:19 5,760,054 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-01-21 20:18 . 2008-01-21 20:20 5,802 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-01-21 20:17 . 2008-01-21 20:17 <DIR> d-------- C:\WINDOWS\BricoPacks
2008-01-21 17:55 . 2008-01-21 17:55 <DIR> d-------- C:\Program Files\Mayoko
2008-01-20 17:24 . 2008-01-20 17:24 0 --a------ C:\WINDOWS\jppc.INI
2008-01-19 16:11 . 2008-01-19 16:11 876 --a------ C:\WINDOWS\$_hpcst$.hpc
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\WINDOWS\Subtitle Downloader
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\Program Files\Subtitle Downloader
2008-01-13 00:56 . 2008-01-21 20:40 <DIR> d-------- C:\Program Files\iolo
2008-01-13 00:56 . 2006-03-28 08:54 696,320 --a------ C:\WINDOWS\system32\libeay32.dll
2008-01-13 00:56 . 2006-03-28 08:55 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2008-01-13 00:56 . 2008-01-13 00:56 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2008-01-09 22:40 . 2008-01-09 22:40 17,408 --a------ C:\psapi.dll
2008-01-08 13:22 . 2008-01-08 13:22 <DIR> d-------- C:\Program Files\FireTrust
2008-01-07 18:05 . 2008-01-07 18:05 <DIR> d-------- C:\Program Files\Lavasoft RegHance
2008-01-06 16:23 . 2008-01-25 15:32 <DIR> d-a------ C:\Program Files\(HijackThis)
2008-01-06 15:59 . 2008-01-25 15:27 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-05 11:16 . 2008-01-05 11:16 94 ---h----- C:\WINDOWS\system32\spv1_WCssg.ini
2008-01-05 10:20 . 2008-01-05 10:20 <DIR> d-------- C:\Program Files\SkyGrabber275
2008-01-04 12:53 . 2008-01-07 16:49 <DIR> d-------- C:\Program Files\OpenVPN
2008-01-04 11:32 . 2008-01-17 14:17 <DIR> d-------- C:\Program Files\ProgDVB

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 14:32 --------- d---a-w C:\Program Files\(HijackThis)
2008-01-25 13:48 4,078 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-22 22:44 --------- d-----w C:\Program Files\Winamp
2008-01-14 12:51 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-01-07 17:03 --------- d-----w C:\Program Files\Lavasoft
2008-01-04 10:26 --------- d-----w C:\Program Files\DVB-S PowerInstall
2008-01-04 10:26 --------- d-----w C:\Program Files\Common Files\Elecard
2008-01-01 23:44 --------- d-----w C:\Program Files\vPlug Files Center
2007-11-30 14:12 --------- d-----w C:\Program Files\GameHouse Games Collection
2007-11-28 17:47 --------- d-----w C:\Program Files\AnGo´s Game Collection
2007-11-14 10:40 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-11-11 06:59 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 06:59 249,856 ------w C:\WINDOWS\Setup1.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2004-12-28 23:01 544768 C:\WINDOWS\sm56hlpr.exe]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-09-20 20:52 222472]

C:\Documents and Settings\wizard\Start Menu\Programs\Startup\
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 08:43:08 180224]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2000-11-22 14:39:16 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-03-03 12:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
--a------ 2001-11-29 01:00 28672 C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:56 1667584 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
C:\Program Files\OpenVPN\bin\openvpn-gui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskBar]
--a------ 2002-05-08 01:00 122880 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskTray]
--a------ 2001-06-29 01:00 163840 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
--a------ 2002-07-02 10:56 24576 C:\WINDOWS\system32\CTHELPER.EXE

R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys [2002-07-19 08:10]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2005-08-21 21:12]
S3 SIVDRIVER;SIV Kernel Driver;C:\WINDOWS\system32\Drivers\SIVX32.SYS [2006-01-13 15:29]
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 12:07]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8316a8ef-8f6c-11dc-a1c6-00d0d70ec459}]
\shell\Setup\command - H:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 16:17:28 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 09:13:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
.
Completion time: 2008-01-26 9:15:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-26 08:15:09

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ko je trenutno na forumu
 

Ukupno su 1033 korisnika na forumu :: 45 registrovanih, 9 sakrivenih i 979 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100ka, _Rade, babaroga, Bluper, bojank, Boris90, branko7, ccoogg123, darkangel, DeerHunter, Denaya, Dimitrije Paunovic, djboj, Excalibur13, FOX, h8propaganda, havoc995, Kandrbandrdzilo, Koca Popovic, kolle.the.kid, Kubovac, kybonacci, laganini123, laurusri, Mediator, menges, Mile80, milenko crazy north, mkukoleca, mnn2, MrNo, Nemanja.M, nick79, SD izvidjac, Shinobi, Simon simonović, srbijaiznadsvega, Srky Boy, Vatreni Zmaj, vladetije, voja64, Wrangler, zastavnik, zillbg, šumar bk2