Provera. Pronasao neke pretnje i uklonio.

Provera. Pronasao neke pretnje i uklonio.

offline
  • Pridružio: 15 Maj 2009
  • Poruke: 963

Napisano: 11 Sep 2009 11:49

E ovako. Danas sam azurirao zastitu koju imam na kompjuteru i skenirao u safe mod nadajuci se da ce to resiti moje probleme sa korisnicima ali nije. Skenirao sam znaci sa MBAM, AVG, Spybot S&D. Svi su ponesto nasli. Postavicu i njihove logove.

MBAM
https://www.mycity.rs/must-login.png

AVG
[url=http://www.mycity.rs/slika.php?slika=150045_125266587_untitled1.JPG][/url]
Prve dve pretnje se gledaju (ostale nisu bitne).

Spybot S&D
Double.Click
Nista vise nije naso.

DDS (Ver_09-07-30.01) - NTFSx86
Run by tata at 10:50:04.93 on Fri 09/11/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1277 [GMT 2:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\nMtsk.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\tata\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - No File
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - No File
BHO: {EB5CEE80-030A-4ED8-8E20-454E9C68380F} - No File
BHO: {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - No File
TB: {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg8\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [nMTaskBarService] nMtsk.exe
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
dRunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32
IE: Iz&vezi u Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
AppInit_DLLs: c:\windows\system32\guard32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tata\applic~1\mozilla\firefox\profiles\wg5zssnz.default\
FF - plugin: c:\program files\google\google updater\2.4.1591.6512\npCIDetect13.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2009-5-6 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-17 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-17 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-17 108552]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-8-24 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-8-24 24208]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-17 297752]
R2 cmdAgent;COMODO Firewall Pro Helper Service;c:\program files\comodo\firewall\cmdagent.exe [2009-8-24 519936]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\common files\nero\nero backitup 4\NBService.exe [2009-7-20 935208]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2009-8-9 4096]
R3 fvdscsi;fvdscsi;c:\windows\system32\drivers\fvdscsi.sys [2009-7-21 72478]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-3-15 279680]
S3 FXDrv32;FXDrv32;\??\d:\fxdrv32.sys --> d:\FXDrv32.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [2009-3-18 7168]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\ghidpnp.sys --> c:\windows\system32\drivers\gHidPnp.Sys [?]
S3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\drivers\gmoups2.sys --> c:\windows\system32\drivers\gMouPS2.sys [?]
S4 cdawdm;CDAWDM;c:\windows\system32\drivers\cdawdm.sys --> c:\windows\system32\drivers\CDAWDM.sys [?]

=============== Created Last 30 ================

2009-09-11 10:38 61,081 a------- C:\untitled.JPG
2009-09-11 09:02 693,760 a------- c:\windows\isRS-000.tmp
2009-09-08 09:32 <DIR> --d----- c:\program files\SIW
2009-09-07 11:36 <DIR> --d----- C:\kole017's documents
2009-09-03 13:47 <DIR> --d----- c:\program files\Aladdin
2009-09-03 13:41 <DIR> --d----- c:\program files\Snowy Space Trip
2009-09-03 13:34 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ScreenSeven
2009-09-03 13:34 <DIR> --d----- c:\program files\phenomedia
2009-09-03 13:24 <DIR> --d----- C:\Skola
2009-08-27 12:10 <DIR> --d----- c:\docume~1\tata\applic~1\BSplayer
2009-08-26 13:00 78,336 a------- c:\windows\system32\ieencode.dll
2009-08-26 13:00 78,336 a------- c:\windows\system32\dllcache\ieencode.dll
2009-08-25 21:01 1,414,440 a------- c:\windows\system32\ShellManager310E2D762.dll
2009-08-25 21:01 774,144 a------- c:\windows\system32\NEROINSTAEC43759.DB
2009-08-25 21:00 0 a------- c:\windows\Irremote.ini
2009-08-24 16:12 <DIR> --d----- c:\docume~1\tata\applic~1\Comodo
2009-08-24 15:53 <DIR> --d----- c:\program files\CCleaner
2009-08-24 14:56 143,104 a------- c:\windows\system32\guard32.dll
2009-08-24 14:56 87,056 a------- c:\windows\system32\drivers\cmdguard.sys
2009-08-24 14:56 24,208 a------- c:\windows\system32\drivers\cmdhlp.sys
2009-08-24 14:56 <DIR> --d----- c:\program files\COMODO
2009-08-24 14:56 <DIR> --d----- c:\docume~1\alluse~1\applic~1\comodo

==================== Find3M ====================

2009-09-11 09:55 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-09-11 09:55 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-09 07:58 30,720 a------- c:\windows\system32\bbcap.dll
2009-08-09 07:58 4,608 a------- c:\windows\system32\bbchlp.dll
2009-08-09 07:58 4,096 a------- c:\windows\system32\drivers\bbcap.sys
2009-07-28 16:33 501,760 a------- c:\windows\system32\3d Landscape Screensaver.exe
2009-07-21 13:36 65,536 a------- c:\windows\system32\VDPross.dat
2009-07-21 08:18 278,984 a------- c:\windows\system32\drivers\atksgt.sys
2009-07-21 08:18 25,416 a------- c:\windows\system32\drivers\lirsgt.sys
2009-07-17 09:57 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 08:46 13,184 a------- c:\windows\system32\scncap.dll
2009-03-15 23:46 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009031520090316\index.dat

============= FINISH: 10:50:32.96 ===============

https://www.mycity.rs/must-login.png

Gmer:
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png

Dopuna: 11 Sep 2009 11:51

Napravio sam gresku kod slike Mr. Green. Ispravite to posto ja ne mogu.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Zdravo,

pogledacemo.

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 15 Maj 2009
  • Poruke: 963

Napisano: 11 Sep 2009 20:00

ComboFix 09-09-10.03 - mimi 09/11/2009 19:46.3.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1386 [GMT 2:00]
Running from: c:\documents and settings\mimi\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\Programs\Incoming Forces Playable Demo

.
((((((((((((((((((((((((( Files Created from 2009-08-11 to 2009-09-11 )))))))))))))))))))))))))))))))
.

2009-09-11 17:31 . 2009-09-11 17:31 -------- d-----w- c:\documents and settings\mimi\Application Data\Malwarebytes
2009-09-11 11:18 . 2009-09-11 11:22 -------- d-----w- c:\documents and settings\lozinka\Application Data\Nero
2009-09-11 07:58 . 2009-09-11 07:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-09-11 06:05 . 2009-09-11 06:05 -------- d-----w- c:\documents and settings\tata\Local Settings\Application Data\Mozilla
2009-09-08 07:32 . 2009-09-08 07:32 -------- d-----w- c:\program files\SIW
2009-09-07 09:36 . 2009-09-07 17:17 -------- d-----w- C:\kole017's documents
2009-09-07 09:25 . 2009-09-07 09:25 -------- d-----w- c:\documents and settings\Administrator\Application Data\Comodo
2009-09-03 11:47 . 2009-09-03 11:47 -------- d-----w- c:\program files\Aladdin
2009-09-03 11:41 . 2009-09-03 11:41 -------- d-----w- c:\program files\Snowy Space Trip
2009-09-03 11:34 . 2009-09-03 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\ScreenSeven
2009-09-03 11:34 . 2009-09-03 11:34 -------- d-----w- c:\program files\phenomedia
2009-09-03 11:24 . 2009-09-05 05:51 -------- d-----w- C:\Skola
2009-08-27 10:10 . 2009-08-27 10:10 -------- d-----w- c:\documents and settings\tata\Application Data\BSplayer
2009-08-27 10:06 . 2009-08-27 10:06 -------- d-----w- c:\documents and settings\mimi\Application Data\Comodo
2009-08-26 11:00 . 2009-04-29 04:49 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-26 11:00 . 2009-04-29 04:49 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-08-25 19:01 . 2008-02-28 11:26 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2009-08-25 16:14 . 2009-08-25 16:14 -------- d-----w- c:\documents and settings\tata\Application Data\Winamp
2009-08-24 14:55 . 2009-08-24 14:55 -------- d-----w- c:\documents and settings\lozinka\Application Data\Comodo
2009-08-24 14:12 . 2009-08-24 14:12 -------- d-----w- c:\documents and settings\tata\Application Data\Comodo
2009-08-24 13:53 . 2009-08-24 13:53 -------- d-----w- c:\program files\CCleaner
2009-08-24 12:56 . 2009-08-24 13:49 -------- d-----w- c:\documents and settings\All Users\Application Data\comodo
2009-08-24 12:56 . 2009-08-24 12:56 87056 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-08-24 12:56 . 2009-08-24 12:56 79760 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-08-24 12:56 . 2009-08-24 12:56 24208 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-08-24 12:56 . 2009-08-24 12:56 143104 ----a-w- c:\windows\system32\guard32.dll
2009-08-24 12:56 . 2009-08-24 12:56 -------- d-----w- c:\program files\COMODO

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-11 17:36 . 2009-05-14 08:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-11 10:05 . 2009-06-05 16:26 -------- d-----w- c:\program files\Wise Registry Cleaner
2009-09-11 10:02 . 2009-06-05 16:27 -------- d-----w- c:\program files\Wise Disk Cleaner
2009-09-11 08:21 . 2009-07-20 15:44 -------- d-----w- c:\program files\Glary Utilities
2009-09-11 07:57 . 2009-05-28 07:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-11 07:55 . 2009-07-17 07:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-11 07:55 . 2009-07-17 07:57 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-11 07:55 . 2009-07-17 07:57 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-11 07:36 . 2009-05-19 18:53 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-10 12:54 . 2009-05-28 07:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2009-05-28 07:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 17:17 . 2009-07-31 17:35 -------- d-----w- c:\program files\Counter-Strike 1.6
2009-09-03 17:52 . 2009-03-16 07:49 49952 ----a-w- c:\documents and settings\tata\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-03 12:00 . 2009-03-30 06:13 -------- d-----w- c:\program files\Common Files\Nero
2009-09-03 12:00 . 2009-03-30 06:13 -------- d-----w- c:\program files\Nero
2009-09-03 11:59 . 2009-03-30 06:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-09-03 11:34 . 2009-03-15 21:55 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-03 11:34 . 2009-03-15 21:54 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-26 11:02 . 2009-07-17 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-24 14:56 . 2009-03-28 18:44 49952 ----a-w- c:\documents and settings\lozinka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-11 10:12 . 2009-05-11 20:44 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-11 10:09 . 2009-08-11 10:09 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-08-11 10:06 . 2009-08-11 10:06 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-11 05:57 . 2009-08-11 05:57 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2009-08-10 11:30 . 2009-06-08 18:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-09 09:31 . 2009-08-09 09:31 4 ----a-w- c:\windows\csdf_sdum.dat
2009-08-09 05:58 . 2009-08-09 05:58 4608 ----a-w- c:\windows\system32\bbchlp.dll
2009-08-09 05:58 . 2009-08-09 05:58 4096 ----a-w- c:\windows\system32\drivers\bbcap.sys
2009-08-09 05:58 . 2009-08-09 05:58 30720 ----a-w- c:\windows\system32\bbcap.dll
2009-08-09 05:58 . 2009-08-09 05:58 -------- d-----w- c:\documents and settings\All Users\Application Data\LogSys
2009-08-06 16:01 . 2009-08-06 16:01 -------- d-----w- c:\program files\PDFCreator
2009-08-06 15:10 . 2009-08-06 15:10 -------- d-----w- c:\program files\Adolix
2009-08-05 16:46 . 2009-08-05 16:46 -------- d-----w- c:\documents and settings\mimi\Application Data\GlarySoft
2009-08-03 06:20 . 2009-07-30 18:44 -------- d-----w- c:\program files\Winamp
2009-08-03 06:18 . 2009-07-30 15:35 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-08-02 07:12 . 2009-08-02 07:12 -------- d-----w- c:\program files\7-Zip
2009-07-31 14:15 . 2009-08-09 08:04 -------- d-----w- c:\program files\Primer1
2009-07-31 08:39 . 2009-07-31 08:30 -------- d-----w- c:\documents and settings\lozinka\Application Data\Winamp
2009-07-28 14:33 . 2009-07-28 14:33 501760 ----a-w- c:\windows\system32\3d Landscape Screensaver.exe
2009-07-28 09:30 . 2009-07-28 09:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Thunderbird
2009-07-24 05:58 . 2009-07-24 05:58 -------- d-----w- c:\program files\Panda USB Vaccine
2009-07-23 17:23 . 2009-07-22 10:15 -------- d-----w- c:\program files\ICQ6.5
2009-07-22 10:43 . 2009-03-24 19:19 -------- d-----w- c:\documents and settings\mimi\Application Data\FarStone
2009-07-21 16:52 . 2009-03-18 21:14 -------- d-----w- c:\documents and settings\tata\Application Data\FarStone
2009-07-21 12:13 . 2009-07-21 12:13 -------- d-----w- c:\documents and settings\lozinka\Application Data\FarStone
2009-07-21 11:36 . 2009-07-21 11:36 65536 ----a-w- c:\windows\system32\VDPross.dat
2009-07-21 11:34 . 2009-07-21 11:34 -------- d-----w- c:\program files\FarStone
2009-07-21 06:18 . 2009-07-21 06:18 278984 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-07-21 06:18 . 2009-07-21 06:18 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-07-20 15:15 . 2009-07-20 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-17 07:57 . 2009-07-17 07:57 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-17 07:57 . 2009-07-17 07:57 -------- d-----w- c:\program files\AVG
2009-07-17 07:57 . 2009-07-17 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-22 06:46 . 2009-06-22 06:46 9984 ----a-w- c:\windows\system32\drivers\scncap.sys
2009-06-22 06:46 . 2009-06-22 06:46 13184 ----a-w- c:\windows\system32\scncap.dll
2009-06-14 13:50 . 2009-06-14 13:50 0 ----a-w- c:\windows\nsreg.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 14:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-07-12 29896704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-02 13529088]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-02 86016]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-11 2007832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-02 1630208]
"nMTaskBarService"="nMtsk.exe" - c:\windows\nMtsk.exe [2003-07-22 90112]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-04-29 124928]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-11 07:55 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^H@cKeR^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [5/6/2009 1:01 PM 11264]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/17/2009 9:57 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/17/2009 9:57 AM 108552]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [8/24/2009 2:56 PM 87056]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [8/24/2009 2:56 PM 24208]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/17/2009 9:57 AM 297752]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [8/9/2009 7:58 AM 4096]
R3 fvdscsi;fvdscsi;c:\windows\system32\drivers\fvdscsi.sys [7/21/2009 1:35 PM 72478]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [3/15/2009 11:54 PM 279680]
S3 FXDrv32;FXDrv32;\??\d:\fxdrv32.sys --> d:\FXDrv32.sys [?]
S3 genmcmnUSB;USB Scroll Mouse Driver;c:\windows\system32\drivers\gflmouhid.sys [3/18/2009 11:09 PM 7168]
S3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\Drivers\gHidPnp.Sys --> c:\windows\system32\Drivers\gHidPnp.Sys [?]
S3 gMouPS2;PS2 Scroll Mouse Device;c:\windows\system32\DRIVERS\gMouPS2.sys --> c:\windows\system32\DRIVERS\gMouPS2.sys [?]
S4 cdawdm;CDAWDM;c:\windows\system32\DRIVERS\CDAWDM.sys --> c:\windows\system32\DRIVERS\CDAWDM.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D58F39FF-953E-4F45-898F-59F243B9A523}]
RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,Register
.
Contents of the 'Scheduled Tasks' folder

2009-09-11 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-08-10 14:55]

2009-09-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-25 20:01]

2009-09-11 c:\windows\Tasks\PandaUSBVaccine.job
- c:\program files\Panda USB Vaccine\RunInteractiveWin.exe [2009-07-24 10:30]

2009-09-11 c:\windows\Tasks\User_Feed_Synchronization-{B14E244A-857E-478D-A028-C263BA7C72CF}.job
- c:\windows\system32\msfeedssync.exe [2008-04-14 17:36]

2009-09-11 c:\windows\Tasks\User_Feed_Synchronization-{E106F666-B61F-483C-9C61-03E8C1FBB77C}.job
- c:\windows\system32\msfeedssync.exe [2008-04-14 17:36]

2009-06-08 c:\windows\Tasks\Wise Disk Cleaner 4.job
- c:\program files\Wise Disk Cleaner\WiseDiskCleaner.exe [2009-06-05 13:35]

2009-06-08 c:\windows\Tasks\Wise Registry Cleaner 4.job
- c:\program files\Wise Registry Cleaner\WiseRegistryCleaner.exe [2009-06-05 22:16]
.
.
------- Supplementary Scan -------
.
IE: Iz&vezi u Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -

BHO-{EB5CEE80-030A-4ED8-8E20-454E9C68380F} - (no file)
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-11 19:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\ESET\ESET Security\CurrentVersion\Info]
@Denied: (3) (LocalSystem)
"DataDir"="ESET\\ESET Smart Security\\"
"EditionName"="Student Edition"
"LanguageId"=dword:00000409
"ProductBase"=dword:00000001
"ProductCode"="{4CEBE5E6-D1FD-4BDF-8C9C-29A9A3CC2B7C}"
"ProductName"="ESET Smart Security"
"ProductType"="ess"
"ProductVersion"="3.0.684.0"
"ScannerVersion"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(704)
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll

- - - - - - - > 'explorer.exe'(2012)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-09-11 19:52
ComboFix-quarantined-files.txt 2009-09-11 17:52

Pre-Run: 92,373,663,744 bytes free
Post-Run: 92,387,684,352 bytes free

234 --- E O F --- 2009-08-25 18:01

Sto se tice Recovery Consloe za nju je potrebna konekcija sto ja tada nisam mogao da priustim pa sam nastavio bez nje. Ovo Incoming Forces Playable Demo je ostalo od njene deinstalacije (u pitanju je igrica) jer nisam mogao da je uklonim iz nekog razloga.

Dopuna: 11 Sep 2009 20:04

A sto se tice Comoda Virus Defence sekciju nisam uspeo da pronadjem ali sam ga iskljucio (desni klik na ikonicu pa Exit) i iskljucio sam da se pokrece sa windowsom a Defence + mi je uvek iskljucen.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

A, koji su problemi koji se javljaju?

offline
  • Pridružio: 15 Maj 2009
  • Poruke: 963

Vise nema ni jednog problema. Bilo je u pitanju ovo:
http://www.mycity.rs/Windows/Problem-sa-korisnicima.html
Nije mi radio User Accounts i gpedit.msc a kada su pronadjene ove 9 pretnje odlucio sam da otvorim temu ovde da proverim posto mi posle ciscenja jos nisu radile te dve stvari. Na kraju je ispalo samo da je IE8 problem.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

ok.

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

combofix /u

Primeti da postoji razmak između "ComboFix" i "/u".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

offline
  • Pridružio: 15 Maj 2009
  • Poruke: 963

Ok. Hvala.

Ko je trenutno na forumu
 

Ukupno su 1111 korisnika na forumu :: 46 registrovanih, 6 sakrivenih i 1059 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, A.R.Chafee.Jr., babaroga, bladesu, bojan_t, branko7, cifra, cikadeda, crnitrn, darkojbn, Denaya, djboj, djordje92sm, Dorcolac, Draganeli, draganl, havoc995, HogarStrashni, kolle.the.kid, Koridor, kvcali, Libertas, ljuba, mane123, Marko Marković, Mendonca, mercedesamg, Milan A. Nikolic, milimoj, mnn2, moldway, Motocar, nebkv, nenooo, nextyamb, novator, pein, Povratak1912, rovac, ruma, sevenino, shlauf, Snorks, Stoilkovic, Tvrtko I, Viktor Petrenko