Poslao: 16 Apr 2008 10:27
|
offline
- gogi100
- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
Molio bih za jos jednu pomoc. Ono sto sam pricao na poslu sam zarazio jos 2 racunara. Evo kako izgleda hijackthis log za jedan od njih. Bitno mi je da njega oporavim
Logfile of HijackThis v1.99.1
Scan saved at 10:22:12, on 16.04.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Documents and Settings\gogi\Desktop\MicroWorld antivirus\izvrsni fajlovi\MWAVSCAN.COM
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\gogi\Desktop\virusi\TR3.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:808
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - c:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = SOPETROVAC.ORG.RS
O17 - HKLM\Software\..\Telephony: DomainName = SOPETROVAC.ORG.RS
O17 - HKLM\System\CCS\Services\Tcpip\..\{3CCD966D-86BB-4B05-AFC7-3656A4FCB338}: NameServer = 192.168.0.119
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = SOPETROVAC.ORG.RS
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = SOPETROVAC.ORG.RS
O20 - AppInit_DLLs: msosdohs00.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: 9BC11C18 - Unknown owner - C:\WINDOWS\system32\2DED3ED8.EXE (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
|
|
|
|
|
Poslao: 17 Apr 2008 14:42
|
offline
- gogi100
- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
log combofix-a je
ComboFix 08-04-15.4 - gogi 2008-04-16 13:31:00.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.250 [GMT 2:00]
Running from: C:\Documents and Settings\gogi\Desktop\virusi\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\dxtmechk
C:\WINDOWS\regedit.com
C:\WINDOWS\system32\k11993426342.exe
C:\WINDOWS\system32\k11998183583.exe
C:\WINDOWS\system32\k119981837214.exe
C:\WINDOWS\system32\k12065112715.exe
C:\WINDOWS\system32\k12065112726.exe
C:\WINDOWS\system32\k12066841263.exe
C:\WINDOWS\system32\k12066841285.exe
C:\WINDOWS\system32\k12067326814.exe
C:\WINDOWS\system32\k12067747063.exe
C:\WINDOWS\system32\k120677471510.exe
C:\WINDOWS\system32\k12069398073.exe
C:\WINDOWS\system32\k12069541213.exe
C:\WINDOWS\system32\k12070259994.exe
C:\WINDOWS\system32\k12071131132.exe
C:\WINDOWS\system32\k12071131143.exe
C:\WINDOWS\system32\k12071987584.exe
C:\WINDOWS\system32\k120719876610.exe
C:\WINDOWS\system32\k12072851165.exe
C:\WINDOWS\system32\k120832659715.exe
C:\WINDOWS\system32\k120832659816.exe
C:\WINDOWS\system32\k120832659917.exe
C:\WINDOWS\system32\k120832660522.exe
C:\WINDOWS\system32\llk1205260603.h
C:\WINDOWS\system32\llk1207832150.h
C:\WINDOWS\system32\msosdohs.dat
C:\WINDOWS\system32\msosdrop.dat
C:\WINDOWS\system32\msosmhfp.dat
C:\WINDOWS\system32\REGKEY.hiv
C:\WINDOWS\system32\taskmgr.com
D:\auto.exe
F:\auto.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DROP
-------\Legacy_FPIDS32
-------\Legacy_MHFP
-------\Legacy_MSFPFIS64
((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
.
2008-04-16 10:15 . 2001-08-17 13:47 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
2008-04-16 10:15 . 2001-08-17 13:47 12,928 --a--c--- C:\WINDOWS\system32\dllcache\dot4prt.sys
2008-04-16 10:14 . 2004-08-03 22:58 207,360 --a------ C:\WINDOWS\system32\drivers\Dot4.sys
2008-04-16 10:14 . 2004-08-03 22:58 207,360 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-04-16 10:14 . 2001-08-17 13:47 23,808 --a------ C:\WINDOWS\system32\drivers\Dot4usb.sys
2008-04-16 10:14 . 2001-08-17 13:47 23,808 --a--c--- C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-04-16 10:08 . 2008-04-16 10:53 0 --a------ C:\23990098.$$$
2008-04-16 09:16 . 2008-04-16 09:16 <DIR> d-------- C:\WINDOWS\system32\EFFA9C20.DLL
2008-04-16 08:15 . 2008-04-16 09:29 78 --ah----- C:\autorun.inf.mwt
2008-04-11 14:49 . 2008-04-11 14:49 4,226,353 --a------ C:\WINDOWS\REGBK01.ZIP
2008-04-11 07:07 . 2008-04-11 12:18 62 --a------ C:\WINDOWS\Update.dat
2008-04-01 13:10 . 2008-04-01 13:10 <DIR> d-------- C:\WINDOWS\PIF
2008-03-31 14:02 . 2008-03-31 14:02 <DIR> d-------- C:\Program Files\Stonisa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-16 11:13 --------- d-----w C:\Documents and Settings\gogi\Application Data\SolidDocuments
2008-04-16 05:13 --------- d-----w C:\Program Files\FreeCap
2008-04-14 07:48 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\SolidDocuments
2008-04-12 06:14 --------- d-----w C:\Program Files\Common Files\Real
2008-04-12 06:13 --------- d-----w C:\Program Files\Online TV Player 3
2008-04-01 04:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 12:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-31 08:54 --------- d-----w C:\Program Files\Evidencija Gradjana
2008-03-29 13:56 180,999 ----a-w C:\Program Files\firebird.log
2008-03-26 12:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-03-19 17:08 --------- d-----w C:\Program Files\Java
2008-03-11 17:49 640 ----a-w C:\WINDOWS\system32\drivers\usbKeyInit.sys.mwt
2008-03-11 17:49 1,024 ----a-w C:\WINDOWS\system32\drivers\usbinite.sys.mwt
2008-03-11 17:04 4,224,123 ----a-w C:\WINDOWS\REGBK00.ZIP
2008-03-05 06:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-05 06:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-05 06:05 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-29 06:09 --------- d-----w C:\Program Files\SolidDocuments
2008-02-29 06:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\SolidDocuments
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 14:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 17:24 86016]
"SoundMan"="SOUNDMAN.EXE" [2003-07-23 18:19 56832 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2002-12-31 14:00 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{003C673E-D7A2-456A-AE04-EB9ABF822FE4}"= C:\DOCUME~1\gogi\LOCALS~1\Temp\k120789031019ow.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 20:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVPSrv]
C:\WINDOWS\AVPSrv.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmdbcs]
C:\WINDOWS\cmdbcs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DbgHlp32]
C:\WINDOWS\DbgHlp32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HB Kernel]
C:\WINDOWS\system32\HBKrnl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kvsc3]
C:\WINDOWS\Kvsc3.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LotusHlp]
C:\WINDOWS\LotusHlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
C:\WINDOWS\mppds.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msccrt]
C:\WINDOWS\msccrt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsIMMs32]
C:\WINDOWS\MsIMMs32.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:21 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsPrint32D]
C:\WINDOWS\MsPrint32D.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAVMon32]
C:\WINDOWS\NAVMon32.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 17:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVDispDrv]
C:\WINDOWS\gvynii.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTSShell]
C:\WINDOWS\PTSShell.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegSrv64D]
C:\WINDOWS\RegSrv64D.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SHAProc]
C:\WINDOWS\SHAProc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSLDyn]
C:\WINDOWS\SSLDyn.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-03-03 04:39 6144 C:\Program Files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upxdnd]
C:\WINDOWS\upxdnd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinForm]
C:\WINDOWS\WinForm.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINSvr32]
C:\WINDOWS\WINSvr32.exE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysM]
C:\WINDOWS\235780M.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysW]
C:\WINDOWS\235780L.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WSockDrv32]
C:\WINDOWS\WSockDrv32.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
S2 9BC11C18;9BC11C18;C:\WINDOWS\system32\2DED3ED8.EXE []
S2 HBKernel;HBKernel Driver;C:\WINDOWS\system32\drivers\HBKernel.sys []
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-16 13:34:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
.
**************************************************************************
.
Completion time: 2008-04-16 13:37:27 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-16 11:37:12
Pre-Run: 106,086,801,408 bytes free
Post-Run: 106,198,499,328 bytes free
Dopuna: 17 Apr 2008 14:42
molim te pomozi ako mozes sto pre. hitno mi je
|
|
|
|
Poslao: 18 Apr 2008 07:40
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Otvoriti Notepad i iskopirati sledeci tekst:
File::
C:\autorun.inf.mwt
C:\WINDOWS\system32\drivers\usbKeyInit.sys.mwt
C:\WINDOWS\system32\drivers\usbinite.sys.mwt
C:\DOCUME~1\gogi\LOCALS~1\Temp\k120789031019ow.dll
C:\WINDOWS\AVPSrv.exE
C:\WINDOWS\cmdbcs.exe
C:\WINDOWS\DbgHlp32.exe
C:\WINDOWS\system32\HBKrnl.dll
C:\WINDOWS\Kvsc3.exE
C:\WINDOWS\LotusHlp.exe
C:\WINDOWS\mppds.exe
C:\WINDOWS\msccrt.exe
C:\WINDOWS\MsIMMs32.exE
C:\WINDOWS\MsPrint32D.exe
C:\WINDOWS\NAVMon32.exE
C:\WINDOWS\gvynii.exe
C:\WINDOWS\PTSShell.exe
C:\WINDOWS\RegSrv64D.exE
C:\WINDOWS\SHAProc.exe
C:\WINDOWS\SSLDyn.exE
C:\WINDOWS\upxdnd.exe
C:\WINDOWS\WinForm.exE
C:\WINDOWS\WINSvr32.exE
C:\WINDOWS\235780M.exe
C:\WINDOWS\235780L.exe
C:\WINDOWS\WSockDrv32.exe
Driver::
2DED3ED8
HBKernel
Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{003C673E-D7A2-456A-AE04-EB9ABF822FE4}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVPSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmdbcs]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DbgHlp32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HB Kernel]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kvsc3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LotusHlp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msccrt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsIMMs32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsPrint32D]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAVMon32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVDispDrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTSShell]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegSrv64D]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SHAProc]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSLDyn]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upxdnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinForm]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINSvr32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysW]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WSockDrv32]
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
|
|
|
|
Poslao: 18 Apr 2008 10:35
|
offline
- gogi100
- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
problem. uradio sam ovako kako je receno ali kad prevucem ovaj .txt fajl izbacuje mali prozorcic ComboFix ali nista se ne desava. Ne pravi Log fajl.
|
|
|
|
Poslao: 19 Apr 2008 17:58
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Probaj ovako:
Otvoriti Notepad i iskopirati sledeci tekst:
Driver::
2DED3ED8
HBKernel
Registry::
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{003C673E-D7A2-456A-AE04-EB9ABF822FE4}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVPSrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cmdbcs]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DbgHlp32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HB Kernel]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kvsc3]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LotusHlp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msccrt]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsIMMs32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsPrint32D]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAVMon32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVDispDrv]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PTSShell]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegSrv64D]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SHAProc]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSLDyn]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upxdnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinForm]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINSvr32]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinSysW]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WSockDrv32]
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
|
|
|
|
Poslao: 20 Apr 2008 09:24
|
offline
- gogi100
- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
Odradio sam ovo ali mi opet nije izbacio .log Mozda ovo bude od koristi. Na kompu imam instaliran spyboot search and destroy 1.5.2 i u tray-u radi tea timer. Njegov log je detektovao sledece
20.04.2008 09:16:55 Allowed (based on user decision) value "GrpConv" (new data: "grpconv -o") added in System Startup global entry!
20.04.2008 09:16:58 Allowed (based on user decision) value "GrpConv" (new data: "") deleted in System Startup global entry!
|
|
|
|
Poslao: 20 Apr 2008 18:05
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Probacemo ovako:
Spybot S&D's Teatimer
Pokrenite Spybot S&D
Kliknite Mode stavku u meniju
Odaberite Advance Mode
Na traci levo kliknite na Tools
Kliknite na Resident
Destiklirajte Resident Tea-Timer
Zatvorite Spybot S&D
Restartujte kompjuter.
Nemojte zaboraviti da ponovo ukljucite ove opcije kada zavrsimo ciscenje.
Kad iskljucis Tea-Timer probaj ponovo skriptu. Ako nece opet, onda skini ponovo CF na Desktop ali ga sacuvaj pod nekim drugim imenom. I onda probaj skriptu. Moguce je da ga neka infekcija blokira.
|
|
|
|
Poslao: 21 Apr 2008 07:26
|
offline
- gogi100
- Građanin
- Pridružio: 26 Jan 2006
- Poruke: 233
|
profunkcionisalo je kad sam iskljucio TeaTimer
log ComboFixa je
ComboFix 08-04-20.2 - gogi 2008-04-21 7:20:10.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1251.1.1033.18.314 [GMT 2:00]
Running from: C:\Documents and Settings\gogi\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\gogi\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-21 to 2008-04-21 )))))))))))))))))))))))))))))))
.
2008-04-16 13:30 . 2008-04-21 07:14 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-04-16 10:15 . 2001-08-17 13:47 12,928 --a------ C:\WINDOWS\system32\drivers\Dot4Prt.sys
2008-04-16 10:15 . 2001-08-17 13:47 12,928 --a--c--- C:\WINDOWS\system32\dllcache\dot4prt.sys
2008-04-16 10:14 . 2004-08-03 22:58 207,360 --a------ C:\WINDOWS\system32\drivers\Dot4.sys
2008-04-16 10:14 . 2004-08-03 22:58 207,360 --a--c--- C:\WINDOWS\system32\dllcache\dot4.sys
2008-04-16 10:14 . 2001-08-17 13:47 23,808 --a------ C:\WINDOWS\system32\drivers\Dot4usb.sys
2008-04-16 10:14 . 2001-08-17 13:47 23,808 --a--c--- C:\WINDOWS\system32\dllcache\dot4usb.sys
2008-04-16 09:16 . 2008-04-16 09:16 <DIR> d-------- C:\WINDOWS\system32\EFFA9C20.DLL
2008-04-16 08:15 . 2008-04-16 09:29 78 --ah----- C:\autorun.inf.mwt
2008-04-11 14:49 . 2008-04-11 14:49 4,226,353 --a------ C:\WINDOWS\REGBK01.ZIP
2008-04-01 13:10 . 2008-04-01 13:10 <DIR> d-------- C:\WINDOWS\PIF
2008-03-31 14:02 . 2008-03-31 14:02 <DIR> d-------- C:\Program Files\Stonisa
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-20 07:31 --------- d-----w C:\Documents and Settings\gogi\Application Data\SolidDocuments
2008-04-20 07:24 --------- d-----w C:\Program Files\FreeCap
2008-04-12 06:14 --------- d-----w C:\Program Files\Common Files\Real
2008-04-12 06:13 --------- d-----w C:\Program Files\Online TV Player 3
2008-04-01 04:58 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-31 12:17 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-31 08:54 --------- d-----w C:\Program Files\Evidencija Gradjana
2008-03-29 13:56 180,999 ----a-w C:\Program Files\firebird.log
2008-03-26 12:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-03-19 17:08 --------- d-----w C:\Program Files\Java
2008-03-11 17:49 640 ----a-w C:\WINDOWS\system32\drivers\usbKeyInit.sys.mwt
2008-03-11 17:49 1,024 ----a-w C:\WINDOWS\system32\drivers\usbinite.sys.mwt
2008-03-11 17:04 4,224,123 ----a-w C:\WINDOWS\REGBK00.ZIP
2008-03-05 06:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-05 06:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-05 06:05 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-02-29 06:09 --------- d-----w C:\Program Files\SolidDocuments
2008-02-29 06:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\SolidDocuments
.
((((((((((((((((((((((((((((( snapshot@2008-04-16_13.37.01.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-16 11:33:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-21 05:16:25 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 17:24 86016]
"SoundMan"="SOUNDMAN.EXE" [2003-07-23 18:19 56832 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2002-12-31 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 20:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 12:21 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 17:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2006-03-03 04:39 6144 C:\Program Files\Unlocker\UnlockerAssistant.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\totalcmd\\TOTALCMD.EXE"=
S2 9BC11C18;9BC11C18;C:\WINDOWS\system32\2DED3ED8.EXE []
|
|
|
|
Poslao: 21 Apr 2008 15:12
|
offline
- helen1
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8620
- Gde živiš: Novi Beograd
|
Iskljuci ponovo Tea-Timer
Otvoriti Notepad i iskopirati sledeci tekst:
File::
C:\autorun.inf.mwt
C:\WINDOWS\system32\drivers\usbKeyInit.sys.mwt
C:\WINDOWS\system32\drivers\usbinite.sys.mwt
Driver::
2DED3ED8
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
Uploaduj mi sledeci fajl na proveru:
C:\WINDOWS\system32\EFFA9C20.DLL
preko ovog linka:
http://www.mycity.rs/ambulanta-upload.php
|
|
|
|