Poslao: 15 Maj 2013 12:46
|
offline
- Pridružio: 29 Apr 2012
- Poruke: 127
|
Zdravo.
Otvorio sam ovu temu u podforumu Windows, jer mi kartica preskace sa signalom za internet.
Probelm se ispoljava tako sto, mi u donjem desnom uglu stoji da nema konekcije (crveni x preko monitora), kada kliknem Repair, neretko se desi da komp zablokira potpuno. Pa sam onda poceo da sumnjam da nisam mozda ubacio neki virus, mada je komp cist cist s obzirom da sam pre neki dan uradio re-install sistema, ali sam mozda uneo neki virus preko programa koje sam instalirao.
Tekst za link
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by Gost at 0:43:36 on 2013-05-16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1476 [GMT 2:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\rserver30\RServer3.exe
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\WINDOWS\system32\rserver30\FamItrfc.Exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\ROCCAT\Kone Mouse\KoneHID.EXE
C:\Program Files\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe
C:\Program Files\ROCCAT\Kone Mouse\osd.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: <No Name>: {9EBF5C54-224C-48A2-BC86-A5EDA9F8ABF9} - c:\windows\system32\mlJBRHwu.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [HKCU] c:\windows\system32\windir\svchost.exe
mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe"
mRun: [Cpu Level Up help] c:\program files\asus\ai suite\CpuLevelUpHelp.exe
mRun: [ASUS Energy Saving] "c:\program files\asus\ai suite\energysaving\PwSave.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RUSB3MON] "c:\program files\renesas electronics\usb 3.0 host controller driver\application\rusb3mon.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [HKLM] c:\windows\system32\windir\svchost.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [Kone] "c:\program files\roccat\kone mouse\KoneHID.EXE"
uExplorerRun: [Policies] c:\windows\system32\windir\svchost.exe
mExplorerRun: [Policies] c:\windows\system32\windir\svchost.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\realte~1.lnk - c:\program files\realtek rtl8185 wireless lan driver and utility\RtWLan.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: NameServer = 109.122.98.116 109.122.98.117
TCP: Interfaces\{50DE23D2-F1AF-4151-9D8D-A957552880A2} : DHCPNameServer = 109.122.98.116 109.122.98.117
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: mlJBRHwu - mlJBRHwu.dll
SEH: <No Name> - {9EBF5C54-224C-48A2-BC86-A5EDA9F8ABF9} - c:\windows\system32\mlJBRHwu.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {SJ447BF0-J621-VFYM-DTX3-02QL2N80FMM3} - c:\windows\system32\windir\svchost.exe
Hosts: 127.0.0.1 mpa.one.microsoft.com
.
============= SERVICES / DRIVERS ===============
.
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2013-5-15 21664]
R1 raddrvv3;raddrvv3;c:\windows\system32\rserver30\raddrvv3.sys [2010-4-21 46280]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2013-5-14 38144]
R2 RServer3;Radmin Server V3;c:\windows\system32\rserver30\rserver3.exe [2010-4-21 1242480]
R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2013-5-14 3574624]
R3 KoneFltr;ROCCAT Kone;c:\windows\system32\drivers\Kone.sys [2013-5-13 13056]
R3 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [2010-4-21 3328]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\drivers\rusb3hub.sys [2013-5-14 80256]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\drivers\rusb3xhc.sys [2013-5-14 171520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2013-05-15 22:38:56 -------- d-----w- c:\documents and settings\gost\local settings\application data\Google
2013-05-15 22:38:47 -------- d-----w- c:\documents and settings\gost\local settings\application data\Adobe
2013-05-15 22:38:43 -------- d-----w- c:\documents and settings\gost\application data\ROCCAT
2013-05-14 23:43:47 21664 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-05-14 23:43:32 -------- d-----w- c:\program files\HWiNFO32
2013-05-14 20:32:17 -------- d-----w- c:\windows\system32\SoftwareDistribution
2013-05-14 06:07:43 80256 ----a-w- c:\windows\system32\drivers\rusb3hub.sys
2013-05-14 06:06:39 -------- d-----w- c:\program files\Realtek WLAN Driver
2013-05-14 06:02:53 356352 ----a-w- c:\windows\system32\nvudisp.exe
.
==================== Find3M ====================
.
2013-05-14 06:16:34 315392 ----a-w- c:\windows\HideWin.exe
2013-05-14 06:16:19 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2013-05-13 21:26:23 58368 ----a-w- c:\windows\system32\mlJBRHwu.dll
2005-09-27 02:56:07 401478 --sh--r- c:\windows\system32\windir\svchost.exe
.
============= FINISH: 0:44:07.17 ===============
mycity.rs/must-login.png
|
|
|
|
|
|
|
Poslao: 15 Maj 2013 13:34
|
offline
- Pridružio: 29 Apr 2012
- Poruke: 127
|
Napisano: 15 Maj 2013 13:21
ja sam instalirao radmin. sad cu da pokrenem skeniranje.
Dopuna: 15 Maj 2013 13:34
Prilikom skeniranja comboFix-a pojavio se Blue Screen Of Death... kaze da je greska nastala zbog plug and play uredjaja...zaboravio sam da izvadim usb hdd. samo da ti kazem, da znas sad cu oept da pokrenem combofix
|
|
|
|
Poslao: 15 Maj 2013 13:41
|
offline
- TwinHeadedEagle
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
OK, izvadi sve prenosive uredjaje koje imas i nemoj ih ukljucivati dok ti ne kazem...
Nastavi sa ComboFix-om...
|
|
|
|
Poslao: 15 Maj 2013 13:44
|
offline
- Pridružio: 29 Apr 2012
- Poruke: 127
|
ComboFix 13-05-14.01 - Stefan 05/16/2013 1:35.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1542 [GMT 2:00]
Running from: c:\documents and settings\Stefan\My Documents\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Stefan\Application Data\Stefanlog.dat
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\mlJBrhwu.dll
c:\windows\system32\windir
c:\windows\system32\windir\svchost.exe
.
.
((((((((((((((((((((((((( Files Created from 2013-04-15 to 2013-05-15 )))))))))))))))))))))))))))))))
.
.
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-12-01 881152]
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe" [2008-01-28 1352704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz.exe" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"RUSB3MON"="c:\program files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512]
"Kone"="c:\program files\ROCCAT\Kone Mouse\KoneHID.EXE" [2011-02-18 1666560]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
REALTEK RTL8185 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe [2013-5-14 770048]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\rserver30\\rserver3.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer_Service.exe"=
.
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [5/15/2013 1:43 AM 21664]
R1 raddrvv3;raddrvv3;c:\windows\system32\rserver30\raddrvv3.sys [4/21/2010 3:02 PM 46280]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [5/14/2013 8:16 AM 38144]
R2 RServer3;Radmin Server V3;c:\windows\system32\rserver30\rserver3.exe [4/21/2010 3:02 PM 1242480]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [5/14/2013 12:00 AM 3574624]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [5/16/2013 12:50 AM 38656]
R3 KoneFltr;ROCCAT Kone;c:\windows\system32\drivers\Kone.sys [5/13/2013 11:51 PM 13056]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\drivers\rusb3hub.sys [5/14/2013 8:07 AM 80256]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\drivers\rusb3xhc.sys [5/14/2013 8:07 AM 171520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-13 21:33 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-05-13 21:32]
.
2013-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-05-13 21:32]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2013-05-16 01:41
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(152)
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\program files\TeamViewer\Version8\TeamViewer.exe
c:\windows\system32\rserver30\FamItrfc.Exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\program files\ASUS\AASP\1.00.59\aaCenter.exe
c:\program files\TeamViewer\Version8\tv_w32.exe
c:\program files\ROCCAT\Kone Mouse\osd.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2013-05-16 01:42:01 - machine was rebooted
ComboFix-quarantined-files.txt 2013-05-15 23:41
.
Pre-Run: 94,859,382,784 bytes free
Post-Run: 94,997,442,560 bytes free
.
- - End Of File - - 8375021802CF1FA9A5CAF5B06475A76B
mycity.rs/must-login.png
|
|
|
|
Poslao: 15 Maj 2013 13:56
|
offline
- TwinHeadedEagle
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
Preuzmi MCShield sa sljedeće adrese:
http://amf.mycity.rs/mcshield/MCShield-Setup.exe
Instaliraj MCShield i sačekaj da se završi uvodno skeniranje.
Kad se završi uvodno skeniranje, ubacuj sve USB memorijske uređaje redom u USB port i svaki zadrži u portu dok MCShield ne izbaci poruku da je skeniranje završeno. Ukoliko imaš više USB uređaja, zabilježi negdje kojim su redom ubacivani.
Objašnjenje: U USB memorijske uređaje spadaju svi oni uređaji koji po priključivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uređaji itd.
Idi na Start -> All Programs -> MCShield -> Logs -> AllScans
Otvoriće ti se izvještaj u Notepad-u čiji sadržaj treba da postaviš u poruku
|
|
|
|
Poslao: 15 Maj 2013 14:02
|
offline
- Pridružio: 29 Apr 2012
- Poruke: 127
|
>>> MCShield AllScans.txt <<<
>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.5.12.1 / Windows XP <<<
5/16/2013 1:59:13 AM > Drive C: - scan started (no label ~98 GB, NTFS HDD )...
=> The drive is clean.
5/16/2013 1:59:13 AM > Drive D: - scan started (no label ~200 GB, NTFS HDD )...
=> The drive is clean.
5/16/2013 1:59:13 AM > Drive E: - scan started (no label ~298 GB, NTFS HDD )...
=> The drive is clean.
>>> MCShield ::Anti-Malware Tool:: v 2.6.3.21 / DB: 2013.5.12.1 / Windows XP <<<
5/16/2013 2:00:42 AM > Disk G: - skeniranje započeto (Transcend ~932 GB, NTFS HDD )...
=> Disk je čist.
|
|
|
|
|