Komp mi je usporen!

2

Komp mi je usporen!

offline
  • Pridružio: 26 Nov 2008
  • Poruke: 24

ComboFix 09-03-06.02 - Goran 2009-03-11 12:27:06.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.59 [GMT 1:00]
Running from: c:\documents and settings\Goran\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Goran\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\documents and settings\LocalService\uirhee.exe
c:\windows\system\wmibusn.exe
c:\windows\system32\bz.exe
c:\windows\system32\jd.exe
c:\windows\system32\nv.exe
c:\windows\system32\ui.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\uirhee.exe
c:\windows\system\wmibusn.exe
c:\windows\system32\bz.exe
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\jd.exe
c:\windows\system32\nv.exe
c:\windows\system32\ui.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_WMIBUSN
-------\Service_WMIBUSn


((((((((((((((((((((((((( Files Created from 2009-02-11 to 2009-03-11 )))))))))))))))))))))))))))))))
.

2009-03-11 02:30 . 2009-03-11 02:30 33,440 --a------ c:\windows\system32\drivers\neeqlnfm.sys
2009-03-11 02:19 . 2009-03-11 02:19 116,224 --------- C:\autoexec.exe
2009-03-11 02:19 . 2009-03-11 02:19 67,584 ---h----- c:\windows\system32\secupdat.dat
2009-03-11 02:19 . 2009-03-11 02:19 13,312 --ah----- c:\documents and settings\LocalService\utwctb.exe
2009-03-08 23:43 . 2009-03-09 01:47 <DIR> d-------- c:\program files\DivX
2009-03-08 15:19 . 2009-03-08 15:35 <DIR> d-------- c:\program files\NoAdware
2009-03-08 04:18 . 2009-03-08 04:20 <DIR> d-------- c:\documents and settings\Goran\Application Data\vlc
2009-03-07 05:07 . 2009-03-07 05:07 <DIR> d-------- c:\program files\Yahoo!
2009-03-07 05:07 . 2009-03-07 05:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-07 04:58 . 2009-03-07 05:09 <DIR> d-------- c:\documents and settings\Goran\Application Data\mIRC
2009-03-07 04:45 . 2009-03-07 04:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nokia
2009-03-07 04:42 . 2009-03-07 04:42 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-07 04:06 . 2009-03-07 04:06 <DIR> dr------- c:\program files\Skype
2009-03-07 04:06 . 2009-03-07 04:06 <DIR> d-------- c:\program files\Common Files\Skype
2009-03-04 12:11 . 2009-03-07 02:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-04 12:11 . 2009-03-04 12:11 <DIR> d-------- c:\documents and settings\Goran\Application Data\Malwarebytes
2009-03-04 12:11 . 2009-03-04 12:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-04 12:11 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-04 12:11 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 02:59 . 2009-02-28 02:59 <DIR> d-------- c:\program files\Eagle USB ADSL Modem
2009-02-28 02:47 . 2004-08-04 00:56 16,384 --a------ c:\windows\system32\ipsink.ax
2009-02-28 02:47 . 2004-08-04 00:56 16,384 --a--c--- c:\windows\system32\dllcache\ipsink.ax
2009-02-28 02:47 . 2004-08-03 23:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 15,360 --a--c--- c:\windows\system32\dllcache\streamip.sys
2009-02-28 02:47 . 2004-08-03 23:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 11,136 --a--c--- c:\windows\system32\dllcache\slip.sys
2009-02-28 02:47 . 2004-08-03 23:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 10,880 --a--c--- c:\windows\system32\dllcache\ndisip.sys
2009-02-28 02:47 . 2004-08-03 22:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2009-02-28 02:47 . 2004-08-03 22:58 5,504 --a--c--- c:\windows\system32\dllcache\mstee.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 11:29 802,848 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-11 11:29 8,400 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-11 11:29 2,800 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-11 11:29 196,640 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-08 17:05 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-08 15:58 5,618,277 ----a-w c:\program files\eav_nt64_enu.msi
2009-03-07 04:07 --------- d-----w c:\documents and settings\Goran\Application Data\Skype
2009-03-07 03:44 --------- d-----w c:\program files\Nokia
2009-03-07 03:43 --------- d-----w c:\program files\Common Files\Nokia
2009-03-07 03:41 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-03-07 03:06 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-03-04 00:39 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-04 00:39 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-04 00:39 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-28 03:40 --------- d-----w c:\documents and settings\Goran\Application Data\Ahead
2009-02-28 01:59 29 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-02-28 01:59 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-12 22:26 306,432 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-12-11 00:33 86,016 ----a-w c:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\system32\dtu100.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-09 4136960]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Goran\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-12-13 1642496]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\Eagle USB ADSL Modem\Eagle Family USB ADSL\dslmon.exe [2009-02-28 929889]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\0autocheck autochk /r \??\c:\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\neeqlnfm.sys]
@="Driver"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R0 neeqlnfm;neeqlnfm;c:\windows\system32\drivers\neeqlnfm.sys [2009-03-11 33440]
R1 ANVIOCTL;ANVIOCTL;c:\windows\system32\drivers\anvioctl.sys [2008-12-12 233816]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 PAC7302;iLook 300;c:\windows\system32\drivers\PAC7302.SYS [2008-12-13 458112]
R3 ReallusionVirtualAudio;Reallusion Virtual Audio;c:\windows\system32\drivers\RLVrtAuCbl.sys [2008-12-13 31616]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-03-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = \blank.htm
IE: &Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-11 12:30:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-602162358-1647877149-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**)**%\OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1116)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\asuskbservice.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-11 12:32:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-11 11:32:28
ComboFix2.txt 2009-03-11 00:55:55
ComboFix3.txt 2009-03-10 11:56:57
ComboFix4.txt 2009-03-08 17:27:12

Pre-Run: 24,628,867,072 bytes free
Post-Run: 24,613,867,520 bytes free

183

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Probacemo jos jednom sa ComboFixom, zato sto se infekcija stalno vraca:

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\system32\drivers\neeqlnfm.sys
C:\autoexec.exe
c:\windows\system32\secupdat.dat
c:\documents and settings\LocalService\utwctb.exe

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\neeqlnfm.sys]

Driver::
neeqlnfm



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 26 Nov 2008
  • Poruke: 24

ComboFix 09-03-10.03 - Goran 2009-03-11 16:27:37.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.68 [GMT 1:00]
Running from: c:\documents and settings\Goran\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Goran\Desktop\CFScript.txt
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
C:\autoexec.exe
c:\documents and settings\LocalService\utwctb.exe
c:\windows\system32\drivers\neeqlnfm.sys
c:\windows\system32\secupdat.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autoexec.exe
c:\documents and settings\LocalService\utwctb.exe
c:\windows\system32\drivers\neeqlnfm.sys
c:\windows\system32\secupdat.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NEEQLNFM
-------\Service_neeqlnfm


((((((((((((((((((((((((( Files Created from 2009-02-11 to 2009-03-11 )))))))))))))))))))))))))))))))
.

2009-03-08 23:43 . 2009-03-09 01:47 <DIR> d-------- c:\program files\DivX
2009-03-08 15:19 . 2009-03-08 15:35 <DIR> d-------- c:\program files\NoAdware
2009-03-08 04:18 . 2009-03-08 04:20 <DIR> d-------- c:\documents and settings\Goran\Application Data\vlc
2009-03-07 05:07 . 2009-03-07 05:07 <DIR> d-------- c:\program files\Yahoo!
2009-03-07 05:07 . 2009-03-07 05:10 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-03-07 04:58 . 2009-03-11 16:20 <DIR> d-------- c:\documents and settings\Goran\Application Data\mIRC
2009-03-07 04:45 . 2009-03-07 04:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\Nokia
2009-03-07 04:42 . 2009-03-07 04:42 <DIR> d-------- c:\program files\MSXML 6.0
2009-03-07 04:06 . 2009-03-07 04:06 <DIR> dr------- c:\program files\Skype
2009-03-07 04:06 . 2009-03-07 04:06 <DIR> d-------- c:\program files\Common Files\Skype
2009-03-04 12:11 . 2009-03-07 02:34 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-04 12:11 . 2009-03-04 12:11 <DIR> d-------- c:\documents and settings\Goran\Application Data\Malwarebytes
2009-03-04 12:11 . 2009-03-04 12:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-04 12:11 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-04 12:11 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-28 02:59 . 2009-02-28 02:59 <DIR> d-------- c:\program files\Eagle USB ADSL Modem
2009-02-28 02:47 . 2004-08-04 00:56 16,384 --a------ c:\windows\system32\ipsink.ax
2009-02-28 02:47 . 2004-08-04 00:56 16,384 --a--c--- c:\windows\system32\dllcache\ipsink.ax
2009-02-28 02:47 . 2004-08-03 23:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 15,360 --a--c--- c:\windows\system32\dllcache\streamip.sys
2009-02-28 02:47 . 2004-08-03 23:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 11,136 --a--c--- c:\windows\system32\dllcache\slip.sys
2009-02-28 02:47 . 2004-08-03 23:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2009-02-28 02:47 . 2004-08-03 23:10 10,880 --a--c--- c:\windows\system32\dllcache\ndisip.sys
2009-02-28 02:47 . 2004-08-03 22:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2009-02-28 02:47 . 2004-08-03 22:58 5,504 --a--c--- c:\windows\system32\dllcache\mstee.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-11 15:29 802,848 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-03-11 15:29 8,400 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-11 15:29 2,800 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-03-11 15:29 196,640 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-03-08 17:05 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-03-08 15:58 5,618,277 ----a-w c:\program files\eav_nt64_enu.msi
2009-03-07 04:07 --------- d-----w c:\documents and settings\Goran\Application Data\Skype
2009-03-07 03:44 --------- d-----w c:\program files\Nokia
2009-03-07 03:43 --------- d-----w c:\program files\Common Files\Nokia
2009-03-07 03:41 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-03-07 03:06 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2009-03-04 00:39 89,601 ----a-w c:\windows\system32\drivers\klick.dat
2009-03-04 00:39 33,808 ----a-w c:\windows\system32\drivers\klbg.sys
2009-03-04 00:39 101,287 ----a-w c:\windows\system32\drivers\klin.dat
2009-02-28 03:40 --------- d-----w c:\documents and settings\Goran\Application Data\Ahead
2009-02-28 01:59 29 ----a-w c:\windows\system32\drivers\adidsl.cfg
2009-02-28 01:59 --------- d--h--w c:\program files\InstallShield Installation Information
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-09 4136960]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Goran\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2008-12-13 1642496]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - c:\program files\Eagle USB ADSL Modem\Eagle Family USB ADSL\dslmon.exe [2009-02-28 929889]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuSubFolders"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
"NoPrinters"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoChangeAnimation"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\c:\0autocheck autochk /r \??\c:\0autocheck autochk *\0lsdelete

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]
R1 ANVIOCTL;ANVIOCTL;c:\windows\system32\drivers\anvioctl.sys [2008-12-12 233816]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 PAC7302;iLook 300;c:\windows\system32\drivers\PAC7302.SYS [2008-12-13 458112]
R3 ReallusionVirtualAudio;Reallusion Virtual Audio;c:\windows\system32\drivers\RLVrtAuCbl.sys [2008-12-13 31616]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-03-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uLocal Page = \blank.htm
IE: &Search
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-11 16:31:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-602162358-1647877149-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**)**%\OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1116)
c:\windows\system32\relog_ap.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\windows\asuskbservice.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-11 16:33:00 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-11 15:32:55
ComboFix2.txt 2009-03-11 11:32:35
ComboFix3.txt 2009-03-11 00:55:55
ComboFix4.txt 2009-03-10 11:56:57
ComboFix5.txt 2009-03-11 15:25:42

Pre-Run: 24,591,998,976 bytes free
Post-Run: 24,581,480,448 bytes free

169

Dopuna: 11 Mar 2009 16:41

evo uradio sam ponovo...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

I, cini mi se da nema vise problematicnih fajlova.

Kako tebi radi?

offline
  • Pridružio: 26 Nov 2008
  • Poruke: 24

sad cu da pogledam kako radi pa javljam.... da li da ga skeniram sa antivirusom i antimalewerom koji imam za svaki slucaj? da vidim hoce li navatati jos nesto?
i htedoh da te pitam imas li neki dobar program zastite da mi das koji smatras da je ok? ocigledno da ovi koje imam i nisu bas nesto...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Skeniraj.

Takodje, bi posle nekog vremena mogao opet da pustis ComboFix i da skeniras, pa da mi das log, da vidim da nece slucajno da ti se vrati infekcija.

Ali prvo uradi ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore



Znaci, radi malo na kompu, pa opet ugasi KAV, skini i pusti CF i daj mi ovde log.

offline
  • Pridružio: 26 Nov 2008
  • Poruke: 24

ok,hava pa se javljam kasnije...
pozz!
Wink

Dopuna: 14 Mar 2009 12:54

ipak nije sve ok....
skenirao sam komp nakon ciscenja,bilo je jos nekih malwerea i virusa,pa sam neke uspeo da pobrisem sa postojecim programima zastite,dok sam neke stavio u karantin...
i tako,kad ostavim komp ukljucen dok nisam kod kuce,pa kad se vratim,opet nahvata nesto iako nisam ni u jednom p2p programu vec sam recimo ovde na forumu online...
kao da nekim magnetima privlaci ovaj moj komp te infekcije,zaista ne znam sta je...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Mozes li da mi postavis te logove od Antivirusa?

offline
  • Pridružio: 26 Nov 2008
  • Poruke: 24

Malwarebytes' Anti-Malware 1.34
Verzija baze podataka: 1849
Windows 5.1.2600 Service Pack 2

3/15/2009 2:52:57 AM
mbam-log-2009-03-15 (02-52-57).txt

Tip skeniranja: Kompletno Skeniranje (A:\|C:\|D:\|E:\|F:\Smajli
Skeniranih objekata: 86809
Proteklo vreme: 11 minute(s), 21 second(s)

Inficirani procesi u memoriji: 0
Inficirani moduli u memoriji: 0
Inficirani kljuèevi u registru: 0
Inficirane vrednosti u registru: 0
Inficirani podaci u registru: 2
Inficirane fascikle: 0
Inficirane datoteke: 1

Inficirani procesi u memoriji:
(Maliciozne stavke nisu detektovane)

Inficirani moduli u memoriji:
(Maliciozne stavke nisu detektovane)

Inficirani kljuèevi u registru:
(Maliciozne stavke nisu detektovane)

Inficirane vrednosti u registru:
(Maliciozne stavke nisu detektovane)

Inficirani podaci u registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Inficirane fascikle:
(Maliciozne stavke nisu detektovane)

Inficirane datoteke:
D:\screensavers\PopularScreensaversSetup2.3.50.26.ZRman000.exe (Adware.MyWeb) -> Quarantined and deleted successfully.

Dopuna: 15 Mar 2009 10:00

skenirao sam ga i sa Ad-Aware 2008 i pronasao je jos infekcija ali obzirom da nema log-a kao koji mogu da kopiram jer ne postoji ta opcija,napisao sam samo sta je to pronasao,cisto da vidis da ima jos infekcija(koji su sad doduse detektovani i unisteni).mozda to nesto pomogne.

Win32.TroyanSpy.Banker (2 komada)
Win32.Troyan-PSW.Delf (2 komada)
MRU Object (7 komada)
SweetIM (2 komada)

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Postavi mi novi ComboFix log, da pogledam nesto.

Ko je trenutno na forumu
 

Ukupno su 1282 korisnika na forumu :: 31 registrovanih, 8 sakrivenih i 1243 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, AleksSE, Andrija357, Arsenije, Atomski čoban, Boris90, branko7, ccoogg123, cikadeda, dekan.m, Denaya, DonRumataEstorski, krkalon, kybonacci, Lieutenant, Lucije Kvint, Marko Marković, mercedesamg, Mi lao shu, Milos1389, MrNo, nemkea71, Nobunaga, Petarvu, shaja1, Snorks, TBF1D, tmanda323, vathra, voja64, zbazin