Nije mi jasno

2

Nije mi jasno

offline
  • Pridružio: 16 Nov 2007
  • Poruke: 16

ComboFix 08-02-13.2 - pepsaja 2008-02-15 0:58:47.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.110 [GMT 1:00]
Running from: C:\Documents and Settings\pepsaja\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pepsaja\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\system32\Win32.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\system32\restore
2008-02-13 22:35 . 2008-02-13 22:37 <DIR> d--hs---- C:\WINDOWS\system32\dllcache
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\srchasst
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-02-13 17:42 . 2008-02-13 17:42 1,894 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-13 17:34 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-13 17:34 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-13 17:34 . 2008-02-08 23:55 85,504 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-13 17:34 . 2008-02-08 10:37 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-13 17:34 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-13 17:34 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-13 17:34 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-06 20:42 . 2005-11-06 00:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-02-06 20:42 . 2005-11-06 00:03 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-06 20:42 . 2005-11-06 00:03 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-02-05 20:19 . 2008-02-05 20:19 0 --a------ C:\LOG2AC.tmp
2008-02-05 20:18 . 2008-02-05 20:20 <DIR> d-------- C:\Documents and Settings\pepsaja\Application Data\U3
2008-01-25 20:42 . 2008-01-25 20:42 <DIR> d-------- C:\wally
2008-01-25 12:57 . 2008-01-25 13:08 0 --a------ C:\WINDOWS\system32\BWFAX
2008-01-25 12:54 . 2008-01-25 12:52 27,648 --a------ C:\WINDOWS\system32\bwprnmon.dll
2008-01-25 12:54 . 2008-01-25 12:54 3,347 --a------ C:\WINDOWS\BWRESTOR.REG
2008-01-25 12:54 . 2008-01-25 12:54 3,045 --a------ C:\WINDOWS\BWCHANGE.REG
2008-01-25 12:54 . 2008-01-25 12:54 0 --a------ C:\WINDOWS\system32\bwprnmon.bak
2008-01-25 12:52 . 2008-01-25 12:52 197,024 --a------ C:\WINDOWS\system\UNIDRV.DLL
2008-01-25 12:52 . 2008-01-25 12:52 37,408 --a------ C:\WINDOWS\system\BITWARED.DRV
2008-01-17 13:22 . 2005-11-06 00:03 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-15 11:47 . 2008-01-15 11:47 <DIR> d-------- C:\Program Files\Microsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-14 21:58 --------- d-----w C:\Program Files\sXe Injected
2008-01-12 19:36 --------- d-----w C:\Program Files\LRC Editor 4
2008-01-06 18:38 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-12-29 14:35 --------- d-----w C:\Documents and Settings\pepsaja\Application Data\uTorrent
2007-11-28 19:58 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-15 00:53 16,768 ----a-w C:\WINDOWS\system32\tcpip_patcher.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 12:47 7311360]
"nwiz"="nwiz.exe" [2005-11-11 12:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 12:47 86016]
"C-Media Mixer"="C:\Program Files\PCI Audio Applications\Mixer.exe" [2000-09-13 11:03 1085440]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-14 15:05 1410304]
"bwprnmon.exe"="C:\BITWARE\NT\bwprnmon.exe" [2008-01-25 12:52 54272]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-03 23:56 388608 C:\WINDOWS\system32\cmd.exe]
"nlhr"="C:\WINDOWS\System32\AdvPack.Dll" [2004-08-03 23:56 99840]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 21:59 44544]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-11-11 19:32:41 847872]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

R0 ALiAGP;ALi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\ALiAGP.sys [2000-08-09 13:08]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-14 15:06]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 18:50]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:25]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-02-15 01:01:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ntvdm.exe
.
**************************************************************************
.
Completion time: 2008-02-15 1:02:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-15 00:02:30
ComboFix2.txt 2008-02-13 21:37:15


Ja ne znam sta radimo i dokle smo stigli, ali hvala ti u svakom slucaju!
Vise nemam onih aktivacija prozora!



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Spybot S&D's Teatimer


Pokrenite Spybot S&D
Kliknite Mode stavku u meniju
Odaberite Advance Mode
Na traci levo kliknite na Tools
Kliknite na Resident
Destiklirajte Resident Tea-Timer
Zatvorite Spybot S&D
Restartujte kompjuter.

Nemojte zaboraviti da ponovo ukljucite ove opcije kada zavrsimo ciscenje.

Otvoriti Notepad i iskopirati sledeci tekst:


Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}]



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Kada zavrsis sa skeniranjem i ciscenjem i ukljucis Spybot S&D's Teatimer dozvoli mu da izvrsi promene u Registry.



offline
  • Pridružio: 16 Nov 2007
  • Poruke: 16

ComboFix 08-02-13.2 - pepsaja 2008-02-15 18:43:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.80 [GMT 1:00]
Running from: C:\Documents and Settings\pepsaja\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pepsaja\Desktop\CFScript.txt

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-01-15 to 2008-02-15 )))))))))))))))))))))))))))))))
.

2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\system32\xircom
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\system32\restore
2008-02-13 22:35 . 2008-02-13 22:37 <DIR> d--hs---- C:\WINDOWS\system32\dllcache
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\WINDOWS\srchasst
2008-02-13 22:35 . 2008-02-13 22:35 <DIR> d-------- C:\Program Files\microsoft frontpage
2008-02-13 17:42 . 2008-02-13 17:42 1,894 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-13 17:34 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-13 17:34 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-13 17:34 . 2008-02-08 23:55 85,504 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-13 17:34 . 2008-02-08 10:37 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-13 17:34 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-13 17:34 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-13 17:34 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-06 20:42 . 2005-11-06 00:03 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-02-06 20:42 . 2005-11-06 00:03 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-06 20:42 . 2005-11-06 00:03 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-02-05 20:19 . 2008-02-05 20:19 0 --a------ C:\LOG2AC.tmp
2008-02-05 20:18 . 2008-02-05 20:20 <DIR> d-------- C:\Documents and Settings\pepsaja\Application Data\U3
2008-01-25 20:42 . 2008-01-25 20:42 <DIR> d-------- C:\wally
2008-01-25 12:57 . 2008-01-25 13:08 0 --a------ C:\WINDOWS\system32\BWFAX
2008-01-25 12:54 . 2008-01-25 12:52 27,648 --a------ C:\WINDOWS\system32\bwprnmon.dll
2008-01-25 12:54 . 2008-01-25 12:54 3,347 --a------ C:\WINDOWS\BWRESTOR.REG
2008-01-25 12:54 . 2008-01-25 12:54 3,045 --a------ C:\WINDOWS\BWCHANGE.REG
2008-01-25 12:54 . 2008-01-25 12:54 0 --a------ C:\WINDOWS\system32\bwprnmon.bak
2008-01-25 12:52 . 2008-01-25 12:52 197,024 --a------ C:\WINDOWS\system\UNIDRV.DLL
2008-01-25 12:52 . 2008-01-25 12:52 37,408 --a------ C:\WINDOWS\system\BITWARED.DRV
2008-01-17 13:22 . 2005-11-06 00:03 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-01-15 11:47 . 2008-01-15 11:47 <DIR> d-------- C:\Program Files\Microsoft

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-15 15:57 --------- d-----w C:\Program Files\sXe Injected
2008-01-12 19:36 --------- d-----w C:\Program Files\LRC Editor 4
2008-01-06 18:38 --------- d-----w C:\Program Files\Common Files\ACD Systems
2007-12-29 14:35 --------- d-----w C:\Documents and Settings\pepsaja\Application Data\uTorrent
2007-11-28 19:58 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-15 00:53 16,768 ----a-w C:\WINDOWS\system32\tcpip_patcher.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 12:47 7311360]
"nwiz"="nwiz.exe" [2005-11-11 12:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 12:47 86016]
"C-Media Mixer"="C:\Program Files\PCI Audio Applications\Mixer.exe" [2000-09-13 11:03 1085440]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-14 15:05 1410304]
"bwprnmon.exe"="C:\BITWARE\NT\bwprnmon.exe" [2008-01-25 12:52 54272]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-03 23:56 388608 C:\WINDOWS\system32\cmd.exe]
"nlhr"="C:\WINDOWS\System32\AdvPack.Dll" [2004-08-03 23:56 99840]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 21:59 44544]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-11-11 19:32:41 847872]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoInstrumentation"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)

R0 ALiAGP;ALi AGP Bus Filter Driver;C:\WINDOWS\system32\DRIVERS\ALiAGP.sys [2000-08-09 13:08]
R1 epfwtdir;epfwtdir;C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-14 15:06]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 18:50]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:25]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-02-15 18:44:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-15 18:45:00
ComboFix-quarantined-files.txt 2008-02-15 17:44:50
ComboFix2.txt 2008-02-15 00:02:41
ComboFix3.txt 2008-02-13 21:37:15

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

offline
  • Pridružio: 16 Nov 2007
  • Poruke: 16

Uradjeno!
Hvala vam puno!!!

Ko je trenutno na forumu
 

Ukupno su 1324 korisnika na forumu :: 183 registrovanih, 13 sakrivenih i 1128 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100ka, 8u47, A.R.Chafee.Jr., Agape, Alooo, alternator, amstel, armor, Arsenije, Asteker, Avalon015, bbogdan, bbrasnjo3, Betty25, Blair, bokisha253, bolenbgd, Boris90, bpvl, ccoogg123, cemix, Centauro, Cicumile, cifra, cole77, CrazyDiablo, csipetcsapat, cvrle312, Dambi, darcaud, Dare, DeerHunter, Dejan_vw, dejanbenkovic, dendrit86, denisnapast2015, Django777, djboj, Djokislav, DJUNTA, Djuro2000, Doca, Dogma21, drale12, Drugsparrow, dule10savic, Dungorth, Electron, Ezbuck, feanor, Feller, Frunze, g_g, gagidjuric, galico, Gerila015, gomago, goran.vvv, hyla, Ice, iceburn, Igritelj, ikan, ivan979, Jakonjveliki, JankoS, Jeremiah, Joksss, Jomini, kikisp, Kobrim, Koridor, Koridor 11, Krusarac, Kubovac, kybonacci, Lelemood, Lucije Kvint, M74AB3, marko.markovic, markoni.slo, mačković, mercedesamg, Mi lao shu, miki kv, Miki01, Miki281, milanpb, milenko crazy north, milenko1980, Millennium, Milos1389, mir, mir juzni, MiroslavD, Mićko, mnn2, moldway, momcilob55, N.e.m.a.nj.a., neko iz mase, Nemanja.M, nemkea71, nenad81, novator, padamacki, Pale2025, panzermilan45, panzerwaffe, Papadubi, Pero, Petarvu, Pilence, pisac12, Plavi Jadran, Podljub, Povratak1912, prashinar, precan, PrincipL, procesor, proka89, promajauglavi, raf87, rakivan, raso7, reakcija1989, rebro1974, repac, RJ, ruso, S-lash, sap, sasovsky, Shadow soldier, share00, Shinobi, silikon, Simulink11000, Sir Budimir, Sićko, Szigetwar, tanakadzo, TBoy, tenkiasta71, The Boss, TheBeastOfMG, TheDictator, Topaz9, TRAVUNIJA, UAV operator, uruk, Username1000, varda, vathra, vazduh, vensla, VJ, Vlad000, Vlado82, Voice1, voja64, vojnik švejk, Vrač, vuk77, vukovi, vuksa72, Vzor50, Wrangler, x011, x9, XBMC, XRF_d, zeka013, ZetaMan, Zoca, zokilivac, zokizemun, Zoran1959, Zvone, zziko, |_MeD_|, Žrnov