Poslao: 19 Sep 2007 14:36
|
offline
- Pridružio: 21 Avg 2007
- Poruke: 56
|
Imam eden problem.. KIS 7.0 imam instalirano i mi pokazuva Hidden Data Sending na nekoja si IP adresa ... napraiv log fajl od HijackThis...
Pozdrav
Logfile of HijackThis v1.99.1
Scan saved at 14:37:21, on 19.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\Program Files\Opera\Opera.exe
D:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\FIN\Desktop\ab\ab.exe
O2 - BHO: (no name) - {4AA7B12D-AB2C-4D16-BCFB-704945A98FDD} - C:\WINDOWS\system32\opnooml.dll (file missing)
O2 - BHO: (no name) - {A41C10D3-D309-45B7-BBB7-FD46034F7272} - C:\WINDOWS\system32\hgggg.dll
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\elchaoep.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Game Device] C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\caodmepj.dll",sitypnow
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: hgggg - C:\WINDOWS\system32\hgggg.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
|
|
|
|
|
Poslao: 20 Sep 2007 14:28
|
offline
- Pridružio: 21 Avg 2007
- Poruke: 56
|
Eve gi logovite od site tri programi...Pisi ako treba uste nesto
Pozdrav
SmitFraudFix v2.226
Scan done at 14:22:40,08, 20.09.2007
Run from C:\Documents and Settings\FIN\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FIN
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FIN\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FIN\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Rustock
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.7.1
»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
VundoFix V6.5.8
Checking Java version...
Sun Java not detected
Scan started at 14:11:46 20.09.2007
Listing files found while scanning....
C:\WINDOWS\system32\ggggh.bak1
C:\WINDOWS\system32\ggggh.bak2
C:\WINDOWS\system32\ggggh.ini
C:\WINDOWS\system32\ggggh.ini2
C:\WINDOWS\system32\ggggh.tmp
C:\WINDOWS\system32\gvethkkj.dll
C:\WINDOWS\system32\hgggg.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\ggggh.bak1
C:\WINDOWS\system32\ggggh.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ggggh.bak2
C:\WINDOWS\system32\ggggh.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ggggh.ini
C:\WINDOWS\system32\ggggh.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ggggh.ini2
C:\WINDOWS\system32\ggggh.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ggggh.tmp
C:\WINDOWS\system32\ggggh.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\gvethkkj.dll
C:\WINDOWS\system32\gvethkkj.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\hgggg.dll
C:\WINDOWS\system32\hgggg.dll Has been deleted!
Performing Repairs to the registry.
Done!
Logfile of HijackThis v1.99.1
Scan saved at 14:31:59, on 20.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\FIN\Desktop\ab\ab.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {152B972F-E0E6-4977-8FFA-CB3C9E0458CC} - C:\WINDOWS\system32\hgggg.dll (file missing)
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\gknrsmqm.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Game Device] C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\jrpobswd.dll",sitypnow
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
|
|
|
|
Poslao: 27 Sep 2007 09:42
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Pokreni HijackThis, skeniraj i čekiraj sledeće linije:
O2 - BHO: (no name) - {152B972F-E0E6-4977-8FFA-CB3C9E0458CC} - C:\WINDOWS\system32\hgggg.dll (file missing)
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\gknrsmqm.dll
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\jrpobswd.dll",sitypnow
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\
a zatim klikni na Fix Checked ( pri tome IE treba biti zatvoren ).
Restartuj kompjuter a zatim pronađi i obriši:
C:\Program Files\Common Files\WinAntiVirus Pro 2007\
C:\WINDOWS\system32\jrpobswd.dll
U idućoj poruci postavi novi HijackThis log.
Dopuna: 27 Sep 2007 9:42
BaDMaN19, hoćemo li raditi dalje na ovome?
Prošlo je nedelju dana... Ukoliko se ne javiš u narednih par dana, tema ide u arhivu.
|
|
|
|
|