Trojanac mozda....

2

Trojanac mozda....

offline
  • Acid_Burn  Male
  • Moderator foruma
  • Glavni moderator foruma Zabava
  • Hellraiser
  • Demon to some. Angel to others
  • Pridružio: 07 Jan 2005
  • Poruke: 25503
  • Gde živiš: Beneath the Black Sky

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:33:51, on 8.6.2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Trust\Trust R-Series Keyboard\StartAutorun.exe
C:\Program Files\Trust\Trust R-Series Keyboard\KMConfig.exe
C:\Windows\RTHDCPL.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\AltBinz\altbinz.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Trust\Trust R-Series Keyboard\KMProcess.exe
C:\Program Files\stunnel\stunnel.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Trust\Trust R-Series Keyboard\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: altbinz.lnk = C:\Program Files\AltBinz\altbinz.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Trust\Trust R-Series Keyboard\KMWDSrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

--
End of file - 5528 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Citat:C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
Promeni ime i folderu i samom EXE fajlu, ne sme da asocira na HijackThis.

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\Users\Siki\AppData\Local\Temp\DVD.exe
C:\Windows\winudpmgr.exe


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Skeniraj ponovo i HijackThisom i postavi novi log. Obavezno pre skeniranja promeni ime foldera i samog EXE fajla HijackThis-a tako da se nigde ne spominje ni HojackThis, ni TrendMicro.

offline
  • Acid_Burn  Male
  • Moderator foruma
  • Glavni moderator foruma Zabava
  • Hellraiser
  • Demon to some. Angel to others
  • Pridružio: 07 Jan 2005
  • Poruke: 25503
  • Gde živiš: Beneath the Black Sky

ComboFix 08-06-07.1 - Siki 08.06.2008 6:25:37.3 - NTFSx86
Running from: C:\Users\Siki\Desktop\ComboFix.exe
Command switches used :: C:\Users\Siki\Desktop\CFScript.txt

FILE ::
C:\Users\Siki\AppData\Local\Temp\DVD.exe
C:\Windows\winudpmgr.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\winudpmgr.exe

.
((((((((((((((((((((((((( Files Created from 2008-05-08 to 2008-06-08 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-08 04:23 --------- d-----w C:\Program Files\Microsystem
2008-06-08 04:20 --------- d---a-w C:\ProgramData\TEMP
2008-06-08 03:57 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-06-08 03:57 107,832 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-06-07 19:51 --------- d-----w C:\ProgramData\DVD Shrink
2008-06-07 19:44 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-05 05:34 --------- d-----w C:\ProgramData\Sandlot Games
2008-06-05 05:34 --------- d-----w C:\Program Files\Common Files\Sandlot Shared
2008-06-03 13:24 --------- d-----w C:\Users\Siki\AppData\Roaming\uTorrent
2008-05-30 19:04 --------- d-----w C:\Program Files\FlashGet
2008-05-27 15:54 --------- d-----w C:\Users\Siki\AppData\Roaming\EA
2008-05-27 15:53 --------- d-----w C:\ProgramData\EA
2008-05-23 19:31 --------- d-----w C:\Program Files\stunnel
2008-05-21 17:02 --------- d-----w C:\Users\Siki\AppData\Roaming\GameHouse
2008-05-21 17:02 --------- d-----w C:\ProgramData\n7-89-o9-3r-4t-r9
2008-05-15 23:18 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-05-12 18:04 --------- d-----w C:\Program Files\Realtek
2008-05-12 18:02 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-05-12 18:02 --------- d-----w C:\Program Files\AvRack
2008-05-12 18:01 --------- d-----w C:\Program Files\Realtek AC97
2008-05-05 20:33 --------- d-----w C:\ProgramData\Ubisoft
2008-05-05 20:32 22,328 ----a-w C:\Users\Siki\AppData\Roaming\PnkBstrK.sys
2008-05-05 20:32 2,337,865 ----a-w C:\Windows\System32\pbsvc.exe
2008-05-05 20:30 --------- d-----w C:\Program Files\DriverCleanerDotNET
2008-04-27 15:44 --------- d-----w C:\ProgramData\Nero
2008-04-27 15:44 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-24 16:32 --------- d-----w C:\Program Files\Unlocker
2008-04-24 15:12 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-24 14:57 --------- d-----w C:\Users\Siki\AppData\Roaming\CDBurnerXP_Soft
2008-04-24 14:52 --------- d-----w C:\Program Files\Nero
2008-04-24 14:52 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-19 19:05 --------- d-----w C:\Users\Siki\AppData\Roaming\Microsoft Games
2008-04-19 18:56 --------- d-----w C:\Program Files\Common Files\Microsoft Games
2008-04-19 18:15 --------- d-----w C:\Program Files\Microsoft Games
2008-04-12 06:28 --------- d-----w C:\Program Files\Google
2008-03-20 04:56 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-01-26 23:05 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [04.04.2007 00:29 165784]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [18.10.2007 12:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [02.11.2006 14:33 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [16.05.2008 01:19 79224]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [11.12.2007 18:06 8530464]
"KMCONFIG"="C:\Program Files\Trust\Trust R-Series Keyboard\StartAutorun.exe" [06.03.2007 14:51 212992]
"RTHDCPL"="RTHDCPL.EXE" [27.05.2006 10:47 16208384 C:\Windows\RTHDCPL.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 11.05.2007 04:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 03.05.2005 18:43 69632 C:\Windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 09.03.2007 18:53 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 11.12.2007 18:06 81920 C:\Windows\system32\NvMcTray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 11.12.2007 18:06 86016 C:\Windows\system32\nvsvc.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PeerGuardian]
--a------ 18.09.2005 19:40 1421824 C:\Program Files\PeerGuardian2\pg2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 27.01.2008 00:50 1232896 C:\Program Files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 28.01.2008 12:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 25.06.2007 22:42 1006264 C:\Program Files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows UDP Control Center]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 02.11.2006 14:32 2159104 C:\Windows\System32\oobefldr.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 02.11.2006 14:33 201728 C:\Program Files\Windows Media Player\WMPNSCFG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-690428932-4065060906-875063553-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{797B56FA-9440-4B44-8D26-54835DFC06A9}C:\\program files\\flashget\\flashget.exe"= UDP:C:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{DD55FB16-E5EC-4654-A6BA-D6AA34A39923}C:\\program files\\flashget\\flashget.exe"= TCP:C:\program files\flashget\flashget.exe:FlashGet
"{2299C258-5274-43D0-8526-3CC4D7A4FC22}"= UDP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{FAEF3C19-F823-4108-B01B-5B86AAA01C48}"= TCP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{9194C592-D687-45E1-99FB-11787ED459D8}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{338F6580-5C98-4D49-B8F9-9A040BAEA164}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{D5873FDF-74A8-4C00-A539-35DF687C7842}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{034B5F9F-B134-4C34-BF75-6571E5E4D5D2}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{A7A48A7D-15CB-45EF-80E7-8A4DACF307FF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{70EEC4B3-07EC-43FA-95E6-3A84E4898B79}C:\\program files\\stunnel\\stunnel.exe"= UDP:C:\program files\stunnel\stunnel.exe:stunnel
"UDP Query User{A67452D4-C2BD-4251-ABE5-A2B4584C3044}C:\\program files\\stunnel\\stunnel.exe"= TCP:C:\program files\stunnel\stunnel.exe:stunnel
"{577FFDCF-345E-4BB4-89E4-6DA75AF6E01E}"= UDP:E:\Games\Bin32\Crysis.exe:Crysis_32
"{DEC8E4A7-1C58-4294-9B19-D35EC7BCC4BD}"= TCP:E:\Games\Bin32\Crysis.exe:Crysis_32
"{F62DED0F-5D70-4298-BFC9-4E25737C3DEA}"= UDP:E:\Games\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{93AE53CD-637B-4D20-AA50-AC106FE09CCE}"= TCP:E:\Games\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"TCP Query User{E442FD3C-D670-4635-A501-4978860D1B2A}C:\\program files\\xfire\\xfire.exe"= UDP:C:\program files\xfire\xfire.exe:Xfire
"UDP Query User{40607226-F71A-469E-89C0-575A41F0EA26}C:\\program files\\xfire\\xfire.exe"= TCP:C:\program files\xfire\xfire.exe:Xfire
"{94C53DDC-6413-472A-8A29-B392E391F8C9}"= UDP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{0A23AAE0-5FF0-4CB7-8403-B0FCB2D44B04}"= TCP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{DCED08CE-11EA-451D-87ED-5E56F5E88436}"= UDP:E:\Games\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)
"{682603B8-AFCD-4323-ABE6-F864774B3C58}"= TCP:E:\Games\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\K]
\shell\AutoRun\command - K:\Setup\rsrc\autorun.exe
\shell\dinstall\command - K:\Directx\dxsetup.exe


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-08 06:37:33
Windows 6.0.6000 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 08.06.2008 6:38:13
ComboFix-quarantined-files.txt 2008-06-08 04:38:07

Pre-Run: 1.173.147.648 bytes free
Post-Run: 1.158.057.984 bytes free

142 --- E O F --- 2008-03-07 15:46:23

Dopuna: 08 Jun 2008 6:45

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:44:20, on 8.6.2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Trust\Trust R-Series Keyboard\StartAutorun.exe
C:\Program Files\Trust\Trust R-Series Keyboard\KMConfig.exe
C:\Windows\RTHDCPL.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Rainlendar\Rainlendar.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Trust\Trust R-Series Keyboard\KMProcess.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsystem\9-11\9-11.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KMCONFIG] C:\Program Files\Trust\Trust R-Series Keyboard\StartAutorun.exe KMConfig.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: altbinz.lnk = C:\Program Files\AltBinz\altbinz.exe
O4 - Startup: Rainlendar.lnk = C:\Program Files\Rainlendar\Rainlendar.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Keyboard And Mouse Communication Service (KMWDSERVICE) - UASSOFT.COM - C:\Program Files\Trust\Trust R-Series Keyboard\KMWDSrv.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe

--
End of file - 5440 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Kako se sada ponasa komp? Ima li jos simptoma?

offline
  • Acid_Burn  Male
  • Moderator foruma
  • Glavni moderator foruma Zabava
  • Hellraiser
  • Demon to some. Angel to others
  • Pridružio: 07 Jan 2005
  • Poruke: 25503
  • Gde živiš: Beneath the Black Sky

Za sada ne....videcu u toku dana kako ce se ponasati....

Jesu li ovi procesi u redu? Deluju mi sumnjivo...

C:\Windows\system32\Dwm.exe
C:\Windows\system32\wbem\unsecapp.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Dwm je zasigurno Vistin standardni proces.
Ovaj unsecapp nisam vidjao ranije, ali sudeci po onome sto sam nasao na netu, i one je legitiman i standardan Vistin.


Javi obavezno kako se komp ponasa (danas, sutra, kad god...), pa da uradimo deinstalaciju ComboFixa.

offline
  • Acid_Burn  Male
  • Moderator foruma
  • Glavni moderator foruma Zabava
  • Hellraiser
  • Demon to some. Angel to others
  • Pridružio: 07 Jan 2005
  • Poruke: 25503
  • Gde živiš: Beneath the Black Sky

bobby ::Javi obavezno kako se komp ponasa (danas, sutra, kad god...), pa da uradimo deinstalaciju ComboFixa.

Ok videcu za koji pa javljam...

Hvala.... Smajli Zagrljaj

Dopuna: 08 Jun 2008 9:56

[quote="Acid_Burn"]bobby ::Javi obavezno kako se komp ponasa (danas, sutra, kad god...), pa da uradimo deinstalaciju ComboFixa.

Ok videcu za koji dan pa javljam...

Hvala.... Smajli Zagrljaj

Dopuna: 12 Jun 2008 6:34

Da kucnem u drvo...nema vise nikavih simptoma....pratio sam stanje aktivno nekoliko dana sve je ok....

Hvala josh jednom.....

Kako deinstalaciju combofixa da odradim?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

offline
  • Acid_Burn  Male
  • Moderator foruma
  • Glavni moderator foruma Zabava
  • Hellraiser
  • Demon to some. Angel to others
  • Pridružio: 07 Jan 2005
  • Poruke: 25503
  • Gde živiš: Beneath the Black Sky

Hmmm....



offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

ComboFix ti nije u pathu ili si ga obrisao rucno.
Nije frka.
Obrisi rucno foldere C:\ComboFix i C:\QooBox, kao i fajl C:\kmd.exe

Ko je trenutno na forumu
 

Ukupno su 915 korisnika na forumu :: 2 registrovanih, 1 sakriven i 912 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: cikadeda, JanaH