Veliki problem, pomoc !

2

Veliki problem, pomoc !

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Uploadovao sam, valjda je to to



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Poslao si pogresan.

Udji na c: particiju i nadji ovaj fajl: nssetup.exe



offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Ne mogu da ga nadjem...

Dopuna: 28 Jan 2009 22:38

Nema toga fajla u C ?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Iskljuci Antivirus.


Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\nssetup.exe
C:\WINDOWS\system32\ru.exe
C:\WINDOWS\system32\iw.exe
C:\WINDOWS\system32\gv.exe
C:\Documents and Settings\Nikola\Application Data\advantage\AdVantage.exe
C:\Program Files\Online Add-on\isfmntr.exe
C:\WINDOWS\usbservice.exe
C:\WINDOWS\system32\mf.exe

Driver::
Usb Service 2.0

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdVantage"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

ComboFix 09-01-21.04 - Nikola 2009-01-28 22:49:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.567 [GMT 1:00]
Running from: c:\documents and settings\Nikola\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nikola\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090128-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point

FILE ::
c:\documents and settings\Nikola\Application Data\advantage\AdVantage.exe
C:\nssetup.exe
c:\program files\Online Add-on\isfmntr.exe
c:\windows\system32\gv.exe
c:\windows\system32\iw.exe
c:\windows\system32\mf.exe
c:\windows\system32\ru.exe
c:\windows\usbservice.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Nikola\Application Data\advantage\AdVantage.exe
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\gv.exe
c:\windows\system32\iw.exe
c:\windows\system32\ru.exe
c:\windows\system32\x.exe
c:\windows\usbservice.exe
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090126215149683.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
c:\documents and settings\Nikola\Favorites\Download programs.url
c:\documents and settings\Nikola\Favorites\Games.url
c:\documents and settings\Nikola\Favorites\Online Security Test.url
c:\documents and settings\Nikola\Favorites\Translator.url
c:\documents and settings\Nikola\Favorites\Videos.url
c:\documents and settings\Nikola\Start Menu\Programs\Download programs.url
c:\documents and settings\Nikola\Start Menu\Programs\Games.url
c:\documents and settings\Nikola\Start Menu\Programs\Translator.url
c:\documents and settings\Nikola\Start Menu\Programs\Videos.url
c:\program files\Sotfone
c:\windows\jestertb.dll
c:\windows\system32\divx.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ISODRIVE
-------\Service_ISODrive
-------\Legacy_SYSDRV32
-------\Legacy_USB_SERVICE_2.0
-------\Service_sysdrv32
-------\Service_Usb Service 2.0


((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))))))
.

2009-01-28 21:53 . 2009-01-28 21:54 <DIR> d-------- C:\USBNoRisk
2009-01-26 22:09 . 2009-01-26 22:09 244 --ah----- C:\sqmnoopt15.sqm
2009-01-26 22:09 . 2009-01-26 22:09 232 --ah----- C:\sqmdata15.sqm
2009-01-26 22:05 . 2009-01-26 22:05 244 --ah----- C:\sqmnoopt14.sqm
2009-01-26 22:05 . 2009-01-26 22:05 232 --ah----- C:\sqmdata14.sqm
2009-01-26 21:51 . 2009-01-26 22:09 23,650 --a------ C:\NSSETUP.EXE-1AD1FEBF.pf
2009-01-26 20:12 . 2009-01-26 20:12 268 --ah----- C:\sqmdata13.sqm
2009-01-26 20:12 . 2009-01-26 20:12 244 --ah----- C:\sqmnoopt13.sqm
2009-01-26 15:16 . 2009-01-26 15:16 268 --ah----- C:\sqmdata12.sqm
2009-01-26 15:16 . 2009-01-26 15:16 244 --ah----- C:\sqmnoopt12.sqm
2009-01-26 11:48 . 2009-01-26 11:48 268 --ah----- C:\sqmdata11.sqm
2009-01-26 11:48 . 2009-01-26 11:48 244 --ah----- C:\sqmnoopt11.sqm
2009-01-14 14:48 . 2009-01-14 14:48 <DIR> d-------- c:\documents and settings\Nikola\Application Data\ImTOO Software Studio
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\program files\Moyea
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\documents and settings\Nikola\Application Data\Moyea
2009-01-14 14:33 . 2008-08-28 18:56 438,272 --a------ c:\windows\system32\vp6vfw.dll
2009-01-14 14:24 . 2009-01-14 14:34 <DIR> d-------- C:\My FLVs
2009-01-14 14:23 . 2009-01-14 14:28 <DIR> d-------- c:\program files\YouTubeRobot
2009-01-14 14:23 . 2007-02-28 13:30 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-01-14 14:23 . 2007-02-28 13:30 1,044,480 --a------ c:\windows\system32\libdivx.dll
2009-01-14 14:23 . 2007-02-28 13:32 716,800 --a------ c:\windows\system32\lameACM.acm
2009-01-14 14:23 . 2007-02-28 13:30 593,920 --a------ c:\windows\system32\dpuGUI11.dll
2009-01-14 14:23 . 2007-02-28 13:30 577,536 --a------ c:\windows\system32\divxdec.ax
2009-01-14 14:23 . 2007-02-28 13:33 389,120 --a------ c:\windows\system32\actskn43.ocx
2009-01-14 14:23 . 2007-02-28 13:30 294,912 --a------ c:\windows\system32\dpu11.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\ssldivx.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\dtu100.dll
2009-01-14 14:23 . 2007-02-28 13:30 86,016 --a------ c:\windows\system32\dpl100.dll
2009-01-14 14:23 . 2007-02-28 13:30 57,344 --a------ c:\windows\system32\dpv11.dll
2009-01-14 14:23 . 2007-02-28 13:32 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\UltraISO
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\Common Files\EZB Systems
2009-01-08 12:25 . 2009-01-21 13:10 238 --a------ c:\windows\mafosav.INI
2009-01-08 12:22 . 2009-01-08 12:22 <DIR> d-------- C:\Buziol Games
2009-01-04 10:42 . 2009-01-04 10:43 35 --a------ c:\windows\mstutor.ini
2009-01-02 10:55 . 2009-01-02 10:55 <DIR> d-------- c:\program files\Xilisoft
2008-12-31 14:49 . 2008-12-31 14:49 <DIR> d-------- C:\svadba
2008-12-31 14:04 . 2008-12-31 14:04 <DIR> d-------- c:\program files\DVD Shrink
2008-12-31 14:04 . 2008-12-31 14:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-31 13:58 . 2008-12-31 13:58 <DIR> d-------- c:\program files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 21:49 --------- d-----w c:\documents and settings\Nikola\Application Data\advantage
2009-01-27 17:10 --------- d-----w c:\program files\The KMPlayer
2009-01-14 13:48 --------- d-----w c:\program files\ImTOO
2009-01-14 13:42 --------- d-----w c:\program files\Total Video Converter
2009-01-08 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-08 12:18 --------- d-----w c:\documents and settings\Nikola\Application Data\LimeWire
2009-01-02 14:30 --------- d-----w c:\documents and settings\Nikola\Application Data\dvdcss
2008-12-31 16:48 --------- d-----w c:\documents and settings\Nikola\Application Data\Skype
2008-12-31 15:07 --------- d-----w c:\documents and settings\Nikola\Application Data\skypePM
2008-12-24 11:58 --------- d-----w c:\program files\YoutubeGet
2008-12-14 13:33 --------- d-----w c:\program files\Folder Lock
2008-12-12 09:46 --------- d-----w c:\program files\Realtek AC97
2008-12-04 20:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 12:15 --------- d-----w c:\program files\WMV9_VCM
2008-12-04 12:12 --------- d-----w c:\program files\1C
2008-12-04 11:54 --------- d-----w c:\program files\DAEMON Tools Pro
2008-12-04 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-04 11:53 --------- d-----w c:\documents and settings\Nikola\Application Data\DAEMON Tools Pro
2008-12-04 11:51 --------- d-----w c:\program files\advantage
2008-12-04 11:46 715,248 ----a-w c:\windows\system32\drivers\sptd.sys
2008-07-14 05:27 9,016 ----a-w c:\program files\tempdecal.wad
2004-07-22 09:51 3,432,656 ----a-w c:\program files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w c:\program files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w c:\program files\BDAXP.cab
2004-07-16 13:30 3,858 ----a-w c:\program files\directx redist.txt
2004-07-09 13:17 13,265,040 ----a-w c:\program files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w c:\program files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w c:\program files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w c:\program files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w c:\program files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w c:\program files\DSETUP.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-05 273864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-24 180269]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2002-01-01 98304]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 c:\windows\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 c:\windows\mixer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MS AntiSpyware 2009"="c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" [BU]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"vidc.X264"= x264vfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WinampAgent"=c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\zBoT Counter 1.6\\hl.exe"=
"c:\\Program Files\\ApexDC++\\ApexDC.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-14 20560]
R4 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2007-04-05 208896]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/ALL.HTM
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-28 22:53:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3E3786AA-5288-665B-DF40-0490A1A5049B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iajdmfhanbcdcgadpg"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
"jajeakffndmddjklomho"=hex:62,61,66,63,00,00
"jajeakffndmddjklomdo"=hex:62,61,6b,63,00,00
"hahekfgcipbjfdbf"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A1A06CD3-E41F-1C1E-ECC2-DB2832F4F556}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaejogeiodcfbekjga"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
"japjoiodakalpbmgdpgo"=hex:62,61,6c,66,00,00
"jaljkkknoabjnadiohae"=hex:62,61,63,67,00,00
"hahdcjiipgkckfpf"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Mouse Driver\KMCONFIG.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Mouse Driver\KMProcess.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-01-28 22:56:31 - machine was rebooted [Nikola]
ComboFix-quarantined-files.txt 2009-01-28 21:56:29

Pre-Run: 5,210,914,816 bytes free
Post-Run: 5,195,788,288 bytes free

281

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Iskljuci Antivirus.

Otvoriti Notepad i iskopirati sledeci tekst:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

ComboFix 09-01-21.04 - Nikola 2009-01-29 11:14:33.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.572 [GMT 1:00]
Running from: c:\documents and settings\Nikola\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nikola\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090128-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090128225746203.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-29 )))))))))))))))))))))))))))))))
.

2009-01-29 10:30 . 2009-01-29 11:17 41,522 -r-hs---- c:\windows\usbservice.exe
2009-01-29 10:30 . 2009-01-29 11:17 41,522 --a------ C:\http.exe
2009-01-28 22:57 . 2009-01-28 22:57 81,931 --a------ C:\ns2setup.exe
2009-01-28 22:57 . 2009-01-28 22:57 20,018 -r-hs---- c:\windows\usbautotuner.exe
2009-01-28 22:57 . 2009-01-28 22:57 20,018 --a------ c:\windows\system32\jx.exe
2009-01-28 21:53 . 2009-01-28 21:54 <DIR> d-------- C:\USBNoRisk
2009-01-26 22:09 . 2009-01-26 22:09 244 --ah----- C:\sqmnoopt15.sqm
2009-01-26 22:09 . 2009-01-26 22:09 232 --ah----- C:\sqmdata15.sqm
2009-01-26 22:05 . 2009-01-26 22:05 244 --ah----- C:\sqmnoopt14.sqm
2009-01-26 22:05 . 2009-01-26 22:05 232 --ah----- C:\sqmdata14.sqm
2009-01-26 21:51 . 2009-01-26 22:09 23,650 --a------ C:\NSSETUP.EXE-1AD1FEBF.pf
2009-01-26 20:12 . 2009-01-26 20:12 268 --ah----- C:\sqmdata13.sqm
2009-01-26 20:12 . 2009-01-26 20:12 244 --ah----- C:\sqmnoopt13.sqm
2009-01-26 15:16 . 2009-01-26 15:16 268 --ah----- C:\sqmdata12.sqm
2009-01-26 15:16 . 2009-01-26 15:16 244 --ah----- C:\sqmnoopt12.sqm
2009-01-26 11:48 . 2009-01-26 11:48 268 --ah----- C:\sqmdata11.sqm
2009-01-26 11:48 . 2009-01-26 11:48 244 --ah----- C:\sqmnoopt11.sqm
2009-01-14 14:48 . 2009-01-14 14:48 <DIR> d-------- c:\documents and settings\Nikola\Application Data\ImTOO Software Studio
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\program files\Moyea
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\documents and settings\Nikola\Application Data\Moyea
2009-01-14 14:33 . 2008-08-28 18:56 438,272 --a------ c:\windows\system32\vp6vfw.dll
2009-01-14 14:24 . 2009-01-14 14:34 <DIR> d-------- C:\My FLVs
2009-01-14 14:23 . 2009-01-14 14:28 <DIR> d-------- c:\program files\YouTubeRobot
2009-01-14 14:23 . 2007-02-28 13:30 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-01-14 14:23 . 2007-02-28 13:30 1,044,480 --a------ c:\windows\system32\libdivx.dll
2009-01-14 14:23 . 2007-02-28 13:32 716,800 --a------ c:\windows\system32\lameACM.acm
2009-01-14 14:23 . 2007-02-28 13:30 593,920 --a------ c:\windows\system32\dpuGUI11.dll
2009-01-14 14:23 . 2007-02-28 13:30 577,536 --a------ c:\windows\system32\divxdec.ax
2009-01-14 14:23 . 2007-02-28 13:33 389,120 --a------ c:\windows\system32\actskn43.ocx
2009-01-14 14:23 . 2007-02-28 13:30 294,912 --a------ c:\windows\system32\dpu11.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\ssldivx.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\dtu100.dll
2009-01-14 14:23 . 2007-02-28 13:30 86,016 --a------ c:\windows\system32\dpl100.dll
2009-01-14 14:23 . 2007-02-28 13:30 57,344 --a------ c:\windows\system32\dpv11.dll
2009-01-14 14:23 . 2007-02-28 13:32 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\UltraISO
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\Common Files\EZB Systems
2009-01-08 12:25 . 2009-01-21 13:10 238 --a------ c:\windows\mafosav.INI
2009-01-08 12:22 . 2009-01-08 12:22 <DIR> d-------- C:\Buziol Games
2009-01-04 10:42 . 2009-01-04 10:43 35 --a------ c:\windows\mstutor.ini

2009-01-02 10:55 . 2009-01-02 10:55 <DIR> d-------- c:\program files\Xilisoft
2008-12-31 14:49 . 2008-12-31 14:49 <DIR> d-------- C:\svadba
2008-12-31 14:04 . 2008-12-31 14:04 <DIR> d-------- c:\program files\DVD Shrink
2008-12-31 14:04 . 2008-12-31 14:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-31 13:58 . 2008-12-31 13:58 <DIR> d-------- c:\program files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 21:49 --------- d-----w c:\documents and settings\Nikola\Application Data\advantage
2009-01-27 17:10 --------- d-----w c:\program files\The KMPlayer
2009-01-14 13:48 --------- d-----w c:\program files\ImTOO
2009-01-14 13:42 --------- d-----w c:\program files\Total Video Converter
2009-01-08 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-08 12:18 --------- d-----w c:\documents and settings\Nikola\Application Data\LimeWire
2009-01-02 14:30 --------- d-----w c:\documents and settings\Nikola\Application Data\dvdcss
2008-12-31 16:48 --------- d-----w c:\documents and settings\Nikola\Application Data\Skype
2008-12-31 15:07 --------- d-----w c:\documents and settings\Nikola\Application Data\skypePM
2008-12-24 11:58 --------- d-----w c:\program files\YoutubeGet
2008-12-14 13:33 --------- d-----w c:\program files\Folder Lock
2008-12-12 09:46 --------- d-----w c:\program files\Realtek AC97
2008-12-04 20:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 12:15 --------- d-----w c:\program files\WMV9_VCM
2008-12-04 12:12 --------- d-----w c:\program files\1C
2008-12-04 11:54 --------- d-----w c:\program files\DAEMON Tools Pro
2008-12-04 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-04 11:53 --------- d-----w c:\documents and settings\Nikola\Application Data\DAEMON Tools Pro
2008-12-04 11:51 --------- d-----w c:\program files\advantage
2008-12-04 11:46 715,248 ----a-w c:\windows\system32\drivers\sptd.sys
2008-07-14 05:27 9,016 ----a-w c:\program files\tempdecal.wad
2004-07-22 09:51 3,432,656 ----a-w c:\program files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w c:\program files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w c:\program files\BDAXP.cab
2004-07-16 13:30 3,858 ----a-w c:\program files\directx redist.txt
2004-07-09 13:17 13,265,040 ----a-w c:\program files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w c:\program files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w c:\program files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w c:\program files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w c:\program files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w c:\program files\DSETUP.dll
.

((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-29 09:27:58 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_75c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-05 273864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-24 180269]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2002-01-01 98304]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 c:\windows\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 c:\windows\mixer.exe]
"Microsoft USB Windows2 Driver"="usbautotuner.exe" [2009-01-28 c:\windows\usbautotuner.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"MS AntiSpyware 2009"="c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"vidc.X264"= x264vfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WinampAgent"=c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\zBoT Counter 1.6\\hl.exe"=
"c:\\Program Files\\ApexDC++\\ApexDC.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\System32\\jx.exe"=
"c:\\WINDOWS\\usbservice.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-14 20560]
R4 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
S4 Usb Service 2.0;Usb Service 2.0;c:\windows\usbservice.exe [2009-01-29 41522]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - USB_SERVICE_2.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/ALL.HTM
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.


**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-29 11:17:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3E3786AA-5288-665B-DF40-0490A1A5049B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iajdmfhanbcdcgadpg"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
"jajeakffndmddjklomho"=hex:62,61,66,63,00,00
"jajeakffndmddjklomdo"=hex:62,61,6b,63,00,00
"hahekfgcipbjfdbf"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A1A06CD3-E41F-1C1E-ECC2-DB2832F4F556}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaejogeiodcfbekjga"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
"japjoiodakalpbmgdpgo"=hex:62,61,6c,66,00,00
"jaljkkknoabjnadiohae"=hex:62,61,63,67,00,00
"hahdcjiipgkckfpf"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-29 11:18:38
ComboFix-quarantined-files.txt 2009-01-29 10:18:35
ComboFix2.txt 2009-01-28 21:56:33

Pre-Run: 5,170,454,528 bytes free
Post-Run: 5,157,793,792 bytes free

233


Dopuna: 29 Jan 2009 11:53

Da dodam da je stanje sve gore, u istom minutu avast prijavljuje adware, malware, trojanca,MS AntiSpyware ne znam otkud on sad, ali i on sve nesto prijavljuje i neregistrovan je. Jedva sam pristupio sajtu i ispisao post

Dopuna: 29 Jan 2009 11:58

Stalno mi iskacu Spyware alert prozori, ne mogu da se odbranim../

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Vidim, infekcija se vratila.

Sta si ti posecivao u medjuvremenu?

Polako, sredicemo. Nadam se da si bio ukljucio Avast posle skeniranja sa ComboFixom?

Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Posjetio sam gmail. Avast sam ukljucio. Bojim se da cu tesko biti u stanju posjecujem sajt, jer sve vise koci. Sad cu pokusati to da uradim. I kako da iskljucim ovaj windows firewall ? Sad cu pokusati to da uradim sto si mi rekao

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Vidi kako je ovde objasnjeno:

[Link mogu videti samo ulogovani korisnici]

Ko je trenutno na forumu
 

Ukupno su 844 korisnika na forumu :: 33 registrovanih, 3 sakrivenih i 808 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: acatomic, Aleksandar Tomić, BOXRR, Cigi, croato, dekan.m, Dimitrise93, Dorcolac, Džekson, Igor Antonic, Ilija Cvorovic, ilija.24, indja, ivan1973, ljuba.b, majstro, MarkoD, Metanoja, MILJEVINAC, Mineral, mir, pein, PrincipL, raf87, shajone, Szigetwar, Trpe Grozni, Tvrtko I, Vatreni Zmaj, Veless, Velizar Laro, vukajlo71, zlatkoa987