Veliki problem, pomoc !

2

Veliki problem, pomoc !

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Uploadovao sam, valjda je to to

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Poslao si pogresan.

Udji na c: particiju i nadji ovaj fajl: nssetup.exe

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Ne mogu da ga nadjem...

Dopuna: 28 Jan 2009 22:38

Nema toga fajla u C ?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Iskljuci Antivirus.


Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\nssetup.exe
C:\WINDOWS\system32\ru.exe
C:\WINDOWS\system32\iw.exe
C:\WINDOWS\system32\gv.exe
C:\Documents and Settings\Nikola\Application Data\advantage\AdVantage.exe
C:\Program Files\Online Add-on\isfmntr.exe
C:\WINDOWS\usbservice.exe
C:\WINDOWS\system32\mf.exe

Driver::
Usb Service 2.0

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdVantage"=-
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

ComboFix 09-01-21.04 - Nikola 2009-01-28 22:49:06.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.567 [GMT 1:00]
Running from: c:\documents and settings\Nikola\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nikola\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090128-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point

FILE ::
c:\documents and settings\Nikola\Application Data\advantage\AdVantage.exe
C:\nssetup.exe
c:\program files\Online Add-on\isfmntr.exe
c:\windows\system32\gv.exe
c:\windows\system32\iw.exe
c:\windows\system32\mf.exe
c:\windows\system32\ru.exe
c:\windows\usbservice.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Nikola\Application Data\advantage\AdVantage.exe
c:\windows\system32\drivers\sysdrv32.sys
c:\windows\system32\gv.exe
c:\windows\system32\iw.exe
c:\windows\system32\ru.exe
c:\windows\system32\x.exe
c:\windows\usbservice.exe
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090126215149683.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
c:\documents and settings\Nikola\Favorites\Download programs.url
c:\documents and settings\Nikola\Favorites\Games.url
c:\documents and settings\Nikola\Favorites\Online Security Test.url
c:\documents and settings\Nikola\Favorites\Translator.url
c:\documents and settings\Nikola\Favorites\Videos.url
c:\documents and settings\Nikola\Start Menu\Programs\Download programs.url
c:\documents and settings\Nikola\Start Menu\Programs\Games.url
c:\documents and settings\Nikola\Start Menu\Programs\Translator.url
c:\documents and settings\Nikola\Start Menu\Programs\Videos.url
c:\program files\Sotfone
c:\windows\jestertb.dll
c:\windows\system32\divx.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ISODRIVE
-------\Service_ISODrive
-------\Legacy_SYSDRV32
-------\Legacy_USB_SERVICE_2.0
-------\Service_sysdrv32
-------\Service_Usb Service 2.0


((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-28 )))))))))))))))))))))))))))))))
.

2009-01-28 21:53 . 2009-01-28 21:54 <DIR> d-------- C:\USBNoRisk
2009-01-26 22:09 . 2009-01-26 22:09 244 --ah----- C:\sqmnoopt15.sqm
2009-01-26 22:09 . 2009-01-26 22:09 232 --ah----- C:\sqmdata15.sqm
2009-01-26 22:05 . 2009-01-26 22:05 244 --ah----- C:\sqmnoopt14.sqm
2009-01-26 22:05 . 2009-01-26 22:05 232 --ah----- C:\sqmdata14.sqm
2009-01-26 21:51 . 2009-01-26 22:09 23,650 --a------ C:\NSSETUP.EXE-1AD1FEBF.pf
2009-01-26 20:12 . 2009-01-26 20:12 268 --ah----- C:\sqmdata13.sqm
2009-01-26 20:12 . 2009-01-26 20:12 244 --ah----- C:\sqmnoopt13.sqm
2009-01-26 15:16 . 2009-01-26 15:16 268 --ah----- C:\sqmdata12.sqm
2009-01-26 15:16 . 2009-01-26 15:16 244 --ah----- C:\sqmnoopt12.sqm
2009-01-26 11:48 . 2009-01-26 11:48 268 --ah----- C:\sqmdata11.sqm
2009-01-26 11:48 . 2009-01-26 11:48 244 --ah----- C:\sqmnoopt11.sqm
2009-01-14 14:48 . 2009-01-14 14:48 <DIR> d-------- c:\documents and settings\Nikola\Application Data\ImTOO Software Studio
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\program files\Moyea
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\documents and settings\Nikola\Application Data\Moyea
2009-01-14 14:33 . 2008-08-28 18:56 438,272 --a------ c:\windows\system32\vp6vfw.dll
2009-01-14 14:24 . 2009-01-14 14:34 <DIR> d-------- C:\My FLVs
2009-01-14 14:23 . 2009-01-14 14:28 <DIR> d-------- c:\program files\YouTubeRobot
2009-01-14 14:23 . 2007-02-28 13:30 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-01-14 14:23 . 2007-02-28 13:30 1,044,480 --a------ c:\windows\system32\libdivx.dll
2009-01-14 14:23 . 2007-02-28 13:32 716,800 --a------ c:\windows\system32\lameACM.acm
2009-01-14 14:23 . 2007-02-28 13:30 593,920 --a------ c:\windows\system32\dpuGUI11.dll
2009-01-14 14:23 . 2007-02-28 13:30 577,536 --a------ c:\windows\system32\divxdec.ax
2009-01-14 14:23 . 2007-02-28 13:33 389,120 --a------ c:\windows\system32\actskn43.ocx
2009-01-14 14:23 . 2007-02-28 13:30 294,912 --a------ c:\windows\system32\dpu11.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\ssldivx.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\dtu100.dll
2009-01-14 14:23 . 2007-02-28 13:30 86,016 --a------ c:\windows\system32\dpl100.dll
2009-01-14 14:23 . 2007-02-28 13:30 57,344 --a------ c:\windows\system32\dpv11.dll
2009-01-14 14:23 . 2007-02-28 13:32 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\UltraISO
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\Common Files\EZB Systems
2009-01-08 12:25 . 2009-01-21 13:10 238 --a------ c:\windows\mafosav.INI
2009-01-08 12:22 . 2009-01-08 12:22 <DIR> d-------- C:\Buziol Games
2009-01-04 10:42 . 2009-01-04 10:43 35 --a------ c:\windows\mstutor.ini
2009-01-02 10:55 . 2009-01-02 10:55 <DIR> d-------- c:\program files\Xilisoft
2008-12-31 14:49 . 2008-12-31 14:49 <DIR> d-------- C:\svadba
2008-12-31 14:04 . 2008-12-31 14:04 <DIR> d-------- c:\program files\DVD Shrink
2008-12-31 14:04 . 2008-12-31 14:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-31 13:58 . 2008-12-31 13:58 <DIR> d-------- c:\program files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 21:49 --------- d-----w c:\documents and settings\Nikola\Application Data\advantage
2009-01-27 17:10 --------- d-----w c:\program files\The KMPlayer
2009-01-14 13:48 --------- d-----w c:\program files\ImTOO
2009-01-14 13:42 --------- d-----w c:\program files\Total Video Converter
2009-01-08 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-08 12:18 --------- d-----w c:\documents and settings\Nikola\Application Data\LimeWire
2009-01-02 14:30 --------- d-----w c:\documents and settings\Nikola\Application Data\dvdcss
2008-12-31 16:48 --------- d-----w c:\documents and settings\Nikola\Application Data\Skype
2008-12-31 15:07 --------- d-----w c:\documents and settings\Nikola\Application Data\skypePM
2008-12-24 11:58 --------- d-----w c:\program files\YoutubeGet
2008-12-14 13:33 --------- d-----w c:\program files\Folder Lock
2008-12-12 09:46 --------- d-----w c:\program files\Realtek AC97
2008-12-04 20:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 12:15 --------- d-----w c:\program files\WMV9_VCM
2008-12-04 12:12 --------- d-----w c:\program files\1C
2008-12-04 11:54 --------- d-----w c:\program files\DAEMON Tools Pro
2008-12-04 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-04 11:53 --------- d-----w c:\documents and settings\Nikola\Application Data\DAEMON Tools Pro
2008-12-04 11:51 --------- d-----w c:\program files\advantage
2008-12-04 11:46 715,248 ----a-w c:\windows\system32\drivers\sptd.sys
2008-07-14 05:27 9,016 ----a-w c:\program files\tempdecal.wad
2004-07-22 09:51 3,432,656 ----a-w c:\program files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w c:\program files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w c:\program files\BDAXP.cab
2004-07-16 13:30 3,858 ----a-w c:\program files\directx redist.txt
2004-07-09 13:17 13,265,040 ----a-w c:\program files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w c:\program files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w c:\program files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w c:\program files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w c:\program files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w c:\program files\DSETUP.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-05 273864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-24 180269]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2002-01-01 98304]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 c:\windows\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 c:\windows\mixer.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MS AntiSpyware 2009"="c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" [BU]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"vidc.X264"= x264vfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WinampAgent"=c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\zBoT Counter 1.6\\hl.exe"=
"c:\\Program Files\\ApexDC++\\ApexDC.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-14 20560]
R4 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2007-04-05 208896]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/star
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/ALL.HTM
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-28 22:53:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3E3786AA-5288-665B-DF40-0490A1A5049B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iajdmfhanbcdcgadpg"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
"jajeakffndmddjklomho"=hex:62,61,66,63,00,00
"jajeakffndmddjklomdo"=hex:62,61,6b,63,00,00
"hahekfgcipbjfdbf"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A1A06CD3-E41F-1C1E-ECC2-DB2832F4F556}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaejogeiodcfbekjga"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
"japjoiodakalpbmgdpgo"=hex:62,61,6c,66,00,00
"jaljkkknoabjnadiohae"=hex:62,61,63,67,00,00
"hahdcjiipgkckfpf"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Mouse Driver\KMCONFIG.exe
c:\progra~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\Mouse Driver\KMProcess.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Common Files\PCSuite\Services\ServiceLayer.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-01-28 22:56:31 - machine was rebooted [Nikola]
ComboFix-quarantined-files.txt 2009-01-28 21:56:29

Pre-Run: 5,210,914,816 bytes free
Post-Run: 5,195,788,288 bytes free

281

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Iskljuci Antivirus.

Otvoriti Notepad i iskopirati sledeci tekst:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6d86f-7e43-11dc-934e-00112fafc531}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26e6da53-7e43-11dc-934e-00112fafc531}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

ComboFix 09-01-21.04 - Nikola 2009-01-29 11:14:33.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.572 [GMT 1:00]
Running from: c:\documents and settings\Nikola\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nikola\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090128-0] *On-access scanning disabled* (Updated)
FW: COMODO Firewall Pro *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090128225746203.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-29 )))))))))))))))))))))))))))))))
.

2009-01-29 10:30 . 2009-01-29 11:17 41,522 -r-hs---- c:\windows\usbservice.exe
2009-01-29 10:30 . 2009-01-29 11:17 41,522 --a------ C:\http.exe
2009-01-28 22:57 . 2009-01-28 22:57 81,931 --a------ C:\ns2setup.exe
2009-01-28 22:57 . 2009-01-28 22:57 20,018 -r-hs---- c:\windows\usbautotuner.exe
2009-01-28 22:57 . 2009-01-28 22:57 20,018 --a------ c:\windows\system32\jx.exe
2009-01-28 21:53 . 2009-01-28 21:54 <DIR> d-------- C:\USBNoRisk
2009-01-26 22:09 . 2009-01-26 22:09 244 --ah----- C:\sqmnoopt15.sqm
2009-01-26 22:09 . 2009-01-26 22:09 232 --ah----- C:\sqmdata15.sqm
2009-01-26 22:05 . 2009-01-26 22:05 244 --ah----- C:\sqmnoopt14.sqm
2009-01-26 22:05 . 2009-01-26 22:05 232 --ah----- C:\sqmdata14.sqm
2009-01-26 21:51 . 2009-01-26 22:09 23,650 --a------ C:\NSSETUP.EXE-1AD1FEBF.pf
2009-01-26 20:12 . 2009-01-26 20:12 268 --ah----- C:\sqmdata13.sqm
2009-01-26 20:12 . 2009-01-26 20:12 244 --ah----- C:\sqmnoopt13.sqm
2009-01-26 15:16 . 2009-01-26 15:16 268 --ah----- C:\sqmdata12.sqm
2009-01-26 15:16 . 2009-01-26 15:16 244 --ah----- C:\sqmnoopt12.sqm
2009-01-26 11:48 . 2009-01-26 11:48 268 --ah----- C:\sqmdata11.sqm
2009-01-26 11:48 . 2009-01-26 11:48 244 --ah----- C:\sqmnoopt11.sqm
2009-01-14 14:48 . 2009-01-14 14:48 <DIR> d-------- c:\documents and settings\Nikola\Application Data\ImTOO Software Studio
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\program files\Moyea
2009-01-14 14:33 . 2009-01-14 14:33 <DIR> d-------- c:\documents and settings\Nikola\Application Data\Moyea
2009-01-14 14:33 . 2008-08-28 18:56 438,272 --a------ c:\windows\system32\vp6vfw.dll
2009-01-14 14:24 . 2009-01-14 14:34 <DIR> d-------- C:\My FLVs
2009-01-14 14:23 . 2009-01-14 14:28 <DIR> d-------- c:\program files\YouTubeRobot
2009-01-14 14:23 . 2007-02-28 13:30 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2009-01-14 14:23 . 2007-02-28 13:30 1,044,480 --a------ c:\windows\system32\libdivx.dll
2009-01-14 14:23 . 2007-02-28 13:32 716,800 --a------ c:\windows\system32\lameACM.acm
2009-01-14 14:23 . 2007-02-28 13:30 593,920 --a------ c:\windows\system32\dpuGUI11.dll
2009-01-14 14:23 . 2007-02-28 13:30 577,536 --a------ c:\windows\system32\divxdec.ax
2009-01-14 14:23 . 2007-02-28 13:33 389,120 --a------ c:\windows\system32\actskn43.ocx
2009-01-14 14:23 . 2007-02-28 13:30 294,912 --a------ c:\windows\system32\dpu11.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\ssldivx.dll
2009-01-14 14:23 . 2007-02-28 13:30 200,704 --a------ c:\windows\system32\dtu100.dll
2009-01-14 14:23 . 2007-02-28 13:30 86,016 --a------ c:\windows\system32\dpl100.dll
2009-01-14 14:23 . 2007-02-28 13:30 57,344 --a------ c:\windows\system32\dpv11.dll
2009-01-14 14:23 . 2007-02-28 13:32 414 --a------ c:\windows\system32\lame_acm.xml
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\UltraISO
2009-01-08 13:12 . 2009-01-08 13:12 <DIR> d-------- c:\program files\Common Files\EZB Systems
2009-01-08 12:25 . 2009-01-21 13:10 238 --a------ c:\windows\mafosav.INI
2009-01-08 12:22 . 2009-01-08 12:22 <DIR> d-------- C:\Buziol Games
2009-01-04 10:42 . 2009-01-04 10:43 35 --a------ c:\windows\mstutor.ini

2009-01-02 10:55 . 2009-01-02 10:55 <DIR> d-------- c:\program files\Xilisoft
2008-12-31 14:49 . 2008-12-31 14:49 <DIR> d-------- C:\svadba
2008-12-31 14:04 . 2008-12-31 14:04 <DIR> d-------- c:\program files\DVD Shrink
2008-12-31 14:04 . 2008-12-31 14:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-31 13:58 . 2008-12-31 13:58 <DIR> d-------- c:\program files\DVD Decrypter

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 21:49 --------- d-----w c:\documents and settings\Nikola\Application Data\advantage
2009-01-27 17:10 --------- d-----w c:\program files\The KMPlayer
2009-01-14 13:48 --------- d-----w c:\program files\ImTOO
2009-01-14 13:42 --------- d-----w c:\program files\Total Video Converter
2009-01-08 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-08 12:18 --------- d-----w c:\documents and settings\Nikola\Application Data\LimeWire
2009-01-02 14:30 --------- d-----w c:\documents and settings\Nikola\Application Data\dvdcss
2008-12-31 16:48 --------- d-----w c:\documents and settings\Nikola\Application Data\Skype
2008-12-31 15:07 --------- d-----w c:\documents and settings\Nikola\Application Data\skypePM
2008-12-24 11:58 --------- d-----w c:\program files\YoutubeGet
2008-12-14 13:33 --------- d-----w c:\program files\Folder Lock
2008-12-12 09:46 --------- d-----w c:\program files\Realtek AC97
2008-12-04 20:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-04 12:15 --------- d-----w c:\program files\WMV9_VCM
2008-12-04 12:12 --------- d-----w c:\program files\1C
2008-12-04 11:54 --------- d-----w c:\program files\DAEMON Tools Pro
2008-12-04 11:54 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Pro
2008-12-04 11:53 --------- d-----w c:\documents and settings\Nikola\Application Data\DAEMON Tools Pro
2008-12-04 11:51 --------- d-----w c:\program files\advantage
2008-12-04 11:46 715,248 ----a-w c:\windows\system32\drivers\sptd.sys
2008-07-14 05:27 9,016 ----a-w c:\program files\tempdecal.wad
2004-07-22 09:51 3,432,656 ----a-w c:\program files\ManagedDX.CAB
2004-07-19 21:58 1,156,363 ----a-w c:\program files\BDANT.cab
2004-07-19 21:53 976,020 ----a-w c:\program files\BDAXP.cab
2004-07-16 13:30 3,858 ----a-w c:\program files\directx redist.txt
2004-07-09 13:17 13,265,040 ----a-w c:\program files\dxnt.cab
2004-07-09 08:13 703,080 ----a-w c:\program files\BDA.cab
2004-07-09 08:13 15,493,481 ----a-w c:\program files\DirectX.cab
2004-07-09 03:08 472,576 ----a-w c:\program files\dxsetup.exe
2004-07-09 03:08 2,242,560 ----a-w c:\program files\dsetup32.dll
2004-07-09 02:03 62,976 ----a-w c:\program files\DSETUP.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-28_22.55.45.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-29 09:27:58 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_75c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-05 273864]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"KMCONFIG"="c:\program files\Mouse Driver\StartAutorun.exe" [2007-03-06 212992]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 339968]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-24 180269]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2002-01-01 98304]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-08 c:\windows\AGRSMMSG.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-03 c:\windows\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 c:\windows\mixer.exe]
"Microsoft USB Windows2 Driver"="usbautotuner.exe" [2009-01-28 c:\windows\usbautotuner.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"MS AntiSpyware 2009"="c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" [BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.ffds"= ffdshow.ax
"vidc.X264"= x264vfw.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"WinampAgent"=c:\program files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\zBoT Counter 1.6\\hl.exe"=
"c:\\Program Files\\ApexDC++\\ApexDC.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\System32\\jx.exe"=
"c:\\WINDOWS\\usbservice.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3478:UDP"= 3478:UDP:stun
"3479:UDP"= 3479:UDP:stun 2
"6112:UDP"= 6112:UDP:stun 3
"5730:UDP"= 5730:UDP:game
"5739:UDP"= 5739:UDP:game 1
"9001:TCP"= 9001:TCP:game 2
"11881:TCP"= 11881:TCP:game 3

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-14 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-12-14 20560]
R4 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Mouse Driver\KMWDSrv.exe [2007-04-05 208896]
S4 Usb Service 2.0;Usb Service 2.0;c:\windows\usbservice.exe [2009-01-29 41522]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - USB_SERVICE_2.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{530b55e8-7e55-11dc-934f-00112fafc531}]
\Shell\Auto\command - F:\fun.xls.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL fun.xls.exe
.
Contents of the 'Scheduled Tasks' folder

2009-01-16 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.daemon-search.com/star
uInternet Settings,ProxyOverride = *.local
IE: Download all by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/ALL.HTM
IE: Download by YouTube Robot - c:\program files\YouTubeRobot\RobotExt.ocx/LINK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.


**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-29 11:17:07
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{3E3786AA-5288-665B-DF40-0490A1A5049B}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iajdmfhanbcdcgadpg"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01
"jajeakffndmddjklomho"=hex:62,61,66,63,00,00
"jajeakffndmddjklomdo"=hex:62,61,6b,63,00,00
"hahekfgcipbjfdbf"=hex:6b,61,6b,63,64,63,67,6d,6e,69,6c,67,6b,69,61,6d,70,6e,
63,63,6a,67,00,01

[HKEY_USERS\S-1-5-21-725345543-287218729-2147145749-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A1A06CD3-E41F-1C1E-ECC2-DB2832F4F556}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaejogeiodcfbekjga"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
"japjoiodakalpbmgdpgo"=hex:62,61,6c,66,00,00
"jaljkkknoabjnadiohae"=hex:62,61,63,67,00,00
"hahdcjiipgkckfpf"=hex:6b,61,6b,6e,64,6e,65,69,6a,6e,64,63,6c,6f,69,6f,66,6f,
6b,63,68,67,00,01
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(636)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-29 11:18:38
ComboFix-quarantined-files.txt 2009-01-29 10:18:35
ComboFix2.txt 2009-01-28 21:56:33

Pre-Run: 5,170,454,528 bytes free
Post-Run: 5,157,793,792 bytes free

233


Dopuna: 29 Jan 2009 11:53

Da dodam da je stanje sve gore, u istom minutu avast prijavljuje adware, malware, trojanca,MS AntiSpyware ne znam otkud on sad, ali i on sve nesto prijavljuje i neregistrovan je. Jedva sam pristupio sajtu i ispisao post

Dopuna: 29 Jan 2009 11:58

Stalno mi iskacu Spyware alert prozori, ne mogu da se odbranim../

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Vidim, infekcija se vratila.

Sta si ti posecivao u medjuvremenu?

Polako, sredicemo. Nadam se da si bio ukljucio Avast posle skeniranja sa ComboFixom?

Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.

offline
  • Pridružio: 28 Jan 2009
  • Poruke: 76

Posjetio sam gmail. Avast sam ukljucio. Bojim se da cu tesko biti u stanju posjecujem sajt, jer sve vise koci. Sad cu pokusati to da uradim. I kako da iskljucim ovaj windows firewall ? Sad cu pokusati to da uradim sto si mi rekao

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Vidi kako je ovde objasnjeno:

http://www.utmem.edu/helpdesk/sp2/sp2firewall.htm

Ko je trenutno na forumu
 

Ukupno su 960 korisnika na forumu :: 30 registrovanih, 8 sakrivenih i 922 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Arahne, avijacija, Bobrock1, bojcistv, dekan.m, Denaya, DPera, HogarStrashni, HrcAk47, JOntra, kuntalo, magna86, mikrimaus, Milometer, milutin134, mrav pesadinac, nebojsag, novator, Oscar, Parker, Prašinar, raketaš, Romibrat, Snorks, Srle993, Tvrtko I, x9, zdrebac, Šraf