Evo mog loga

Evo mog loga

offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

LJudi problem, evo uradio sam hijack this i mozete mi reci sta mi je ovdje sporno, odnosno koji je kritican proces i sta da radim...

Logfile of HijackThis v1.99.1
Scan saved at 1:44:18 AM, on 5/27/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\System32\qmedia.exe
C:\WINDOWS\System32\firewall.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\System32\svcchosst.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\BIHnet\BIHnet.exe
C:\WINDOWS\System32\wmplayer.exe
C:\WINDOWS\system\msdll.exe
C:\WINDOWS\system\msnntlp.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Zlatan\Local Settings\Temp\wz818c\HijackThis.exe

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Winamp Media] C:\WINDOWS\System32\qmedia.exe
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [msvccc66] svcchosst.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [Windows Internet Player] wmplayer.exe
O4 - HKLM\..\RunServices: [msvccc66] svcchosst.exe
O4 - HKLM\..\RunServices: [Windows Internet Player] wmplayer.exe
O4 - HKCU\..\Run: [BIHnet] C:\Program Files\BIHnet\BIHnet.exe
O4 - HKCU\..\Run: [Winamp Media] C:\WINDOWS\System32\qmedia.exe
O4 - HKCU\..\Run: [Windows Internet Player] wmplayer.exe
O4 - Global Startup: icq.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDD9AA9E-7B33-42E5-A7AE-063DED12BE3C}: NameServer = 195.222.32.10 195.222.32.20
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: msdll - Unknown owner - C:\WINDOWS\system\msdll.exe
O23 - Service: msnntlp - Unknown owner - C:\WINDOWS\system\msnntlp.exe
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\System32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

nemoras da ponavljas teme. Onu proslu cu da izbrisem.

Pogledao sam log i definitivno ti je komp inficiran. Ima dosta toga a vec je 3 sata pa ces odgovor dobiti sutra jer log moramo analizirati i videti o kojim se sve zarazama radi.



offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

Komp mi je spor do bola... Hoce mi neko pomochi? @Everybodys_fool ?

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

- skini program Catchme odavde https://www.mycity.rs/must-login.png
- startuj program
- u programu imas dva taba (files i script), klikni na tab Script i tu kopiraj sledeci sadrzaj:

files:
C:\WINDOWS\System32\qmedia.exe 
C:\WINDOWS\System32\firewall.exe
C:\WINDOWS\System32\svcchosst.exe
C:\WINDOWS\System32\wmplayer.exe
C:\WINDOWS\system\msdll.exe
C:\WINDOWS\system\msnntlp.exe
C:\WINDOWS\System32\urdvxc.exe
C:\Program Files\BIHnet\BIHnet.exe


- kada si to iskopirao klikni na dugme Run.

- program ce na tvom desktopu napraviti arhivu catchme.zip.
- catchme.zip uploaduj preko ovog link: http://www.mycity.rs/ambulanta-upload.php

offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

E tnx ali u medjuvremenu sam poludio tako da sam morao format C. Ipak hvala na pokusaju i volio bih da smo uspjeli ovako... Sada nemam nista na hdd-u Sad

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

komp ti je bio poprilicno zarazen i 90% da bi radio mnogo bolje da smo ga ocistili.

Nadam se da si instalirao SP2 jer je SP1 pun rupa koje malwer koristi da bi se ubacio na sistem. SP2 i redovan update AV programa ce ti poprilicno smanjiti muke.

Ko je trenutno na forumu
 

Ukupno su 967 korisnika na forumu :: 29 registrovanih, 3 sakrivenih i 935 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bojank, bokisha253, cinoeye, comi_pfc, debeli, Frunze, Georgius, HogarStrashni, HrcAk47, kbobo, kybonacci, ladro, mane123, mikrimaus, mile23, Milos ZA, Mirage 2000N, mkukoleca, nenad81, Prašinar, Sir Budimir, Snorks, tubular, vaso1, VJ, Vlada78, vladaa012, vladulns, x9