Problem sa MySpace-om

1

Problem sa MySpace-om

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Nijedan browser nece da mi otvori myspace, evo log-a:


Logfile of HijackThis v1.99.1
Scan saved at 0:31:14, on 29.5.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Canon\CAL\CALMAIN.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Opera\Opera.exe
D:\Documents and Settings\dmitko\My Documents\Programi\tr3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBD4A053-BBCB-425D-8296-3EBCB93F1801}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8-) - Canon Inc. - D:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe



online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8643
  • Gde živiš: Novi Beograd

Zdravo,

Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

ComboFix 08-05-29.1 - Dmitar 2008-06-01 17:25:43.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.90 [GMT 2:00]
Running from: D:\Documents and Settings\Dmitar\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\WINDOWS\system32\kdcwn.exe

.
((((((((((((((((((((((((( Files Created from 2008-05-01 to 2008-06-01 )))))))))))))))))))))))))))))))
.

2008-06-01 15:42 . 2008-06-01 15:42 <DIR> d-------- D:\Documents and Settings\Dmitar\Application Data\NCH Swift Sound
2008-05-27 20:03 . 2008-06-01 15:42 <DIR> d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\NCH Swift Sound
2008-05-27 20:02 . 2008-06-01 15:42 <DIR> d-------- D:\Program Files\NCH Swift Sound
2008-05-11 02:55 . 2008-05-11 02:55 376 --a------ D:\WINDOWS\ODBC.INI
2008-05-11 02:54 . 2003-06-18 17:31 17,920 --a------ D:\WINDOWS\system32\mdimon.dll
2008-05-06 23:56 . 2008-05-15 11:13 <DIR> d-------- D:\Program Files\MySpace
2008-05-06 23:56 . 2008-05-06 23:56 <DIR> d-------- D:\Documents and Settings\Dmitar\Application Data\MySpace
2008-05-04 03:23 . 2008-05-04 03:23 <DIR> d-------- D:\Documents and Settings\Dmitar\Application Data\Design Science
2008-05-04 03:22 . 2008-05-04 03:22 <DIR> d-------- D:\Program Files\MathType

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 21:46 --------- d-----w D:\Program Files\Common Files\Ahead
2008-05-27 21:46 --------- d-----w D:\Program Files\Ahead
2008-05-26 23:47 --------- d-----w D:\Program Files\8BallClub
2008-05-20 21:51 --------- d-----w D:\Documents and Settings\Dmitar\Application Data\ZoomBrowser EX
2008-05-20 14:59 --------- d-----w D:\Documents and Settings\Dmitar\Application Data\FrostWire
2008-05-19 20:56 --------- d-----w D:\Program Files\FrostWire
2008-05-19 16:11 --------- d-----w D:\Program Files\AskSBar
2008-05-17 16:28 --------- d-----w D:\Documents and Settings\All Users.WINDOWS\Application Data\ZoomBrowser
2008-05-15 23:13 --------- d-----w D:\Program Files\ACD Systems
2008-05-05 13:52 --------- d-----w D:\Documents and Settings\Dmitar\Application Data\U3
2008-04-30 18:50 --------- d-----w D:\Program Files\Daqarta
2008-04-27 19:07 --------- d-----w D:\Documents and Settings\Dmitar\Application Data\ACD Systems
2008-04-27 18:51 --------- d-----w D:\Program Files\Common Files\ACD Systems
2008-04-16 20:36 --------- d-----w D:\Program Files\Counter-Strike 1.6
2008-04-13 23:57 --------- d-----w D:\Documents and Settings\Dmitar\Application Data\MathWorks
2008-04-13 23:24 --------- d-----w D:\Program Files\MATLAB
2008-04-07 19:48 --------- d-----w D:\Program Files\Optimik
2008-04-06 12:02 --------- d-----w D:\Program Files\Canon
2008-04-06 12:00 --------- d-----w D:\Program Files\Common Files\Canon
2001-11-23 04:08 712,704 ----a-w D:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-05-19 18:11 66912 --a------ D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL" [2008-03-25 13:06 267592]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2008-03-25 13:06 267592]

[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54 5674352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2008-03-29 02:59 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= D:\PROGRA~1\ACEMEG~1\SystemS\Intel\iac25_32.ax
"msacm.sl_anet"= D:\PROGRA~1\ACEMEG~1\SystemS\sl_anet.acm
"vidc.3ivx"= D:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv0"= D:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv1"= D:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3iv2"= D:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.3ivd"= D:\PROGRA~1\ACEMEG~1\SystemS\3ivx\3IVXVF~1.DLL
"vidc.yv12"= D:\PROGRA~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"vidc.divx"= D:\PROGRA~1\ACEMEG~1\SystemS\DivX\DivX511.dll
"vidc.iyuv"= D:\PROGRA~1\ACEMEG~1\SystemS\Intel\iyuv_32.dll
"vidc.yvu9"= D:\PROGRA~1\ACEMEG~1\SystemS\Intel\Iyvu9_32.dll
"vidc.uyvy"= D:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.rsy2"= D:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"vidc.yvyu"= D:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msyuv.dll
"msacm.msaudio1"= D:\PROGRA~1\ACEMEG~1\SystemS\MICROS~1\msaud32.acm

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"D:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"D:\\Program Files\\Counter-Strike 1.6\\hlds.exe"=
"D:\\Program Files\\FrostWire\\FrostWire.exe"=
"D:\\Program Files\\8BallClub\\GameDirector.exe"=

R3 iadusb;MT882;D:\WINDOWS\system32\DRIVERS\glauiad.sys [2006-03-20 09:32]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"D:\Program Files\MSN Messenger\usnsvc.exe" [2007-01-19 13:54]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9ae7ba81-0659-11dd-992d-0018027c2248}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-06-01 17:35:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
D:\WINDOWS\system32\rundll32.exe
D:\Program Files\Canon\CAL\CALMAIN.exe
D:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-06-01 17:46:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-01 15:45:56
ComboFix2.txt 2008-03-21 01:57:51

Pre-Run: 69,132,288 bytes free
Post-Run: 385,544,192 bytes free

123 --- E O F --- 2008-05-31 18:49:33

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8643
  • Gde živiš: Novi Beograd

Postavi mi novi HJT log.

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Logfile of HijackThis v1.99.1
Scan saved at 18:42:39, on 1.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\RunDll32.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\WINDOWS\system32\qttask.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Canon\CAL\CALMAIN.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wuauclt.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Opera\Opera.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Documents and Settings\dmitko\My Documents\Programi\tr3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBD4A053-BBCB-425D-8296-3EBCB93F1801}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8-) - Canon Inc. - D:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8643
  • Gde živiš: Novi Beograd

Uploaduj mi sledeci fajl na proveru:

D:\WINDOWS\inf\OTHER\AUDIO3D.DLL

preko ovog linka:
[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

File upload-ovan....

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8643
  • Gde živiš: Novi Beograd

Pozzz,

pokreni HJT, skeniraj i stikliraj kvadratice ispred sledecih linija:

O17 - HKLM\System\CCS\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBD4A053-BBCB-425D-8296-3EBCB93F1801}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS1\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133
O17 - HKLM\System\CS2\Services\Tcpip\..\{0CDBB3A0-967B-46E8-B7A6-562F744E2A2B}: NameServer = 85.255.116.77,85.255.112.133
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.77 85.255.112.133

I klikni FIX CHECKED

Restartuj kompjuter i potom mi postavi novi HJT log.

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Logfile of HijackThis v1.99.1
Scan saved at 23:36:47, on 3.6.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\MSN Messenger\MsnMsgr.Exe
D:\Program Files\Canon\CAL\CALMAIN.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Opera\Opera.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\dmitko\My Documents\Programi\tr3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: Canon Camera Access Library 8 (CCALib8-) - Canon Inc. - D:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\Program Files\MATLAB\R2006a\webserver\bin\win32\matlabserver.exe

online
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8643
  • Gde živiš: Novi Beograd

Kakvo je sada stanje? Ima li nekih problema, da li je proradio myspace?

Ko je trenutno na forumu
 

Ukupno su 1308 korisnika na forumu :: 136 registrovanih, 9 sakrivenih i 1163 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 13297 - dana 20 Jan 2026 17:42

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, aca018, Agape, ALEXV, amaterSRB, annon, AOE, Apok, Asparagus, Asteker, Avalon015, Bbbggg1979, Bobrock1, bojankrstc, boro975, borya90, BWG, BZ, crazydkure, Crazzer, Dambi, DeerHunter, DENIRO, Despot Đurađ, djonsule, djuradj, DM1994, domenico, draganl, dushan, Gall, Giskard, Gitzherai, Gogi do, GrobarPovratak, Halabit, Hans Gajger, hatman, havoc995, helen1, HrcAk47, igorpet, istina, Istman, Jester, Jomini, K a s p e r, K-1A, Kakarotsvc, kalens021, kaput21, karakaj, kingkong1947, kmnmada, komsija1, Kototamopeva, krca73, Kruger, Kuroje, kybonacci, lcc, Lester Freamon, lima, littlebunny, luka35, Markisa, Marko00, Mercury, mgolub, Miha79, miki69, Miler88, MiljanXD, Milometer, MiloradKomadic, Mimis82, miroslav milanović, mixkax, moldway, nelezele, nemkea71, nevjerna beba, nikoladim, oldtimer, orfanel, Oscar, panzerwaffe, pein, Perudin_92, Petar25, pisac12, PrincipL, Profesor_018, Pv123, R_038, raf87, redstar72, RJ, sales, samp1389, sap, sasovsky, SD izvidjac, sekretar, shiro, Sirius, SOM, srbijaiznadsvega, starlights, stegonosa, stingD, Sukhoi235, Szigetwar, The Boss, tihi-posmatrac, Tihi86, troki1971, Tvrtko I, vaci, VanZan, veljko82, virked, Vlad000, Vlada1389, vladaa012, vladivostok, Voice1, volimpivuvolimrakiju, Walkers, Warrior, xAlex2, Zastava, Zavulon, ZlatniRez, Zoran Rapajić, Žrnov