Problemi sa IE

Problemi sa IE

offline
  • Pridružio: 05 Avg 2008
  • Poruke: 33

Desava mi se da kada u IE kliknem na neki link, umesto naznacenog sajta otvara mi se YouTube (film-za-odrasle)- 2.0, molim Vas da mi pomognete da se resim ove brige!

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 05 Avg 2008
  • Poruke: 33

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:45:58 PM, on 1/8/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20900)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Phone Recorder Plus\PNRCPP.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Dragan\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = google.rs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = socks=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Microsoft - {37566535-A634-5164-5467-5A56453BD4FA} - C:\WINDOWS\promo_freesoft.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [ShowDeskFix] regsvr32 /s /n /i:u shell32 (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85} (NetSeTManager Class) - ebank.agrobanka.rs/Retail/Pages/Download/C.....PlugIn.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O20 - AppInit_DLLs: sockspy.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c94710f0192b80) (gupdate1c94710f0192b80) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: PNRCPP - Teley.com - C:\Program Files\Phone Recorder Plus\PNRCPP.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 11242 bytes

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Za pocetak, deisntaliraj jedan od Antivirus programa (Kaspersky ili Bitdefender).

offline
  • Pridružio: 05 Avg 2008
  • Poruke: 33

Ocistio sam Bit defender

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Privremeno iskljuci sav zastitni softver i uradi sledece :

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 05 Avg 2008
  • Poruke: 33

ComboFix 09-01-08.01 - Dragan 2009-01-08 23:28:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1605 [GMT 1:00]
Running from: c:\documents and settings\Dragan\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Dragan\My Documents\My Music\My Music.url
c:\documents and settings\Dragan\My Documents\My Pictures\My Pictures.url
c:\documents and settings\Dragan\My Documents\My Videos\My Video.url
c:\windows\system32\drivers\npf.sys
c:\windows\system32\NTVBSvcW.tlb
c:\windows\system32\packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wanpacket.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.

2009-01-08 19:54 . 2009-01-08 19:54 <DIR> d-------- c:\program files\Lavasoft
2009-01-08 19:54 . 2009-01-08 19:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-06 14:55 . 2009-01-06 14:55 <DIR> d-------- c:\program files\7-Zip
2009-01-06 13:59 . 2009-01-07 12:03 <DIR> d-------- c:\program files\Tomb Raider - Legend
2009-01-06 13:16 . 2009-01-06 17:58 <DIR> d-------- c:\program files\GameShadow
2009-01-06 11:40 . 2009-01-06 11:40 <DIR> d-------- c:\program files\Actual Rar Repair
2009-01-06 11:27 . 2009-01-06 11:27 <DIR> d-------- c:\program files\ExtractNow
2009-01-04 10:15 . 2009-01-04 10:15 <DIR> d-------- c:\documents and settings\Dragan\Application Data\Lost Marble
2009-01-04 10:14 . 2009-01-04 10:14 <DIR> d-------- c:\program files\Smith Micro
2009-01-04 04:02 . 2009-01-04 04:02 <DIR> d-------- c:\program files\XoftSpySE
2009-01-02 15:19 . 2009-01-02 15:34 <DIR> d-------- c:\documents and settings\Dragan\Application Data\Hide IP NG
2009-01-01 21:42 . 2009-01-01 21:42 <DIR> d-------- c:\documents and settings\Dragan\Application Data\ForgottenRiddles2
2009-01-01 21:40 . 2009-01-01 21:40 <DIR> d-------- c:\program files\Forgotten Riddles - The Moonlight Sonatas
2009-01-01 21:40 . 2009-01-02 18:07 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-01 21:25 . 2009-01-01 21:25 <DIR> d-------- c:\program files\bfgclient
2009-01-01 21:24 . 2009-01-01 21:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-01 20:49 . 2009-01-01 20:49 <DIR> d-------- c:\program files\RegCure
2009-01-01 20:45 . 2009-01-01 20:45 <DIR> d-------- c:\program files\Game_Maker7
2009-01-01 20:45 . 2009-01-01 20:45 0 --ah----- c:\windows\SwSys2.bmp
2009-01-01 20:45 . 2009-01-01 20:45 0 --ah----- c:\windows\SwSys1.bmp
2009-01-01 20:32 . 2009-01-01 20:32 <DIR> d-------- c:\program files\WME DevKit
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\program files\iTunes
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\program files\iPod
2009-01-01 12:20 . 2009-01-01 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-01 12:20 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2009-01-01 12:20 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2009-01-01 12:17 . 2009-01-01 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2009-01-01 12:15 . 2009-01-01 12:20 <DIR> d-------- c:\program files\Common Files\Apple
2009-01-01 12:15 . 2009-01-01 12:16 <DIR> d-------- c:\program files\Apple Software Update
2009-01-01 12:15 . 2009-01-01 12:15 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-12-29 12:46 . 2008-12-29 12:46 69,632 --a------ c:\windows\promo_freesoft.dll
2008-12-19 15:01 . 2008-12-30 19:02 286 --a------ c:\windows\Christmas Adventure 2.ini
2008-12-19 15:00 . 2008-11-26 10:27 4,662,859 --a------ c:\windows\Christmas Adventure 2.scr
2008-12-19 15:00 . 2008-12-19 15:00 682,266 --a------ c:\windows\unins000.exe
2008-12-19 15:00 . 2008-12-19 15:00 3,323 --a------ c:\windows\unins000.dat
2008-12-19 15:00 . 2004-11-02 19:35 2,238 --a------ c:\windows\Christmas Adventure 2.ico
2008-12-15 16:05 . 2008-12-15 16:05 7,680 --ahs---- c:\windows\Thumbs.db
2008-12-15 16:05 . 2008-12-15 16:05 5,120 --ahs---- c:\windows\system32\Thumbs.db
2008-12-14 17:50 . 2003-11-04 15:11 159,744 --a------ c:\windows\system32\lfpng13n.dll
2008-12-13 21:54 . 2008-12-13 21:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Bluetooth
2008-12-13 21:52 . 2008-12-13 21:52 <DIR> d-------- c:\program files\IVT Corporation
2008-12-13 21:52 . 2008-12-13 21:53 32 --a------ c:\windows\0
2008-12-13 21:52 . 2008-12-13 21:52 0 --a------ c:\windows\system32\0
2008-12-13 21:43 . 2004-08-03 23:10 38,016 --a------ c:\windows\system32\drivers\bthmodem.sys
2008-12-13 21:43 . 2004-08-03 23:10 38,016 --a--c--- c:\windows\system32\dllcache\bthmodem.sys
2008-12-13 21:37 . 2004-08-03 22:58 100,992 --a------ c:\windows\system32\drivers\bthpan.sys
2008-12-13 21:37 . 2004-08-03 22:58 100,992 --a--c--- c:\windows\system32\dllcache\bthpan.sys
2008-12-13 21:36 . 2004-08-04 00:56 152,576 --a------ c:\windows\system32\irftp.exe
2008-12-13 21:36 . 2004-08-04 00:56 152,576 --a--c--- c:\windows\system32\dllcache\irftp.exe
2008-12-13 21:36 . 2004-08-03 23:10 59,648 --a------ c:\windows\system32\drivers\rfcomm.sys
2008-12-13 21:36 . 2004-08-03 23:10 59,648 --a--c--- c:\windows\system32\dllcache\rfcomm.sys
2008-12-13 21:36 . 2004-08-04 00:56 27,136 --a------ c:\windows\system32\irmon.dll
2008-12-13 21:36 . 2004-08-04 00:56 27,136 --a--c--- c:\windows\system32\dllcache\irmon.dll
2008-12-13 21:36 . 2004-08-03 23:10 18,944 --a------ c:\windows\system32\drivers\BTHUSB.SYS
2008-12-13 21:36 . 2004-08-03 23:10 18,944 --a--c--- c:\windows\system32\dllcache\bthusb.sys
2008-12-13 21:36 . 2004-08-03 23:10 17,024 --a------ c:\windows\system32\drivers\BthEnum.sys
2008-12-13 21:36 . 2004-08-03 23:10 17,024 --a--c--- c:\windows\system32\dllcache\bthenum.sys
2008-12-13 21:36 . 2004-08-04 00:56 8,192 --a------ c:\windows\system32\wshirda.dll
2008-12-13 21:36 . 2004-08-04 00:56 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2008-12-09 18:52 . 2008-12-09 18:53 <DIR> d-------- c:\windows\system32\Adobe
2008-12-08 21:35 . 2008-12-08 21:35 <DIR> d-------- c:\program files\Ubisoft
2008-12-08 18:28 . 2004-01-05 23:42 118,784 --a------ c:\windows\system32\SkyDll.dll
2008-12-08 18:28 . 2004-01-05 23:42 118,784 --a------ c:\windows\system32\Sky2PCUI.dll
2008-12-08 18:28 . 2004-01-05 19:50 102,400 --a------ c:\windows\system32\libbz2.dll
2008-12-08 17:48 . 2008-12-08 17:48 <DIR> d-------- c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-08 17:00 . 2008-12-08 17:00 <DIR> d-------- c:\documents and settings\Dragan\Application Data\TuneUp Software
2008-12-08 17:00 . 2008-12-08 17:00 355,584 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-12-08 17:00 . 2008-05-29 09:28 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-12-08 16:59 . 2008-12-08 17:00 <DIR> d-------- c:\program files\TuneUp Utilities 2008
2008-12-08 16:59 . 2008-12-08 16:59 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-12-08 15:54 . 2008-12-08 16:28 592 --a------ c:\windows\chgkey.vbs

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 22:31 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-01-08 22:29 925,728 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-08 22:29 7,770,144 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-08 22:29 63,880 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-08 22:29 6,340 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-08 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\BitDefender
2009-01-08 18:53 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-01-08 00:51 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-01 20:09 --------- d-----w c:\program files\Bonjour
2009-01-01 12:01 --------- d-----w c:\program files\Common Files\Adobe
2009-01-01 11:21 --------- d-----w c:\documents and settings\Dragan\Application Data\Apple Computer
2009-01-01 11:17 --------- d-----w c:\program files\QuickTime
2008-12-24 20:31 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-23 15:21 --------- d-----w c:\documents and settings\Dragan\Application Data\gtk-2.0
2008-12-19 20:19 --------- d-----w c:\program files\Google
2008-12-10 16:49 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-08 17:28 --------- d-----w c:\program files\TechniSat DVB
2008-12-08 15:30 --------- d-----w c:\documents and settings\Dragan\Application Data\zweitgeist
2008-12-08 11:05 --------- d-----w c:\program files\Di recnik
2008-12-07 13:58 --------- d-----w c:\program files\GameSpy Arcade
2008-12-07 13:55 --------- d-----w c:\program files\Firefly Studios
2008-12-06 15:07 --------- d-----w c:\program files\CCleaner
2008-12-04 21:43 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-12-04 15:45 --------- d-----w c:\program files\WinPcap
2008-12-04 15:30 74,240 ----a-w c:\windows\ST6UNST.EXE
2008-12-04 15:30 253,952 ------w c:\windows\Setup1.exe
2008-11-30 15:19 --------- d-----w c:\program files\D-Tools
2008-11-29 20:49 --------- d-----w c:\program files\Flash Wallpaper Maker
2008-11-29 19:30 --------- d-----w c:\program files\weblin
2008-11-29 06:50 --------- d-----w c:\program files\Launchy
2008-11-29 06:50 --------- d-----w c:\documents and settings\Dragan\Application Data\Launchy
2008-11-21 11:24 --------- d-----w c:\documents and settings\Dragan\Application Data\Canon
2008-11-21 11:14 98,304 ----a-w c:\windows\DUMPc3bd.tmp
2008-11-21 06:48 98,304 ----a-w c:\windows\DUMPc0fe.tmp
2008-11-21 06:45 98,304 ----a-w c:\windows\DUMPbfc5.tmp
2008-11-21 06:37 98,304 ----a-w c:\windows\DUMPc505.tmp
2008-11-20 16:46 --------- d-----w c:\program files\ElcomSoft
2008-11-18 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\CanonIJPLM
2008-11-18 08:48 --------- d-----w c:\documents and settings\Dragan\Application Data\Media Player Classic
2008-11-08 21:18 --------- d-----w c:\program files\Gimp-2.0
2008-10-28 12:50 22,328 ----a-w c:\documents and settings\Dragan\Application Data\PnkBstrK.sys
2008-10-14 13:16 155,995 ----a-w c:\windows\java\Packages\8CWQ7DBR.ZIP
2008-10-14 12:54 315,392 ----a-w c:\windows\HideWin.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-15 39408]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2007-05-17 661369]
Server4PC.lnk - c:\program files\TechniSat DVB\bin\Server4PC.exe [2008-12-08 430080]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
"msacm.l3fhg"= mp3fhg.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Launchy.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Launchy.lnk
backup=c:\windows\pss\Launchy.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
--a------ 2007-04-03 17:50 1603152 c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
--a------ 2007-05-14 17:01 644696 c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 00:56 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\filehippo.com]
--a------ 2008-10-22 13:51 147968 c:\program files\filehippo.com\UpdateChecker.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GAINWARD]
--a------ 2008-07-03 15:50 2177576 c:\program files\EXPERTool\TBPANEL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 11:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-09-17 23:55 13574144 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-09-17 23:55 86016 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
--a------ 2007-02-04 11:02 79400 c:\program files\ScanSoft\OmniPageSE4\OpWareSE4.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
--a------ 2006-10-25 08:03 210472 c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-11-15 11:39 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMonitorVMUVC]
--a------ 2007-04-13 17:08 114688 c:\program files\Vimicro\Vimicro UVC USB2.0 PC Camera\x86\VMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 16:43 4670704 c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zweitgeist Assistant]
--a------ 2008-11-29 20:30 192512 c:\program files\weblin\weblinAssistant.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-r------- 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-09-17 23:55 1657376 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-r------- 2008-02-13 07:31 16857600 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\TechniSat DVB\\bin\\Server4PC.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"e:\\STARI KOMPJUTER\\Disk C\\Program Filles\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 SKYNET;B2C2 Broadband Receiver PCI Adapter;c:\windows\system32\drivers\SkyNET.sys [2008-10-14 446884]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [2008-10-15 248448]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [2008-10-15 476032]
R4 PNRCPP;PNRCPP;c:\program files\Phone Recorder Plus\PNRCPP.exe [2005-08-08 397312]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
S4 gupdate1c94710f0192b80;Google Update Service (gupdate1c94710f0192b80);c:\program files\Google\Update\GoogleUpdate.exe [2008-11-15 133104]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-01-08 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:09]

2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-01-08 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-11-15 12:09]

2009-01-08 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 19:55]

2009-01-08 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 19:55]

2009-01-08 c:\windows\Tasks\XoftSpySE 2.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 18:08]

2009-01-04 c:\windows\Tasks\XoftSpySE.job
- c:\program files\XoftSpySE\XoftSpy.exe [2008-12-23 18:08]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-BDAgent - c:\program files\Softwin\BitDefender10\bdagent.exe
MSConfigStartUp-BDMCon - c:\program files\Softwin\BitDefender10\bdmcon.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.rs/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = plimus.com,www.plimus.com,regnow.com,www.regnow.com,
uInternet Settings,ProxyServer = socks=
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

O16 -: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

c:\windows\system32\NetSeTAPI.dll - c:\windows\system32\PexCryptoAPI.dll
O16 -: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85}
hxxps://ebank.agrobanka.rs/Retail/Pages/Download/CABS/DigitrustApiNetSetPlugIn.cab
c:\windows\Downloaded Program Files\DigitrustApiNetSetPlugin.inf
FF - ProfilePath - c:\documents and settings\Dragan\Application Data\Mozilla\Firefox\Profiles\j2zpbja0.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\jaman.js - pref("network.protocol-handler.warn-external.jaman", false);
.
.
------- File Associations -------
.
inifile\shell\mv2player\command="c:\program files\Mv2Player\Mv2PlayerPlus.exe" "%1"
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-08 23:31:35
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-08 23:32:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-08 22:32:50

Pre-Run: 30,274,301,952 bytes free
Post-Run: 30,219,710,464 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

334 --- E O F --- 2008-12-07 20:58:13

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\promo_freesoft.dll


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Ko je trenutno na forumu
 

Ukupno su 1102 korisnika na forumu :: 34 registrovanih, 7 sakrivenih i 1061 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, Bobrock1, cavatina, cenejac111, CikaKURE, comi_pfc, doktor1964, FileFinder, galerija, HrcAk47, Kubovac, Leonov, ljuba, Luka1998, MB120mm, mercedesamg, Mi lao shu, Milenaaa, Milos ZA, Milos82, Mlav, mocnijogurt, Ne doznajem se u oružje, nemkea71, Parker, procesor, rodoljub, Singidunumac, suton, tomigun, Trpe Grozni, vlajkox, wolverined4, 1107