Evo mog loga

Evo mog loga

offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

LJudi problem, evo uradio sam hijack this i mozete mi reci sta mi je ovdje sporno, odnosno koji je kritican proces i sta da radim...

Logfile of HijackThis v1.99.1
Scan saved at 1:44:18 AM, on 5/27/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\System32\qmedia.exe
C:\WINDOWS\System32\firewall.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\WINDOWS\System32\svcchosst.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\BIHnet\BIHnet.exe
C:\WINDOWS\System32\wmplayer.exe
C:\WINDOWS\system\msdll.exe
C:\WINDOWS\system\msnntlp.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Zlatan\Local Settings\Temp\wz818c\HijackThis.exe

O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\System32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\System32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [Winamp Media] C:\WINDOWS\System32\qmedia.exe
O4 - HKLM\..\Run: [Windows Network Firewall] C:\WINDOWS\System32\firewall.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [msvccc66] svcchosst.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [Windows Internet Player] wmplayer.exe
O4 - HKLM\..\RunServices: [msvccc66] svcchosst.exe
O4 - HKLM\..\RunServices: [Windows Internet Player] wmplayer.exe
O4 - HKCU\..\Run: [BIHnet] C:\Program Files\BIHnet\BIHnet.exe
O4 - HKCU\..\Run: [Winamp Media] C:\WINDOWS\System32\qmedia.exe
O4 - HKCU\..\Run: [Windows Internet Player] wmplayer.exe
O4 - Global Startup: icq.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDD9AA9E-7B33-42E5-A7AE-063DED12BE3C}: NameServer = 195.222.32.10 195.222.32.20
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: msdll - Unknown owner - C:\WINDOWS\system\msdll.exe
O23 - Service: msnntlp - Unknown owner - C:\WINDOWS\system\msnntlp.exe
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\System32\PnkBstrB.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

nemoras da ponavljas teme. Onu proslu cu da izbrisem.

Pogledao sam log i definitivno ti je komp inficiran. Ima dosta toga a vec je 3 sata pa ces odgovor dobiti sutra jer log moramo analizirati i videti o kojim se sve zarazama radi.



offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

Komp mi je spor do bola... Hoce mi neko pomochi? @Everybodys_fool ?

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

- skini program Catchme odavde [Link mogu videti samo ulogovani korisnici]
- startuj program
- u programu imas dva taba (files i script), klikni na tab Script i tu kopiraj sledeci sadrzaj:

files:
C:\WINDOWS\System32\qmedia.exe 
C:\WINDOWS\System32\firewall.exe
C:\WINDOWS\System32\svcchosst.exe
C:\WINDOWS\System32\wmplayer.exe
C:\WINDOWS\system\msdll.exe
C:\WINDOWS\system\msnntlp.exe
C:\WINDOWS\System32\urdvxc.exe
C:\Program Files\BIHnet\BIHnet.exe


- kada si to iskopirao klikni na dugme Run.

- program ce na tvom desktopu napraviti arhivu catchme.zip.
- catchme.zip uploaduj preko ovog link: [Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 27 Maj 2007
  • Poruke: 3

E tnx ali u medjuvremenu sam poludio tako da sam morao format C. Ipak hvala na pokusaju i volio bih da smo uspjeli ovako... Sada nemam nista na hdd-u Sad

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

komp ti je bio poprilicno zarazen i 90% da bi radio mnogo bolje da smo ga ocistili.

Nadam se da si instalirao SP2 jer je SP1 pun rupa koje malwer koristi da bi se ubacio na sistem. SP2 i redovan update AV programa ce ti poprilicno smanjiti muke.

Ko je trenutno na forumu
 

Ukupno su 875 korisnika na forumu :: 127 registrovanih, 14 sakrivenih i 734 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 10x10.9, 357magnum, alke12, Alojzije, ambra, Asteker, Baltimor, Barista, Batko.VD.65, belov, bobor, bojan313, boogie123, BOXRR, Brabant, Brankojle, bukefal, cavatina, celeron, Centauro, chichabg, Ciri1994, cojapop, cole77, crnirocko, Daba75, Dare, darios, davorb, DejanSt, dekan.m, DonRumataEstorski, Dovla 1980, draganche.rs, Duce, Dzumanga, Ercomero, Ezbuck, Folkstar, galerija, Georgius, Goga, Goran 0000, Goran_, Great White, HogarStrashni, immicro, Jakonjveliki, jalos, Jecmendo, Jester, jon istvan, JOntra, Jovan.D, jugoslav.70, koliko, Kredit, Kukuvaja, lacko, Litostroton, LjubisaR, Marko Marković, mat, mercedesamg, Metanoja, mgolub, Mig 29, Milanče222, milenko crazy north, mino bosanac, nebidrag, nenad81, nikolapetkovic, Nmr, Nomica, Ognjen D., ozzy, perunnurep, Piicoki, Plavi1, PO1974, Polifon, Povratak1912, Prašinar, proka1ng, Promising0, Puch300GD, Radoslava, razumihin, Resnica, RiV, RJ, Romibrat, Rothmans, S-lash, S2M, sale_bih, Sami_1ali, samocitam, Sharpshooter, Shinobi, Sir Budimir, Siti2, siwoti, Smor, starlights, Stevan Visoki, t.e.m.p.l.a.r., Tas011, TheDictator, theNedjeljko, Tila Painen, Topaz9, trpche, vazduh, Vitomir, Vlada78, voja64, Volfero, volimpivuvolimrakiju, x011, Zastava, zixmix, zlatkoa987, ZlatniRez, zmajbre, Žoržo