HELP..... nepoznato

HELP..... nepoznato

offline
  • Pridružio: 21 Apr 2008
  • Poruke: 102
  • Gde živiš: Maklosevac, Nasice, Hrvatska

Imam problema sa konekcijom na internet...... Kada god se spajam uvijek izbacuje sljedecu adresu: [EDITOVANO]
nije mi jasno o cemu se tu radi.... Da li imam problema sa spywareom, spamom ili bilo cime drugim.....
Molio bih vas za pomoc jer se ne mogu spajat niti preko IE, niti preko Mozille.... jedino ide preko MS Outlooka..... Probao sam rijesavati problem preko raznih programa (TM PC-cillin, Ad-aware, VundoFix i Hijack This) i uopce niti jedan nije nasao problem. Na internetu sam nasao neke podatke u vezi ove IP adrese ali nigdje ne pise konkretno s cime se to rijesava..... Hvala na pomoci unaprijed.

offline
  • DEMIAN  Male
  • Legendarni građanin
  • IT Manager
  • Pridružio: 25 Mar 2005
  • Poruke: 3706
  • Gde živiš: The darkest place on earth..

Šta si konkretno sređivao HijackThis-om? Možeš li da postaviš svež log po onom izdvojenom uputstvu koje se nalazi ovde u Ambulanti?

offline
  • Pridružio: 21 Apr 2008
  • Poruke: 102
  • Gde živiš: Maklosevac, Nasice, Hrvatska

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:12:44, on 21.4.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Netropa\Multimedia Keyboard\TrayMon.exe
C:\Program Files\Netropa\Onscreen Display\OSD.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = vip.hr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = vip.hr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by VIPonline
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [BM1b276e35] Rundll32.exe "C:\WINDOWS\system32\tfdatbho.dll",s
O4 - HKLM\..\Run: [18145da9] rundll32.exe "C:\WINDOWS\system32\mbnghhei.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

--
End of file - 4463 bytes

Dopuna: 21 Apr 2008 20:17

Ubiti.... Ubijao sam sve sumnjive procese..... Na kraju niti jedan nije koji bi trebao biti.

Dopuna: 21 Apr 2008 20:42

Ovako.... U mapi *.*\Local Settings\Temporary Internet Files nas nasao dva file koji odgovaraju IP adresama koji mi se izbacuju kada se spajam na internet i jedan cookie....

1. file: idkfa Internet adress: 82.98.235.78/b/idkfa.dll?uid=91E28A8AFB6011.....ffid=67608

2. file: kriv Internet adress: 89.188.16.57/clvraff/kriv.dll?uid=91E28A8AF.....;rid=vm_bm


cookie: zoran@89.188.16.22





neznam da li ce to pomoci ista.....

offline
  • DEMIAN  Male
  • Legendarni građanin
  • IT Manager
  • Pridružio: 25 Mar 2005
  • Poruke: 3706
  • Gde živiš: The darkest place on earth..

Pomoći će koliko je to realno moguće posle te tvoje intrvencije ako detaljno pratiš uputstva koja ti budem napisao.

1.) Preuzmi program ATF Cleaner i sačuvaj ga na Desktop.

Štikliraj Select All i nakon toga klikni na Empty Selected.
Kada se pojavi poruka Done Cleaning zatvori program.

2.) Pokreni HijackThis i idi na opciju "Do a system scan only". Štikliraj i obriši sledeće linije:

O4 - HKLM\..\Run: [BM1b276e35] Rundll32.exe "C:\WINDOWS\system32\tfdatbho.dll",s
O4 - HKLM\..\Run: [18145da9] rundll32.exe "C:\WINDOWS\system32\mbnghhei.dll",b

3.) Zatim skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 21 Apr 2008
  • Poruke: 102
  • Gde živiš: Maklosevac, Nasice, Hrvatska

ComboFix 08-04-20.5 - Zoran 2008-04-22 7:46:04.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.139 [GMT 2:00]
Running from: C:\Documents and Settings\Zoran.ZRDESING\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\bcukiilr.dll
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\efhurkjr.dll
C:\WINDOWS\system32\hgghgff.dll
C:\WINDOWS\system32\iehhgnbm.ini
C:\WINDOWS\system32\iifddba.dll
C:\WINDOWS\system32\kbpqtvhs.ini
C:\WINDOWS\system32\kublassq.dll
C:\WINDOWS\system32\lxxfcsnn.dll
C:\WINDOWS\system32\mbnghhei.dll
C:\WINDOWS\system32\nfcskpbl.dll
C:\WINDOWS\system32\ngqsumkb.dll
C:\WINDOWS\system32\nnnkhfe.dll
C:\WINDOWS\system32\ofrhcveh.dll
C:\WINDOWS\system32\qssalbuk.ini
C:\WINDOWS\system32\shvtqpbk.dll
C:\WINDOWS\system32\tfdatbho.dll
C:\WINDOWS\system32\uxyay.ini
C:\WINDOWS\system32\uxyay.ini2
C:\WINDOWS\system32\vmahraec.dll
C:\WINDOWS\system32\vqjryokm.dll
C:\WINDOWS\system32\vvbkqlen.dll
C:\WINDOWS\system32\vyeikgvf.dll
C:\WINDOWS\system32\xdnatblv.dll
C:\WINDOWS\system32\yayxu.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_6TO4
-------\Service_6to4
-------\Service_NwSapAgent


((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.

2008-04-17 22:44 . 2008-04-17 22:44 287 --a------ C:\WINDOWS\game.ini
2008-04-17 22:31 . 2008-04-17 22:31 <DIR> d-------- C:\Program Files\Activision
2008-04-17 02:00 . 2008-04-17 18:03 <DIR> d-------- C:\VundoFix Backups
2008-04-15 18:29 . 2008-04-15 18:29 0 --a------ C:\WINDOWS\BM1b276e35.xml
2008-04-12 00:21 . 2008-04-17 01:40 1,812,287 --ahs---- C:\WINDOWS\system32\ncweiiwt.ini
2008-04-11 01:39 . 2008-04-13 13:25 <DIR> d-------- C:\Program Files\Mah Jong Quest
2008-04-11 01:32 . 2008-04-11 01:38 <DIR> d-------- C:\Program Files\Mahjong Mania Deluxe
2008-04-10 23:20 . 2008-04-12 00:19 1,563,278 --ahs---- C:\WINDOWS\system32\dxrwjjhk.ini
2008-04-09 23:18 . 2008-04-10 23:20 1,562,978 --ahs---- C:\WINDOWS\system32\qrxunfrj.ini
2008-04-09 22:16 . 2008-04-09 22:19 2,186,003 --ahs---- C:\WINDOWS\system32\ywhxsvvn.ini
2008-03-29 02:38 . 2008-04-09 22:07 1,584,669 --ahs---- C:\WINDOWS\system32\awkkweyt.ini
2008-03-28 02:16 . 2008-03-29 02:32 1,583,349 --ahs---- C:\WINDOWS\system32\mamgnuhn.ini
2008-03-28 00:16 . 2008-03-28 00:16 <DIR> d-------- C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Application Data\Xfire
2008-03-26 21:19 . 2008-04-18 16:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-26 21:19 . 2008-03-26 21:19 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-24 00:13 . 2008-04-11 01:30 <DIR> d-------- C:\Program Files\Jigsaw365
2008-03-23 23:37 . 2008-03-23 23:37 <DIR> d-------- C:\Program Files\Dropheads
2008-03-23 23:30 . 2008-03-23 23:33 <DIR> d-------- C:\Program Files\Bricks of Egypt
2008-03-22 23:13 . 2008-03-22 23:13 <DIR> d-------- C:\Program Files\LabPacks
2008-03-22 21:17 . 2004-01-29 02:49 10,240 --a------ C:\WINDOWS\system32\forcelibrary.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 00:22 --------- d-----w C:\Program Files\Trend Micro
2008-04-14 17:45 --------- d-----w C:\Program Files\ATI Technologies
2008-04-12 12:57 --------- d-----w C:\Program Files\Anti-Blaxx
2008-04-10 23:39 --------- d-----w C:\Program Files\Mah Jong Medley
2008-04-01 10:10 --------- d-----w C:\Program Files\Winamp
2008-03-29 19:51 --------- d-----w C:\Program Files\5 Spots II
2008-03-24 11:48 --------- d-----w C:\Program Files\Magic Inlay
2008-03-17 00:43 --------- d-----w C:\Program Files\Cheatbook Database 2008
2008-03-11 22:15 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-03-10 23:43 --------- d-----w C:\Program Files\Blox World
2008-03-10 20:16 --------- d-----w C:\Program Files\Ice Breaker
2008-03-10 19:42 --------- d-----w C:\Program Files\Zzed
2008-03-10 15:14 --------- d-----w C:\Program Files\Wonderland Secret Worlds
2008-03-06 23:11 --------- d-----w C:\Program Files\Carls Classics
2008-03-06 20:08 --------- d-----w C:\Program Files\Dark Archon
2008-03-06 20:04 --------- d-----w C:\Program Files\Brixout XP
2008-03-06 20:03 --------- d-----w C:\Program Files\Break Quest
2008-03-06 14:33 --------- d-----w C:\Program Files\Slingo
2008-03-06 14:33 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\funkitron
2008-03-06 14:06 --------- d-----w C:\Program Files\Rocket Bowl
2008-03-06 14:06 --------- d-----w C:\Program Files\Reaktor
2008-03-04 18:44 --------- d-----w C:\Program Files\Wonderland
2008-03-04 17:18 --------- d-----w C:\Program Files\Deep Sea Adventures
2008-03-04 17:14 --------- d-----w C:\Program Files\Chicken Village
2008-03-04 16:36 --------- d-----w C:\Program Files\Garfield Goes to Pieces
2008-03-04 16:33 --------- d-----w C:\Program Files\Slyder Adventures
2008-03-04 16:17 --------- d-----w C:\Program Files\Pulsarius
2008-03-04 16:14 --------- d-----w C:\Program Files\Gold Miner
2008-03-03 23:58 --------- d-----w C:\Program Files\Pirates of Treasure Island
2008-03-03 23:35 --------- d-----w C:\Program Files\Aquacade
2008-03-02 15:18 --------- d-----w C:\Program Files\Bubblefish Bob
2008-03-01 18:34 --------- d-----w C:\Program Files\Secret Chamber
2008-03-01 18:31 --------- d-----w C:\Program Files\River Raider II
2008-03-01 18:18 --------- d-----w C:\Program Files\Ricochet Xtreme
2008-03-01 17:09 --------- d-----w C:\Program Files\Troll
2008-03-01 15:34 --------- d-----w C:\Program Files\Platypus
2008-03-01 15:28 --------- d-----w C:\Program Files\MadCaps
2008-03-01 15:26 --------- d-----w C:\Program Files\Dr Blobs Organism
2008-03-01 15:06 --------- d-----w C:\Program Files\Chicken Invaders
2008-03-01 14:53 --------- d-----w C:\Program Files\Alpha Ball
2008-03-01 14:52 --------- d-----w C:\Program Files\Alien Sky
2008-02-29 15:01 --------- d-----w C:\Program Files\Air Strike II Gulf Thunder
2008-02-29 14:39 156,312 ----a-w C:\WINDOWS\Ahriman's Prophecy Uninstaller.exe
2008-02-29 14:39 --------- d-----w C:\Program Files\Ahriman's Prophecy
2008-02-29 14:38 --------- d-----w C:\Program Files\Add Em Up
2008-02-29 14:19 --------- d-----w C:\Program Files\Absolute Blue
2008-02-28 19:34 --------- d-----w C:\Program Files\Xeno Assault II
2008-02-27 22:30 --------- d-----w C:\Program Files\Soda Pipes
2008-02-27 22:24 --------- d-----w C:\Program Files\Moleculous
2008-02-27 22:03 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\PlayFirst
2008-02-27 22:03 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\Mind Control Software
2008-02-27 21:25 --------- d-----w C:\Program Files\Feed The Snake
2007-12-23 18:21 19,936 ----a-w C:\Documents and Settings\Zoran.ZRDESING\Application Data\GDIPFONTCACHEV1.DAT
2003-12-31 22:43 24,192 -c--a-w C:\Documents and Settings\Zoran\usbsermptxp.sys
2003-12-31 22:43 22,768 -c--a-w C:\Documents and Settings\Zoran\usbsermpt.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2000-09-28 13:11 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe" [2005-11-25 21:51 819262]
"SoundMan"="SOUNDMAN.EXE" [2003-06-11 04:12 55296 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 21:10 339968]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2002-12-31 14:00 15360]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-05-01 09:06:50 389120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnkhfe]
nnnkhfe.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.lameacm"= lameACM.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\Bela\\bela.exe"=
"\\\\RAJIC-510981905\\E\\Program Files\\EA GAMES\\Need For Speed Underground\\Speed.exe"=
"C:\\Program Files\\Mad Cars\\madcars.exe"=
"E:\\Program Files\\Croteam\\Serious Sam\\Bin\\SeriousSam.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"E:\\Program Files\\Electronic Arts\\Need for Speed Carbon\\NFSC.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"25600:TCP"= 25600:TCP:class

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2000-06-06 14:51]
R2 AVMPORT;AVMPORT;C:\WINDOWS\system32\drivers\avmport.sys [2000-11-14 00:00]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2000-09-13 17:18]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08441a40-7cbd-11dc-a6ba-0050fcb68b49}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fc93c61-f461-11dc-afd4-0050fcb68b49}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a19cb2-7c0e-11dc-bb2c-0050fcb68b49}]
\Shell\AutoRun\command - H:\Autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{667ead60-802d-11dc-a6c9-0050fcb68b49}]
\Shell\AutoRun\command - G:\setupSNK.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f2c9150-c845-11dc-af39-0050fcb68b49}]
\Shell\AutoRun\command - G:\setupSNK.exe

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-04-22 07:52:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
C:\Program Files\Netropa\Onscreen Display\osd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-04-22 7:56:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-22 05:56:29

Pre-Run: 5,774,286,848 bytes free
Post-Run: 5,701,738,496 bytes free

229 --- E O F --- 2008-03-22 15:17:43

Dopuna: 22 Apr 2008 8:18

jos bih htjeo dodati da, dok mi je ComboFix scanirao komp, TM PC-cillin je u medjuvremenu izbacio Window da je nadjen novi virus u mapi Temp..... Eicar_test_file...... *.*\Temp\Av-test.txt ........ Ako je od ikakve pomoci.....

offline
  • DEMIAN  Male
  • Legendarni građanin
  • IT Manager
  • Pridružio: 25 Mar 2005
  • Poruke: 3706
  • Gde živiš: The darkest place on earth..

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\WINDOWS\BM1b276e35.xml
C:\WINDOWS\system32\ncweiiwt.ini
C:\WINDOWS\system32\dxrwjjhk.ini
C:\WINDOWS\system32\qrxunfrj.ini
C:\WINDOWS\system32\ywhxsvvn.ini
C:\WINDOWS\system32\awkkweyt.ini
C:\WINDOWS\system32\mamgnuhn.ini
C:\WINDOWS\system32\killVBS.vbs

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnkhfe]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{08441a40-7cbd-11dc-a6ba-0050fcb68b49}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1fc93c61-f461-11dc-afd4-0050fcb68b49}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31a19cb2-7c0e-11dc-bb2c-0050fcb68b49}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{667ead60-802d-11dc-a6c9-0050fcb68b49}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6f2c9150-c845-11dc-af39-0050fcb68b49}]



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja

offline
  • Pridružio: 21 Apr 2008
  • Poruke: 102
  • Gde živiš: Maklosevac, Nasice, Hrvatska

ComboFix 08-04-20.5 - Zoran 2008-04-23 11:33:35.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.140 [GMT 2:00]
Running from: C:\Documents and Settings\Zoran.ZRDESING\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Zoran.ZRDESING\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\BM1b276e35.xml
C:\WINDOWS\system32\awkkweyt.ini
C:\WINDOWS\system32\dxrwjjhk.ini
C:\WINDOWS\system32\killVBS.vbs
C:\WINDOWS\system32\mamgnuhn.ini
C:\WINDOWS\system32\ncweiiwt.ini
C:\WINDOWS\system32\qrxunfrj.ini
C:\WINDOWS\system32\ywhxsvvn.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\BM1b276e35.xml
C:\WINDOWS\IIEsv44JBS5X.dll
C:\WINDOWS\IIEsv44JBS5X2.dll
C:\WINDOWS\system32\awkkweyt.ini
C:\WINDOWS\system32\dxrwjjhk.ini
C:\WINDOWS\system32\mamgnuhn.ini
C:\WINDOWS\system32\ncweiiwt.ini
C:\WINDOWS\system32\qrxunfrj.ini
C:\WINDOWS\system32\ywhxsvvn.ini
C:\WINDOWS\XMMR810eno.dll

.
((((((((((((((((((((((((( Files Created from 2008-03-23 to 2008-04-23 )))))))))))))))))))))))))))))))
.

2008-04-22 11:23 . 2008-04-22 11:23 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-22 11:23 . 2008-04-22 11:24 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-04-22 11:22 . 2008-04-22 11:22 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-17 22:44 . 2008-04-17 22:44 287 --a------ C:\WINDOWS\game.ini
2008-04-17 22:31 . 2008-04-17 22:31 <DIR> d-------- C:\Program Files\Activision
2008-04-11 01:39 . 2008-04-22 17:21 <DIR> d-------- C:\Program Files\Mah Jong Quest
2008-04-11 01:32 . 2008-04-11 01:38 <DIR> d-------- C:\Program Files\Mahjong Mania Deluxe
2008-03-28 00:16 . 2008-03-28 00:16 <DIR> d-------- C:\Documents and Settings\NetworkService.NT AUTHORITY.000\Application Data\Xfire
2008-03-26 21:19 . 2008-04-18 16:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-26 21:19 . 2008-03-26 21:19 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-24 00:13 . 2008-04-11 01:30 <DIR> d-------- C:\Program Files\Jigsaw365
2008-03-23 23:37 . 2008-03-23 23:37 <DIR> d-------- C:\Program Files\Dropheads
2008-03-23 23:30 . 2008-03-23 23:33 <DIR> d-------- C:\Program Files\Bricks of Egypt

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-17 21:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-17 00:22 --------- d-----w C:\Program Files\Trend Micro
2008-04-14 17:45 --------- d-----w C:\Program Files\ATI Technologies
2008-04-12 12:57 --------- d-----w C:\Program Files\Anti-Blaxx
2008-04-10 23:39 --------- d-----w C:\Program Files\Mah Jong Medley
2008-04-01 10:10 --------- d-----w C:\Program Files\Winamp
2008-03-29 19:51 --------- d-----w C:\Program Files\5 Spots II
2008-03-24 11:48 --------- d-----w C:\Program Files\Magic Inlay
2008-03-22 21:13 --------- d-----w C:\Program Files\LabPacks
2008-03-17 00:43 --------- d-----w C:\Program Files\Cheatbook Database 2008
2008-03-11 22:15 --------- d-----w C:\Program Files\Common Files\EasyInfo
2008-03-10 23:43 --------- d-----w C:\Program Files\Blox World
2008-03-10 20:16 --------- d-----w C:\Program Files\Ice Breaker
2008-03-10 19:42 --------- d-----w C:\Program Files\Zzed
2008-03-10 15:14 --------- d-----w C:\Program Files\Wonderland Secret Worlds
2008-03-06 23:11 --------- d-----w C:\Program Files\Carls Classics
2008-03-06 20:08 --------- d-----w C:\Program Files\Dark Archon
2008-03-06 20:04 --------- d-----w C:\Program Files\Brixout XP
2008-03-06 20:03 --------- d-----w C:\Program Files\Break Quest
2008-03-06 14:33 --------- d-----w C:\Program Files\Slingo
2008-03-06 14:33 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\funkitron
2008-03-06 14:06 --------- d-----w C:\Program Files\Rocket Bowl
2008-03-06 14:06 --------- d-----w C:\Program Files\Reaktor
2008-03-04 18:44 --------- d-----w C:\Program Files\Wonderland
2008-03-04 17:18 --------- d-----w C:\Program Files\Deep Sea Adventures
2008-03-04 17:14 --------- d-----w C:\Program Files\Chicken Village
2008-03-04 16:36 --------- d-----w C:\Program Files\Garfield Goes to Pieces
2008-03-04 16:33 --------- d-----w C:\Program Files\Slyder Adventures
2008-03-04 16:17 --------- d-----w C:\Program Files\Pulsarius
2008-03-04 16:14 --------- d-----w C:\Program Files\Gold Miner
2008-03-03 23:58 --------- d-----w C:\Program Files\Pirates of Treasure Island
2008-03-03 23:35 --------- d-----w C:\Program Files\Aquacade
2008-03-02 15:18 --------- d-----w C:\Program Files\Bubblefish Bob
2008-03-01 18:34 --------- d-----w C:\Program Files\Secret Chamber
2008-03-01 18:31 --------- d-----w C:\Program Files\River Raider II
2008-03-01 18:18 --------- d-----w C:\Program Files\Ricochet Xtreme
2008-03-01 17:09 --------- d-----w C:\Program Files\Troll
2008-03-01 15:34 --------- d-----w C:\Program Files\Platypus
2008-03-01 15:28 --------- d-----w C:\Program Files\MadCaps
2008-03-01 15:26 --------- d-----w C:\Program Files\Dr Blobs Organism
2008-03-01 15:06 --------- d-----w C:\Program Files\Chicken Invaders
2008-03-01 14:53 --------- d-----w C:\Program Files\Alpha Ball
2008-03-01 14:52 --------- d-----w C:\Program Files\Alien Sky
2008-02-29 15:01 --------- d-----w C:\Program Files\Air Strike II Gulf Thunder
2008-02-29 14:39 156,312 ----a-w C:\WINDOWS\Ahriman's Prophecy Uninstaller.exe
2008-02-29 14:39 --------- d-----w C:\Program Files\Ahriman's Prophecy
2008-02-29 14:38 --------- d-----w C:\Program Files\Add Em Up
2008-02-29 14:19 --------- d-----w C:\Program Files\Absolute Blue
2008-02-28 19:34 --------- d-----w C:\Program Files\Xeno Assault II
2008-02-27 22:30 --------- d-----w C:\Program Files\Soda Pipes
2008-02-27 22:24 --------- d-----w C:\Program Files\Moleculous
2008-02-27 22:03 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\PlayFirst
2008-02-27 22:03 --------- d-----w C:\Documents and Settings\Zoran.ZRDESING\Application Data\Mind Control Software
2008-02-27 21:25 --------- d-----w C:\Program Files\Feed The Snake
2007-12-23 18:21 19,936 ----a-w C:\Documents and Settings\Zoran.ZRDESING\Application Data\GDIPFONTCACHEV1.DAT
2003-12-31 22:43 24,192 -c--a-w C:\Documents and Settings\Zoran\usbsermptxp.sys
2003-12-31 22:43 22,768 -c--a-w C:\Documents and Settings\Zoran\usbsermpt.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 14:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MULTIMEDIA KEYBOARD"="C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe" [2000-09-28 13:11 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2005\pccguide.exe" [2005-11-25 21:51 819262]
"SoundMan"="SOUNDMAN.EXE" [2003-06-11 04:12 55296 C:\WINDOWS\SOUNDMAN.EXE]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 21:10 339968]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2002-12-31 14:00 15360]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 11:01:04 83360]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-05-01 09:06:50 389120]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i263_32.drv
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.lameacm"= lameACM.acm
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\Bela\\bela.exe"=
"\\\\RAJIC-510981905\\E\\Program Files\\EA GAMES\\Need For Speed Underground\\Speed.exe"=
"C:\\Program Files\\Mad Cars\\madcars.exe"=
"E:\\Program Files\\Croteam\\Serious Sam\\Bin\\SeriousSam.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"E:\\Program Files\\Electronic Arts\\Need for Speed Carbon\\NFSC.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"25600:TCP"= 25600:TCP:class

R1 msikbd2k;Multimedia Keyboard Filter Driver;C:\WINDOWS\system32\DRIVERS\msikbd2k.sys [2000-06-06 14:51]
R2 AVMPORT;AVMPORT;C:\WINDOWS\system32\drivers\avmport.sys [2000-11-14 00:00]
R2 nhksrv;Netropa NHK Server;C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe [2000-09-13 17:18]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-04-23 11:36:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\snmp.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Netropa\Multimedia Keyboard\Traymon.exe
C:\Program Files\Netropa\Onscreen Display\osd.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
.
**************************************************************************
.
Completion time: 2008-04-23 11:39:36 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-23 09:39:33
ComboFix2.txt 2008-04-22 05:56:34

Pre-Run: 6,977,724,416 bytes free
Post-Run: 6,927,269,888 bytes free

198 --- E O F --- 2008-03-22 15:17:43

Dopuna: 23 Apr 2008 11:49

Jos mi nesto nije jasno..... svaki put kada ComboFix zavrsavao rad..... PC-cillin mi je izbacio da je nasao novi threat..... Ime file-a: Av-test.txt

offline
  • DEMIAN  Male
  • Legendarni građanin
  • IT Manager
  • Pridružio: 25 Mar 2005
  • Poruke: 3706
  • Gde živiš: The darkest place on earth..

Eicar test file nije virus a ni pretnja. Možeš da ga brišeš slobodno. Verovatno su ga implementirali u ComboFix radi provere AV. Neke vrste malware-a mogu lako i efikasno da disejbluju sve poznate AV i AS programe.

Reci mi ima li napredka nekog posle ovoga što smo uradili? Vidim da pišeš sa Firefox-a..

offline
  • Pridružio: 21 Apr 2008
  • Poruke: 102
  • Gde živiš: Maklosevac, Nasice, Hrvatska

Da. Napokon je sve proradilo i komp mi je poceo brze raditi. Internet veza se poboljsala. Hvala puno na pomoci.

Ko je trenutno na forumu
 

Ukupno su 733 korisnika na forumu :: 6 registrovanih, 0 sakrivenih i 727 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: goxin, Koridor, Miškić, opt1, vobo, yrraf