Imam virusa, spyware. Komp se ledi

1

Imam virusa, spyware. Komp se ledi

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Reinstalirao sam sistem prije par dana, i neki dan ostavio sam komp da skidam nesto i otisao u skolu, kad sam se vratio komp je bio zarazen. Niko nije koristio komp tada. Na desktopu mi se promjenio wall na njemu pise da imam spyware.
evo loga:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:22 AM, on 3/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608-)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\sbwltbxa.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\DOCUME~1\Bojan\LOCALS~1\Temp\IMAdvertiser.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sbwltbxa.exe,
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {13197ace-6851-45c3-a7ff-c281324d5489} - (no file)
O2 - BHO: (no name) - {15651c7c-e812-44a2-a9ac-b467a2233e7d} - (no file)
O2 - BHO: (no name) - {4e1075f4-eec4-4a86-add7-cd5f52858c31} - (no file)
O2 - BHO: (no name) - {4e7bd74f-2b8d-469e-92c6-ce7eb590a94d} - (no file)
O2 - BHO: (no name) - {5929cd6e-2062-44a4-b2c5-2c7e78fbab38} - (no file)
O2 - BHO: (no name) - {5dafd089-24b1-4c5e-bd42-8ca72550717b} - (no file)
O2 - BHO: (no name) - {5fa6752a-c4a0-4222-88c2-928ae5ab4966} - (no file)
O2 - BHO: (no name) - {622cc208-b014-4fe0-801b-874a5e5e403a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8674aea0-9d3d-11d9-99dc-00600f9a01f1} - (no file)
O2 - BHO: (no name) - {965a592f-8efa-4250-8630-7960230792f1} - (no file)
O2 - BHO: (no name) - {9c5b2f29-1f46-4639-a6b4-828942301d3e} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765728274} - (no file)
O2 - BHO: (no name) - {fc3a74e5-f281-4f10-ae1e-733078684f3c} - (no file)
O2 - BHO: (no name) - {ffff0001-0002-101a-a3c9-08002b2f49fb} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IMprocess] C:\DOCUME~1\Bojan\LOCALS~1\Temp\IMAdvertiser.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 7603 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Zdravo,

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ovako je izgledao wall, a poslije skeniranja sa ComboFix je nestao.

Evo log:

ComboFix 08-03-27.3 - Bojan 2008-03-29 11:47:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.454 [GMT 1:00]
Running from: C:\Documents and Settings\Bojan\My Documents\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\seekmo
C:\Program Files\seekmo\seekmohook.dll
C:\WINDOWS\180ax.exe
C:\WINDOWS\2020search.dll
C:\WINDOWS\2020search2.dll
C:\WINDOWS\bjam.dll
C:\WINDOWS\bokja.exe
C:\WINDOWS\cdsm32.dll
C:\WINDOWS\default.htm
C:\WINDOWS\mspphe.dll
C:\WINDOWS\mssvr.exe
C:\WINDOWS\saiemod.dll
C:\WINDOWS\salm.exe
C:\WINDOWS\stcloader.exe
C:\WINDOWS\swin32.dll
C:\WINDOWS\system32\msixu.dll
C:\WINDOWS\system32\wer8274.dll
C:\WINDOWS\system32\winfrun32.bin
C:\WINDOWS\TEMP\salm.exe
C:\WINDOWS\updatetc.exe
C:\WINDOWS\voiceip.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_npf


((((((((((((((((((((((((( Files Created from 2008-02-28 to 2008-03-29 )))))))))))))))))))))))))))))))
.

2008-03-29 11:51 . 2008-03-29 11:54 <DIR> d-------- C:\Program Files\seekmo
2008-03-29 11:07 . 2008-03-29 11:07 <DIR> d-------- C:\VundoFix Backups
2008-03-29 11:04 . 2008-03-29 11:04 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-28 15:27 . 2008-03-28 15:27 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-03-28 06:56 . 2008-03-28 06:56 <DIR> d-------- C:\Program Files\180searchassistant
2008-03-28 06:56 . 2008-03-28 06:56 <DIR> d-------- C:\Program Files\180search assistant
2008-03-27 16:38 . 2008-03-27 16:38 <DIR> d-------- C:\Program Files\180solutions
2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Program Files\Web Page Maker V2
2008-03-27 16:25 . 2008-03-27 16:25 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Web Page Maker V2
2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-27 16:24 . 2008-03-27 16:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-27 16:23 . 2008-03-27 16:23 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-26 23:27 . 2008-03-26 23:27 376 --a------ C:\WINDOWS\ODBC.INI
2008-03-26 23:26 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-03-26 23:25 . 2008-03-26 23:25 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-03-26 23:25 . 2008-03-26 23:25 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-03-26 23:22 . 2008-03-26 23:22 <DIR> dr-h----- C:\MSOCache
2008-03-26 15:33 . 2008-03-26 15:33 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\IM-Names
2008-03-26 11:40 . 2008-03-26 11:40 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Grisoft
2008-03-26 11:40 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-26 11:34 . 2008-03-26 11:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Rabio
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\zango
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\Sysmnt
2008-03-26 07:14 . 2008-03-26 07:14 <DIR> d-------- C:\Program Files\stc
2008-03-26 07:01 . 2008-03-26 07:01 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Syntrillium
2008-03-26 06:59 . 2008-03-26 06:59 90,537 --a------ C:\WINDOWS\system32\sbwltbxa.exe
2008-03-23 23:38 . 2008-03-23 23:38 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-03-23 23:38 . 2008-03-23 23:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-03-23 23:37 . 2008-03-23 23:40 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-03-23 23:29 . 2008-03-28 16:17 482 --a------ C:\WINDOWS\wcx_ftp.ini
2008-03-23 22:53 . 2008-03-28 23:55 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-23 22:51 . 2008-03-23 22:51 <DIR> d-------- C:\Program Files\Common Files\LightScribe
2008-03-23 22:49 . 2008-03-23 22:54 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Ahead
2008-03-23 22:43 . 2008-03-23 22:43 <DIR> d-------- C:\Program Files\Nero
2008-03-23 22:43 . 2008-03-23 22:50 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-03-23 22:43 . 2008-03-23 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-03-22 17:17 . 2008-03-22 17:17 <DIR> d-------- C:\WINDOWS\system32\QuickTime
2008-03-22 15:55 . 2008-03-22 17:17 <DIR> d-------- C:\Program Files\Macromedia
2008-03-22 15:55 . 2008-03-22 16:41 <DIR> d-------- C:\Program Files\Common Files\Macromedia
2008-03-22 15:54 . 2008-03-22 17:15 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-03-22 15:52 . 2008-03-22 15:52 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Media Player Classic
2008-03-22 15:44 . 2008-03-22 15:44 <DIR> d--h----- C:\WINDOWS\PIF
2008-03-22 12:18 . 2008-03-22 12:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-22 10:40 . 2007-12-07 03:21 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-22 10:40 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-22 10:40 . 2007-07-01 04:36 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-22 10:40 . 2007-12-07 03:21 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-22 10:40 . 2007-12-07 03:21 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-22 10:40 . 2007-12-07 03:21 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-22 10:40 . 2007-12-07 03:21 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-22 10:40 . 2007-12-07 03:21 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-22 10:40 . 2007-12-06 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-22 03:05 . 2004-09-01 09:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-03-21 18:05 . 2008-03-22 12:12 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-03-21 18:05 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-03-21 14:40 . 2008-03-21 14:40 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-21 14:40 . 2008-03-29 08:00 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\AVG7
2008-03-21 14:40 . 2008-03-21 14:40 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-03-21 14:39 . 2008-03-26 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-21 14:39 . 2008-03-21 14:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-21 14:30 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-03-21 14:30 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-03-21 13:29 . 2008-03-21 13:29 <DIR> d-------- C:\Program Files\uTorrent
2008-03-21 13:29 . 2008-03-29 10:56 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\uTorrent
2008-03-21 13:04 . 2008-03-21 13:04 12,736 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-03-20 22:42 . 2008-03-20 22:42 38 --a------ C:\WINDOWS\avisplitter.INI
2008-03-20 22:14 . 2008-03-20 22:32 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\vlc
2008-03-20 20:22 . 2008-03-28 17:19 2,535 --a------ C:\WINDOWS\WINCMD.INI
2008-03-20 20:20 . 2008-03-20 20:22 <DIR> d-------- C:\Program Files\TotalCmd
2008-03-20 20:20 . 2008-03-28 21:07 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\skypePM
2008-03-20 20:20 . 2008-03-20 20:20 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-03-20 20:19 . 2008-03-28 21:12 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Skype
2008-03-20 20:18 . 2008-03-20 20:19 <DIR> d-------- C:\Program Files\Skype
2008-03-20 20:18 . 2008-03-20 20:18 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-03-20 20:18 . 2008-03-20 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-03-20 20:13 . 2008-03-20 20:13 <DIR> d-------- C:\Program Files\Notepad++
2008-03-20 20:13 . 2008-03-20 22:41 <DIR> d-------- C:\Program Files\Mv2Player
2008-03-20 20:13 . 2008-03-21 13:04 <DIR> d-------- C:\Program Files\mIRC
2008-03-20 20:13 . 2008-03-24 00:05 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\Notepad++
2008-03-20 20:13 . 2008-03-21 13:07 <DIR> d-------- C:\Documents and Settings\Bojan\Application Data\mIRC
2008-03-20 19:59 . 2008-03-20 19:59 304 --ah----- C:\sqmdata03.sqm
2008-03-20 19:59 . 2008-03-20 19:59 244 --ah----- C:\sqmnoopt03.sqm
2008-03-20 19:57 . 2008-03-20 19:57 268 --ah----- C:\sqmdata02.sqm
2008-03-20 19:57 . 2008-03-20 19:57 244 --ah----- C:\sqmnoopt02.sqm
2008-03-20 19:29 . 2008-03-20 19:29 268 --ah----- C:\sqmdata01.sqm
2008-03-20 19:29 . 2008-03-20 19:29 244 --ah----- C:\sqmnoopt01.sqm
2008-03-20 18:46 . 2008-03-20 18:46 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-03-20 18:46 . 2008-03-20 18:46 <DIR> d-------- C:\Program Files\MSN Messenger
2008-03-20 18:46 . 2008-03-26 21:44 <DIR> d-------- C:\Documents and Settings\Bojan\Contacts
2008-03-20 18:46 . 2008-03-20 18:46 268 --ah----- C:\sqmdata00.sqm
2008-03-20 18:46 . 2008-03-20 18:46 244 --ah----- C:\sqmnoopt00.sqm
2008-03-20 18:01 . 2008-03-20 18:01 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-03-20 18:01 . 2003-06-27 14:11 491,520 --a------ C:\WINDOWS\Au51Fun.exe
2008-03-20 18:01 . 2000-05-18 14:43 108,978 --a------ C:\WINDOWS\TTTest.wav
2008-03-20 16:46 . 2008-03-20 16:46 16 --a------ C:\WINDOWS\wininit.ini
2008-03-20 16:44 . 2008-03-20 16:44 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-20 16:44 . 2008-03-20 16:44 <DIR> d-------- C:\Program Files\CCleaner
2008-03-20 16:09 . 2006-06-14 09:47 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-03-20 16:09 . 2006-06-14 09:47 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-03-20 16:07 . 2000-10-20 18:28 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-26 06:14 8,960 ----a-w C:\WINDOWS\shdocpl.dll
2008-03-22 14:54 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-20 14:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-20 14:31 --------- d-----w C:\Program Files\Opera
2008-03-20 14:31 --------- d-----w C:\Program Files\Foxit Software
2008-03-20 14:31 --------- d-----w C:\Program Files\Ares
2008-03-20 14:30 --------- d-----w C:\Program Files\Winamp
2008-03-20 14:30 --------- d-----w C:\Program Files\VideoLAN
2008-03-20 14:30 --------- d-----w C:\Documents and Settings\Bojan\Application Data\Winamp
2008-03-20 14:28 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-03-20 14:27 --------- d-----w C:\Program Files\Java
2008-03-20 14:27 --------- d-----w C:\Program Files\Common Files\Java
2008-03-20 14:19 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2007-07-16 22:54 961536]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-01 09:00 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04 139264]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 16:50 4620288]
"nwiz"="nwiz.exe" [2004-10-29 16:50 921600 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 16:50 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-21 14:39 411648]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40 155648]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-21 14:39 145920]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-29 11:54:34
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-03-29 11:58:19 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-29 10:58:15
Pre-Run: 16,304,640,000 bytes free
Post-Run: 16,249,679,872 bytes free
.
2008-03-27 15:48:32 --- E O F ---

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Vidim da si koristio i Vundo Fix,mozes li log da postavis,da vidimo da li je on nesto uklonio?

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

On nije nista nasao...

Dopuna: 29 Mar 2008 12:17

A sta je ovo za recovery console? Jel moram imati instaliranu? I ako da, kako se instalira?

Dopuna: 29 Mar 2008 12:18

Sad mi komp ok radi. Jel bi trebao provjeriti jos nesto? Ili sam cist? =)

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Nismo jos zavrsili. U toku dana cu ti napisati skriptu koja ce da ukloni ostatak.

kuckamo se kasnije... :-D

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ok, hvala puno! Do javljanja...

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Skini Ewido micro (8Mb) :
http://downloads.ewido.net/ewido_micro.exe

Kako se radi sa Ewido micro:
- na prvom ekranu odaberi sve particije (štikliraj polja ispred njih)
- klikni na dugme Start Scan
- nakon završenog skeniranja klikni na Save Report i snimi log fajl na sigurno mesto
- klikni na Remove Infections
- iskopiraj nam ovde sadržaj log fajla koji je malopre snimljen

Nakon skeniranja sa Ewidom i postavljanja log fajla, postavi nam i svez log programa HijackThis.

offline
  • Gad  Male
  • Počasni građanin
  • Pridružio: 19 Maj 2005
  • Poruke: 932

Ewido nije nista nasao, kaze nema infekcija... A evo log za hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:58:08 PM, on 3/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608-)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6166 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ajmo jos jednom CF:


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

Ko je trenutno na forumu
 

Ukupno su 939 korisnika na forumu :: 43 registrovanih, 4 sakrivenih i 892 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 9k38, A.R.Chafee.Jr., AC-DC, aramis s, babaroga, bojcistv, Bokiboks, Boris90, cavatina, CikaKURE, doktor123, dragoljub11987, flash12, FOX, Georgius, Goran 0000, goxin, hawkeye, Karla, kihot, kolle.the.kid, Kubovac, Marko Marković, mercedesamg, Mercury, milenko crazy north, milutin134, moldway, muaddib, Oscar, Parker, Petarvu, procesor, saputnik plavetnila, sasa87, Srle993, stegonosa, Stoilkovic, vathra, Vatreni Zmaj, voja64, VP6919, žeks62