Izvjestaj

Izvjestaj

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:49:08, on 30.11.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = daemon-search.com/default
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{98DE8D30-6EC2-4237-BAF0-1B18CC8F3B92}: NameServer = 195.29.149.196 195.29.149.197
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 4483 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Hvala na izvestaju. A sta ja sada treba sa njim da radim? Na sta se u stvari zalis?

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

A sorry,problem je u tom sto mi se ikone maknu svakih 5-6 sekundi i taskbar i sve,i tako par puta,a poslije toga mi se makne i ne pojavljuje se nista vise.Preko task manager pokrecem sve programe.Ovo mi je izvjestaj iz Hijack This pa sad...Sta da napravim?radio sam izvjestaj i u Malwerbytes anti i procitao da se radi o nekom trojan vundo...

Dopuna: 30 Nov 2008 14:27

ako bi mi mogao pomoci bio bih ti zahvalan,

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Probajmo sledece:

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

ComboFix 08-11-30.01 - User 2008-11-30 18:47:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1632 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\awtussPi.dll
c:\windows\Tasks\kdvaklby.job

----- BITS: Possible infected sites -----

hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.

2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\User\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 14:12 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-30 13:49 . 2008-11-30 13:49 <DIR> d-------- C:\New Folder
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-29 18:22 . 2008-11-29 18:22 268 --ah----- C:\sqmdata11.sqm
2008-11-29 18:22 . 2008-11-29 18:22 244 --ah----- C:\sqmnoopt11.sqm
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\program files\ESET
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-29 17:57 . 2008-11-29 17:57 <DIR> d-------- c:\documents and settings\Administrator
2008-11-29 17:45 . 2008-11-29 17:45 268 --ah----- C:\sqmdata10.sqm
2008-11-29 17:45 . 2008-11-29 17:45 244 --ah----- C:\sqmnoopt10.sqm
2008-11-29 17:32 . 2008-11-29 17:32 268 --ah----- C:\sqmdata09.sqm
2008-11-29 17:32 . 2008-11-29 17:32 244 --ah----- C:\sqmnoopt09.sqm
2008-11-29 17:21 . 2008-11-29 17:21 268 --ah----- C:\sqmdata08.sqm
2008-11-29 17:21 . 2008-11-29 17:21 244 --ah----- C:\sqmnoopt08.sqm
2008-11-29 17:20 . 2008-11-29 17:20 268 --ah----- C:\sqmdata07.sqm
2008-11-29 17:20 . 2008-11-29 17:20 244 --ah----- C:\sqmnoopt07.sqm
2008-11-29 16:34 . 2008-11-29 16:34 <DIR> d-------- c:\documents and settings\User\Application Data\Sports Interactive
2008-11-29 16:34 . 2008-11-29 17:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:28 <DIR> d--h----- c:\program files\Zero G Registry
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d-------- c:\program files\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d--h----- c:\documents and settings\User\InstallAnywhere
2008-11-29 14:39 . 2008-11-29 14:39 <DIR> d-------- c:\program files\Sony Setup
2008-11-15 20:13 . 2008-11-15 20:13 <DIR> dr-h----- c:\documents and settings\User\Application Data\SecuROM
2008-11-15 19:52 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-15 19:52 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-15 19:52 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-15 19:52 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-11-15 19:52 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-15 19:52 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-15 19:52 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-15 19:51 . 2008-11-15 19:51 <DIR> d-------- c:\windows\Logs
2008-11-15 19:51 . 2008-11-15 19:51 22,328 --a------ c:\documents and settings\User\Application Data\PnkBstrK.sys
2008-11-15 19:50 . 2008-11-15 19:50 2,250,024 --a------ c:\windows\system32\pbsvc.exe
2008-11-14 20:53 . 2008-11-29 12:10 <DIR> d-------- c:\program files\FlashGet
2008-11-14 19:50 . 2008-11-14 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\KONAMI
2008-11-14 19:47 . 2008-11-14 19:47 <DIR> d-------- c:\program files\KONAMI
2008-11-14 19:11 . 2008-11-14 19:11 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-11-14 18:51 . 2008-11-14 18:51 <DIR> d-------- c:\program files\PokerStars
2008-11-14 18:23 . 2008-11-14 18:23 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-14 17:58 . 2008-11-29 18:27 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-14 17:58 . 2008-11-14 17:58 <DIR> d-------- c:\documents and settings\User\Application Data\DAEMON Tools
2008-11-14 17:51 . 2008-11-14 17:51 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-03 15:35 . 2008-11-03 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Windows Live
2008-11-02 11:52 . 2008-11-02 13:03 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Circle Developement
2008-11-01 14:22 . 2008-11-02 13:03 <DIR> d-------- c:\program files\MSN Messenger
2008-11-01 14:09 . 2008-11-01 14:09 <DIR> d-------- c:\documents and settings\User\Tracing
2008-11-01 13:48 . 2008-11-01 13:48 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2008-11-01 13:45 . 2008-11-01 13:45 <DIR> d-------- c:\program files\Microsoft
2008-11-01 13:35 . 2008-11-01 13:35 <DIR> d-------- c:\program files\Common Files\Windows Live
2008-10-31 22:56 . 2008-10-31 22:56 <DIR> d-------- c:\documents and settings\User\Application Data\Samsung
2008-10-31 22:28 . 2003-02-21 18:42 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-10-31 22:28 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2008-10-31 22:27 . 2007-05-02 11:11 109,704 --a------ c:\windows\system32\drivers\ss_mdm.sys
2008-10-31 22:27 . 2007-05-02 11:11 83,592 --a------ c:\windows\system32\drivers\ss_bus.sys
2008-10-31 22:27 . 2007-05-02 11:11 15,112 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_whnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_wh.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cm.sys
2008-10-31 22:27 . 2008-10-31 22:52 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2008-10-31 19:24 . 2008-10-31 19:24 <DIR> d-------- c:\program files\YouTube Downloader
2008-10-31 17:43 . 2008-10-31 17:43 <DIR> d-------- c:\program files\Lavalys
2008-10-18 08:55 . 2008-10-18 08:56 <DIR> d-------- c:\program files\PhotomatixPro3
2008-10-18 08:54 . 2008-10-18 08:54 <DIR> d-------- c:\windows\system32\URTTemp
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\program files\iPod
2008-10-17 19:06 . 2008-11-29 16:15 <DIR> d-------- c:\documents and settings\User\Application Data\Apple Computer
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-17 19:06 . 2008-04-17 12:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-10-17 19:06 . 2008-04-17 12:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\program files\QuickTime
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-17 19:04 . 2008-10-17 19:05 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\program files\Apple Software Update
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 12:41 --------- d-----w c:\documents and settings\User\Application Data\DNA
2008-11-29 17:46 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-29 16:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 16:06 --------- d-----w c:\documents and settings\User\Application Data\BitTorrent
2008-11-29 11:05 --------- d-----w c:\documents and settings\User\Application Data\LimeWire
2008-11-15 18:51 22,328 -c--a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-15 18:50 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-15 18:50 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2008-11-14 16:37 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 10:54 --------- d-----w c:\program files\Winamp
2008-10-31 21:27 --------- d-----w c:\program files\Samsung
2008-10-18 19:58 --------- d-----w c:\program files\DNA
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 04:42 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 17:51 486856 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"ose"=3 (0x3)
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"d:\\Igrice\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [7/1/2008 9:04:40 AM 34312]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [7/25/2008 2:39:19 PM 1310720]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [10/2/2002 11:09:08 PM 31504]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [10/31/2008 10:27:55 PM 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [10/31/2008 10:27:55 PM 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [10/31/2008 10:27:55 PM 109704]
S4 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\MSN Messenger\usnsvc.exe" [1/19/2007 12:54:14 PM 97136]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cdb7121-a8ba-11dd-a4b6-001e8c67a2c5}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{AFAF8314-45C9-4EC5-9317-A9C24E01D0AC} - (no file)
ShellExecuteHooks-{AFAF8314-45C9-4EC5-9317-A9C24E01D0AC} - (no file)
Notify-jkkICUki - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w2kw3akq.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - d:\itunes\Mozilla Plugins\npitunes.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-30 18:49:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
.
**************************************************************************
.
Completion time: 2008-11-30 18:50:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-30 17:50:44

Pre-Run: 6.335.070.208 bytes free
Post-Run: 6,258,266,112 bytes free

211

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Otvoriti Notepad i iskopirati sledeci tekst:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cdb7121-a8ba-11dd-a4b6-001e8c67a2c5}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Kazi mi kako se sada ponasa racunar? Jesu li simptomi jos uvek prisutni?

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

ComboFix 08-11-30.01 - User 2008-11-30 19:32:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1643 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.

2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\User\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 14:12 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-30 13:49 . 2008-11-30 13:49 <DIR> d-------- C:\New Folder
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-29 18:22 . 2008-11-29 18:22 268 --ah----- C:\sqmdata11.sqm
2008-11-29 18:22 . 2008-11-29 18:22 244 --ah----- C:\sqmnoopt11.sqm
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\program files\ESET
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-29 17:57 . 2008-11-29 17:57 <DIR> d-------- c:\documents and settings\Administrator
2008-11-29 17:45 . 2008-11-29 17:45 268 --ah----- C:\sqmdata10.sqm
2008-11-29 17:45 . 2008-11-29 17:45 244 --ah----- C:\sqmnoopt10.sqm
2008-11-29 17:32 . 2008-11-29 17:32 268 --ah----- C:\sqmdata09.sqm
2008-11-29 17:32 . 2008-11-29 17:32 244 --ah----- C:\sqmnoopt09.sqm
2008-11-29 17:21 . 2008-11-29 17:21 268 --ah----- C:\sqmdata08.sqm
2008-11-29 17:21 . 2008-11-29 17:21 244 --ah----- C:\sqmnoopt08.sqm
2008-11-29 17:20 . 2008-11-29 17:20 268 --ah----- C:\sqmdata07.sqm
2008-11-29 17:20 . 2008-11-29 17:20 244 --ah----- C:\sqmnoopt07.sqm
2008-11-29 16:34 . 2008-11-29 16:34 <DIR> d-------- c:\documents and settings\User\Application Data\Sports Interactive
2008-11-29 16:34 . 2008-11-29 17:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:28 <DIR> d--h----- c:\program files\Zero G Registry
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d-------- c:\program files\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d--h----- c:\documents and settings\User\InstallAnywhere
2008-11-29 14:39 . 2008-11-29 14:39 <DIR> d-------- c:\program files\Sony Setup
2008-11-15 20:13 . 2008-11-15 20:13 <DIR> dr-h----- c:\documents and settings\User\Application Data\SecuROM
2008-11-15 19:52 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-15 19:52 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-15 19:52 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-15 19:52 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-11-15 19:52 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-15 19:52 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-15 19:52 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-15 19:51 . 2008-11-15 19:51 <DIR> d-------- c:\windows\Logs
2008-11-15 19:51 . 2008-11-15 19:51 22,328 --a------ c:\documents and settings\User\Application Data\PnkBstrK.sys
2008-11-15 19:50 . 2008-11-15 19:50 2,250,024 --a------ c:\windows\system32\pbsvc.exe
2008-11-14 20:53 . 2008-11-29 12:10 <DIR> d-------- c:\program files\FlashGet
2008-11-14 19:50 . 2008-11-14 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\KONAMI
2008-11-14 19:47 . 2008-11-14 19:47 <DIR> d-------- c:\program files\KONAMI
2008-11-14 19:11 . 2008-11-14 19:11 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-11-14 18:51 . 2008-11-14 18:51 <DIR> d-------- c:\program files\PokerStars
2008-11-14 18:23 . 2008-11-14 18:23 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-14 17:58 . 2008-11-29 18:27 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-14 17:58 . 2008-11-14 17:58 <DIR> d-------- c:\documents and settings\User\Application Data\DAEMON Tools
2008-11-14 17:51 . 2008-11-14 17:51 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-03 15:35 . 2008-11-03 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Windows Live
2008-11-02 11:52 . 2008-11-02 13:03 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Circle Developement
2008-11-01 14:22 . 2008-11-02 13:03 <DIR> d-------- c:\program files\MSN Messenger
2008-11-01 14:09 . 2008-11-01 14:09 <DIR> d-------- c:\documents and settings\User\Tracing
2008-11-01 13:48 . 2008-11-01 13:48 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2008-11-01 13:45 . 2008-11-01 13:45 <DIR> d-------- c:\program files\Microsoft
2008-11-01 13:35 . 2008-11-01 13:35 <DIR> d-------- c:\program files\Common Files\Windows Live
2008-10-31 22:56 . 2008-10-31 22:56 <DIR> d-------- c:\documents and settings\User\Application Data\Samsung
2008-10-31 22:28 . 2003-02-21 18:42 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-10-31 22:28 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2008-10-31 22:27 . 2007-05-02 11:11 109,704 --a------ c:\windows\system32\drivers\ss_mdm.sys
2008-10-31 22:27 . 2007-05-02 11:11 83,592 --a------ c:\windows\system32\drivers\ss_bus.sys
2008-10-31 22:27 . 2007-05-02 11:11 15,112 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_whnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_wh.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cm.sys
2008-10-31 22:27 . 2008-10-31 22:52 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2008-10-31 19:24 . 2008-10-31 19:24 <DIR> d-------- c:\program files\YouTube Downloader
2008-10-31 17:43 . 2008-10-31 17:43 <DIR> d-------- c:\program files\Lavalys
2008-10-18 08:55 . 2008-10-18 08:56 <DIR> d-------- c:\program files\PhotomatixPro3
2008-10-18 08:54 . 2008-10-18 08:54 <DIR> d-------- c:\windows\system32\URTTemp
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\program files\iPod
2008-10-17 19:06 . 2008-11-29 16:15 <DIR> d-------- c:\documents and settings\User\Application Data\Apple Computer
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-17 19:06 . 2008-04-17 12:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-10-17 19:06 . 2008-04-17 12:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\program files\QuickTime
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-17 19:04 . 2008-10-17 19:05 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\program files\Apple Software Update
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 12:41 --------- d-----w c:\documents and settings\User\Application Data\DNA
2008-11-29 17:46 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-29 16:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 16:06 --------- d-----w c:\documents and settings\User\Application Data\BitTorrent
2008-11-29 11:05 --------- d-----w c:\documents and settings\User\Application Data\LimeWire
2008-11-15 18:51 22,328 -c--a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-15 18:50 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-15 18:50 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2008-11-14 16:37 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 10:54 --------- d-----w c:\program files\Winamp
2008-10-31 21:27 --------- d-----w c:\program files\Samsung
2008-10-18 19:58 --------- d-----w c:\program files\DNA
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 04:42 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 17:51 486856 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"ose"=3 (0x3)
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"d:\\Igrice\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [7/1/2008 9:04:40 AM 34312]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [7/25/2008 2:39:19 PM 1310720]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [10/2/2002 11:09:08 PM 31504]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [10/31/2008 10:27:55 PM 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [10/31/2008 10:27:55 PM 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [10/31/2008 10:27:55 PM 109704]
S4 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\MSN Messenger\usnsvc.exe" [1/19/2007 12:54:14 PM 97136]
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-30 19:33:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(864)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-11-30 19:33:45
ComboFix-quarantined-files.txt 2008-11-30 18:33:41
ComboFix2.txt 2008-11-30 17:50:47

Pre-Run: 6.250.278.912 bytes free
Post-Run: 6,240,550,912 bytes free

180

Dopuna: 30 Nov 2008 19:45

hvala ti puno,evo radi...hvala!!

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Treba jos samo da deinstaliramo ComboFix:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 1028 korisnika na forumu :: 83 registrovanih, 10 sakrivenih i 935 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -[CoA]-, airsuba, armor, babaroga, Beria, Bobrock1, bojank, bojcistv, Brada i Gibanica, BSD, Bubimir, Cobi026, comi_pfc, darcaud, darios, Denaya, DENIRO, Djokislav, draganl, Drug pukovnik, Frunze, gomago, goxin, Griffon vulture, helen1, Hitri, hyla, ivan1973, jmsk, JOntra, Još malo pa deda, kairos, konstruktor, kunktator, larisadanilenko, laurusri, liman, lord sir giga, Lucije Kvint, markoskjk, mcgunner, mercedesamg, mihajlot2013, Milan A. Nikolic, miodrag, Miskohd, Miškić, nekitamonebitanlik, nenooo, NoOneEver Dreams, nuke92, operniki, panzerwaffe, Parker, pein, Penzula, pera12345, prle122, procesor, raskoljnikov, rikirubio, RJ, Rocker, royst33, ruma, samsung, simazr, Snorks, spektorsky, ssekir75, stegonosa, strn, Stuka76, t84dar, taz1cl, Toni, tubular, upitnik, VJ, vladom6, |_MeD_|, Žukov, 1107