Izvjestaj

Izvjestaj

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:49:08, on 30.11.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\User\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = daemon-search.com/default
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O4 - HKLM\..\Run: [C6501Sound] RunDll32 c6501.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{98DE8D30-6EC2-4237-BAF0-1B18CC8F3B92}: NameServer = 195.29.149.196 195.29.149.197
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 4483 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Hvala na izvestaju. A sta ja sada treba sa njim da radim? Na sta se u stvari zalis?

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

A sorry,problem je u tom sto mi se ikone maknu svakih 5-6 sekundi i taskbar i sve,i tako par puta,a poslije toga mi se makne i ne pojavljuje se nista vise.Preko task manager pokrecem sve programe.Ovo mi je izvjestaj iz Hijack This pa sad...Sta da napravim?radio sam izvjestaj i u Malwerbytes anti i procitao da se radi o nekom trojan vundo...

Dopuna: 30 Nov 2008 14:27

ako bi mi mogao pomoci bio bih ti zahvalan,

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Probajmo sledece:

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

ComboFix 08-11-30.01 - User 2008-11-30 18:47:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1632 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\awtussPi.dll
c:\windows\Tasks\kdvaklby.job

----- BITS: Possible infected sites -----

hxxp://childhe.com
.
((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.

2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\User\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 14:12 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-30 13:49 . 2008-11-30 13:49 <DIR> d-------- C:\New Folder
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-29 18:22 . 2008-11-29 18:22 268 --ah----- C:\sqmdata11.sqm
2008-11-29 18:22 . 2008-11-29 18:22 244 --ah----- C:\sqmnoopt11.sqm
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\program files\ESET
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-29 17:57 . 2008-11-29 17:57 <DIR> d-------- c:\documents and settings\Administrator
2008-11-29 17:45 . 2008-11-29 17:45 268 --ah----- C:\sqmdata10.sqm
2008-11-29 17:45 . 2008-11-29 17:45 244 --ah----- C:\sqmnoopt10.sqm
2008-11-29 17:32 . 2008-11-29 17:32 268 --ah----- C:\sqmdata09.sqm
2008-11-29 17:32 . 2008-11-29 17:32 244 --ah----- C:\sqmnoopt09.sqm
2008-11-29 17:21 . 2008-11-29 17:21 268 --ah----- C:\sqmdata08.sqm
2008-11-29 17:21 . 2008-11-29 17:21 244 --ah----- C:\sqmnoopt08.sqm
2008-11-29 17:20 . 2008-11-29 17:20 268 --ah----- C:\sqmdata07.sqm
2008-11-29 17:20 . 2008-11-29 17:20 244 --ah----- C:\sqmnoopt07.sqm
2008-11-29 16:34 . 2008-11-29 16:34 <DIR> d-------- c:\documents and settings\User\Application Data\Sports Interactive
2008-11-29 16:34 . 2008-11-29 17:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:28 <DIR> d--h----- c:\program files\Zero G Registry
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d-------- c:\program files\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d--h----- c:\documents and settings\User\InstallAnywhere
2008-11-29 14:39 . 2008-11-29 14:39 <DIR> d-------- c:\program files\Sony Setup
2008-11-15 20:13 . 2008-11-15 20:13 <DIR> dr-h----- c:\documents and settings\User\Application Data\SecuROM
2008-11-15 19:52 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-15 19:52 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-15 19:52 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-15 19:52 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-11-15 19:52 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-15 19:52 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-15 19:52 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-15 19:51 . 2008-11-15 19:51 <DIR> d-------- c:\windows\Logs
2008-11-15 19:51 . 2008-11-15 19:51 22,328 --a------ c:\documents and settings\User\Application Data\PnkBstrK.sys
2008-11-15 19:50 . 2008-11-15 19:50 2,250,024 --a------ c:\windows\system32\pbsvc.exe
2008-11-14 20:53 . 2008-11-29 12:10 <DIR> d-------- c:\program files\FlashGet
2008-11-14 19:50 . 2008-11-14 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\KONAMI
2008-11-14 19:47 . 2008-11-14 19:47 <DIR> d-------- c:\program files\KONAMI
2008-11-14 19:11 . 2008-11-14 19:11 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-11-14 18:51 . 2008-11-14 18:51 <DIR> d-------- c:\program files\PokerStars
2008-11-14 18:23 . 2008-11-14 18:23 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-14 17:58 . 2008-11-29 18:27 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-14 17:58 . 2008-11-14 17:58 <DIR> d-------- c:\documents and settings\User\Application Data\DAEMON Tools
2008-11-14 17:51 . 2008-11-14 17:51 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-03 15:35 . 2008-11-03 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Windows Live
2008-11-02 11:52 . 2008-11-02 13:03 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Circle Developement
2008-11-01 14:22 . 2008-11-02 13:03 <DIR> d-------- c:\program files\MSN Messenger
2008-11-01 14:09 . 2008-11-01 14:09 <DIR> d-------- c:\documents and settings\User\Tracing
2008-11-01 13:48 . 2008-11-01 13:48 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2008-11-01 13:45 . 2008-11-01 13:45 <DIR> d-------- c:\program files\Microsoft
2008-11-01 13:35 . 2008-11-01 13:35 <DIR> d-------- c:\program files\Common Files\Windows Live
2008-10-31 22:56 . 2008-10-31 22:56 <DIR> d-------- c:\documents and settings\User\Application Data\Samsung
2008-10-31 22:28 . 2003-02-21 18:42 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-10-31 22:28 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2008-10-31 22:27 . 2007-05-02 11:11 109,704 --a------ c:\windows\system32\drivers\ss_mdm.sys
2008-10-31 22:27 . 2007-05-02 11:11 83,592 --a------ c:\windows\system32\drivers\ss_bus.sys
2008-10-31 22:27 . 2007-05-02 11:11 15,112 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_whnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_wh.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cm.sys
2008-10-31 22:27 . 2008-10-31 22:52 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2008-10-31 19:24 . 2008-10-31 19:24 <DIR> d-------- c:\program files\YouTube Downloader
2008-10-31 17:43 . 2008-10-31 17:43 <DIR> d-------- c:\program files\Lavalys
2008-10-18 08:55 . 2008-10-18 08:56 <DIR> d-------- c:\program files\PhotomatixPro3
2008-10-18 08:54 . 2008-10-18 08:54 <DIR> d-------- c:\windows\system32\URTTemp
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\program files\iPod
2008-10-17 19:06 . 2008-11-29 16:15 <DIR> d-------- c:\documents and settings\User\Application Data\Apple Computer
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-17 19:06 . 2008-04-17 12:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-10-17 19:06 . 2008-04-17 12:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\program files\QuickTime
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-17 19:04 . 2008-10-17 19:05 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\program files\Apple Software Update
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 12:41 --------- d-----w c:\documents and settings\User\Application Data\DNA
2008-11-29 17:46 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-29 16:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 16:06 --------- d-----w c:\documents and settings\User\Application Data\BitTorrent
2008-11-29 11:05 --------- d-----w c:\documents and settings\User\Application Data\LimeWire
2008-11-15 18:51 22,328 -c--a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-15 18:50 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-15 18:50 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2008-11-14 16:37 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 10:54 --------- d-----w c:\program files\Winamp
2008-10-31 21:27 --------- d-----w c:\program files\Samsung
2008-10-18 19:58 --------- d-----w c:\program files\DNA
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 04:42 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 17:51 486856 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"ose"=3 (0x3)
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"d:\\Igrice\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [7/1/2008 9:04:40 AM 34312]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [7/25/2008 2:39:19 PM 1310720]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [10/2/2002 11:09:08 PM 31504]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [10/31/2008 10:27:55 PM 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [10/31/2008 10:27:55 PM 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [10/31/2008 10:27:55 PM 109704]
S4 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\MSN Messenger\usnsvc.exe" [1/19/2007 12:54:14 PM 97136]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cdb7121-a8ba-11dd-a4b6-001e8c67a2c5}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -

BHO-{AFAF8314-45C9-4EC5-9317-A9C24E01D0AC} - (no file)
ShellExecuteHooks-{AFAF8314-45C9-4EC5-9317-A9C24E01D0AC} - (no file)
Notify-jkkICUki - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\w2kw3akq.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF -: plugin - d:\itunes\Mozilla Plugins\npitunes.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-30 18:49:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
.
**************************************************************************
.
Completion time: 2008-11-30 18:50:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-30 17:50:44

Pre-Run: 6.335.070.208 bytes free
Post-Run: 6,258,266,112 bytes free

211

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Otvoriti Notepad i iskopirati sledeci tekst:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5cdb7121-a8ba-11dd-a4b6-001e8c67a2c5}]


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Kazi mi kako se sada ponasa racunar? Jesu li simptomi jos uvek prisutni?

offline
  • Pridružio: 30 Nov 2008
  • Poruke: 20

ComboFix 08-11-30.01 - User 2008-11-30 19:32:48.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1250.1.1033.18.1643 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-30 )))))))))))))))))))))))))))))))
.

2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\User\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-11-30 14:12 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 14:12 . 2008-10-22 16:27 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 14:12 . 2008-10-22 16:27 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-30 13:49 . 2008-11-30 13:49 <DIR> d-------- C:\New Folder
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-29 19:09 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-29 18:22 . 2008-11-29 18:22 268 --ah----- C:\sqmdata11.sqm
2008-11-29 18:22 . 2008-11-29 18:22 244 --ah----- C:\sqmnoopt11.sqm
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\program files\ESET
2008-11-29 18:18 . 2008-11-29 18:18 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-29 17:57 . 2008-11-29 17:57 <DIR> d-------- c:\documents and settings\Administrator
2008-11-29 17:45 . 2008-11-29 17:45 268 --ah----- C:\sqmdata10.sqm
2008-11-29 17:45 . 2008-11-29 17:45 244 --ah----- C:\sqmnoopt10.sqm
2008-11-29 17:32 . 2008-11-29 17:32 268 --ah----- C:\sqmdata09.sqm
2008-11-29 17:32 . 2008-11-29 17:32 244 --ah----- C:\sqmnoopt09.sqm
2008-11-29 17:21 . 2008-11-29 17:21 268 --ah----- C:\sqmdata08.sqm
2008-11-29 17:21 . 2008-11-29 17:21 244 --ah----- C:\sqmnoopt08.sqm
2008-11-29 17:20 . 2008-11-29 17:20 268 --ah----- C:\sqmdata07.sqm
2008-11-29 17:20 . 2008-11-29 17:20 244 --ah----- C:\sqmnoopt07.sqm
2008-11-29 16:34 . 2008-11-29 16:34 <DIR> d-------- c:\documents and settings\User\Application Data\Sports Interactive
2008-11-29 16:34 . 2008-11-29 17:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:28 <DIR> d--h----- c:\program files\Zero G Registry
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d-------- c:\program files\Sports Interactive
2008-11-29 16:27 . 2008-11-29 16:27 <DIR> d--h----- c:\documents and settings\User\InstallAnywhere
2008-11-29 14:39 . 2008-11-29 14:39 <DIR> d-------- c:\program files\Sony Setup
2008-11-15 20:13 . 2008-11-15 20:13 <DIR> dr-h----- c:\documents and settings\User\Application Data\SecuROM
2008-11-15 19:52 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-15 19:52 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-15 19:52 . 2008-05-30 14:19 507,400 --a------ c:\windows\system32\XAudio2_1.dll
2008-11-15 19:52 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-11-15 19:52 . 2008-05-30 14:18 238,088 --a------ c:\windows\system32\xactengine3_1.dll
2008-11-15 19:52 . 2008-05-30 14:17 65,032 --a------ c:\windows\system32\XAPOFX1_0.dll
2008-11-15 19:52 . 2008-05-30 14:17 25,608 --a------ c:\windows\system32\X3DAudio1_4.dll
2008-11-15 19:51 . 2008-11-15 19:51 <DIR> d-------- c:\windows\Logs
2008-11-15 19:51 . 2008-11-15 19:51 22,328 --a------ c:\documents and settings\User\Application Data\PnkBstrK.sys
2008-11-15 19:50 . 2008-11-15 19:50 2,250,024 --a------ c:\windows\system32\pbsvc.exe
2008-11-14 20:53 . 2008-11-29 12:10 <DIR> d-------- c:\program files\FlashGet
2008-11-14 19:50 . 2008-11-14 19:50 <DIR> d-------- c:\documents and settings\All Users\Application Data\KONAMI
2008-11-14 19:47 . 2008-11-14 19:47 <DIR> d-------- c:\program files\KONAMI
2008-11-14 19:11 . 2008-11-14 19:11 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2008-11-14 18:51 . 2008-11-14 18:51 <DIR> d-------- c:\program files\PokerStars
2008-11-14 18:23 . 2008-11-14 18:23 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-14 17:58 . 2008-11-29 18:27 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-14 17:58 . 2008-11-14 17:58 <DIR> d-------- c:\documents and settings\User\Application Data\DAEMON Tools
2008-11-14 17:51 . 2008-11-14 17:51 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-03 15:35 . 2008-11-03 15:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Windows Live
2008-11-02 11:52 . 2008-11-02 13:03 <DIR> d-------- c:\program files\Messenger Plus! Live
2008-11-02 11:52 . 2008-11-02 11:52 <DIR> d-------- c:\program files\Circle Developement
2008-11-01 14:22 . 2008-11-02 13:03 <DIR> d-------- c:\program files\MSN Messenger
2008-11-01 14:09 . 2008-11-01 14:09 <DIR> d-------- c:\documents and settings\User\Tracing
2008-11-01 13:48 . 2008-11-01 13:48 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2008-11-01 13:45 . 2008-11-01 13:45 <DIR> d-------- c:\program files\Microsoft
2008-11-01 13:35 . 2008-11-01 13:35 <DIR> d-------- c:\program files\Common Files\Windows Live
2008-10-31 22:56 . 2008-10-31 22:56 <DIR> d-------- c:\documents and settings\User\Application Data\Samsung
2008-10-31 22:28 . 2003-02-21 18:42 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-10-31 22:28 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2008-10-31 22:27 . 2007-05-02 11:11 109,704 --a------ c:\windows\system32\drivers\ss_mdm.sys
2008-10-31 22:27 . 2007-05-02 11:11 83,592 --a------ c:\windows\system32\drivers\ss_bus.sys
2008-10-31 22:27 . 2007-05-02 11:11 15,112 --a------ c:\windows\system32\drivers\ss_mdfl.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_whnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_wh.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cmnt.sys
2008-10-31 22:27 . 2007-05-02 11:11 12,424 --a------ c:\windows\system32\drivers\ss_cm.sys
2008-10-31 22:27 . 2008-10-31 22:52 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2008-10-31 19:24 . 2008-10-31 19:24 <DIR> d-------- c:\program files\YouTube Downloader
2008-10-31 17:43 . 2008-10-31 17:43 <DIR> d-------- c:\program files\Lavalys
2008-10-18 08:55 . 2008-10-18 08:56 <DIR> d-------- c:\program files\PhotomatixPro3
2008-10-18 08:54 . 2008-10-18 08:54 <DIR> d-------- c:\windows\system32\URTTemp
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\program files\iPod
2008-10-17 19:06 . 2008-11-29 16:15 <DIR> d-------- c:\documents and settings\User\Application Data\Apple Computer
2008-10-17 19:06 . 2008-10-17 19:06 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-17 19:06 . 2008-04-17 12:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-10-17 19:06 . 2008-04-17 12:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\program files\QuickTime
2008-10-17 19:05 . 2008-10-17 19:05 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-17 19:04 . 2008-10-17 19:05 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\program files\Apple Software Update
2008-10-17 19:04 . 2008-10-17 19:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 12:41 --------- d-----w c:\documents and settings\User\Application Data\DNA
2008-11-29 17:46 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-29 16:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 16:06 --------- d-----w c:\documents and settings\User\Application Data\BitTorrent
2008-11-29 11:05 --------- d-----w c:\documents and settings\User\Application Data\LimeWire
2008-11-15 18:51 22,328 -c--a-w c:\windows\system32\drivers\PnkBstrK.sys
2008-11-15 18:50 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2008-11-15 18:50 107,832 ----a-w c:\windows\system32\PnkBstrB.exe
2008-11-14 16:37 --------- d-----w c:\program files\Common Files\Adobe
2008-11-01 10:54 --------- d-----w c:\program files\Winamp
2008-10-31 21:27 --------- d-----w c:\program files\Samsung
2008-10-18 19:58 --------- d-----w c:\program files\DNA
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 04:42 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-01-17 17:51 486856 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 d:\itunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MDM"=2 (0x2)
"ose"=3 (0x3)
"usnjsvc"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"d:\\LimeWire\\LimeWire.exe"=
"d:\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=
"d:\\Igrice\\Tom Clancy's Rainbow Six Vegas 2\\Tom Clancy's Rainbow Six Vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [7/1/2008 9:04:40 AM 34312]
R3 c65013264;C-Media CM6501 Like Sound UDAX Interface;c:\windows\system32\drivers\c6501.sys [7/25/2008 2:39:19 PM 1310720]
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);c:\windows\system32\DRIVERS\RMSPPPOE.SYS [10/2/2002 11:09:08 PM 31504]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);c:\windows\system32\DRIVERS\ss_bus.sys [10/31/2008 10:27:55 PM 83592]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;c:\windows\system32\DRIVERS\ss_mdfl.sys [10/31/2008 10:27:55 PM 15112]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;c:\windows\system32\DRIVERS\ss_mdm.sys [10/31/2008 10:27:55 PM 109704]
S4 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\MSN Messenger\usnsvc.exe" [1/19/2007 12:54:14 PM 97136]
.
Contents of the 'Scheduled Tasks' folder

2008-11-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-11-30 19:33:27
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(864)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2008-11-30 19:33:45
ComboFix-quarantined-files.txt 2008-11-30 18:33:41
ComboFix2.txt 2008-11-30 17:50:47

Pre-Run: 6.250.278.912 bytes free
Post-Run: 6,240,550,912 bytes free

180

Dopuna: 30 Nov 2008 19:45

hvala ti puno,evo radi...hvala!!

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Treba jos samo da deinstaliramo ComboFix:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 1248 korisnika na forumu :: 57 registrovanih, 8 sakrivenih i 1183 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Acivi, adamantadv, amaterSRB, Andrija357, armor, ArmyBoss, Atomski čoban, bojankrstc, bokisha253, ccoogg123, comi_pfc, dane007, Dannyboy, darcaud, dekan.m, Dimitrije Paunovic, dragoljub11987, dule10savic, Georgius, Gosha101980, goxin, hooraay, hyla, JimmyNapoli, karevski, Levi, Marko Marković, mgolub, Mi lao shu, milenko crazy north, milimoj, moldway, Ne doznajem se u oružje, nebkv, ObelixSRB, operniki, Panter, panzerwaffe, pein, Rakenica, royst33, Shinobi, Sir Budimir, slonic_tonic, SR-3m, Srle993, suton, Tragač, Tvrtko I, VJ, vlad4, Vlada1389, Vlada78, VP6919, Wrangler, 1107