Log na sken

Log na sken

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

Naime,nisam bio kuci oko 10 dana i toliko je comp bio bez neta a braca su mi isli na svakakve sajtove(pa vjerujem i na (film-za-odrasle)-o) i kada sam dosao komp je bio katastrofa,u procesima je npr bilo tri explorer.exe i 3 lsass.exe. Komp bi sam isao u log off haos brate. I ja sam instalirao kaspersky 2009 i kada je skenirao on je nasao oko 20 trojanaca i sve je to pobrisao (nadam se da je sve) i sada evo da dam log na sken da vidim ima li jos cega sto kaspersky nije uklonio.


LOG


DDS (Ver_09-07-30.01) - NTFSx86
Run by erin at 14:31:48.75 on 14-Aug-09
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.256.111 [GMT 2:00]

AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\erin\Desktop\dds.scr
C:\WINDOWS\system32\msfeedssync.exe

============== Pseudo HJT Report ===============

uStart Page = [Link mogu videti samo ulogovani korisnici]
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2009\ievkbd.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {dbc80044-a445-435b-bc74-9c25c1c588a9} - Java(tm) Plug-In 2 SSV Helper
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2009\avp.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Banner Ad Blocker - c:\program files\kaspersky lab\kaspersky internet security 2009\ie_banner_deny.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - {85E0B171-04FA-11D1-B7DA-00A0C90348D6} - c:\program files\kaspersky lab\kaspersky internet security 2009\SCIEPlgn.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - [Link mogu videti samo ulogovani korisnici]
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\adialhk.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\erin\applic~1\mozilla\firefox\profiles\ycx7qknu.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - plugin: c:\documents and settings\erin\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\opera\program\plugins\npmmaud.dll
FF - plugin: c:\program files\opera\program\plugins\npmmprog.dll
FF - plugin: c:\program files\opera\program\plugins\npmmvid.dll
FF - plugin: c:\program files\opera\program\plugins\npmmzip.dll
FF - plugin: c:\program files\opera\program\plugins\nppl3260.dll
FF - plugin: c:\program files\opera\program\plugins\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2008-7-21 121872]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-1-29 33808]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2009-8-13 226832]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\drivers\klfltdev.sys [2008-3-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-4-30 24592]
R3 SNPHV71;PC Camera (602a VGA);c:\windows\system32\drivers\snphv71.sys [2009-5-8 231040]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2009-5-11 136704]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2009-5-11 8320]

=============== Created Last 30 ================


==================== Find3M ====================

2009-08-13 16:42 33,808 a------- c:\windows\system32\drivers\klbg.sys
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-03 19:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-25 10:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 10:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 10:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-24 13:18 92,928 a------- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 16:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 16:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-12 14:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 14:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 16:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 08:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-03 21:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-06-02 18:11 85,504 a------- c:\windows\system32\ff_vfw.dll
2009-06-01 17:30 355,584 a------- c:\windows\system32\TuneUpDefragService.exe
2009-05-31 14:25 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-29 23:37 205,824 a------- c:\windows\system32\xvidvfw.dll
2009-05-29 23:31 881,664 a------- c:\windows\system32\xvidcore.dll
2009-05-22 21:44 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat

============= FINISH: 14:33:01.98 ===============


[Link mogu videti samo ulogovani korisnici]


[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Sudeći po logovima, ovde ne bi trebalo biti aktivnog malware-a.



offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

Super,KIS je sve odradio
Pozdrav

Ko je trenutno na forumu
 

Ukupno su 1618 korisnika na forumu :: 349 registrovanih, 20 sakrivenih i 1249 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -[CoA]-, -Max-, 33 bren, 357magnum, 5.56, 015, 6.5lapua, _stipa_, advokat84, Agape, AK - 230, akaherz994, Aleksa-, AleksandarV, aleph_one, ArmFPGA, Asteker, Aster Blistok, atmel, AudioTehnica, avijacija, Ba4e, babaroga, Badja, BaneM75, bbrasnjo3, Bgorando, black venom, Bo96, Bob.Rock, boj.an, bojan313, bojan_t, bojanstros9, bojcistv, Bojke549, bokicacar, Bombona, Boris.A, Boris90, boromir, Borski1977, BORUTUS, boskelazo, Bosnjo, bounty hunters, brandža84, branko7, brufen, BSD, BUDDAR70, Burundi, Butcher, cenejac111, Cicumile, CikaKURE, Civa, coaaco, Colt D, Comyymoc, crazydkure, Crazzer, CrveniSolaris, dane007, darios, dd201176, Dd41d41, DeerHunter, Dejan_vw, dejandr, dejankm, dekan.m, Deki Duga Devetka, del boy, Denaya, Desmond, Df410, Dimitrije Paunovic, Dioniss, Dixtrix, djboj, Djole3621, DjomlaHomer, dnevnasoba, Dorcolac, draganl, dskrlec33, Duh sa sekirom, Duh16, dusanobr, dushan, Dzigy, Dzil, Dzoni2412, Dzumanga, Eagle_1, ElGenius, esko_hz, Fabius, Feller, Fructo, gasazem, gasha, Geran136, GH69, ginjica, gmlale, gobrad, goran.vvv, goranperović66, halkin gol, Hans Gajger, hellenic, Hitri, Homislav, HrcAk47, hyla, ibssa, igorpet, ikan, Iluzionista, Insan, InzenjerBL, IQ116, Istman, ivan_8282, ivanhoe31, j-22orao, Jan, Jezekijel, jodzula, Joja, Još malo pa deda, K a s p e r, Kamov, Karla, kaskadija, Kazablankasrb, kobaja77, Kobrim, kokodakalo, Kole1975, kolle.the.kid, kondenzator, kori, kozhedub, Kriglord, Krusarac, Kubovac, Kum Ruzvelt, Kupresko polje, Kure126-7, kybonacci, ladro, laganini123, lakala, lakson001, Lance Guest, laurusri, Lazur_01, Lester Freamon, Levi, Litostroton, Ljusa, lmn, Lobo, louderik, LUDI, luja, luka35, Luke Pathfinder, M1los, M74AB3, Mae, Makarid, Maki1981, Malahit, Mane88, Marko Marković, marko.markovic, MarkoDzimi, markolopin, MarkoW, marsi, marsovac 2, mačković, MDrasko, Medojed, Michellefromrezistance, Miki01, Miki281, miki69, mikrimaus, milanpb, milimoj, MiljanXD, Millennium, Milo97, Milometer, milos.cbr, mir juzni, MiroslavD, Mis uz pusku, mishkooo, Misterrno, mitja123, Mićko, MK10, mkukoleca, mm1811, Muki 123, museum, mushroom, mux, naki011, narandzasti, Natuzzi, nebkv, neko iz mase, Nemanja Opalić, Nemanja.M, nemkea71, nick79, Njubara, Nobunaga, ObicanUser, oblivion, ognjentrm, Orlova, paja69, Papadubi, Paško, Pekman, Permaldar, Pero Petković, Perudin_92, petrovicrs, Piani Jazzer, ping15, Plavi1, PlayerOne, Posmatrac77OKB, Prečanin30, prikolica, Primus17, PrincipL, procesor, Pururin, rachmoff, Ran, raso76, raster12, Recce, Remarqe, risima, RiV, Rocky I, Romuluss, RS28, ruma, sabros, Sale0501, Salence74, Samo gledam, Sanda, saputnik plavetnila, sarma, savuni, Semberija, sevenino, shlauf, sijecanj, simazr, simicnenadbg, Simonsen23, siwoti, Sky diver 29, Smiljkovich, snikolic, sovanova95, SOVO515, spektorsky, srbijaiznadsvega, Srpska zauvjek, ssekir75, Str2022, StrahinjicOgnjen, strawman, strn, Su 57, suton, Szigetwar, Tajpan, Tandrkalo, taz1cl, tesa, theBorer, tmanda323, tomigun, tomo2, Topaz9, Totem, totopoto, Tragač, Trpe Grozni, TTN, tubular, ujke, US_Rank_0, v82, VaRvArI 85, vathra, vensla, virked, Vitomir, Vlada1389, vladao75, vladas87, vlado_pg, vladoje, vlahale, voja64, Vojkan Petrovic, vojnik švejk, Vojvoda81, volimpivuvolimrakiju, VOŽD, VPV, vukovi, wize, wizzardone, Wrangler, x011, Yekaterinburg, yiyi, yrraf, Yugol33, Zastava, zdrebac, Zeljo980, zemljanin, ZlatniRez, zoran77, Zrcalo, Zvrk, zzeljko, Žoržo, šakalakazu, Đurđevdan