Navala exe fajlova na C particiji

Navala exe fajlova na C particiji

offline
  • Pridružio: 13 Dec 2011
  • Poruke: 6

Napisano: 23 Dec 2011 16:53

Od pre 15 dana računar je počeo usporeno da radi, a onda se tu pojavilo još niz problema - OE neće da skine mejlove, preskakanje kursora po tekstu, Otvaranje programa predugo traje...
Onda sam primetio na c: neke čudne naziive fajlova - preko Tools- Folder Options postavio sam vidljive sistemseke i nevidljive fajlove, kad tamo haos - lmfove.exe, iwcjbc, hpao.exe, cafdma....još preko pedesetak sličnihi uz to ikone prečice tipa ksnls, hokipr itd.
Instalirao sam nanovo NOD32, ali je sve van kontrole xxx prozora sa fajlovima koji idu u karantin i isto zolliko koji nije moguće očistiti, u NOD32 neki tasteri koji nisu kompletni sa atpisom ...
Ukratko to je to...
mycity.rs/must-login.png




.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Run by Pc at 10:59:09 on 2011-12-23
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1013.484 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Samsung\Samsung PC Studio 7\PCSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\winamp toolbar\winamptbServer.exe
C:\DOCUME~1\Pc\LOCALS~1\Temp\wineejfi.exe
C:\WINDOWS\TEMP\winoedh.exe
C:\WINDOWS\TEMP\winxlbhpu.exe
C:\DOCUME~1\Pc\LOCALS~1\Temp\wintbij.exe
C:\WINDOWS\TEMP\winkhqgcx.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\TEMP\kycoc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\TEMP\winbknt.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.rs/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Winamp Toolbar Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
mURLSearchHooks: Winamp Toolbar Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: IeCatch2 Class: {a5366673-e8ca-11d3-9cd9-0090271d075b} - c:\progra~1\flashget\jccatch.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: FlashGet Bar: {e0e899ab-f487-11d5-8d29-0050ba6940e3} - c:\progra~1\flashget\fgiebar.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [NBJ] "c:\program files\ahead\nero backitup\NBJ.exe"
uRun: [S60 PC Suite Tray] "c:\program files\samsung\samsung pc studio 7\PCSuite.exe" -onlytray
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Samsung.PCSync] "c:\program files\samsung\samsung pc studio 7\PcSync2.exe" /NoDialog
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
mPolicies-explorer: UseDesktopIniCache = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
dPolicies-system: DisableTaskMgr = 1 (0x1)
dPolicies-system: DisableRegistryTools = 1 (0x1)
IE: Download All by FlashGet - c:\program files\flashget\jc_all.htm
IE: Download using FlashGet - c:\program files\flashget\jc_link.htm
IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - c:\progra~1\flashget\flashget.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.1.2.20 10.1.2.5
TCP: Interfaces\{2997AE9F-6C53-4FCE-8370-85036488933A} : DhcpNameServer = 10.1.2.20 10.1.2.5
TCP: Interfaces\{4B463FE4-15AC-4DF5-9547-CE3CF0119D35} : NameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\pc\application data\mozilla\firefox\profiles\52fr2465.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.winamp.com/search/search?query={searchTerms}&invocationType=tb50-ff-winamp-chromesbox-en-us&tb_uuid=20110720061418062&tb_oid=20-07-2011&tb_mrud=20-07-2011&query=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/webhp?hl=sr
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/redirector/sredir?sredir=2685&invocationType=tb50-ff-winamp-ab-en-us&tb_uuid=20110720061418062&tb_oid=20-07-2011&tb_mrud=20-07-2011&query=
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\52fr2465.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\MailUtil.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\52fr2465.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampPlayer.dll
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Easy YouTube Video Downloader: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b} - %profile%\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
FF - Ext: 1-Click YouTube Video Downloader: YoutubeDownloader@PeterOlayev.com - %profile%\extensions\YoutubeDownloader@PeterOlayev.com
FF - Ext: Winamp Toolbar: {0b38152b-1b20-484d-a11f-5e04a9b0661f} - %profile%\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
============= SERVICES / DRIVERS ===============
.
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
R3 amsint32;amsint32;\??\c:\windows\system32\drivers\hnknn.sys --> c:\windows\system32\drivers\hnknn.sys [?]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2010-8-5 44032]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-8-5 1684736]
S3 cxbu0wdm;OMNIKEY 3x21;c:\windows\system32\drivers\cxbu0wdm.sys [2011-11-7 119040]
.
=============== Created Last 30 ================
.
2011-12-23 07:40:52 103140 --sh--r- C:\aouanv.exe
2011-12-23 07:40:11 103140 --sh--r- C:\dlddjf.pif
2011-12-23 07:39:24 103140 --sh--r- C:\xcagn.exe
2011-12-23 07:38:37 103140 --sh--r- C:\nbeasf.exe
2011-12-23 07:37:44 103140 --sh--r- C:\kgbjp.pif
2011-12-23 07:33:10 103140 --sh--r- C:\fuej.exe
2011-12-23 07:21:21 103140 --sh--r- C:\scvgtj.pif
2011-12-23 07:20:32 103140 --sh--r- C:\qjih.pif
2011-12-23 07:19:50 103140 --sh--r- C:\jpijeo.exe
2011-12-23 07:19:11 103140 --sh--r- C:\uhvi.exe
2011-12-23 07:18:31 103140 --sh--r- C:\jdct.pif
2011-12-23 07:17:52 103140 --sh--r- C:\alfrue.exe
2011-12-23 07:17:11 103140 --sh--r- C:\umec.exe
2011-12-23 07:16:32 103140 --sh--r- C:\igcf.pif
2011-12-23 07:15:53 103140 --sh--r- C:\evqs.pif
2011-12-23 07:15:14 103140 --sh--r- C:\ypfx.exe
2011-12-23 07:14:34 103140 --sh--r- C:\dsxyj.pif
2011-12-23 07:13:44 103140 --sh--r- C:\ygyxu.exe
2011-12-23 07:12:52 103140 --sh--r- C:\dkfbwa.exe
2011-12-23 07:12:11 103140 --sh--r- C:\pacvv.exe
2011-12-23 07:11:17 103140 --sh--r- C:\hokipr.pif
2011-12-23 07:10:27 103140 --sh--r- C:\avqrik.pif
2011-12-23 07:09:46 103140 --sh--r- C:\tapy.pif
2011-12-23 07:08:59 103140 --sh--r- C:\cafdma.exe
2011-12-23 07:08:18 103140 --sh--r- C:\ksnylc.pif
2011-12-23 07:07:27 103140 --sh--r- C:\iwcjbc.exe
2011-12-23 07:06:47 103140 --sh--r- C:\sngic.pif
2011-12-23 07:06:08 103140 --sh--r- C:\sypfaw.exe
2011-12-23 07:05:29 103140 --sh--r- C:\tkpqth.exe
2011-12-23 07:04:50 103140 --sh--r- C:\hpaao.exe
2011-12-23 07:04:11 103140 --sh--r- C:\nhnjrx.exe
2011-12-23 07:03:31 103140 --sh--r- C:\tfjai.pif
2011-12-23 07:02:52 103140 --sh--r- C:\krrik.exe
2011-12-23 07:02:12 103140 --sh--r- C:\xxqa.pif
2011-12-23 07:01:33 103140 --sh--r- C:\wwev.exe
2011-12-23 07:00:42 103140 --sh--r- C:\lmfove.exe
2011-12-23 06:59:53 103140 --sh--r- C:\urnay.exe
2011-12-23 06:59:12 103140 --sh--r- C:\ekul.pif
2011-12-23 06:58:22 103140 --sh--r- C:\ehalxk.pif
2011-12-23 06:57:34 103140 --sh--r- C:\vgyuj.pif
2011-12-23 06:56:49 103140 --sh--r- C:\qamcoo.exe
2011-12-23 06:56:00 103140 --sh--r- C:\btqvq.exe
2011-12-23 06:55:18 103140 --sh--r- C:\thvxcr.pif
2011-12-23 06:54:29 103140 --sh--r- C:\llrjd.exe
2011-12-23 06:53:48 103140 --sh--r- C:\eppdrm.exe
2011-12-23 06:53:08 103140 --sh--r- C:\xqor.exe
2011-12-23 06:52:26 103140 --sh--r- C:\lvuhka.exe
2011-12-23 06:51:46 103140 --sh--r- C:\deutoc.exe
2011-12-23 06:51:05 103140 --sh--r- C:\cnyeq.exe
2011-12-23 06:50:24 103140 --sh--r- C:\uibei.pif
2011-12-23 06:49:45 103140 --sh--r- C:\sbpdgm.exe
2011-12-23 06:49:06 103140 --sh--r- C:\lgrv.pif
2011-12-23 06:48:28 103140 --sh--r- C:\ugdd.exe
2011-12-23 06:47:38 103140 --sh--r- C:\grstb.pif
2011-12-23 06:46:49 103140 --sh--r- C:\oouclh.pif
2011-12-23 06:45:46 103140 --sh--r- C:\nqqym.pif
2011-12-23 06:44:54 103140 --sh--r- C:\nelt.pif
2011-12-23 06:44:01 103140 --sh--r- C:\cefkjd.pif
2011-12-23 06:43:15 103140 --sh--r- C:\ojdsg.pif
2011-12-23 06:42:35 103140 --sh--r- C:\gqvjw.pif
2011-12-23 06:41:45 103140 --sh--r- C:\rpib.exe
2011-12-23 06:41:02 103140 --sh--r- C:\ocbw.pif
2011-12-23 06:40:21 103140 --sh--r- C:\sicrc.pif
2011-12-23 06:39:41 103140 --sh--r- C:\xkdqm.exe
2011-12-23 06:39:03 103140 --sh--r- C:\axaec.pif
2011-12-23 06:38:24 103140 --sh--r- C:\hnicm.exe
2011-12-23 06:37:45 103140 --sh--r- C:\beamwu.pif
2011-12-23 06:37:05 103140 --sh--r- C:\qeug.pif
2011-12-23 06:36:24 103140 --sh--r- C:\mvoh.pif
2011-12-23 06:35:43 103140 --sh--r- C:\vxtr.pif
2011-12-23 06:35:04 103140 --sh--r- C:\nplat.exe
2011-12-23 06:34:15 103140 --sh--r- C:\utxsc.exe
2011-12-23 06:33:25 103140 --sh--r- C:\lfbfsb.pif
2011-12-23 06:32:26 103140 --sh--r- C:\cwaxk.exe
2011-12-23 06:31:32 103140 --sh--r- C:\pudtr.pif
2011-12-23 06:30:41 103140 --sh--r- C:\ypbpu.pif
2011-12-23 06:30:00 103140 --sh--r- C:\kbop.exe
2011-12-23 06:29:21 103140 --sh--r- C:\tsft.pif
2011-12-23 06:28:35 103140 --sh--r- C:\xxcsel.exe
2011-12-23 06:27:46 103140 --sh--r- C:\tvrbrl.pif
2011-12-23 06:27:06 103140 --sh--r- C:\xhockd.exe
2011-12-23 06:26:24 103140 --sh--r- C:\mrsuv.pif
2011-12-23 06:25:44 103140 --sh--r- C:\ckba.pif
2011-12-23 06:24:51 103140 --sh--r- C:\uurgsx.exe
2011-12-23 06:24:11 103140 --sh--r- C:\crbd.exe
2011-12-23 06:23:31 103140 --sh--r- C:\bxvcb.pif
2011-12-23 06:22:51 103140 --sh--r- C:\fxilo.exe
2011-12-23 06:22:12 103140 --sh--r- C:\ihetov.exe
2011-12-23 06:21:32 103140 --sh--r- C:\sioht.pif
2011-12-23 06:20:43 103140 --sh--r- C:\ltfffs.pif
2011-12-23 06:19:50 103140 --sh--r- C:\prvwtp.pif
2011-12-23 06:19:01 103140 --sh--r- C:\vyald.exe
2011-12-23 06:17:54 103140 --sh--r- C:\eusd.exe
2011-12-23 06:17:09 103140 --sh--r- C:\dcaxj.exe
2011-12-23 06:16:04 103140 --sh--r- C:\hyhh.exe
2011-12-23 06:13:38 103140 --sh--r- C:\jsmi.pif
2011-12-23 06:12:44 103140 --sh--r- C:\dhsbk.pif
2011-12-23 06:11:44 103140 --sh--r- C:\lpjkw.pif
2011-12-23 06:10:14 103140 --sh--r- C:\oyfmj.exe
2011-12-23 06:09:31 103140 --sh--r- C:\lgwlmw.exe
2011-12-23 06:08:42 103140 --sh--r- C:\anbylm.pif
2011-12-23 06:07:58 103140 --sh--r- C:\iaxnx.pif
2011-12-23 06:07:05 103140 --sh--r- C:\kmaqn.pif
2011-12-22 13:43:11 -------- d-----w- c:\program files\UlisesSoft
2011-12-22 13:27:12 103140 --sh--r- C:\oibtla.exe
2011-12-22 13:15:57 -------- d-----w- C:\ComboFix
2011-12-15 06:50:06 -------- d-----w- c:\windows\system32\LogFiles
2011-12-13 13:45:45 -------- d-----w- c:\windows\SchCache
.
==================== Find3M ====================
.
2011-12-13 13:50:40 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, gmer.net
Windows 5.1.2600 Disk: WDC_WD800BB-75JHC0 rev.06.01C06 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe >>UNKNOWN [0x86DCA688]<<
_asm { MOV EAX, 0x86dca5a8; XCHG [ESP], EAX; PUSH EAX; PUSH 0x86da7684; RET ; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; }
1 ntkrnlpa!IofCallDriver[0x804EE120] -> \Device\Harddisk0\DR0[0x86D77AB8]
\Driver\Disk[0x86CF1910] -> IRP_MJ_CREATE -> 0x86DCA688
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\Disk -> 0x86dca688
user & kernel MBR OK
Warning: possible MBR rootkit infection !
.
============= FINISH: 11:00:16.49 ===============





mycity.rs/must-login.png


mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

Dopuna: 23 Dec 2011 16:56

[img][/img]

offline
  • Pridružio: 26 Avg 2010
  • Poruke: 10622
  • Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building

U sistemu imaš fajl-infektora Sality koga nije moguće ukloniti iz aktivnog Windows-a.
Pročitaj ovo upustvo:
http://www.mycity.rs/Zastitni-programi/Rescue-CD-prirucnik.html
odaberi jedan i sa njim skreniraj diskove.

Ako uspiješ, postavi svježe DDS i GMER izvještaje, a ako ti ne pođe za rukom, bojim se da je onda jedino rješenje format.

Napomena: nemoj koristiti USB memorijske uređaje dok ti to ne zatražim, a ako se odlučiš na formatiranje diska reci nam to kako bi ti dali upustva šta ćeš da uradiš i šta ne smiješ da radiš nakon instalacije sistema.

Ko je trenutno na forumu
 

Ukupno su 862 korisnika na forumu :: 6 registrovanih, 3 sakrivenih i 853 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, Lazarus, Milometer, pera12345, suton, uruk