Pomoc, imam smaracki virus

Pomoc, imam smaracki virus

offline
  • Pridružio: 11 Avg 2008
  • Poruke: 65
  • Gde živiš: Vancouver

neznam kako ali mi se zakacio program windowsxp2008 antivirus,koji mi je odma pokazao da imam 1036 virusa,i program mi se pojavljivao u desnom donjem uglu.uspeo sam da ga izbrisem ali sada mi se pojavljuje plavi ekran na kojem pise da jedan od softvera ili drivera neradi dobro i da postoje neki problemi u windows-u.


molim za pomoc sta da radim?

GUZ - Glavom U Zid

Dopuna: 11 Avg 2008 13:20

evo ga log file od hijackthis programa



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:17:16, on 11.8.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\drivers\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\maki & ika\Desktop\almbulanta program\TR3.exe.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! ¤u¨a¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live pomagac za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! ¤u¨a¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdnkx.exe] C:\WINDOWS\system32\kdnkx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6F750203-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: M-Audio USB Installer (MAudioUSBService) - M-Audio - C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

--
End of file - 5716 bytes

Dopuna: 11 Avg 2008 13:23

moj antivirsuni program je nod32 smart security 3.0.650.0 ne prepoznaje nijedan virus u kompjuteru......

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Poz...




Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 11 Avg 2008
  • Poruke: 65
  • Gde živiš: Vancouver

ComboFix 08-08-10.05 - maki & ika 2008-08-11 22:49:11.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1595 [GMT 2:00]
Running from: C:\Documents and Settings\maki & ika\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
Error: Cfiles.dat

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\maki & ika\Application Data\rhcn18j0ec3n
C:\WINDOWS\system32\blphcj18j0ec3n.scr
C:\WINDOWS\system32\kdnkx.exe
C:\WINDOWS\system32\lphcj18j0ec3n.exe
C:\WINDOWS\system32\msvcsv60.dll
C:\WINDOWS\system32\pphcj18j0ec3n.exe

.
((((((((((((((((((((((((( Files Created from 2008-07-11 to 2008-08-11 )))))))))))))))))))))))))))))))
.

2008-08-11 16:19 . 2008-08-11 16:19 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-08-11 16:19 . 2008-08-11 16:49 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\IDM
2008-08-11 16:19 . 2008-08-11 22:56 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\DMCache
2008-08-10 21:30 . 2008-08-10 21:30 6,409 --a------ C:\WINDOWS\Sysvxd.exe
2008-08-10 14:15 . 2001-08-23 12:00 18,688 --a------ C:\WINDOWS\system32\drivers\cdaudio.sys
2008-08-10 14:15 . 2001-08-23 12:00 18,688 --a--c--- C:\WINDOWS\system32\dllcache\cdaudio.sys
2008-08-10 14:13 . 2008-08-10 14:13 25,088 --a------ C:\WINDOWS\system32\drivers\svchost.exe
2008-08-06 21:39 . 2005-08-30 17:59 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2008-08-06 21:39 . 2005-08-30 17:57 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2008-08-06 21:39 . 2005-08-30 17:58 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2008-08-06 21:39 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2008-08-06 21:39 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2008-08-06 21:39 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2008-08-06 21:39 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2008-08-06 21:38 . 2008-08-06 21:38 <DIR> d-------- C:\Program Files\Samsung
2008-07-30 19:05 . 2008-07-30 19:05 268 --ah----- C:\sqmdata03.sqm
2008-07-30 19:05 . 2008-07-30 19:05 244 --ah----- C:\sqmnoopt03.sqm
2008-07-30 00:50 . 2008-07-30 00:50 268 --ah----- C:\sqmdata02.sqm
2008-07-30 00:50 . 2008-07-30 00:50 244 --ah----- C:\sqmnoopt02.sqm
2008-07-27 01:38 . 2008-08-10 09:45 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\skypePM
2008-07-27 01:38 . 2008-07-27 01:38 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Program Files\Skype
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-07-27 01:36 . 2008-08-10 15:25 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\Skype
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-25 17:30 . 2008-07-25 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\POPWWPROFILES
2008-07-24 14:49 . 2004-11-26 12:16 225,280 --a------ C:\WINDOWS\system32\ReWire.dll
2008-07-24 01:12 . 2008-07-24 01:12 <DIR> d-------- C:\Program Files\Bornemark
2008-07-23 17:08 . 2007-03-14 21:08 157,812 --a------ C:\WINDOWS\system32\trial-reset.exe
2008-07-23 17:06 . 2008-07-23 17:06 <DIR> d-------- C:\Program Files\TruePianos
2008-07-23 16:07 . 2008-07-23 16:10 <DIR> d-------- C:\Program Files\Native Instruments
2008-07-19 21:06 . 2008-08-06 21:40 <DIR> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2008-07-19 21:06 . 2005-11-29 16:17 2,067,140 -ra------ C:\WINDOWS\system32\avcodec.dll
2008-07-19 21:06 . 2006-01-09 13:27 679,936 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2008-07-19 21:06 . 2006-02-07 15:53 659,456 --a------ C:\WINDOWS\system32\FunDecFilter.ax
2008-07-19 21:06 . 2006-02-07 15:54 532,480 --a------ C:\WINDOWS\system32\FunEncFilter.ax
2008-07-19 21:06 . 2005-12-28 13:36 188,416 --a------ C:\WINDOWS\system32\FunOggDecFilter.ax
2008-07-19 21:06 . 2005-12-15 16:53 69,632 --a------ C:\WINDOWS\system32\FunEQFilter.ax
2008-07-19 21:06 . 2006-02-07 15:53 61,440 --a------ C:\WINDOWS\system32\mp4_vcodec.dll
2008-07-19 21:06 . 2005-12-15 16:53 57,344 --a------ C:\WINDOWS\system32\FunVideoAdjustFilter.ax
2008-07-19 21:06 . 2005-12-17 19:40 53,248 --a------ C:\WINDOWS\system32\FunVideoResizeFilter.ax
2008-07-19 21:06 . 2005-12-15 16:54 53,248 --a------ C:\WINDOWS\system32\FunImgFilter.ax
2008-07-19 21:05 . 2005-08-13 05:06 22,486 -ra------ C:\WINDOWS\system32\UnInstall_Driver.ico
2008-07-17 20:04 . 2008-08-06 21:34 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\Samsung
2008-07-17 20:02 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-07-17 20:02 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-07-17 20:01 . 2008-07-19 21:05 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-07-17 20:01 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-07-14 13:54 . 2008-07-14 13:54 40 --a------ C:\WINDOWS\smartvideoconverter.ini
2008-07-14 13:29 . 2008-07-15 23:10 67 --a------ C:\WINDOWS\#1 Video Converter.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-11 17:21 --------- d-----w C:\Program Files\AMT
2008-08-10 18:00 196,608 ----a-w C:\WINDOWS\system32\drivers\nVivid.bin
2008-08-06 19:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-24 12:53 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\Steinberg
2008-07-23 14:43 --------- d-----w C:\Program Files\EDIROL
2008-07-21 17:17 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-21 09:57 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-07 12:08 --------- d-----w C:\Program Files\WinASPI
2008-07-03 00:54 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-06-30 21:29 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-30 21:29 --------- d--h--r C:\Documents and Settings\maki & ika\Application Data\SecuROM
2008-06-26 11:49 196,608 ----a-w C:\WINDOWS\system32\drivers\nAsmedia.bin
2008-06-26 11:39 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-06-20 11:27 --------- d-----w C:\Program Files\ESET
2008-06-18 12:17 --------- d-----w C:\Program Files\AAS
2008-06-18 12:17 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\Applied Acoustics Systems
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 14:19 --------- d-----w C:\Program Files\IK Multimedia
2008-06-12 14:12 --------- d-----w C:\Program Files\DigiDesign
2008-06-12 14:11 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\InstallShield
2008-06-12 13:51 --------- d-----w C:\Program Files\M-Audio
2008-06-12 13:09 --------- d-----w C:\Program Files\Steinberg
2008-06-12 12:59 --------- d-----w C:\Program Files\Cakewalk
2008-06-12 12:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Cakewalk
2008-06-12 12:10 --------- d-----w C:\Program Files\Common Files\Digidesign
2008-06-12 12:09 --------- d-----w C:\Program Files\XLN Audio
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-09-10 16:54 2540976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2007-12-11 04:59 307200]
"M-Audio Taskbar Icon"="C:\WINDOWS\System32\M-AudioTaskBarIcon.exe" [2005-12-13 10:39 91136]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-08-28 10:58 380928]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 77824 C:\WINDOWS\SOUNDMAN.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 MAudioUSBService;M-Audio USB Installer;C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe [2005-12-02 09:20]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-08-28 10:58]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 MAUSB;Service for M-Audio Fast Track Pro Driver (WDM);C:\WINDOWS\system32\DRIVERS\mausb.sys [2005-12-13 10:39]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-08-28 10:58]
R4 atidgllk;atidgllk;C:\WINDOWS\atidgllk.sys [2007-08-28 10:57]
S2 docker19;docker19;C:\WINDOWS\system32\drivers\docker19.sys []
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 11:31]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12c2f3ab-57e6-11dd-a255-0014852fb404}]
\Shell\Auto\command - activexdebugger32.exe f
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL activexdebugger32.exe e
\Shell\explore\Command - activexdebugger32.exe f
\Shell\open\Command - activexdebugger32.exe f

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25a70765-2342-11dd-a1ba-0014852fb404}]
\Shell\AutoRun\command - I:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ff5d2cf-2341-11dd-ab20-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91bf48f8-281f-11dd-a1cc-0014852fb404}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-C:\WINDOWS\system32\kdnkx.exe - C:\WINDOWS\system32\kdnkx.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\maki & ika\Application Data\Mozilla\Firefox\Profiles\l4i3t1ar.default\
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll


**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-08-11 22:56:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\WINDOWS\\system32\\kdnkx.exe"="C:\\WINDOWS\\system32\\kdnkx.exe"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2008-08-11 23:01:38 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-11 21:01:36

Pre-Run: 5,065,531,392 bytes free
Post-Run: 5,361,725,440 bytes free

188 --- E O F --- 2008-07-20 23:54:55

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Upload-uj sledeće file-ove na proveru:

C:\WINDOWS\system32\drivers\nVivid.bin
C:\WINDOWS\system32\trial-reset.exe


preko ovog linka: http://www.mycity.rs/ambulanta-upload.php


-------------------------------------------------------------------------------------



Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\WINDOWS\Sysvxd.exe
C:\WINDOWS\system32\drivers\svchost.exe

Driver::
docker19

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12c2f3ab-57e6-11dd-a255-0014852fb404}]




Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 11 Avg 2008
  • Poruke: 65
  • Gde živiš: Vancouver

uradio sam sve sto si rekao,uploadovao sam ona 2 fajla,hvala unapred



ComboFix 08-08-11.01 - maki & ika 2008-08-12 17:03:04.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1587 [GMT 2:00]
Running from: C:\Documents and Settings\maki & ika\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\maki & ika\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\Sysvxd.exe
.
Error: Cfiles.dat

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\Sysvxd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_docker19


((((((((((((((((((((((((( Files Created from 2008-07-12 to 2008-08-12 )))))))))))))))))))))))))))))))
.

2008-08-12 02:02 . 2008-08-12 02:02 <DIR> d-------- C:\Program Files\Real
2008-08-12 02:02 . 2008-08-12 02:02 <DIR> d-------- C:\Program Files\Common Files\xing shared
2008-08-12 02:02 . 2008-08-12 02:02 <DIR> d-------- C:\Program Files\Common Files\Real
2008-08-11 16:19 . 2008-08-11 16:19 <DIR> d-------- C:\Program Files\Internet Download Manager
2008-08-11 16:19 . 2008-08-11 16:49 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\IDM
2008-08-11 16:19 . 2008-08-12 17:06 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\DMCache
2008-08-10 14:15 . 2001-08-23 12:00 18,688 --a------ C:\WINDOWS\system32\drivers\cdaudio.sys
2008-08-10 14:15 . 2001-08-23 12:00 18,688 --a--c--- C:\WINDOWS\system32\dllcache\cdaudio.sys
2008-08-06 21:39 . 2005-08-30 17:59 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2008-08-06 21:39 . 2005-08-30 17:57 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2008-08-06 21:39 . 2005-08-30 17:58 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2008-08-06 21:39 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2008-08-06 21:39 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2008-08-06 21:39 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2008-08-06 21:39 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2008-08-06 21:38 . 2008-08-06 21:38 <DIR> d-------- C:\Program Files\Samsung
2008-07-30 19:05 . 2008-07-30 19:05 268 --ah----- C:\sqmdata03.sqm
2008-07-30 19:05 . 2008-07-30 19:05 244 --ah----- C:\sqmnoopt03.sqm
2008-07-30 00:50 . 2008-07-30 00:50 268 --ah----- C:\sqmdata02.sqm
2008-07-30 00:50 . 2008-07-30 00:50 244 --ah----- C:\sqmnoopt02.sqm
2008-07-27 01:38 . 2008-08-10 09:45 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\skypePM
2008-07-27 01:38 . 2008-07-27 01:38 56 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Program Files\Skype
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-07-27 01:36 . 2008-08-10 15:25 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\Skype
2008-07-27 01:36 . 2008-07-27 01:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-07-25 17:30 . 2008-07-25 17:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\POPWWPROFILES
2008-07-24 14:49 . 2004-11-26 12:16 225,280 --a------ C:\WINDOWS\system32\ReWire.dll
2008-07-24 01:12 . 2008-07-24 01:12 <DIR> d-------- C:\Program Files\Bornemark
2008-07-23 17:08 . 2007-03-14 21:08 157,812 --a------ C:\WINDOWS\system32\trial-reset.exe
2008-07-23 17:06 . 2008-07-23 17:06 <DIR> d-------- C:\Program Files\TruePianos
2008-07-23 16:07 . 2008-07-23 16:10 <DIR> d-------- C:\Program Files\Native Instruments
2008-07-19 21:06 . 2008-08-06 21:40 <DIR> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2008-07-19 21:06 . 2005-11-29 16:17 2,067,140 -ra------ C:\WINDOWS\system32\avcodec.dll
2008-07-19 21:06 . 2006-01-09 13:27 679,936 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2008-07-19 21:06 . 2006-02-07 15:53 659,456 --a------ C:\WINDOWS\system32\FunDecFilter.ax
2008-07-19 21:06 . 2006-02-07 15:54 532,480 --a------ C:\WINDOWS\system32\FunEncFilter.ax
2008-07-19 21:06 . 2005-12-28 13:36 188,416 --a------ C:\WINDOWS\system32\FunOggDecFilter.ax
2008-07-19 21:06 . 2005-12-15 16:53 69,632 --a------ C:\WINDOWS\system32\FunEQFilter.ax
2008-07-19 21:06 . 2006-02-07 15:53 61,440 --a------ C:\WINDOWS\system32\mp4_vcodec.dll
2008-07-19 21:06 . 2005-12-15 16:53 57,344 --a------ C:\WINDOWS\system32\FunVideoAdjustFilter.ax
2008-07-19 21:06 . 2005-12-17 19:40 53,248 --a------ C:\WINDOWS\system32\FunVideoResizeFilter.ax
2008-07-19 21:06 . 2005-12-15 16:54 53,248 --a------ C:\WINDOWS\system32\FunImgFilter.ax
2008-07-19 21:05 . 2005-08-13 05:06 22,486 -ra------ C:\WINDOWS\system32\UnInstall_Driver.ico
2008-07-17 20:04 . 2008-08-06 21:34 <DIR> d-------- C:\Documents and Settings\maki & ika\Application Data\Samsung
2008-07-17 20:02 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-07-17 20:02 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-07-17 20:01 . 2008-07-19 21:05 <DIR> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-07-17 20:01 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-07-14 13:54 . 2008-07-14 13:54 40 --a------ C:\WINDOWS\smartvideoconverter.ini
2008-07-14 13:29 . 2008-07-15 23:10 67 --a------ C:\WINDOWS\#1 Video Converter.INI

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-12 11:16 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-08-12 00:02 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-12 00:02 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-08-11 17:21 --------- d-----w C:\Program Files\AMT
2008-08-10 18:00 196,608 ----a-w C:\WINDOWS\system32\drivers\nVivid.bin
2008-08-06 19:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-24 12:53 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\Steinberg
2008-07-23 14:43 --------- d-----w C:\Program Files\EDIROL
2008-07-21 17:17 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-21 09:57 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-07-07 12:08 --------- d-----w C:\Program Files\WinASPI
2008-07-03 00:54 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-06-30 21:29 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-06-30 21:29 --------- d--h--r C:\Documents and Settings\maki & ika\Application Data\SecuROM
2008-06-26 11:49 196,608 ----a-w C:\WINDOWS\system32\drivers\nAsmedia.bin
2008-06-20 11:27 --------- d-----w C:\Program Files\ESET
2008-06-18 12:17 --------- d-----w C:\Program Files\AAS
2008-06-18 12:17 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\Applied Acoustics Systems
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 14:19 --------- d-----w C:\Program Files\IK Multimedia
2008-06-12 14:12 --------- d-----w C:\Program Files\DigiDesign
2008-06-12 14:11 --------- d-----w C:\Documents and Settings\maki & ika\Application Data\InstallShield
2008-06-12 13:51 --------- d-----w C:\Program Files\M-Audio
2008-06-12 13:09 --------- d-----w C:\Program Files\Steinberg
2008-06-12 12:59 --------- d-----w C:\Program Files\Cakewalk
2008-06-12 12:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Cakewalk
2008-06-12 12:10 --------- d-----w C:\Program Files\Common Files\Digidesign
2008-06-12 12:09 --------- d-----w C:\Program Files\XLN Audio
.

((((((((((((((((((((((((((((( snapshot@2008-08-11_23.01.17.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-12-08 22:32:40 273,408 ----a-w C:\WINDOWS\system32\pncrt.dll
+ 2008-08-12 00:02:01 278,528 ----a-w C:\WINDOWS\system32\pncrt.dll
+ 2008-08-12 00:02:02 6,656 ----a-w C:\WINDOWS\system32\pndx5016.dll
+ 2008-08-12 00:02:02 5,632 ----a-w C:\WINDOWS\system32\pndx5032.dll
+ 2008-08-12 00:02:05 185,944 ----a-w C:\WINDOWS\system32\rmoc3260.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"IDMan"="C:\Program Files\Internet Download Manager\IDMan.exe" [2007-09-10 16:54 2540976]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2007-12-11 04:59 307200]
"M-Audio Taskbar Icon"="C:\WINDOWS\System32\M-AudioTaskBarIcon.exe" [2005-12-13 10:39 91136]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2008-03-13 16:48 1443072]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-08-28 10:58 380928]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-12 02:02 185896]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 11:09 77824 C:\WINDOWS\SOUNDMAN.EXE]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 MAudioUSBService;M-Audio USB Installer;C:\Program Files\M-Audio\Fast Track Pro\MAUSBInst.exe [2005-12-02 09:20]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-08-28 10:58]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
R3 MAUSB;Service for M-Audio Fast Track Pro Driver (WDM);C:\WINDOWS\system32\DRIVERS\mausb.sys [2005-12-13 10:39]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-08-28 10:58]
R4 atidgllk;atidgllk;C:\WINDOWS\atidgllk.sys [2007-08-28 10:57]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 11:31]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{25a70765-2342-11dd-a1ba-0014852fb404}]
\Shell\AutoRun\command - I:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ff5d2cf-2341-11dd-ab20-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{91bf48f8-281f-11dd-a1cc-0014852fb404}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-08-12 17:06:16
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2008-08-12 17:11:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-12 15:11:50
ComboFix2.txt 2008-08-11 21:01:39

Pre-Run: 5,374,492,672 bytes free
Post-Run: 5,331,693,568 bytes free

189 --- E O F --- 2008-07-20 23:54:55

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Obriši: C:\WINDOWS\system32\trial-reset.exe



Postoje li trenutno neki problemi?

Postavi svež HijackThis logfile.

offline
  • Pridružio: 11 Avg 2008
  • Poruke: 65
  • Gde živiš: Vancouver

obrisao sam ga

za sada nema nikakvih problema,hvala puno jos jednom

dr. Boro,....


da li da odradim svez log sa HijackThis??????

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Nema potrebe. Odradi samo sledeće:


Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


To je sve...

Ko je trenutno na forumu
 

Ukupno su 963 korisnika na forumu :: 24 registrovanih, 3 sakrivenih i 936 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, AC-DC, aleksmajstor, BSD, darkangel, flash12, hyla, ILGromovnik, JOntra, Još malo pa deda, Lord Nem, Lubica, m0nstrum_, Milos82, mrvica78, Nobunaga, pein, Rocky I, sovanova95, Srle993, Stija zmija, vaso1, wizzardone, zlaya011