Problem sa Google-om

2

Problem sa Google-om

offline
  • Pridružio: 21 Maj 2004
  • Poruke: 316
  • Gde živiš: Nis

Ovako izgleda SDFix log:

DFix: Version 1.68

Run by nn - uto 27.02.2007 @ 23:26:38,21

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
MsLS32

Path:
"C:\WINDOWS\MsLS32.exe"

MsLS32 Deleted

Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\inet20126\www.google.com\index.html - Deleted
C:\WINDOWS\inet20126\www.google.com\thank.html - Deleted
C:\WINDOWS\inet20126\www.google.com\Google_files\hp0.gif - Deleted
C:\WINDOWS\inet20126\www.google.com\Google_files\hp1.gif - Deleted
C:\WINDOWS\inet20126\www.google.com\Google_files\hp2.gif - Deleted
C:\WINDOWS\inet20126\www.google.com\Google_files\hp3.gif - Deleted
C:\Documents and Settings\nn\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\nn\Local Settings\Temp\6.dllb - Deleted
C:\WINDOWS\system32\eraseme_24155.exe - Deleted
C:\DOCUME~1\nn\LOCALS~1\Temp\temp_3702390.bat - Deleted
C:\DOCUME~1\nn\LOCALS~1\Temp\temp_3702781.bat - Deleted
C:\DOCUME~1\nn\LOCALS~1\Temp\temp_3713593.bat - Deleted
C:\WINDOWS\system32\drivers\etc\hosts.tim - Deleted
C:\WINDOWS\system32\TFTP1288 - Deleted
C:\WINDOWS\system32\TFTP1304 - Deleted
C:\WINDOWS\system32\TFTP1368 - Deleted
C:\WINDOWS\system32\TFTP1604 - Deleted
C:\WINDOWS\system32\TFTP1608 - Deleted
C:\WINDOWS\system32\TFTP1616 - Deleted
C:\WINDOWS\system32\TFTP1640 - Deleted
C:\WINDOWS\system32\TFTP1668 - Deleted
C:\WINDOWS\system32\TFTP1672 - Deleted
C:\WINDOWS\system32\TFTP1716 - Deleted
C:\WINDOWS\system32\TFTP1824 - Deleted
C:\WINDOWS\system32\TFTP1828 - Deleted
C:\WINDOWS\system32\TFTP184 - Deleted
C:\WINDOWS\system32\TFTP1932 - Deleted
C:\WINDOWS\system32\TFTP196 - Deleted
C:\WINDOWS\system32\TFTP2024 - Deleted
C:\WINDOWS\system32\TFTP2032 - Deleted
C:\WINDOWS\system32\TFTP2216 - Deleted
C:\WINDOWS\system32\TFTP240 - Deleted
C:\WINDOWS\system32\TFTP256 - Deleted
C:\WINDOWS\system32\TFTP2592 - Deleted
C:\WINDOWS\system32\TFTP2612 - Deleted
C:\WINDOWS\system32\TFTP3124 - Deleted
C:\WINDOWS\system32\TFTP320 - Deleted
C:\WINDOWS\system32\TFTP3724 - Deleted
C:\WINDOWS\system32\TFTP420 - Deleted
C:\WINDOWS\system32\TFTP576 - Deleted
C:\WINDOWS\system32\TFTP804 - Deleted
C:\WINDOWS\system32\TFTP896 - Deleted
C:\WINDOWS\system32\TFTP908 - Deleted
C:\WINDOWS\system32\TFTP932 - Deleted
C:\WINDOWS\system32\TFTP992 - Deleted


Folder C:\WINDOWS\inet20126 - Removed

ADS Check:

C:\WINDOWS\system32
No streams found.


Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"c:\\cs.exe"="C:\\cs.exe:*:Enabled:Server"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"c:\\cs.exe"="C:\\cs.exe:*:Enabled:Server"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\download\www.infostud.com\stipendije\Thumbs.db
C:\WINDOWS\system32\config\default.tmp.LOG
C:\WINDOWS\system32\config\software.tmp.LOG
C:\WINDOWS\system32\config\system.tmp.LOG

Add/Remove Programs List:

1337player (remove only)
EA SPORTS online 2005
AC3Filter (remove only)
Conexant AccessRunner USB ADSL WAN Adapter
Adobe Photoshop 7.0
Adobe Shockwave Player
ATI - Software Uninstall Utility
ATI Display Driver
BitComet 0.70
Call of Duty
SafeCast Shared Components
MetaFrame Presentation Server Web Client for Win32
CUR_CONVERTER
CutePDF Writer 2.7
Deluxe Ski Jump 3 v1.4.0
Dictionary 2000 5.5
DivX 4.11 Codec
DNJ Recnik 1.00
eMusic - 50 Free MP3 offer
EvilLyrics
ffdshow (remove only)
FlashDiskManager V4.03
FLV Player 1.3.3
FTP Voyager 12.3
GetRight
Grammatica
Izvrçni deo GTK+ 2.6.9 rev a (samo uklanjanje)
Hair Pro 2005 Light
HijackThis 1.99.1
ICQ 5.1
IDP Companion
Call of Duty - United Offensive
Active Virus Shield
Intermex IndOk DEMO
Intermex Interakta - Krivicni postupak DEMO
Intermex PCC demo
Intermex Sudska Praksa DEMO
K-Lite Codec Pack
MetaProducts Offline Explorer Pro
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
mIRC
Mozilla Firefox (1.5.0.9)
MV2Player (remove only)
Oxford Advanced Genie
QuickTime
RealPlayer
Shareaza verzija 2.2.1.0
Adobe Flash Player 9 ActiveX
Skype 2.5
Table Tennis Pro V2 Lite (V2.32)
Tefter
ICQ Toolbar
Total Commander (Remove or Repair)
Trillian
Vozacki Testovi 1.5
Winamp (remove only)
WinMPG Video Convert 5.4
WinRAR archiver
WinZip
Wonderland v1.04
X-Lite 3.0
AOL Security Toolbar
XviD MPEG-4 Codec
XviD MPEG-4 Video Codec
ZoneAlarm
Zuma Deluxe 1.0
ATI Control Panel
InstallRTC
Google Toolbar for Internet Explorer
Google Earth
Microsoft AutoRoute 2001
Microsoft Office 2003 programski dodatak za preslovljavanje
ArcSoft PhotoImpression 4
Moorhuhn Soccer
ASUS GameFace
Microsoft .NET Framework 2.0
Java 2 Runtime Environment, SE v1.4.2_04
Active Virus Shield
Ford Racing 2
Windows Live Messenger
Microsoft Office Professional Edition 2003
Digimax Viewer 2.1
Call of Duty - United Offensive
Adobe Reader 8
ACDSee 9 Photo Manager
Microsoft .NET Framework 1.1
Kurir 2007
FIFA 2005
SoundMAX
Windows Live Sign-in Assistant
Digimax Reader

Finished
A ovako svež HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 23:44:25, on 27.2.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Samsung\Digimax Viewer 2.1\STImgBrowser.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\programs\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.infosky.net/
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTP06568 Class - {311F9DE8-6126-4EEE-B15F-65CBB3B4F9F6} - C:\Program Files\AOL Security Toolbar\AOL_security_toolbar.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - C:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: AOL Security Toolbar - {3BB63FD4-3C00-44D7-94A9-5DE211900DEF} - C:\Program Files\AOL Security Toolbar\AOL_security_toolbar.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [System CSRSS Patch] scrtkfg.exe
O4 - Startup: .protected
O4 - Startup: desktop(2).ini
O4 - Global Startup: .protected
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download the &current page with Offline Explorer - file://C:\Program Files\Offline Explorer Pro\Add_AllO.htm
O8 - Extra context menu item: Download using Offline &Explorer - file://C:\Program Files\Offline Explorer Pro\Add_UrlO.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\update.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.d.....o-eula.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Con.....0440352000
O17 - HKLM\System\CCS\Services\Tcpip\..\{093C636E-88A9-4BC6-9663-32B6F9E2C3DF}: NameServer = 77.105.0.2 77.105.0.17
O17 - HKLM\System\CS1\Services\Tcpip\..\{093C636E-88A9-4BC6-9663-32B6F9E2C3DF}: NameServer = 77.105.0.2 77.105.0.17
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Program Files\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Hvala vam svima na pomoći. Upravo sam video da je problem rešen tj. google sajt mi ponovo radi. Tako da možete da zaključate temu. Samo mi prvo objasnite o kom virusu se ovde radilo (prvi put sam se sreo sa virusima koji blokiraju otvaranje samo jednog sajta).

HVALA JOŠ JEDNOM SVIMA NA POMOĆI! WELL DONE Smile

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Filipe, ajde pronadji sledeci fajl:
C:\SDFix\backups\backups.zip
I uploaduj ga ovde:
http://www.mycity.rs/ambulanta-upload.php

Pokusaj takodje da uploadujes i sledece fajlove:
C:\cs.exe
scrtkfg.exe (ovaj ces morati da potrazis u kom je folderu)

Dopuna: 27 Feb 2007 23:48

Nije gotovo, racunar je jos zarazen.

offline
  • Pridružio: 21 Maj 2004
  • Poruke: 316
  • Gde živiš: Nis

Uspeo sam da upoladujem samo prvi fajl (C:\SDFix\backups\backups.zip )

Ostala 2 nisam pronašao.Nema ih na navedenim lokacijama.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Startuj ponovo HJT, skeniraj, pa stikliraj polja ispred sledecih linija:
R3 - URLSearchHook: (no name) - _{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)
O4 - HKLM\..\RunServices: [System CSRSS Patch] scrtkfg.exe
O4 - Startup: .protected
O4 - Startup: desktop(2).ini
O4 - Global Startup: .protected
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: Digimax Viewer 2.1.lnk = ?
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/runaware.d.....o-eula.cab

Klikni Fix Checked

Nakon toga potrazi i obrisi sledeci folder:
C:\Program Files\TV Media\

Na kraju, restartuj racunar i postavi svez log HJT-a.

Dopuna: 12 Mar 2007 1:33

Posto se Filip ne javlja, tema ide u arhivu.

12 Mar 2007 01:34 bobby Zaključavanje topica Razlog: Javiti se na PP ukoliko je potrebno aktiviranje teme  
Ko je trenutno na forumu
 

Ukupno su 851 korisnika na forumu :: 42 registrovanih, 8 sakrivenih i 801 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: anta, Atomski čoban, bankulen, bojank, Boris90, cikadeda, dankisha, darionis, drimer, dushan, FOX, Georgius, Ivica1102, Karla, Krvava Devetka, laurusri, Lošmi, mercedesamg, Metanoja, mik7, milenko crazy north, MiroslavD, mrav pesadinac, Ne doznajem se u oružje, nemkea71, nikoladim, nuke92, Oscar, pein, Pohovani_00, radoznao, rodoljub, Romibrat, Srle993, stegonosa, Tvrtko I, vathra, vladulns, vlajkox, wolverined4, zeo, šumar bk2