Problem so Windows

Problem so Windows

offline
  • Pridružio: 21 Avg 2007
  • Poruke: 56

Imam eden problem.. KIS 7.0 imam instalirano i mi pokazuva Hidden Data Sending na nekoja si IP adresa ... napraiv log fajl od HijackThis...
Pozdrav


Logfile of HijackThis v1.99.1
Scan saved at 14:37:21, on 19.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
D:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\Program Files\Opera\Opera.exe
D:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\FIN\Desktop\ab\ab.exe

O2 - BHO: (no name) - {4AA7B12D-AB2C-4D16-BCFB-704945A98FDD} - C:\WINDOWS\system32\opnooml.dll (file missing)
O2 - BHO: (no name) - {A41C10D3-D309-45B7-BBB7-FD46034F7272} - C:\WINDOWS\system32\hgggg.dll
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\elchaoep.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Game Device] C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\caodmepj.dll",sitypnow
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: hgggg - C:\WINDOWS\system32\hgggg.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav, BaDMaN19...

Pokreni HijackThis, skeniraj i štikliraj sledeće linije:

02 - BHO: (no name) - {4AA7B12D-AB2C-4D16-BCFB-704945A98FDD} - C:\WINDOWS\system32\opnooml.dll (file missing)
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"

a zatim klikni na Fix Checked.

--------------------

Preuzmi VundoFix:
http://www.atribune.org/ccount/click.php?id=4

* Dvoklikom se startuje fajl VundoFix.exe.
* Izabere opcija Scan for Vundo.
* Posle završenog skeniranja i pojave poruke Done Searching for files klikne se na OK.
* Sada, kada je skeniranje obavljeno potrebno je kliknuti na opciju Remove Vundo.
* Po pojavljivanju upita o uklanjaju Vundo fajlova klikne se na Yes.
* Pokretanje ove opcije učiniće Desktop privremeno praznim u cilju pripreme sistema za uklanjanje Vundo-a.
* Po završetku, pojaviće se obaveštenje o gašnjenju računara, klikne se OK.
* Uključi se računar i podigne sistem iznova.

--------------------

Nakon toga:
1) Preuzmi program SmitfraudFix sa ovog linka.

2.) Extract-uj program na desktop. (Takodje na ovaj način pripremi i program Hijack This koje će se kasnije koristiti)

3.) Restartuj računar i podigni sistem u Safe Mode-u. [ Safe Mode info link

4.) Pronadji na desktop-u folder gde si raspakovao SmitfraudFix program i dvoklikom pokreni fajl SmitfraudFix.cmd.
Kada se alat za uklanjanje prvi put startuje pokazaće ti se ekran za odobrenje. Jednostavno pretisni bilo koje dugme na tastaturi da bi prešao na sledeći nivo.

5.)



6.) Program će početi sa čišćenjem kompjutera. Posle završenog čišćenja SmitfraudFix-om
pokrenuće ti se Windows-ov program Disk Cleanup.



--------------------

Pronađi i obriši folder:

C:\Program Files\Save

--------------------

U idućoj poruci postavi novi HijackThis log, C:\vundofix.txt i C:\rapport.txt.

offline
  • Pridružio: 21 Avg 2007
  • Poruke: 56

Eve gi logovite od site tri programi...Pisi ako treba uste nesto
Pozdrav

SmitFraudFix v2.226

Scan done at 14:22:40,08, 20.09.2007
Run from C:\Documents and Settings\FIN\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FIN


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\FIN\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\FIN\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{46C3D4C9-EC60-464F-A6F3-62FE0AF6B5AF}: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{AE40986D-FD0D-458D-8B49-03A0E50ADC3B}: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.7.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=10.3.0.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.7.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


VundoFix V6.5.8

Checking Java version...

Sun Java not detected
Scan started at 14:11:46 20.09.2007

Listing files found while scanning....

C:\WINDOWS\system32\ggggh.bak1
C:\WINDOWS\system32\ggggh.bak2
C:\WINDOWS\system32\ggggh.ini
C:\WINDOWS\system32\ggggh.ini2
C:\WINDOWS\system32\ggggh.tmp
C:\WINDOWS\system32\gvethkkj.dll
C:\WINDOWS\system32\hgggg.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ggggh.bak1
C:\WINDOWS\system32\ggggh.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ggggh.bak2
C:\WINDOWS\system32\ggggh.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ggggh.ini
C:\WINDOWS\system32\ggggh.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ggggh.ini2
C:\WINDOWS\system32\ggggh.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ggggh.tmp
C:\WINDOWS\system32\ggggh.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\gvethkkj.dll
C:\WINDOWS\system32\gvethkkj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\hgggg.dll
C:\WINDOWS\system32\hgggg.dll Has been deleted!

Performing Repairs to the registry.
Done!


Logfile of HijackThis v1.99.1
Scan saved at 14:31:59, on 20.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\DAEMON Tools\daemon.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Cyberlink\Shared files\RichVideo.exe
C:\Program Files\OpenVPN\bin\openvpn.exe
C:\Program Files\Opera\Opera.exe
C:\Documents and Settings\FIN\Desktop\ab\ab.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {152B972F-E0E6-4977-8FFA-CB3C9E0458CC} - C:\WINDOWS\system32\hgggg.dll (file missing)
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\gknrsmqm.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - C:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] D:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Game Device] C:\PROGRA~1\Genius\G-08GA~1\JoyUpDrv.EXE
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\jrpobswd.dll",sitypnow
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pokreni HijackThis, skeniraj i čekiraj sledeće linije:

O2 - BHO: (no name) - {152B972F-E0E6-4977-8FFA-CB3C9E0458CC} - C:\WINDOWS\system32\hgggg.dll (file missing)
O2 - BHO: (no name) - {E64F0381-0053-4842-B3E5-08F6C4A0AEB6} - C:\WINDOWS\system32\gknrsmqm.dll
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Common Files\WinAntiVirus Pro 2007\mav_startupmon.exe"
O4 - HKLM\..\Run: [FolderView] rundll32.exe "C:\WINDOWS\system32\jrpobswd.dll",sitypnow
O20 - Winlogon Notify: opnooml - C:\WINDOWS\
O20 - Winlogon Notify: winxby32 - C:\WINDOWS\

a zatim klikni na Fix Checked ( pri tome IE treba biti zatvoren ).

Restartuj kompjuter a zatim pronađi i obriši:

C:\Program Files\Common Files\WinAntiVirus Pro 2007\
C:\WINDOWS\system32\jrpobswd.dll

U idućoj poruci postavi novi HijackThis log.

Dopuna: 27 Sep 2007 9:42

BaDMaN19, hoćemo li raditi dalje na ovome?

Prošlo je nedelju dana... Ukoliko se ne javiš u narednih par dana, tema ide u arhivu.

offline
  • Pridružio: 21 Avg 2007
  • Poruke: 56

Ok e, fala mnogu se sredija rabotite.. Pozdrav

Ko je trenutno na forumu
 

Ukupno su 1140 korisnika na forumu :: 54 registrovanih, 6 sakrivenih i 1080 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, Areal84, Atomski čoban, babaroga, Bobrock1, Boris90, comi_pfc, Dimitrije Paunovic, djboj, Djokislav, Dorcolac, flash12, FOX, ginjica, gomago, grenadir, havoc995, Herman Terrance Aubrey, Insan, jaeger, krkalon, Kubovac, Levi, Lošmi, M1los, madza, mercedesamg, Mi lao shu, MiG-29M2, milenko crazy north, milutin134, Mixelotti, mnn2, nenad81, pacika, Parker, randja26, Rogan33, royst33, S2M, samsung, Sančo, sasa87, slonic_tonic, Smiljke, Srky Boy, Srle993, Steeeefan, Vatreni Zmaj, VJ, vladaa012, wizzardone, YU-UKI, zodiac94