Provera

Provera

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 556

juce mi je od jedanput usporio komp u tom trenutku sam imao instaliran nod32 i on nista nije naso pa sam ga izbrisao pa instaliro kaspersky koji je nasao dosta nekih packet trojan pa zelim da proverim da li ima jos neki
https://www.mycity.rs/must-login.png



Logfile of HijackThis v1.99.1
Scan saved at 15:32:35, on 25.1.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TechniSat DVB\bin\Server4PC.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\(HijackThis)\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gg-game.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: UberIcon.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
O4 - Global Startup: Server4PC.lnk = C:\Program Files\TechniSat DVB\bin\Server4PC.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business XII.SP1\RpcSandraSrv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Postavljeni logfile ne pokazuje znakove malware-a.

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 556

ok znaci nema vise virusa ali ne znam sta mi tako koci komp

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Iz tvog prvog posta stekoh utisak da je sada stanje bolje...

No, dobro. Proverićemo još nešto.


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 27 Avg 2005
  • Poruke: 556

pre nego sto sam poceo da skeniram sa ComboFix kaspersky je nasao trojan download i izbrisao ga ja mislim da je sad sve u redu sa kompom ali evo ti log od ComboFix

ComboFix 08-01-23.1C - wizard 2008-01-26 9:09:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.642 [GMT 1:00]
Running from: C:\Documents and Settings\wizard\Desktop\ComboFix(3).exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\0_exception.nls
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\kdlre.exe
C:\WINDOWS\system32\systeminfo.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_RUNTIME
-------\runtime


((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.

2008-01-26 09:08 . <DIR> C:\WINDOWS\LastGood.Tmp
2008-01-26 09:08 . 2001-08-23 13:00 375,808 --a------ C:\WINDOWS\system32\cmd.exe
2008-01-26 09:08 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-25 15:47 . 2008-01-25 15:47 <DIR> d-------- C:\VundoFix Backups
2008-01-25 15:27 . 2008-01-25 15:27 88,205 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-25 15:27 . 2008-01-25 15:27 84,621 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-25 15:26 . 2008-01-26 09:12 3,788,320 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-25 15:26 . 2008-01-26 09:11 54,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-25 15:26 . 2008-01-26 09:13 4,128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-25 15:26 . 2008-01-26 09:11 2,456 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-25 15:20 . 2008-01-25 15:20 <DIR> d-------- C:\kav
2008-01-21 20:20 . 2008-01-21 20:20 65,862 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-01-21 20:19 . 2008-01-21 20:19 5,760,054 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-01-21 20:18 . 2008-01-21 20:20 5,802 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-01-21 20:17 . 2008-01-21 20:17 <DIR> d-------- C:\WINDOWS\BricoPacks
2008-01-21 17:55 . 2008-01-21 17:55 <DIR> d-------- C:\Program Files\Mayoko
2008-01-20 17:24 . 2008-01-20 17:24 0 --a------ C:\WINDOWS\jppc.INI
2008-01-19 16:11 . 2008-01-19 16:11 876 --a------ C:\WINDOWS\$_hpcst$.hpc
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\WINDOWS\Subtitle Downloader
2008-01-17 13:46 . 2008-01-17 13:46 <DIR> d-------- C:\Program Files\Subtitle Downloader
2008-01-13 00:56 . 2008-01-21 20:40 <DIR> d-------- C:\Program Files\iolo
2008-01-13 00:56 . 2006-03-28 08:54 696,320 --a------ C:\WINDOWS\system32\libeay32.dll
2008-01-13 00:56 . 2006-03-28 08:55 155,648 --a------ C:\WINDOWS\system32\ssleay32.dll
2008-01-13 00:56 . 2008-01-13 00:56 406 --a------ C:\WINDOWS\system32\ioloBootDefrag.cfg
2008-01-09 22:40 . 2008-01-09 22:40 17,408 --a------ C:\psapi.dll
2008-01-08 13:22 . 2008-01-08 13:22 <DIR> d-------- C:\Program Files\FireTrust
2008-01-07 18:05 . 2008-01-07 18:05 <DIR> d-------- C:\Program Files\Lavasoft RegHance
2008-01-06 16:23 . 2008-01-25 15:32 <DIR> d-a------ C:\Program Files\(HijackThis)
2008-01-06 15:59 . 2008-01-25 15:27 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-05 11:16 . 2008-01-05 11:16 94 ---h----- C:\WINDOWS\system32\spv1_WCssg.ini
2008-01-05 10:20 . 2008-01-05 10:20 <DIR> d-------- C:\Program Files\SkyGrabber275
2008-01-04 12:53 . 2008-01-07 16:49 <DIR> d-------- C:\Program Files\OpenVPN
2008-01-04 11:32 . 2008-01-17 14:17 <DIR> d-------- C:\Program Files\ProgDVB

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 14:32 --------- d---a-w C:\Program Files\(HijackThis)
2008-01-25 13:48 4,078 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-22 22:44 --------- d-----w C:\Program Files\Winamp
2008-01-14 12:51 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-01-07 17:03 --------- d-----w C:\Program Files\Lavasoft
2008-01-04 10:26 --------- d-----w C:\Program Files\DVB-S PowerInstall
2008-01-04 10:26 --------- d-----w C:\Program Files\Common Files\Elecard
2008-01-01 23:44 --------- d-----w C:\Program Files\vPlug Files Center
2007-11-30 14:12 --------- d-----w C:\Program Files\GameHouse Games Collection
2007-11-28 17:47 --------- d-----w C:\Program Files\AnGo´s Game Collection
2007-11-14 10:40 218,624 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-11-11 06:59 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-11-11 06:59 249,856 ------w C:\WINDOWS\Setup1.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="sm56hlpr.exe" [2004-12-28 23:01 544768 C:\WINDOWS\sm56hlpr.exe]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-09-20 20:52 222472]

C:\Documents and Settings\wizard\Start Menu\Programs\Startup\
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 08:43:08 180224]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Server4PC.lnk - C:\Program Files\TechniSat DVB\bin\Server4PC.exe [2000-11-22 14:39:16 450560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^wizard^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
path=C:\Documents and Settings\wizard\Start Menu\Programs\Startup\Sonic CinePlayer Quick Launch.lnk
backup=C:\WINDOWS\pss\Sonic CinePlayer Quick Launch.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-03-03 12:00 335872 C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2005-08-11 16:30 249856 C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2005-08-11 16:30 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
--a------ 2001-11-29 01:00 28672 C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:56 1667584 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
C:\Program Files\OpenVPN\bin\openvpn-gui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSystemAnalyzer]
C:\Program Files\iolo\System Mechanic Professional 7\SMSystemAnalyzer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskBar]
--a------ 2002-05-08 01:00 122880 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TaskTray]
--a------ 2001-06-29 01:00 163840 C:\Program Files\Creative\SBAudigy\TaskBar\CTLTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
--------- 2000-05-11 01:00 90112 C:\WINDOWS\UpdReg.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINDVDPatch]
--a------ 2002-07-02 10:56 24576 C:\WINDOWS\system32\CTHELPER.EXE

R1 Cinemsup;Cinemsup;C:\WINDOWS\system32\drivers\Cinemsup.sys [2002-07-19 08:10]
R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;C:\WINDOWS\system32\DRIVERS\SkyNET.SYS [2005-08-21 21:12]
S3 SIVDRIVER;SIV Kernel Driver;C:\WINDOWS\system32\Drivers\SIVX32.SYS [2006-01-13 15:29]
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 12:07]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8316a8ef-8f6c-11dc-a1c6-00d0d70ec459}]
\shell\Setup\command - H:\setup.exe

.
Contents of the 'Scheduled Tasks' folder
"2008-01-25 16:17:28 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-26 09:13:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
.
Completion time: 2008-01-26 9:15:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-26 08:15:09

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ko je trenutno na forumu
 

Ukupno su 1380 korisnika na forumu :: 24 registrovanih, 6 sakrivenih i 1350 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Areal84, Bane san, bestguarder, cifra, Djokislav, FileFinder, Georgius, indja, jackreacher011011, krkalon, ladro, laki_bb, maCvele, Mi lao shu, Milometer, Oscar2, Parker, SlaKoj, stegonosa, vathra, vlad the impaler, Volkhov-M, W123, zzapNDjuric99