Šta dalje??

2

Šta dalje??

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Hvala za fajl, stigao je i potvrdjujem da je u pitanju maliciozan fajl.
Pronadji sve kopije tog fajla kod sebe na disku i obrisi ih. Takodje mozes obrisati i C:\Submit.zip jer nam vise ne treba.

Sto se tice one poruke koja ti se pojavila, to te tvoj NOD pita da li zelis da uradis upgrade na noviju verziju. Ovo vise ne spada u nas domen odlucivanja.

Log ti je sada cist. Da li se jos javljaju preusmeravanja prilikom ukljucivanja IE-a ?

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Goooood morning MySity!
Našao sam par tih fajlova (prodsrvs.exe) u system-u32 i obrisao ih.Sad ostaje da sačekam i vidim da li je problem rešen.
Nego imam par pitanja i jedan predlog.
- bobby pitaš me da li mi se javljaju preusmeravanja prilikom uključivanja na internet.Da li to misliš na pojavljivanje sajta koji mi pravi probem(mi je pravio problem).
- Da li da čuvam HijackThis (da li služi samo za log-ovanje).
Jedno pitanje koje nije u vezi sa temom(obrišite ako mislite da je potrebno).Gde da potražim uputstvo za ubacivanje sličice sa strane pisma i koja je svrha tekstova u dnu pisma?
Jedan predlog(možda nije za ambulantu).Od kako koristim int. nisam naišao na nešto bolje od MyCity-ja...organizacija, teme, podforumi, kompleksni i detaljni odgovori i naravno svi oni koji su to omogućili!!!!
Ali da li bi mogla da se otvori jedna tema(verovatno u Antivirusima)koja bi pomogla mnogima nedovoljno upućenim u mogućnosti kompa. kako bi izbegli bespotrebno lutanje int-om. i skupljanje raznih virusa.Konkretno mislim na programe koji to sprečavaju.
Čitajući podforume u Antivirusima mogu da kažem da se tu manje iskusni korisnici (a i iskusniji) mogu baš zbuniti, jer je sve u stilu ovaj program je bolji - ovaj nije ...ovaj ima ovu manu - ovaj onu itd.Naravno da svaki ima i prednosti i mane.
Zato nije loše da napravite jednu listu (po abecednom redu zbog mnogih skeptika u vezi rangiranja) 5 - 10 programa svih Antivirus podforuma kako freeware tako i buy i tako rešite mnoge nedoumice i probleme u vezi naših životnih saputnika.
Eto i ja sam već 2h. bez smetnji na int-u.Izgleda da je problem rešen.
Zato momci (bez izuzetaka) i svi ostali još jednom Veliko Hvala i zdravi mi bili!!!!!!
Pozdrav Maha!!

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Za sliku sa leve strane, koja se naziva avatar, ides skroz gore na vrhu sajta na opciju Profil, i tu mozes da podesavas i avatar, i tvoj potpis koji ce da se pojavljuje ispod poruka.

Sto se tice predloga teme o antivirusima, urednici sajta ne mogu tu puno da ti pomognu iz razloga sto MyCity ima jako dobru saradnju sa par antivirus firmi, pa smo odlucili da ne dajemo korisnicima preporuke tipa "uzmi ovaj antivirus, on je dobar" da bi smo odrzali dobre odnose sa antivirus kompanijama.
Bolje ni nemoj da otvaras takvu temu na forumu, posto ih je bilo vec par desetina, i uvek se svede na to da svako ima svog ljubimca kog ce da ti preporuci.

Sto se naseg problema ovde tice, moje pitanje se odnosilo na onu pocetnu stranicu u Internet Exploreru koja ti je predstavljala problem, za koju rece da se vise ne pojavljuje.

Ja cu ovu temu da ostavim otvorenom jos nedelju dana, pa ako se infekcija vrati ti se onda javi. Nakon nedelju dana temu prebacujem u Arhivu, pa ces morati da mi posaljes Privatnu Poruku ukoliko se infekcija vrati nakon toga.

Veliki pozdrav

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Hvala bobby!

Što se programa tiče preporučite Antivirus, Anti spy/ad/malware, Firewall od firmi sa kojima saradjujete i tako no problem!Da napomenem uputstva sa ex - Super Sajta su prava stvar.
To da svako ima svog ljubimca stoji ali mislim da ste i stručniji i kompetentniji za preporuku.

Dopuna: 13 Mar 2007 12:58

Ha..Prerano se radujem.Eto meni opet lepih devojčica.
bobby šta sad??

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Postavi mi novi HJT log da vidimo sta i kako.
Da li se ova infekcija pojavila nakon instalacije nekog programa?
Puno free programa dolaze sa ovakvim "dodacima", narocito screensaveri.
Da li se pojavila nakon skidanja nekog video ili audio fajla sa p2p mreza (emule, torrent...)?
Fajlovi koji se po defaultu otvaraju u Windows Media Playeru mogu da izazovu ovakav tip infekcije.

Jel ista od ovoga sto sam nabrajao?

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Evo novog HJT-a.

Logfile of HijackThis v1.99.1
Scan saved at 13:41:57, on 13.3.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\VisualTooltip\VisualToolTip.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Musicmatch\Musicmatch Jukebox\MMDiag.exe
D:\Super Utilities\SuperUtil.exe
D:\Super Utilities\SuperUtil.exe
C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\DOCUME~1\-\LOCALS~1\Temp\{C65B97CF-008F-4462-9640-367A52D1CCFD}\Blaero Start Orb.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\-\Desktop\Hijack This\airmj.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKLM\..\Run: [VisualTooltip] C:\Program Files\VisualTooltip\VisualToolTip.exe
O4 - HKLM\..\Run: [Blaero Start Orb] C:\Program Files\Blaero Start Orb\Blaero Start Orb.exe
O4 - HKLM\..\Run: [Styler] C:\Program Files\Styler\Styler.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Utilities] D:\Super Utilities\SuperUtil.exe /min
O4 - HKCU\..\Run: [smartwallpaper] C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{77930581-C0D7-454A-8055-4FBF5FB69BB1}: NameServer = 82.208.208.10 213.246.55.5
O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

Skinuo sam i instalirao samo GOM Player i Musicmatch Jukebox ..a da i 44 skins for Winamp.možda i neke wallpaper-e?
Sigurno nisam ništa otvarao WMP-om.Koristim KM Player , CyberLink PowerDVD , MV2Player.

Dopuna: 13 Mar 2007 13:52

Još i ovo smartwallpaper.exe skinuto i instalirano.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Vidim gde je problem. Treba mi malo vremena da pripremim uputstvo za otklanjanje.

Dopuna: 13 Mar 2007 14:19

Skini FixWareout sa jedne od sledecih adresa:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Snimi ga na desktop i pokreni instalaciju. U toku instalacije ce biti ponudjena opcija Run fixit koja treba da bude ukljucena.
Odmah nakon instalacije ce poceti skeniranje, nakon cega ce da ti zatrazi restartovanje racunara.
Kada se racunar restartuje, posle ucitavanja Desktopa ce na ekranu da se pojavi log fajl kojeg ces nam ovde iskopirati.

Nakon toga idi dole na Start > Run> tu ukucaj CMD i stisni Enter.
U konzoli koja ce da se otvori ukucaj ipconfig /flushdns i stisni Enter.

Nakon svega toga, napravi svez HJT log da vidimo sta smo uspeli da sredimo a sta nismo.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"ATICCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\cli.exe\" runtime -Delay"
"nod32kui"="\"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE"
"LClock"="C:\\Program Files\\LClock\\LClock.exe"
"Vista Sidebar"="C:\\Program Files\\Vista Sidebar\\sidebar.exe"
"VisualTooltip"="C:\\Program Files\\VisualTooltip\\VisualToolTip.exe"
"Blaero Start Orb"="C:\\Program Files\\Blaero Start Orb\\Blaero Start Orb.exe"
"Styler"="C:\\Program Files\\Styler\\Styler.exe"
"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"
"xdbtyawi"="c:\\windows\\system32\\xdbtyawi.exe xdbtyawi"
"MimBoot"="C:\\PROGRA~1\\Musicmatch\\Musicmatch Jukebox\\mimboot.exe"
"MMTray"="\"C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Super Utilities"="D:\\Super Utilities\\SuperUtil.exe /min"
"smartwallpaper"="C:\\Program Files\\Ectosoft\\Smart Wallpaper Lite\\smartwallpaper.exe"
"Free Download Manager"="C:\\Program Files\\Free Download Manager\\fdm.exe -autorun"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»

Ovo je valjda to što se traži.

A evo i svežeg HJT-a.

Logfile of HijackThis v1.99.1
Scan saved at 16:06:26, on 13.3.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CDBurnerXP\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\VisualTooltip\VisualToolTip.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\-\LOCALS~1\Temp\{16D2B358-5B5C-4E81-ADB5-9581F0F42B8E}\Blaero Start Orb.exe
D:\Super Utilities\SuperUtil.exe
C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe
D:\Super Utilities\SuperUtil.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\CMD.exe
C:\Documents and Settings\-\Desktop\Hijack This\airmj.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.windowsxlive.net
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [Vista Sidebar] C:\Program Files\Vista Sidebar\sidebar.exe
O4 - HKLM\..\Run: [VisualTooltip] C:\Program Files\VisualTooltip\VisualToolTip.exe
O4 - HKLM\..\Run: [Blaero Start Orb] C:\Program Files\Blaero Start Orb\Blaero Start Orb.exe
O4 - HKLM\..\Run: [Styler] C:\Program Files\Styler\Styler.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\Musicmatch\Musicmatch Jukebox\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Super Utilities] D:\Super Utilities\SuperUtil.exe /min
O4 - HKCU\..\Run: [smartwallpaper] C:\Program Files\Ectosoft\Smart Wallpaper Lite\smartwallpaper.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
O4 - Startup: Y'z ToolBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{77930581-C0D7-454A-8055-4FBF5FB69BB1}: NameServer = 82.208.208.10 213.246.55.5
O20 - AppInit_DLLs: C:\PROGRA~1\Agnitum\OUTPOS~1\wl_hook.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1\outpost.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Izgled da si zapatio neku novu nepoznatu vrstu wareouta.
Sumnjiv mi je sledeci fajl:
c:\windows\system32\xdbtyawi.exe

Uploaduj mi ga na http://www.mycity.rs/ambulanta-upload.php da ga posaljem tipu koji pravi FixWareout.

Ja sada izlazim iz stana, bicu tu ponovo veceras.

offline
  • maha  Male
  • Super građanin
  • Pridružio: 06 Dec 2006
  • Poruke: 1152

Taj fajl ga nema tamo gde si mi rekao da tražim.

Ko je trenutno na forumu
 

Ukupno su 868 korisnika na forumu :: 18 registrovanih, 2 sakrivenih i 848 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., Boris90, comi_pfc, laki_bb, loon123, Marko Marković, Mixelotti, operniki, procesor, raketaš, repac, S2M, stegonosa, wolverined4, wulfy, yrraf, zdrebac