Ukratko...

Ukratko...

offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

...Kompjuter sa posla se cudno ponasa tj. usporen je do suza. Pokretao je silne procese prilikom startovanja oko 400mb posto sam ugasio silne nepotrebne procese i deinstalirao sve bespotrebne aplikacije sada radi na nekih 200mb. Ima AVG instaliran nakon skeniranja ne prijavljuje viruse.( jako cudno posto taj kompjuter koristi bar 10-ak ljudi.) To me je navelo da probam i sa kaspersky online scan on je pronasao adware komada 8 postavicu log kasperskog i hijack log ako neko ima vremena da pogleda
hvala Ivanho
mycity.rs/must-login.png

mycity.rs/must-login.png

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:56 AM, on 3/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\vesna\Desktop\New Folder\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = runonce.msn.com/?v=msgrv75
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?e9b37259ace4483aab6cedf6e61383ab
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?e9b37259ace4483aab6cedf6e61383ab
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D69485C-EAB1-42AE-93C1-B5A53F238C5A} (FileInterface Class) - online.bancaintesabeograd.com/RetailDLL/FSINT.dll
O16 - DPF: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85} (NetSeTManager Class) - secure.deltabanka.rs/Pages/Download/CABS/DigitrustApiNetSetPlugIn.cab
O16 - DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} (ProxyModule Class) - online.bancaintesabeograd.com/RetailDLL/SGCMSCCD.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4ECC869-ECC7-4B99-B334-36B8D33FE578}: NameServer = 192.168.1.5
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 5184 bytes


----------------------------------


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, March 1, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, February 28, 2009 22:02:15
Records in database: 1856817
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 83908
Threat name: 8
Infected objects: 12
Suspicious objects: 0
Duration of the scan: 01:17:05


File name / Threat name / Threats count
C:\Documents and Settings\vesna\Local Settings\Temp\mirc63.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro 5.0 GAINBundle\DivXPro5GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro 5.0.2 GAINBundle\DivXPro502GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro Video Bundle 5.0\DivXPro5GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\DivX 5.03 Pro\DivXPro503GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.SaveNow.ag 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.SaveNow.aw 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\WINDOWS\Temp\D7C.WUT\vvsdl.cab Infected: not-a-virus:AdWare.Win32.SaveNow.cc 1
D:\Kodak\My Documents\Downloads\Programs\mirc617.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

The selected area was scanned.

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.

offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

Izvinjavam se zbog kasnjenja nisam radio 2 dana tako da nisam imao pristup netu i racunaru.
mycity.rs/must-login.png

mycity.rs/must-login.png


Hvala

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Logovi su čisti - ovde nema aktivnog malware-a.

offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

Zahvaljujem se u ime preduzec'e Smile

Ko je trenutno na forumu
 

Ukupno su 957 korisnika na forumu :: 48 registrovanih, 8 sakrivenih i 901 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., amaterSRB, Amigdala, anta, Bobrock1, comi_pfc, darkojbn, debeli, djboj, flash12, GenZee, HrcAk47, ILGromovnik, Karla, Krvava Devetka, Leonov, Lieutenant, mercedesamg, Mercury, miodrag, Mlav, mrav pesadinac, nebojsag, Njemac, Parker, pavlo, pedja.st, radoznao, rajkoplje, raptorsi, Ripanjac, sasa87, Simon simonović, slonic_tonic, Steeeefan, styg, Sumadija34, Tas011, TheBeastOfMG, Toper, Trpe Grozni, vathra, Vlad000, vladulns, voja64, yrraf, žeks62