Ukratko...

Ukratko...

offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

...Kompjuter sa posla se cudno ponasa tj. usporen je do suza. Pokretao je silne procese prilikom startovanja oko 400mb posto sam ugasio silne nepotrebne procese i deinstalirao sve bespotrebne aplikacije sada radi na nekih 200mb. Ima AVG instaliran nakon skeniranja ne prijavljuje viruse.( jako cudno posto taj kompjuter koristi bar 10-ak ljudi.) To me je navelo da probam i sa kaspersky online scan on je pronasao adware komada 8 postavicu log kasperskog i hijack log ako neko ima vremena da pogleda
hvala Ivanho
[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:56 AM, on 3/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\vesna\Desktop\New Folder\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - [Link mogu videti samo ulogovani korisnici]\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - [Link mogu videti samo ulogovani korisnici]
O8 - Extra context menu item: Open in new background tab - [Link mogu videti samo ulogovani korisnici]\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?e9b37259ace4483aab6cedf6e61383ab
O8 - Extra context menu item: Open in new foreground tab - [Link mogu videti samo ulogovani korisnici]\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?e9b37259ace4483aab6cedf6e61383ab
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D69485C-EAB1-42AE-93C1-B5A53F238C5A} (FileInterface Class) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {62CF4D10-EBA7-45DA-ACA0-4B002E8B3A85} (NetSeTManager Class) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} (ProxyModule Class) - [Link mogu videti samo ulogovani korisnici]
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4ECC869-ECC7-4B99-B334-36B8D33FE578}: NameServer = 192.168.1.5
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

--
End of file - 5184 bytes


----------------------------------


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Sunday, March 1, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, February 28, 2009 22:02:15
Records in database: 1856817
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\

Scan statistics:
Files scanned: 83908
Threat name: 8
Infected objects: 12
Suspicious objects: 0
Duration of the scan: 01:17:05


File name / Threat name / Threats count
C:\Documents and Settings\vesna\Local Settings\Temp\mirc63.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro 5.0 GAINBundle\DivXPro5GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro 5.0.2 GAINBundle\DivXPro502GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Codecs\DivX Pro Video Bundle 5.0\DivXPro5GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3102 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\DivX 5.03 Pro\DivXPro503GAINBundle.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.SaveNow.ag 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.SaveNow.aw 1
C:\Documents and Settings\vesna\My Documents\Kodeci\Players\theacidwiz@hemo.net\RadLight 3\RadLight 3.03 [R5].exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
C:\Program Files\mIRC\backups\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.63 1
C:\WINDOWS\Temp\D7C.WUT\vvsdl.cab Infected: not-a-virus:AdWare.Win32.SaveNow.cc 1
D:\Kodak\My Documents\Downloads\Programs\mirc617.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.617 1

The selected area was scanned.



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde ta dva fajla koja smo malopre snimili.



offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

Izvinjavam se zbog kasnjenja nisam radio 2 dana tako da nisam imao pristup netu i racunaru.
[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]


Hvala

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Logovi su čisti - ovde nema aktivnog malware-a.

offline
  • Pridružio: 05 Nov 2008
  • Poruke: 14

Zahvaljujem se u ime preduzec'e Smile

Ko je trenutno na forumu
 

Ukupno su 916 korisnika na forumu :: 60 registrovanih, 14 sakrivenih i 842 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 04bokibole, 357magnum, A.R.Chafee.Jr., alberto, Aleksa 3215, bokicacar, boromir, BOXRR, darionis, DeerHunter, dejno, djboj, DM1994, FOX, frankavoort, Georgius, Goxy1, Hans Gajger, howyesno, ivanb, Jester, Kajzer Soze, Karaula, komsija1, kovac9mm, kuntakinte, Mackomen, Makarid, markolopin, marre, Mi lao shu, mikoyan21, milenko crazy north, miltonhewitt6, MiroslavD, N.e.m.a.nj.a., Ne doznajem se u oružje, nemkea71, OrestSand, Pilence, PlayerOne, prasinar, precan, RAKITNICA, rakivan, repac, S-lash, Sinduk, Siti2, ss10, StankoVrankovic, Titan, Tvrtko I, uruk, vlada13874, Vlada78, wolf431, Zastava, zdrebac, zziko