[bobby] Log na prvojeru

2

[bobby] Log na prvojeru

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

boby,opet mi je uskocio ali ovaj put ga nema prikazanog u hijackthis a ni gore pomenuti amvo remover nece da ga ukloni?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Daj mi novi HijackThis i ComboFix log. ComboFix skini ponovo, posto je najverovatnije vec updateovan.

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

Evo hijack log a combo stize z par min



Logfile of HijackThis v1.99.1
Scan saved at 20:05:33, on 6/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
D:\Documents and Settings\erin\My Documents\Erin\Windows\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V.....5093096078
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

Dopuna: 01 Jun 2008 20:16

evo i comba(prijavio je bio da je erase amvo.dll neke fajlove)


ComboFix 08-05-29.1 - erin 2008-06-01 20:08:45.3 - NTFSx86
Running from: C:\Documents and Settings\erin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll

.
((((((((((((((((((((((((( Files Created from 2008-05-01 to 2008-06-01 )))))))))))))))))))))))))))))))
.

2008-06-01 15:20 . 2008-06-01 15:20 <DIR> d-------- C:\tmpDownload
2008-06-01 15:20 . 2008-06-01 15:21 <DIR> d-------- C:\tmp
2008-05-30 06:55 . 2008-05-30 06:55 6,144 --ahs---- C:\WINDOWS\Thumbs.db
2008-05-25 22:44 . 2008-05-25 22:44 <DIR> d-------- C:\Documents and Settings\erin\Application Data\ABBYY
2008-05-25 22:43 . 2008-05-25 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ABBYY
2008-05-25 22:40 . 2008-05-25 22:46 <DIR> d-------- C:\Program Files\ABBYY FineReader 7.0 Professional Edition
2008-05-22 22:36 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-05-22 22:36 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-05-22 22:36 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-05-21 12:27 . 2008-05-21 12:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-05-21 12:27 . 2008-05-21 12:28 <DIR> d-------- C:\Documents and Settings\erin\Application Data\Skype
2008-05-21 12:27 . 2008-05-21 12:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-05-21 12:26 . 2008-05-21 12:27 <DIR> d-------- C:\Program Files\Skype
2008-05-20 14:09 . 2008-06-01 13:39 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-05-20 13:55 . 2008-05-20 14:00 <DIR> d-------- C:\Program Files\Fma
2008-05-20 13:55 . 2008-05-20 13:55 <DIR> d-------- C:\Documents and Settings\erin\Application Data\FMA
2008-05-14 00:11 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-13 10:57 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-13 10:57 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-13 10:57 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-12 21:07 . 2008-02-05 17:06 103,367 -r-hs---- C:\2ifetri.cmd
2008-05-12 16:08 . 2008-05-12 16:08 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-12 16:08 . 2008-05-25 12:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-12 16:03 . 2008-05-12 16:04 <DIR> d-------- C:\Program Files\Winamp
2008-05-05 19:38 . 2008-05-27 16:52 316 --a------ C:\WINDOWS\win.ini
2008-05-05 19:23 . 2006-10-18 23:47 8,231,936 --a------ C:\WINDOWS\system32\wmploc.backup
2008-05-05 19:23 . 2006-10-17 13:05 105,984 --a------ C:\WINDOWS\system32\url.backup
2008-05-05 19:21 . 2004-08-04 00:56 8,384,000 --a------ C:\WINDOWS\system32\shell32.backup
2008-05-05 19:20 . 2004-08-04 00:56 983,552 --a------ C:\WINDOWS\system32\setupapi.backup
2008-05-05 19:20 . 2004-08-04 00:56 657,920 --a------ C:\WINDOWS\system32\rasdlg.backup
2008-05-05 19:20 . 2004-08-04 00:56 343,040 --a------ C:\WINDOWS\system32\cmdial32.backup
2008-05-05 19:20 . 2004-08-04 00:56 298,496 --a------ C:\WINDOWS\system32\sysdm.backup
2008-05-05 19:20 . 2004-08-04 00:56 163,840 --a------ C:\WINDOWS\system32\credui.backup
2008-05-05 19:20 . 2004-08-04 00:56 10,752 --a------ C:\WINDOWS\hh.backup
2008-05-05 19:17 . 2008-05-10 18:11 <DIR> d-------- C:\WINDOWS\VIPv3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-01 17:16 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-01 12:43 --------- d-----w C:\Documents and Settings\erin\Application Data\LimeWire
2008-06-01 11:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-01 11:39 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-05-25 10:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\RFA_Backups
2008-05-17 17:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-28 23:10 --------- d-----w C:\Program Files\Common Files\NSV
2008-04-28 18:36 --------- d-----w C:\Documents and Settings\erin\Application Data\ESET
2008-04-28 18:33 --------- d-----w C:\Program Files\ESET
2008-04-28 18:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-04-28 11:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-28 11:46 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-04-26 11:50 --------- d-----w C:\Program Files\Opera
2008-04-20 16:36 --------- d-----w C:\Documents and Settings\erin\Application Data\Teleca
2008-04-16 18:11 --------- d-----w C:\Program Files\Audacity 1.3 Beta
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.

------- Sigcheck -------

2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe

2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll

2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe

2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe

2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe

2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amva]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=

R3 SNPHV71;PC Camera (602a VGA);C:\WINDOWS\system32\DRIVERS\snphv71.sys [2002-11-08 18:24]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43c80b35-0b1c-11dd-9854-e524d390b132}]
\Shell\AutoRun\command - F:\2ifetri.cmd
\Shell\explore\Command - F:\2ifetri.cmd
\Shell\open\Command - F:\2ifetri.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43c80b36-0b1c-11dd-9854-e524d390b132}]
\Shell\AutoRun\command - G:\2ifetri.cmd
\Shell\explore\Command - G:\2ifetri.cmd
\Shell\open\Command - G:\2ifetri.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cecfcedf-c68c-11dc-97c8-f84ff3382347}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Autorun.exe

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-01 20:11:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-01 20:12:44
ComboFix-quarantined-files.txt 2008-06-01 18:12:37

Pre-Run: 16,246,398,976 bytes free
Post-Run: 16,249,831,424 bytes free

144 --- E O F --- 2008-06-01 11:45:49

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Evo ga dropper: C:\2ifetri.cmd
Nije mi samo jasno sta ga je startovalo. Izgleda da ti je ostao neki inficirani USB stick ili HDD, mozda i mobilni ili SD kartica.

Sta su ti drajvovi G: i FConfused
USB ili CD/DVD?

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

USB i to uglavnom od tel(tel G i memorijska F) ali kada sam obrisao prosli put(sve radilo extra) i ja rijesih da formatiram sve usb stick-ove i zadnji mi je opet zarazio.
Sada mi sve opet radi tj ima hidden filles i sve otvara super.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Daj mi nov ComboFix log da sredim registry i da vidim koja je situacija sa fajlovima.

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

ComboFix 08-06-01.3 - erin 2008-06-01 21:51:36.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.48 [GMT 2:00]
Running from: C:\Documents and Settings\erin\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-05-01 to 2008-06-01 )))))))))))))))))))))))))))))))
.

2008-05-30 06:55 . 2008-05-30 06:55 6,144 --ahs---- C:\WINDOWS\Thumbs.db
2008-05-25 22:44 . 2008-05-25 22:44 <DIR> d-------- C:\Documents and Settings\erin\Application Data\ABBYY
2008-05-25 22:43 . 2008-05-25 22:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ABBYY
2008-05-25 22:40 . 2008-05-25 22:46 <DIR> d-------- C:\Program Files\ABBYY FineReader 7.0 Professional Edition
2008-05-22 22:36 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-05-22 22:36 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-05-22 22:36 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-05-22 22:36 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-05-21 12:27 . 2008-05-21 12:27 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-05-21 12:27 . 2008-05-21 12:28 <DIR> d-------- C:\Documents and Settings\erin\Application Data\Skype
2008-05-21 12:27 . 2008-05-21 12:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-05-21 12:26 . 2008-05-21 12:27 <DIR> d-------- C:\Program Files\Skype
2008-05-20 14:09 . 2008-06-01 20:59 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-05-20 13:55 . 2008-05-20 14:00 <DIR> d-------- C:\Program Files\Fma
2008-05-14 00:11 . 2004-08-04 00:56 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-05-13 10:57 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-05-13 10:57 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-05-13 10:57 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-05-12 21:07 . 2008-02-05 17:06 103,367 -r-hs---- C:\2ifetri.cmd
2008-05-12 16:08 . 2008-05-12 16:08 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-12 16:08 . 2008-05-25 12:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-12 16:03 . 2008-05-12 16:04 <DIR> d-------- C:\Program Files\Winamp
2008-05-05 19:38 . 2008-05-27 16:52 316 --a------ C:\WINDOWS\win.ini
2008-05-05 19:23 . 2006-10-18 23:47 8,231,936 --a------ C:\WINDOWS\system32\wmploc.backup
2008-05-05 19:23 . 2006-10-17 13:05 105,984 --a------ C:\WINDOWS\system32\url.backup
2008-05-05 19:21 . 2004-08-04 00:56 8,384,000 --a------ C:\WINDOWS\system32\shell32.backup
2008-05-05 19:20 . 2004-08-04 00:56 983,552 --a------ C:\WINDOWS\system32\setupapi.backup
2008-05-05 19:20 . 2004-08-04 00:56 657,920 --a------ C:\WINDOWS\system32\rasdlg.backup
2008-05-05 19:20 . 2004-08-04 00:56 343,040 --a------ C:\WINDOWS\system32\cmdial32.backup
2008-05-05 19:20 . 2004-08-04 00:56 298,496 --a------ C:\WINDOWS\system32\sysdm.backup
2008-05-05 19:20 . 2004-08-04 00:56 163,840 --a------ C:\WINDOWS\system32\credui.backup
2008-05-05 19:20 . 2004-08-04 00:56 10,752 --a------ C:\WINDOWS\hh.backup
2008-05-05 19:17 . 2008-05-10 18:11 <DIR> d-------- C:\WINDOWS\VIPv3

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-01 19:39 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-06-01 19:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\RFA_Backups
2008-06-01 12:43 --------- d-----w C:\Documents and Settings\erin\Application Data\LimeWire
2008-06-01 11:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-01 11:39 --------- d-----w C:\Program Files\Common Files\Teleca Shared
2008-05-17 17:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-28 23:10 --------- d-----w C:\Program Files\Common Files\NSV
2008-04-28 18:36 --------- d-----w C:\Documents and Settings\erin\Application Data\ESET
2008-04-28 18:33 --------- d-----w C:\Program Files\ESET
2008-04-28 18:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-04-28 11:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-28 11:46 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-04-26 11:50 --------- d-----w C:\Program Files\Opera
2008-04-20 16:36 --------- d-----w C:\Documents and Settings\erin\Application Data\Teleca
2008-04-16 18:11 --------- d-----w C:\Program Files\Audacity 1.3 Beta
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.

------- Sigcheck -------

2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2004-08-04 00:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\dllcache\svchost.exe

2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2004-08-04 00:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\dllcache\ws2_32.dll

2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2004-08-04 00:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\dllcache\winlogon.exe

2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\dllcache\ndis.sys
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys

2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\dllcache\ip6fw.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys

2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\services.exe
2004-08-04 00:56 108032 c6ce6eec82f187615d1002bb3bb50ed4 C:\WINDOWS\system32\dllcache\services.exe

2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\lsass.exe
2004-08-04 00:56 13312 84885f9b82f4d55c6146ebf6065d75d2 C:\WINDOWS\system32\dllcache\lsass.exe

2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\ctfmon.exe
2004-08-04 00:56 15360 24232996a38c0b0cf151c2140ae29fc8 C:\WINDOWS\system32\dllcache\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cecfcedf-c68c-11dc-97c8-f84ff3382347}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Autorun.exe

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-01 21:54:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-06-01 21:56:10
ComboFix-quarantined-files.txt 2008-06-01 19:55:55

Pre-Run: 16,296,108,032 bytes free
Post-Run: 16,284,921,856 bytes free

130 --- E O F --- 2008-06-01 11:45:49

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Gde ovo nestade samo od sebe:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43c80b35-0b1c-11dd-9854-e524d390b132}]
\Shell\AutoRun\command - F:\2ifetri.cmd
\Shell\explore\Command - F:\2ifetri.cmd
\Shell\open\Command - F:\2ifetri.cmd

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43c80b36-0b1c-11dd-9854-e524d390b132}]
\Shell\AutoRun\command - G:\2ifetri.cmd
\Shell\explore\Command - G:\2ifetri.cmd
\Shell\open\Command - G:\2ifetri.cmd


Obrisi sedeci fajl:
C:\2ifetri.cmd

Moze da se desi da ga imas u rootu svih particija, i na USB stickovima/mobilnom.

offline
  • nirre  Male
  • Super građanin
  • Pridružio: 26 Mar 2005
  • Poruke: 1489
  • Gde živiš: Podgorica

bobby ::Gde ovo nestade samo od sebe:

moze li biti da je nestalo jer posle odradjenog combofixa sam pokrenuo opet amvo remover pa kad vidjoh da sve radi izbrisah combo pa sam ga sada opet skinuo da ti dam ovaj zadnji log?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Moguce je da je do tog Amvo removera. Ne znam sta tacno taj alat radi.
Obrisi jos samo onaj fajl sto sam ti rekao, i ocisti stickove.
Ne zaboravi da drzis SHIFT dok ubacujes stickove.

Ko je trenutno na forumu
 

Ukupno su 1377 korisnika na forumu :: 33 registrovanih, 12 sakrivenih i 1332 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., bankulen, bojank, cenejac111, CikaKURE, debeli, dika69, doktor123, draganl, dushan, elenemste, flash12, FOX, hologram, jackreacher011011, janbo, Karla, ladro, laurusri, mercedesamg, Metanoja, milutin134, ozzy, radoznao, raptorsi, Srle993, stagezin, stegonosa, TheBeastOfMG, Webb, Zoca, |_MeD_|, šumar bk2