hijack. Sta dalje?

hijack. Sta dalje?

offline
  • Pridružio: 25 Okt 2008
  • Poruke: 5

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:39, on 2008-10-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Milosav.LICNO-E55977640.000\Desktop\New Folder\TR3.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24E9519B-3F70-429B-99BC-4B2B49B96F66} - (no file)
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SACert Class - {740FE5FB-65F1-46C5-9E54-A19C8A8D7AC2} - C:\WINDOWS\system32\SoftAheadCert.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-861567501-963894560-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - Global Startup: Pinnacle Scheduler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Statistika mrežnog Anti-Virusa - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.hp.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: HPDCS - {BA135F49-A12C-4E26-A2C4-6EA945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
O20 - Winlogon Notify: khfeDuSI - C:\WINDOWS\
O23 - Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kasperski Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8-) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\Program Files\ReaConverter 5.5 Pro\rcp_scheduler.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 8251 bytes

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Koristiš dva antivirus programa - odluči se za jednog, a drugi deinstaliraj.


Zatim postavi svež HijackThis logfile i opiši na koji način se ispoljavaju problemi oko kojih tražiš pomoć.

offline
  • Pridružio: 25 Okt 2008
  • Poruke: 5

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:17, on 2008-10-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Milosav.LICNO-E55977640.000\Desktop\New Folder\TR3.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24E9519B-3F70-429B-99BC-4B2B49B96F66} - (no file)
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: SACert Class - {740FE5FB-65F1-46C5-9E54-A19C8A8D7AC2} - C:\WINDOWS\system32\SoftAheadCert.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe
O4 - HKLM\..\Run: [Launch Ai Booster] "C:\Program Files\ASUS\Ai Booster\OverClk.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-861567501-963894560-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - Global Startup: Pinnacle Scheduler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Statistika mrežnog Anti-Virusa - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O9 - Extra 'Tools' menuitem: &Quick Login rs-mp3.com - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Funnsystems YuMp3Com-User-Authorization\YuMp3ComLogin.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.hp.com (HKLM)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: HPDCS - {BA135F49-A12C-4E26-A2C4-6EA945999072} - C:\Program Files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
O20 - Winlogon Notify: khfeDuSI - C:\WINDOWS\
O23 - Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kasperski Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8-) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ReaConverter scheduler service (rcp_service) - ReaSoft - C:\Program Files\ReaConverter 5.5 Pro\rcp_scheduler.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 7626 bytes

Dopuna: 25 Okt 2008 16:37

Koristim Kaspersky, medjutim pre par dana poceli su problemi. Nece da otvori jedan hard disk (particija GSmile, morao sam desni klik pa Explore da bih ga otvorio, normalan Open nacin nije hteo. Ponekad se Win zakuca, ponekad izbaci onaj Debug/Don't Send/Send prozor kada otvaram disk G:

Imam licenciranu verziju KAV-a i redovno se azurira (svaki dan), medjutim naso sam na netu neki text, pa sam instalirao Aviru, on mi je pri skeniranju nasao nekog trojanca (TR/Pass(zabranjeno).B) putanja je bila u nekom Temp folderu u Documets&Settings na disku C:

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.





Arrow Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 25 Okt 2008
  • Poruke: 5

ComboFix 08-10-24.02 - Milosav 2008-10-25 16:59:18.2 - NTFSx86
Running from: C:\Documents and Settings\Milosav.LICNO-E55977640.000\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\RECYCLER\ADAPT_Installer.exe
C:\resycled
C:\resycled\boot.com
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\system32\crtdbgpm.dll
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\w32apiw.dll
C:\WINDOWS\system32\wpcap.dll
G:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Legacy_OREANS32
-------\Service_NPF
-------\Service_oreans32


((((((((((((((((((((((((( Files Created from 2008-09-25 to 2008-10-25 )))))))))))))))))))))))))))))))
.

2008-10-25 13:27 . 2008-10-25 13:27 <DIR> d-------- C:\Program Files\Trend Micro
2008-10-25 11:40 . 2008-10-25 11:45 <DIR> d-------- C:\Documents and Settings\Milosav.LICNO-E55977640.000\Application Data\uTorrent
2008-10-25 09:14 . 2008-10-25 09:14 <DIR> d-------- C:\Documents and Settings\Milosav.LICNO-E55977640.000\Application Data\ABBYY
2008-10-24 22:40 . 2008-10-24 22:40 <DIR> d-------- C:\Documents and Settings\Milosav.LICNO-E55977640.000\Application Data\RCP 5
2008-10-24 22:33 . 2008-10-24 22:33 <DIR> d-------- C:\Documents and Settings\Milosav.LICNO-E55977640.000\Application Data\ATI
2008-10-24 22:32 . 2008-10-24 22:32 <DIR> d-------- C:\Documents and Settings\Milosav.LICNO-E55977640.000
2008-10-24 22:19 . 2008-10-24 22:19 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\RCP 5
2008-10-24 13:09 . 2008-10-24 13:09 67 --a------ C:\WINDOWS\tpw.ini
2008-10-23 19:14 . 2008-10-23 19:16 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-10-22 16:53 . 2008-10-22 16:53 <DIR> d-------- C:\Documents and Settings\Administrator
2008-10-22 09:18 . 2008-10-22 09:18 0 --a------ C:\ARK64.tmp
2008-10-21 19:57 . 2008-10-21 19:58 <DIR> d-------- C:\Program Files\Audacity 1.3 Beta (Unicode)
2008-10-18 23:38 . 2008-10-18 23:51 <DIR> d-------- C:\TP
2008-10-10 14:46 . 2008-10-22 13:16 <DIR> d-------- C:\Program Files\web convertor to avi
2008-10-09 21:16 . 2008-10-09 21:18 <DIR> d-------- C:\Program Files\DVDZip 4.0
2008-10-09 21:16 . 1999-09-10 12:06 5,600 --a------ C:\WINDOWS\system\WINASPI.DLL
2008-10-09 21:16 . 1999-09-10 12:06 4,672 --a------ C:\WINDOWS\system\WOWPOST.EXE
2008-10-09 18:11 . 2004-08-03 22:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-10-09 18:11 . 2004-08-03 22:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-10-09 18:10 . 2008-10-09 18:10 <DIR> d-------- C:\Program Files\Logitech
2008-10-09 18:10 . 2008-10-09 18:10 <DIR> d-------- C:\Program Files\Common Files\Logitech
2008-10-09 18:10 . 2004-04-14 10:54 163,840 --a------ C:\WINDOWS\system32\WmJoyFrc.dll
2008-10-09 18:10 . 2004-04-14 11:08 44,064 --a------ C:\WINDOWS\system32\drivers\WmXlCore.sys
2008-10-09 18:10 . 2004-04-14 11:08 21,280 --a------ C:\WINDOWS\system32\drivers\WmFilter.sys
2008-10-09 18:10 . 2004-04-14 11:08 10,144 --a------ C:\WINDOWS\system32\drivers\WmBEnum.sys
2008-10-09 18:10 . 2004-04-14 11:08 5,600 --a------ C:\WINDOWS\system32\drivers\WmVirHid.sys
2008-10-09 17:57 . 2008-03-05 15:56 3,786,760 --a------ C:\WINDOWS\system32\D3DX9_37.dll
2008-10-06 15:48 . 2008-10-06 15:48 87 --a------ C:\WINDOWS\dswplug.ini
2008-10-06 15:47 . 2000-12-22 22:27 73,728 --a------ C:\WINDOWS\system32\mplaw7.dll
2008-10-06 15:47 . 2000-12-22 22:19 73,728 --a------ C:\WINDOWS\system32\mplaa6.dll
2008-10-06 15:47 . 2000-12-22 22:19 61,440 --a------ C:\WINDOWS\system32\mplam6.dll
2008-10-06 15:47 . 2000-12-22 14:11 19,968 --a------ C:\WINDOWS\system32\cpuinf32.dll
2008-10-06 15:45 . 2008-10-06 15:45 <DIR> d-------- C:\Program Files\Ulead Systems
2008-10-06 15:45 . 2008-10-06 15:45 <DIR> d-------- C:\Program Files\Common Files\SONY Digital Images
2008-10-04 18:52 . 2008-10-04 18:52 <DIR> d-------- C:\Program Files\VSO
2008-10-04 18:52 . 2004-05-04 12:53 1,645,320 --a------ C:\WINDOWS\gdiplus.dll
2008-10-04 18:52 . 2006-05-20 17:16 1,184,984 --a------ C:\WINDOWS\system32\wvc1dmod.dll
2008-10-04 18:52 . 2006-05-11 20:21 626,688 --a------ C:\WINDOWS\system32\vp7vfw.dll
2008-10-04 18:52 . 2006-09-29 13:24 217,127 --a------ C:\WINDOWS\system32\drv43260.dll
2008-10-04 18:52 . 2006-09-29 13:25 208,935 --a------ C:\WINDOWS\system32\drv33260.dll
2008-10-04 18:52 . 2006-09-29 13:26 176,165 --a------ C:\WINDOWS\system32\drv23260.dll
2008-10-04 18:52 . 2007-03-18 21:37 65,602 --a------ C:\WINDOWS\system32\cook3260.dll
2008-10-04 13:39 . 2008-10-08 07:58 613 --a------ C:\WINDOWS\0
2008-10-04 13:39 . 2008-10-08 07:58 95 --a------ C:\WINDOWS\99999
2008-10-04 13:39 . 2008-10-08 07:59 90 --a------ C:\WINDOWS\Numerical
2008-10-04 13:39 . 2008-10-08 07:59 88 --a------ C:\WINDOWS\Spatial
2008-10-04 13:39 . 2008-10-08 07:59 87 --a------ C:\WINDOWS\Verbal
2008-10-04 13:39 . 2008-10-08 07:59 87 --a------ C:\WINDOWS\Memory
2008-10-04 13:39 . 2008-10-08 07:59 86 --a------ C:\WINDOWS\Logic
2008-10-04 13:39 . 2008-10-08 07:59 84 --a------ C:\WINDOWS\Fun
2008-10-04 13:34 . 2008-10-04 13:35 <DIR> d-------- C:\Program Files\GameTop.com
2008-10-04 13:33 . 2008-10-04 13:33 <DIR> d-------- C:\Program Files\Oak Systems
2008-10-04 13:24 . 2008-10-10 21:58 376 --a------ C:\WINDOWS\wTRTv5.ini
2008-10-04 13:23 . 2008-10-04 13:29 <DIR> d-------- C:\Program Files\worldTVRT
2008-10-03 22:38 . 2008-10-03 22:40 <DIR> d-------- C:\Dev-Pas
2008-10-03 13:58 . 2008-10-03 13:58 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\7Wonders2
2008-10-03 13:44 . 2008-10-03 13:44 45,056 --a------ C:\WINDOWS\NCUNINST.EXE
2008-10-03 13:42 . 2008-10-03 13:42 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2008-10-02 18:48 . 2008-10-02 18:48 <DIR> d-------- C:\Program Files\HDD Health
2008-10-02 18:48 . 2008-10-02 18:48 <DIR> d-------- C:\Program Files\AVI ReComp
2008-10-01 19:49 . 2008-10-01 19:49 <DIR> d-------- C:\WINDOWS\Funnsystems
2008-10-01 19:49 . 2008-10-01 19:49 <DIR> d-------- C:\Program Files\Funnsystems YuMp3Com-User-Authorization
2008-10-01 09:08 . 2008-10-01 09:08 <DIR> d-------- C:\Program Files\EngAdven
2008-10-01 09:08 . 2008-10-01 09:08 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\engadven
2008-09-27 21:10 . 2008-09-27 21:10 <DIR> d-------- C:\divx
2008-09-26 20:23 . 2008-09-26 20:23 <DIR> d-------- C:\Program Files\Real
2008-09-26 20:23 . 2008-09-26 20:23 <DIR> d-------- C:\Program Files\MSN Messenger

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-25 15:04 40,158,752 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-25 15:03 1,443,616 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-25 15:01 561,716 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-25 15:01 145,712 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-25 14:15 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-10-25 14:09 --------- d-----w C:\Program Files\Warcraft III
2008-10-25 11:50 --------- d-----w C:\Program Files\Garena
2008-10-22 10:58 --------- d-----w C:\Program Files\CodedColor
2008-10-21 18:59 --------- d-----w C:\Program Files\VeryPDF PDF2Word v3.0
2008-10-21 18:49 --------- d-----w C:\Program Files\Pure Sudoku
2008-10-21 18:37 --------- d-----w C:\Program Files\Any Video Converter Professional
2008-10-21 18:01 --------- d-----w C:\Program Files\MediaCoder
2008-10-21 13:22 --------- d-----w C:\Program Files\GordianKnot
2008-10-18 15:17 3,532 ----a-w C:\drmHeader.bin
2008-10-14 12:13 --------- d-----w C:\Program Files\Hattrick Forever
2008-10-12 07:13 --------- d-----w C:\Program Files\DivX
2008-10-09 16:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-06 13:52 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Ulead Systems
2008-10-04 16:52 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-10-03 11:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\CodedColor
2008-10-02 16:48 --------- d-----w C:\Program Files\XviD
2008-10-02 16:48 --------- d-----w C:\Program Files\AviSynth 2.5
2008-09-24 18:33 --------- d-----w C:\Program Files\Makayama Interactive
2008-09-21 09:56 --------- d-----w C:\Program Files\FreeUndelete
2008-09-20 13:13 88,064 ----a-w C:\WINDOWS\AMUninst01c.exe
2008-09-20 13:13 --------- d-----w C:\Program Files\Change Extension
2008-09-20 12:39 --------- d-----w C:\Program Files\URUSoft
2008-09-13 15:08 --------- d-----w C:\Program Files\Pegasus Imaging
2008-09-10 20:14 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-09-10 20:09 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-10 20:09 --------- d-----w C:\Program Files\Bonjour
2008-09-10 19:59 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-09-08 06:36 --------- d-----w C:\Program Files\Norton PC Checkup
2008-09-08 06:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-07 15:54 --------- d-----w C:\Program Files\VideoReDoPlus
2008-09-07 15:54 --------- d-----w C:\Program Files\E.M. PowerPoint Video Converter
2008-09-07 15:54 --------- d-----w C:\Program Files\All Sound Recorder XP
2008-09-07 15:53 --------- d-----w C:\Program Files\Avidemux 2.4
2008-09-05 11:22 --------- d-----w C:\Program Files\ReaConverter 5.5 Pro
2008-09-05 11:21 --------- d-----w C:\Program Files\Easy Real Converter
2008-09-04 20:07 98,304 ----a-w C:\WINDOWS\system32\SoftAheadCert.dll
2008-09-04 20:07 33,824 ----a-w C:\WINDOWS\system32\drivers\oreans32.sys
2008-09-04 20:02 --------- d-----w C:\Program Files\FormatFactory
2008-09-04 14:07 --------- d-----w C:\Program Files\PhotoStudio
2008-09-04 14:06 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\byngo
2008-09-04 12:49 --------- d-----w C:\Program Files\Exact Audio Copy
2008-09-04 12:47 --------- d-----w C:\Program Files\FDRLab
2008-09-02 12:37 --------- d-----w C:\Program Files\(zabranjeno)PDF
2008-08-31 16:21 --------- d-----w C:\Program Files\EasyBiorhythmCalculator
2008-08-31 09:54 --------- d-----w C:\Program Files\Photobie
2008-08-31 09:54 --------- d-----w C:\Program Files\NCH Software
2008-08-31 09:13 --------- d-----w C:\Program Files\Sudoku Challenge
2008-08-30 07:18 --------- d-----w C:\Program Files\artPrint v1.2
2008-08-26 15:20 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\X3mE Yamb
2008-08-26 14:51 --------- d-----w C:\Program Files\AllToAVI
2008-07-26 10:35 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"PCTVRemote"="C:\Program Files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe" [2002-10-11 61699]
"Launch Ai Booster"="C:\Program Files\ASUS\Ai Booster\OverClk.exe" [2005-06-16 3627520]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2007-06-28 218376]
"RTHDCPL"="RTHDCPL.EXE" [2005-05-25 C:\WINDOWS\RTHDCPL.EXE]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Pinnacle Scheduler.lnk - C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe [2008-05-20 241664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoChangeAnimation"= 0 (0x0)
"NoStrCmpLogical"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.PIM1"= PCLEPIM1.dll
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\vio\dvacm.acm
"msacm.MPEGacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
"msacm.avis"= ff_acm.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.ACDV"= ACDV.dll
"VIDC.MJPG"= pvmjpg30.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\DiskTrix\\UltimateDefrag\\UDefrag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder

2008-10-25 C:\WINDOWS\Tasks\GlaryInitialize.job
- C:\Program Files\Glary Utilities\initialize.exe [2008-04-09 13:22]
.
- - - - ORPHANS REMOVED - - - -

BHO-{24E9519B-3F70-429B-99BC-4B2B49B96F66} - (no file)
Notify-khfeDuSI - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Milosav.LICNO-E55977640.000\Application Data\Mozilla\Firefox\Profiles\qjukhbxk.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
.
.
------- File Associations -------
.
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-10-25 17:03:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Photodex\ProShowProducer\scsiaccess.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2008-10-25 17:08:34 - machine was rebooted [Milosav]
ComboFix-quarantined-files.txt 2008-10-25 15:08:30

Pre-Run: 21,879,848,960 bytes free
Post-Run: 21,944,664,064 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

255

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Kakvo je sada stanje?

offline
  • Pridružio: 25 Okt 2008
  • Poruke: 5

Hehe, radi sve perfekt. Hvala puno!!!

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Preostaje još da uradiš sledeće:
Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore



To je sve.

offline
  • Pridružio: 25 Okt 2008
  • Poruke: 5

Done! Hvala jos jednom.

Ko je trenutno na forumu
 

Ukupno su 812 korisnika na forumu :: 49 registrovanih, 6 sakrivenih i 757 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Bane san, Bloody, bojank, Boskovic, caesar, comi991, Cufo, djboj, dozorni, dragoljub11987, dragon986, Drug pukovnik, dukikan, dzoni19, flash12, FOX, Georgius, goxin, ivicasimo, Jovan Nenad, laki_bb, MB120mm, mercedesamg, Mercury, Mixelotti, mnn2, moldway, pedja.st, proleter373, RiV, rovac, sakota79, samsung, shone34, Simon simonović, Sirius, slonic_tonic, suton, Tenk, Toni, Tragač, trajkoni018, virked, vlvl, vsn111, willie, Zi0mek, zixo