[ Sybreeder @ 24.01.2010. 12:28 ] @
Poslednjih par dana se desavaju jako cudne stvari sa mojim racunarom! Naime, prvo mi je NOD 32 izbacio sledece upozorenje:
"Virus scanner initialization failed. Most of ESET NOD32 Antivirus modules will not function properly"
Par sati nakon sto sam reinstalirao NOD PC je zablokirao, morao sam da ga restartujem. To se desilo vise puta u toku dana. Sinoc sam gledao seriju i u jednom trenutku je nestao ton, ponovo restart!
Jutros sam hteo da se ulogujem na odredjen forum i kada sam klikuno na box za username, pored 2 username-a, koja cesto koristim, u drop listi mi je izbacio josh jedan koji nikada u zivotu nisam koristio! Kao da se neko ulogovao sa mog kompa! Skenirao sam pc sa NOD 32 v4.0.468 (redovno updatovan), nista nije pronasao. Posle sam uradio scan sa Malwarebytes-om, nasao je 4 zarazena fajla koje sam posle obrisao. Takodje sam koristion ESET Online scanner koji je pronasao sledece fajlove:

C:\Windows\reset.exe Win32/Packed.Autoit.Gen application deleted - quarantined
I:\-DOWNLOADS-\nod40474.rar probably a variant of Win32/Agent trojan deleted - quarantined


Inace redovno updatujem Windows (7 Ultimate).

HJT LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:52:45 PM, on 1/24/2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [USB Gamepad] C:\Windows\USB Vibration\dr100&110\USB Gamepad.exe -boot
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

--
End of file - 4927 bytes
[ magna86 @ 24.01.2010. 13:48 ] @
Skini DDS Program na Desktop
http://download.bleepingcomputer.com/sUBs/dds.scr

Dvoklikom pokreni dds.scr

Kad zavrsi, DDS ce otvoriti dva loga:
1. DDS.txt
2. Attach.txt
Oba izvestaja sacuvaj na Desktop.
Kopiraj mi DDS.txt.
[ Dashkes @ 24.01.2010. 13:49 ] @
U logu nema nista sumnjivo. Za svaki slucaj skenirajte racunar Dr.Web CureIt!-om.
[ Sybreeder @ 24.01.2010. 13:55 ] @

DDS (Ver_09-12-01.01) - NTFSx86
Run by Sybreeder at 14:54:23.63 on Sun 01/24/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_17
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3071.1714 [GMT 1:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Users\Sybreeder\Desktop\dds.scr
C:\Windows\system32\conhost.exe

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [amd_dc_opt] c:\program files\amd\dual-core optimizer\amd_dc_opt.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe
mRun: [USB Gamepad] c:\windows\usb vibration\dr100&110\USB Gamepad.exe -boot
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\users\sybree~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\stardo~1.lnk - c:\program files\stardock\objectdock\ObjectDock.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\sybree~1\appdata\roaming\mozilla\firefox\profiles\ro40ptxt.default\
FF - plugin: c:\users\sybreeder\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-7-15 176128]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-1-21 12672]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-9-29 735960]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-9-29 95896]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2010-1-23 236368]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2010-1-23 19160]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S2 .EsetTrialReset;Eset Trial Reset;c:\windows\system32\regedt32.exe [2009-7-14 9216]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 hid7906;hid7906;c:\windows\system32\drivers\hid7906.sys [2010-1-21 34963]
S3 hid8101;hid8101;c:\windows\system32\drivers\hid8101.sys [2010-1-21 37024]
S3 hid8103;hid8103;c:\windows\system32\drivers\hid8103.sys [2010-1-21 34587]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2010-1-8 16896]

=============== Created Last 30 ================

2010-01-24 11:47:54 0 d-----w- c:\program files\Trend Micro
2010-01-23 19:30:14 0 d-----w- c:\users\sybree~1\appdata\roaming\Malwarebytes
2010-01-23 19:30:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-23 19:30:08 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-23 19:30:08 0 d-----w- c:\programdata\Malwarebytes
2010-01-23 19:30:07 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-23 18:47:39 0 d-----w- c:\users\sybree~1\appdata\roaming\ESET
2010-01-21 18:50:19 977920 ----a-w- c:\windows\system32\wininet.dll
2010-01-21 18:04:17 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-21 15:26:05 37024 ----a-w- c:\windows\system32\drivers\hid8101.sys
2010-01-21 15:26:05 34587 ----a-w- c:\windows\system32\drivers\hid8103.sys
2010-01-21 15:26:04 34963 ----a-w- c:\windows\system32\drivers\hid7906.sys
2010-01-21 15:26:04 0 d-----w- c:\windows\USB Vibration
2010-01-21 15:25:45 0 d-----w- c:\program files\USB Vibration
2010-01-21 00:28:38 69632 ----a-w- c:\windows\system32\jsdriver.dll
2010-01-21 00:28:38 143360 ----a-w- c:\windows\system32\jspage.dll
2010-01-21 00:28:37 0 d-----w- c:\program files\Usb Game Pad
2010-01-20 23:17:03 12672 ----a-w- c:\windows\system32\drivers\cpuz132_x32.sys
2010-01-20 23:17:02 0 d-----w- c:\program files\CPUID
2010-01-14 10:07:12 70656 ----a-w- c:\windows\system32\fontsub.dll
2010-01-14 10:07:12 108544 ----a-w- c:\windows\system32\t2embed.dll
2010-01-11 10:13:04 0 d-----w- c:\program files\Movie Maker 2.6
2010-01-10 17:04:19 0 d-----w- c:\programdata\Ubisoft
2010-01-08 14:27:59 0 d-----w- c:\windows\system32\RTCOM
2010-01-08 14:26:51 0 d--h--w- c:\program files\Temp
2010-01-08 14:21:30 102912 ----a-w- c:\windows\asio4all.dll
2010-01-08 14:21:21 102912 ----a-w- c:\windows\system32\asio4all.dll
2010-01-08 14:21:04 102912 ----a-w- c:\windows\system32\drivers\asio4all.dll
2010-01-08 13:16:50 0 d-----w- c:\users\sybreeder\Tracing
2010-01-08 13:15:03 0 d-----w- c:\program files\Microsoft
2010-01-08 13:14:46 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-08 13:08:25 0 d-----w- c:\program files\common files\Windows Live
2010-01-08 12:05:14 368640 ----a-w- c:\windows\system32\ReWire.dll
2010-01-08 12:05:14 233472 ----a-w- c:\windows\system32\Rex Shared Library.dll
2010-01-08 12:05:14 1324544 ----a-w- c:\windows\system32\SYNSOAIR.DLL
2010-01-08 12:04:34 0 d-----w- c:\program files\common files\VST3
2010-01-08 12:04:34 0 d-----w- c:\program files\common files\Steinberg
2010-01-08 11:29:22 0 d-----w- c:\program files\Steinberg
2010-01-08 11:26:18 16896 ----a-w- c:\windows\system32\drivers\SynasUSB.sys
2010-01-08 11:26:17 757760 ------w- c:\windows\system32\SYNSOACC.dll
2010-01-08 11:26:17 401462 ----a-w- c:\windows\system32\temp.002
2010-01-08 11:11:50 0 d-----w- c:\programdata\Pinnacle
2010-01-08 11:10:57 401462 ----a-w- c:\windows\system32\temp.001
2010-01-08 10:35:47 0 d-----w- c:\program files\common files\DigiDesign
2010-01-08 10:32:40 0 d-----w- c:\program files\ASIO4ALL v2
2010-01-08 10:17:51 0 d-----w- c:\program files\Toontrack
2010-01-07 21:03:11 0 d-----w- c:\program files\MSECache
2010-01-07 21:01:26 16 ----a-w- c:\windows\system32\reg16b77win.dll
2010-01-07 21:01:02 14 ----a-w- c:\windows\system32\pro16b77win.dll
2010-01-07 21:00:33 0 d-----w- c:\program files\Abdio
2010-01-06 21:59:01 0 d-----w- c:\windows\system32\xlive
2010-01-06 21:59:01 0 d-----w- c:\program files\Microsoft Games for Windows - LIVE
2010-01-06 21:57:40 0 d-----w- c:\program files\AMD
2010-01-06 12:18:33 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-01-06 12:18:33 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-01-05 14:40:23 0 d-----w- c:\windows\system32\Adobe
2010-01-04 20:35:51 0 d-----w- c:\windows\PCHEALTH
2010-01-04 20:34:20 0 d-----w- c:\programdata\Microsoft Help
2010-01-04 16:51:15 0 d-----w- c:\program files\VID_0E8F&PID_0003
2010-01-04 15:13:19 8704 ----a-w- c:\windows\system32\drivers\Amfilter.sys
2010-01-04 15:13:19 13824 ----a-w- c:\windows\system32\drivers\Amusbprt.sys
2010-01-04 15:13:13 0 d-----w- c:\program files\A4Tech
2010-01-04 09:40:48 0 d-----w- c:\program files\Smart PC Solutions
2010-01-03 20:56:47 0 d-----w- c:\program files\Game Cam V2
2010-01-03 18:48:52 0 d-----w- c:\program files\Game Graphic Studio
2010-01-03 17:50:30 0 d-----w- c:\program files\VSTPlugins
2010-01-03 17:50:07 0 d-----w- c:\users\sybree~1\appdata\roaming\FXpansion
2010-01-02 05:51:13 0 d-----w- c:\programdata\Apple
2010-01-01 17:07:14 0 d-----w- c:\program files\Stardock
2010-01-01 17:07:14 0 d-----w- c:\program files\common files\Stardock
2010-01-01 15:06:38 156672 ----a-w- c:\windows\system32\rmc_fixasf.exe
2010-01-01 15:06:37 237568 ----a-w- c:\windows\system32\rmc_rtspdl.dll
2010-01-01 14:56:38 323584 ----a-w- c:\windows\system32\AUDIOGENIE2.DLL
2010-01-01 14:56:07 0 d-----w- c:\windows\Replay Media Catcher
2010-01-01 14:55:57 0 d-----w- c:\program files\Replay Media Catcher
2010-01-01 14:20:58 0 d-----w- c:\users\sybree~1\appdata\roaming\Ashampoo
2010-01-01 14:17:03 0 d-----w- c:\programdata\ashampoo
2010-01-01 14:16:42 0 d-----w- c:\program files\Ashampoo
2010-01-01 14:05:01 0 d-----w- c:\program files\common files\DivX Shared
2010-01-01 14:05:00 0 d-----w- c:\program files\DivX
2010-01-01 13:38:18 0 d-----w- c:\programdata\WhereIsIt
2010-01-01 13:38:18 0 d-----w- c:\program files\WhereIsIt
2010-01-01 13:01:35 0 d-----w- c:\programdata\Hewlett-Packard
2010-01-01 11:30:54 0 d-----w- c:\programdata\FLEXnet
2010-01-01 11:27:23 0 d-----w- c:\programdata\Adobe
2010-01-01 11:25:04 0 d-----w- c:\program files\common files\Macrovision Shared
2010-01-01 10:43:37 0 d-----w- c:\users\sybree~1\appdata\roaming\Steinberg
2010-01-01 10:43:26 2892 ----a-w- c:\windows\system32\audcon.sys
2010-01-01 10:43:26 0 d-----w- c:\programdata\Syncrosoft
2010-01-01 10:42:52 401462 ----a-w- c:\windows\system32\temp.000
2010-01-01 10:37:05 0 d-----w- c:\program files\Guitar Pro 5
2010-01-01 10:22:46 0 d---a-w- c:\programdata\TEMP
2010-01-01 10:22:46 0 d-----w- c:\users\sybree~1\appdata\roaming\URSoft
2010-01-01 10:22:38 0 d-----w- c:\program files\Your Uninstaller 2010
2010-01-01 09:29:03 0 d-----w- C:\scripts
2010-01-01 08:09:16 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2009-12-31 19:09:05 0 d-----w- c:\program files\DigiTech
2009-12-31 19:09:04 0 dc-h--w- c:\programdata\{0F75B6CC-232D-4858-B2DB-FA9E000D32EC}
2009-12-31 01:46:02 0 d-----w- c:\program files\The KMPlayer
2009-12-30 23:08:43 0 d-----w- c:\programdata\ATI
2009-12-30 23:07:38 0 d-----w- c:\program files\common files\ATI Technologies
2009-12-30 23:07:25 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-12-30 23:01:55 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2009-12-30 23:01:50 0 d-sh--w- c:\windows\Installer
2009-12-30 22:57:38 0 d-----w- c:\program files\Realtek
2009-12-30 22:54:33 0 d-----w- c:\program files\ATI Technologies
2009-12-30 22:54:31 0 d-----w- c:\program files\ATI
2009-12-30 22:48:54 0 d-sh--w- C:\Recovery
2009-12-30 22:48:53 713888 ----a-w- c:\windows\system32\PerfStringBackup.INI
2009-12-30 22:48:43 0 d-----w- c:\windows\system32\wbem\Performance
2009-12-30 14:35:33 0 ----a-w- c:\windows\ativpsrm.bin
2009-12-30 14:32:52 0 d-----w- c:\windows\Panther
2009-12-30 11:47:38 0 d-----w- c:\programdata\Electronic Arts
2009-12-30 11:34:49 1202 ----a-w- c:\windows\system32\ealregsnapshot1.reg
2009-12-30 11:05:37 440080 ----a-w- c:\windows\system32\d3dx10.dll
2009-12-30 11:04:57 0 d-----w- c:\programdata\KONAMI
2009-12-30 01:30:33 0 d-----w- c:\program files\Cryptload_1.1.8
2009-12-30 00:34:23 0 d-----w- c:\program files\common files\EZB Systems
2009-12-30 00:34:15 0 d-----w- c:\program files\UltraISO
2009-12-30 00:31:07 545 ----a-w- c:\windows\UC.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\RAR.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\PKZIP.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\PKUNZIP.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\NOCLOSE.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\LHA.PIF
2009-12-30 00:31:07 545 ----a-w- c:\windows\ARJ.PIF
2009-12-30 00:31:07 0 d-----w- c:\users\sybree~1\appdata\roaming\GHISLER
2009-12-30 00:31:07 0 d-----w- C:\totalcmd
2009-12-30 00:21:54 257024 ----a-w- c:\windows\system32\msv1_0.dll
2009-12-30 00:21:25 2048 ----a-w- c:\windows\system32\tzres.dll
2009-12-30 00:20:34 728648 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-12-30 00:20:33 2613248 ----a-w- c:\windows\explorer.exe
2009-12-30 00:20:33 1320960 ----a-w- c:\windows\system32\CertEnroll.dll
2009-12-30 00:20:32 507568 ----a-w- c:\windows\system32\winload.exe
2009-12-30 00:20:32 442920 ----a-w- c:\windows\system32\winresume.exe
2009-12-30 00:20:31 293888 ----a-w- c:\windows\system32\atmfd.dll
2009-12-30 00:20:31 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2009-12-30 00:20:30 34816 ----a-w- c:\windows\system32\msasn1.dll
2009-12-30 00:14:11 0 d-----w- c:\users\sybree~1\appdata\roaming\AIMP
2009-12-30 00:12:33 0 d-----w- c:\program files\AIMP2
2009-12-30 00:09:32 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-29 23:36:13 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-29 23:31:51 409088 ----a-w- c:\windows\system32\systemcpl.dll
2009-12-29 23:14:34 0 d-----w- c:\programdata\ESET
2009-12-29 23:14:34 0 d-----w- c:\program files\ESET

==================== Find3M ====================

2010-01-08 14:26:54 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-12-29 23:31:51 13824 ----a-w- c:\windows\system32\slwga.dll
2009-11-30 17:02:40 171144 ----a-w- c:\windows\system32\xliveinstall.dll
2009-11-30 17:02:38 72840 ----a-w- c:\windows\system32\xliveinstallhost.exe
2009-11-06 09:59:54 15406728 ----a-w- c:\windows\system32\xlive.dll
2009-11-06 09:59:54 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2009-10-29 04:48:52 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-10-29 04:48:52 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 14:54:34.71 ===============
[ magna86 @ 24.01.2010. 14:31 ] @
Ovi logovi izgledaju prilicno cisto. Ne bih rekao da ovde ima nesto maliciozno.
No za svaki slucaj mozes odraditi ovo sto ti je @Dashkes napisao.

Sta je u ovom folderu? prazan je?
C:\scripts
[ Sybreeder @ 24.01.2010. 14:36 ] @
u c:\scripts je samo jedna greasemonkey scripta...hteo sam da ubacim scriptu u operu, nista opasno!!!

Evo, upravo skeniram sa Dr web-om, za sada je nasao jedan Trojan.Click.28608

Mozda sam uspeo da ocistim sve sa malwarebytes-om i ESET online scan-om...u svakom slucaju, posle ovog prelazim na neki novi AV...nije prvi put da je NOD zakazao!!!
[ ki111er @ 24.01.2010. 15:22 ] @
Da ne otvaram novu temu pitanje je sledece:
Imam jednog nazovi drugara koji provodi dane i dane cackajuci i zezajuci se sa kompom. I pre nove godine preko MSN-a mi stize poruka od njega da se odjavim za trenutak. Kako sam se odjavio, u tom trenutku zatrepereo mi je monitor cuo sam onaj zvuk za USB i rekoh sta li mi ovaj uradi. Probao sam da se ulogujem tad na MSN izbacalio mi je poruku tipa da je account zauzet i da ne mogu da se ulogujem. Probam jos par puta i izbaci mi to isto. Tad popizdim ulogujem se na hotmail i posaljem mu mail da mi odblokira MSN. Odmah mi je odblokirao i ja ga pitam sta mi je to uradio kaze da je pisao neki program i da se tek sprema za Facebook i Myspace. Tada mi je OS bila 7-ica, od tog trenutka mi se komp cudno ponasa. Instalirao sam win jos 3 puta posle tog ali stalno cujem onaj zvuk kada ubacis USB, nemam instaliran MSN a ne prijavljuje mi nikakav virus Nod 32 i AVG. Ae kazite mi sta da radim, da promenim password na MSN-u, da napomenem da on nije znao password i nemam pojma sta je time uradio mom kompu. Ili sam ja paranoican ili sta. Molim samo objasnjenje o ovom mom problemu? Komp mi ne koci niti sam primetio tako nesto?
[ Aleksandar Maletic @ 24.01.2010. 15:47 ] @
@Sybreeder,to ti je totalna greska,prelazak na drugi AV...do tog zakazivanja nije doslo zbog NOD-a,nego si,ili instalirao krekovanu varijantu ili si ga instalirao kad je vec bilo kasno...gomilu virusa mozes da navuces pri prvom konektovanju na net nakon instaliranja operativnog sistema...a u krajnjem slucaju,treba voditi racuna o svemu,zastita se ne svodi na prosto instaliranje AV-a,jer on moze da ti zastiti sistem nekih 50%,podjednako je bitna i disciplina korisnika...
[ Aleksandar Maletic @ 24.01.2010. 15:49 ] @
Reci cu ti samo jedno: kloni se MSN-a...!!!
[ ki111er @ 24.01.2010. 21:07 ] @
Citat:
Aleksandar Maletic: Reci cu ti samo jedno: kloni se MSN-a...!!!


Ne razumem, Moze li neko objasnjenje?
[ Aleksandar Maletic @ 24.01.2010. 21:26 ] @
Najprostije receno,pun je malware-a i vecina hack afera je povezana sa MSN-om...toliko o tome... :)))
[ ki111er @ 26.01.2010. 22:09 ] @
Hvala.
[ kristi1 @ 27.01.2010. 07:56 ] @
Garantovano je znao pass, zato ti je i trazio da se izlogujes, resenje je da promenis pass, mozes da postavis i DDS log da vidimo da nema neki keylogger ili sl.
[ ki111er @ 28.01.2010. 16:35 ] @
Citat:
kristi1: Garantovano je znao pass, zato ti je i trazio da se izlogujes, resenje je da promenis pass, mozes da postavis i DDS log da vidimo da nema neki keylogger ili sl.


Ma nema sanse taj lik je dolazio samo jednom kod mene...
[ milanzarkov @ 11.02.2010. 10:34 ] @
Resenje za tvoj problem je prilicno jednostavno...smejaces se kad ti kazem. Samo pokreni UPDATE baze virusa. Kad se odradi UPDATE svi servisi koji se nisu startovali prilikom pokretanja antivirusnog programa time bice popaljeni.