[ nekoooo @ 29.01.2010. 23:27 ] @
Ne razumem se nesto u zastitu racunara i ovaj problem mi se javlja da ne mogu da skeniram a kad palim komp, nekad se po dva puta zaglavi i tako...da ne pricam puno evo par slika...![]() ![]() ![]() |
[ nekoooo @ 29.01.2010. 23:27 ] @
[ magna86 @ 29.01.2010. 23:48 ] @
Skini program Malwarebytes' Anti-Malware
Dvoklikom pokreni instalaciju Na samom pocetku proveri da li su stiklirane ove opcije Update Malwarebytes' Anti-Malware Launch Malwarebytes Anti-Malware Zatim klikni Finish. Izaberi opciju Perform Quick Scan i klikni Scan. Po zavrsetku procesa klikni OK, Show Results: u listi detektovanog malware-a proveri da li su obelezene sve stavke i klikni Remove Selected. Po zavrsetku ciscenja zakaci MBAM log na forum. .................. Skini DDS Program na Desktop http://download.bleepingcomputer.com/sUBs/dds.scr Dvoklikom pokreni dds.scr Kad zavrsi, DDS ce otvoriti dva loga: 1. DDS.txt 2. Attach.txt Oba izvestaja sacuvaj na Desktop. Kopiraj mi DDS.txt [ nekoooo @ 30.01.2010. 10:34 ] @
Znaci pre toga ne treba da izbrisem nod?
[ Sc0rp10 @ 30.01.2010. 11:22 ] @
Ne.
[ nekoooo @ 30.01.2010. 12:29 ] @
Malwarebytes' Anti-Malware 1.44
Database version: 3662 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 30.1.2010 13:07:50 mbam-log-2010-01-30 (13-07-50).txt Scan type: Quick Scan Objects scanned: 130827 Time elapsed: 7 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\secfile (Trojan.Fakealert) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: D:\Documents and Settings\Srdjo\Start Menu\Programs\Startup\siszyd32.exe (Trojan.Agent) -> Delete on reboot. D:\Documents and Settings\Srdjo\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully. D:\Documents and Settings\NetworkService\Application Data\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully. D:\Documents and Settings\Srdjo\Application Data\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully. ...................... A od DDS-a sam dobio nesto sto sam poslao magni86 na pp [ magna86 @ 30.01.2010. 18:38 ] @
Citat: A od DDS-a sam dobio nesto sto sam poslao magni86 na pp Ma slobodno postavljaj logove ovde ![]() Obrisi taj program (DDS) i skini novi na desktop. Ponovo ga pokreni. kopiraj mi DDS log. I reci mi ima li poboljsanja? [ magna86 @ 30.01.2010. 19:56 ] @
edit:
Mirori DDS Programa:: http://download.bleepingcomputer.com/sUBs/dds.com Skini DDS program sa ovih linkova i skeniraj komp po uputstvu [ nekoooo @ 31.01.2010. 12:41 ] @
E sad sam dobio DSS.txt i Attach.txt
Evo DDS.txt DDS (Ver_09-12-01.01) - NTFSx86 Run by Srdjo at 13:38:07,67 on ned 31.01.2010 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1255 [GMT 1:00] AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} ============== Running Processes =============== D:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe D:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe D:\WINDOWS\system32\spoolsv.exe D:\WINDOWS\Explorer.EXE D:\WINDOWS\system32\RUNDLL32.EXE D:\WINDOWS\RTHDCPL.EXE D:\Program Files\Winamp\winampa.exe D:\Program Files\Java\jre6\bin\jusched.exe D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe D:\Program Files\WinFast\WFDTV\DTVSchdl.exe D:\Program Files\WinFast\WFDTV\WFWIZ.exe D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe D:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe D:\WINDOWS\system32\ctfmon.exe D:\Program Files\Skype\Phone\Skype.exe D:\Program Files\uTorrent\uTorrent.exe D:\Program Files\Windows Live\Messenger\msnmsgr.exe D:\Program Files\WinZip\WZQKPICK.EXE D:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe svchost.exe C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe D:\Program Files\Java\jre6\bin\jqs.exe D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe D:\WINDOWS\system32\nvsvc32.exe D:\WINDOWS\system32\PnkBstrA.exe D:\WINDOWS\system32\PnkBstrB.exe D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe D:\WINDOWS\system32\svchost.exe -k imgsvc D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe D:\Program Files\PC Connectivity Solution\ServiceLayer.exe D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe D:\WINDOWS\system32\wuauclt.exe D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe D:\Documents and Settings\Srdjo\Desktop\dds.com ============== Pseudo HJT Report =============== uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = <local> uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://search.live.com/sphome.aspx uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll mURLSearchHooks: H - No File mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - d:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office12\GRA8E1~1.DLL BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "d:\program files\common files\nero\lib\NMBgMonitor.exe" uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe uRun: [Skype] "d:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [uTorrent] "d:\program files\utorrent\uTorrent.exe" uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Google Update] "d:\documents and settings\srdjo\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [SkyTel] SkyTel.EXE mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [NeroFilterCheck] d:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "d:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [WinampAgent] "d:\program files\winamp\winampa.exe" mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe" mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime mRun: [WinFastDTV] d:\program files\winfast\wfdtv\DTVSchdl.exe mRun: [WinFast Schedule] d:\program files\winfast\wfdtv\WFWIZ.exe mRun: [egui] "d:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice mRun: [<NO NAME>] mRun: [StatusClient] d:\program files\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto mRun: [TomcatStartup] d:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe mRun: [PCSuiteTrayApplication] d:\program files\nokia\nokia pc suite 6\LaunchApplication.exe -startup mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRun: [CTFMON.EXE] d:\windows\system32\CTFMON.EXE dRun: [Nokia.PCSync] d:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog StartupFolder: d:\docume~1\srdjo\startm~1\programs\startup\adobeg~1.lnk - d:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - d:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - d:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - d:\program files\common files\autodesk shared\acstart16.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - d:\program files\winzip\WZQKPICK.EXE IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Google Sidewiki... - d:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office11\REFIEBAR.DLL Trusted Zone: bancaintesabeograd.com\online DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~2\office12\GR99D3~1.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - d:\docume~1\srdjo\applic~1\mozilla\firefox\profiles\i11jdko6.default\ FF - component: d:\documents and settings\srdjo\application data\mozilla\firefox\profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - plugin: d:\documents and settings\srdjo\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: d:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: d:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [2009-3-11 159616] R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [2009-3-11 5248] R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256] R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360] R2 ekrn;ESET Service;d:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840] R2 StarWindService;StarWind iSCSI Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-2 217600] R3 WFIOCTL;WFIOCTL;d:\program files\winfast\wfdtv\WFIOCTL.sys [2009-6-27 9446] S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\google\update\GoogleUpdate.exe [2009-6-28 133104] S2 icivlqm;Config Boot;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336] S2 mvyif;Boot Shell;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336] S2 nvenwtbvt;Microsoft Helper;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336] S2 wefigtj;System Server;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336] =============== Created Last 30 ================ 2010-01-30 11:56:09 0 d-----w- d:\docume~1\srdjo\applic~1\Malwarebytes 2010-01-30 11:56:05 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2010-01-30 11:56:03 19160 ----a-w- d:\windows\system32\drivers\mbam.sys 2010-01-30 11:56:03 0 d-----w- d:\docume~1\alluse~1\applic~1\Malwarebytes 2010-01-30 11:56:02 0 d-----w- d:\program files\Malwarebytes' Anti-Malware 2010-01-15 19:52:18 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys 2010-01-15 19:52:18 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys 2010-01-15 19:52:13 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys 2010-01-15 19:52:13 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys 2010-01-15 19:52:11 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys 2010-01-15 19:52:11 8192 ----a-w- d:\windows\system32\drivers\Changer.sys ==================== Find3M ==================== 2009-12-22 05:42:49 662016 ----a-w- d:\windows\system32\wininet.dll 2009-12-22 05:42:45 81920 ----a-w- d:\windows\system32\ieencode.dll ============= FINISH: 13:38:27,96 =============== [ magna86 @ 31.01.2010. 14:08 ] @
* Skini Combofix program
Poseti ovu stranicu za download linki Uputstvo za koriscenje Combofix programa: http://www.elitesecurity.org/t...e-programa-HijackThis-ComboFix * Privremeno iskljuci svoj AntiVirus program. Poseti ovu stranicu za uputstvo: http://www.bleepingcomputer.com/forums/topic114351.html * Pokreni Combofix! Kad alat zavrsi skeniranje otvorice notepad sa izvestajem (log). Kopiraj taj izvestaj ovde. (tipicna lokacija loga: C:\ComboFix.txt) [ nekoooo @ 31.01.2010. 15:15 ] @
Evo ga:
ComboFix 10-01-30.05 - Srdjo 31.01.2010 16:07:28.1.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1658 [GMT 1:00] Running from: d:\documents and settings\Srdjo\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . D:\setup.exe D:\Thumbs.db d:\windows\n.tmp d:\windows\system32\_000013_.tmp.dll d:\windows\system32\Dvbpws.dll . ((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-31 ))))))))))))))))))))))))))))))) . 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Malwarebytes 2010-01-30 11:56 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes 2010-01-30 11:56 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware 2010-01-15 19:52 . 2004-08-03 21:59 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys 2010-01-15 19:52 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\Changer.sys 2010-01-08 10:24 . 2009-12-16 13:42 43008 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll 2010-01-08 10:24 . 2009-12-16 13:42 340480 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll 2010-01-08 10:24 . 2009-12-16 13:41 346624 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll 2010-01-08 10:24 . 2009-12-16 13:42 872960 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll 2010-01-06 10:20 . 2010-01-06 10:20 -------- d-----w- d:\documents and settings\Srdjo\Local Settings\Application Data\WinZip . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-01-31 14:59 . 2009-11-10 17:52 -------- d-----w- d:\documents and settings\Srdjo\Application Data\uTorrent 2010-01-31 14:59 . 2009-09-20 14:49 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Skype 2010-01-30 10:23 . 2009-09-20 14:55 -------- d-----w- d:\documents and settings\Srdjo\Application Data\skypePM 2010-01-16 09:59 . 2010-01-16 09:59 16 ----a-w- d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat 2010-01-14 06:24 . 2009-12-02 11:22 79488 ----a-w- d:\documents and settings\Srdjo\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-01-13 22:47 . 2009-05-05 12:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help 2010-01-06 10:20 . 2009-03-11 20:46 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip 2010-01-04 16:15 . 2009-06-30 19:16 133120 ----a-w- d:\documents and settings\Srdjo\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe 2009-12-27 18:54 . 2009-12-27 18:54 -------- d-----w- d:\program files\URUSoft 2009-12-27 18:48 . 2009-12-27 18:48 -------- d-----w- d:\program files\TimeAdjuster 2009-12-27 02:03 . 2009-12-27 02:03 -------- d-----w- d:\program files\Microsoft CAPICOM 2.1.0.2 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Microsoft 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live SkyDrive 2009-12-25 23:12 . 2009-12-25 23:12 -------- d-----w- d:\program files\Common Files\Windows Live 2009-12-22 05:42 . 2004-08-03 22:56 662016 ----a-w- d:\windows\system32\wininet.dll 2009-12-22 05:42 . 2004-08-03 22:56 81920 ----a-w- d:\windows\system32\ieencode.dll 2009-12-21 07:53 . 2009-03-11 19:24 -------- d-----w- d:\program files\Google 2009-11-23 12:26 . 2009-10-02 10:00 664 ----a-w- d:\windows\system32\d3d9caps.dat 2009-11-21 16:36 . 2004-08-03 22:56 470528 ----a-w- d:\windows\AppPatch\aclayers.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024] "swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-15 68856] "Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336] "uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-11-10 289584] "msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "Google Update"="d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-04 135664] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SkyTel"="SkyTel.EXE" [2007-06-15 1826816] "NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "nwiz"="nwiz.exe" [2008-10-07 1630208] "NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416] "NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328] "WinampAgent"="d:\program files\Winamp\winampa.exe" [2008-04-01 36352] "SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888] "GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "WinFastDTV"="d:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112] "WinFast Schedule"="d:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816] "egui"="d:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640] "StatusClient"="d:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864] "TomcatStartup"="d:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648] "PCSuiteTrayApplication"="d:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360] "Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896] d:\documents and settings\Srdjo\Start Menu\Programs\Startup\ Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] d:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] Adobe Reader Speed Launch.lnk - d:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-10 10872] WinZip Quick Pick.lnk - d:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "d:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"= "d:\\WINDOWS\\system32\\PnkBstrA.exe"= "d:\\WINDOWS\\system32\\PnkBstrB.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"= "d:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault(tm)\\mohpa.exe"= "d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"= "d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\proobj.exe"= "d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "d:\\Program Files\\LimeWire\\LimeWire.exe"= "d:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"= "d:\\Program Files\\uTorrent\\uTorrent.exe"= "d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "d:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [11.3.2009 20:19 5248] R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256] R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360] R2 ekrn;ESET Service;d:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840] S0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [11.3.2009 20:19 159616] S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\Google\Update\GoogleUpdate.exe [28.6.2009 18:30 133104] S2 icivlqm;Config Boot;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336] S2 mvyif;Boot Shell;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336] S2 nvenwtbvt;Microsoft Helper;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336] S2 wefigtj;System Server;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336] S3 WFIOCTL;WFIOCTL;d:\program files\WinFast\WFDTV\WFIOCTL.sys [27.6.2009 16:34 9446] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs mvyif nvenwtbvt wefigtj icivlqm . Contents of the 'Scheduled Tasks' folder 2010-01-30 d:\windows\Tasks\AppleSoftwareUpdate.job - d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2010-01-31 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30] 2010-01-31 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30] 2010-01-30 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003Core.job - d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33] 2010-01-31 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003UA.job - d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = <local> uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html Trusted Zone: bancaintesabeograd.com\online FF - ProfilePath - d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\ FF - component: d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll . - - - - ORPHANS REMOVED - - - - Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-01-31 16:11 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\icivlqm] "ServiceDll"="d:\windows\system32\kqwxs.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mvyif] "ServiceDll"="d:\windows\system32\kqwxs.dll" -- [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wefigtj] "ServiceDll"="d:\windows\system32\kqwxs.dll" . Completion time: 2010-01-31 16:12:58 ComboFix-quarantined-files.txt 2010-01-31 15:12 Pre-Run: 1.296.629.760 bytes free Post-Run: 2.556.616.704 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer - - End Of File - - 61B8DD1DDFEFD1C33541C12DA4C2C943 [ magna86 @ 31.01.2010. 21:54 ] @
Imas opasne rootkit-ove u sistemu...to pravi problem...
Otvori Notepad i kopiraj tekst koji se nalazi ispod: Citat: File:: d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat d:\windows\system32\kqwxs.dll Driver:: icivlqm mvyif nvenwtbvt wefigtj NetSvcs:: mvyif nvenwtbvt wefigtj icivlqm Registry:: [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\icivlqm] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mvyif] [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wefigtj] Klikni na File\Save as i sacuvaj tekst kao CFScript na desktop ![]() Prati uputstvo sa slike i prevuci CFScript.txt preko ikonice ComboFix.exe To ce startovati ComboFix, mozda ce doci do restarta sistema (to je normalno) Kada zavrsi,pojavice se log koji ces kopirati ovde i reci mi ima li poboljsanja. [ nekoooo @ 01.02.2010. 12:48 ] @
E ima poboljsanja, komp bolje radi i nod je skenirao sve bez problema
Evo uradio sam i ovo poslednje sto je trebalo ComboFix 10-01-31.03 - Srdjo 01.02.2010 13:34:38.2.2 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1610 [GMT 1:00] Running from: d:\documents and settings\Srdjo\Desktop\ComboFix.exe Command switches used :: d:\documents and settings\Srdjo\Desktop\CFScript.txt AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Resident AV is active FILE :: "d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat" "d:\windows\system32\kqwxs.dll" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . D:\Thumbs.db d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat d:\windows\system32\Dvbpws.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ICIVLQM -------\Legacy_MVYIF -------\Legacy_NVENWTBVT -------\Legacy_WEFIGTJ -------\Service_icivlqm -------\Service_mvyif -------\Service_nvenwtbvt -------\Service_wefigtj ((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 ))))))))))))))))))))))))))))))) . 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Malwarebytes 2010-01-30 11:56 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes 2010-01-30 11:56 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys 2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware 2010-01-15 19:52 . 2004-08-03 21:59 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys 2010-01-15 19:52 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys 2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\Changer.sys 2010-01-08 10:24 . 2009-12-16 13:42 43008 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll 2010-01-08 10:24 . 2009-12-16 13:42 340480 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll 2010-01-08 10:24 . 2009-12-16 13:41 346624 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll 2010-01-08 10:24 . 2009-12-16 13:42 872960 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll 2010-01-06 10:20 . 2010-01-06 10:20 -------- d-----w- d:\documents and settings\Srdjo\Local Settings\Application Data\WinZip . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-02-01 12:41 . 2009-11-10 17:52 -------- d-----w- d:\documents and settings\Srdjo\Application Data\uTorrent 2010-02-01 12:41 . 2009-09-20 14:49 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Skype 2010-01-30 10:23 . 2009-09-20 14:55 -------- d-----w- d:\documents and settings\Srdjo\Application Data\skypePM 2010-01-14 06:24 . 2009-12-02 11:22 79488 ----a-w- d:\documents and settings\Srdjo\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-01-13 22:47 . 2009-05-05 12:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help 2010-01-06 10:20 . 2009-03-11 20:46 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip 2010-01-04 16:15 . 2009-06-30 19:16 133120 ----a-w- d:\documents and settings\Srdjo\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe 2009-12-27 18:54 . 2009-12-27 18:54 -------- d-----w- d:\program files\URUSoft 2009-12-27 18:48 . 2009-12-27 18:48 -------- d-----w- d:\program files\TimeAdjuster 2009-12-27 02:03 . 2009-12-27 02:03 -------- d-----w- d:\program files\Microsoft CAPICOM 2.1.0.2 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Microsoft 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live 2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live SkyDrive 2009-12-25 23:12 . 2009-12-25 23:12 -------- d-----w- d:\program files\Common Files\Windows Live 2009-12-22 05:42 . 2004-08-03 22:56 662016 ------w- d:\windows\system32\wininet.dll 2009-12-22 05:42 . 2004-08-03 22:56 81920 ----a-w- d:\windows\system32\ieencode.dll 2009-12-21 07:53 . 2009-03-11 19:24 -------- d-----w- d:\program files\Google 2009-11-23 12:26 . 2009-10-02 10:00 664 ----a-w- d:\windows\system32\d3d9caps.dat 2009-11-21 16:36 . 2004-08-03 22:56 470528 ----a-w- d:\windows\AppPatch\aclayers.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024] "swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-15 68856] "Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336] "uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-11-10 289584] "msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] "Google Update"="d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-04 135664] "ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SkyTel"="SkyTel.EXE" [2007-06-15 1826816] "NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "nwiz"="nwiz.exe" [2008-10-07 1630208] "NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416] "NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136] "NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328] "WinampAgent"="d:\program files\Winamp\winampa.exe" [2008-04-01 36352] "SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888] "GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016] "QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-05-26 413696] "WinFastDTV"="d:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112] "WinFast Schedule"="d:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816] "egui"="d:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640] "StatusClient"="d:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864] "TomcatStartup"="d:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648] "PCSuiteTrayApplication"="d:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360] "Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896] d:\documents and settings\Srdjo\Start Menu\Programs\Startup\ Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] d:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664] Adobe Reader Speed Launch.lnk - d:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-10 10872] WinZip Quick Pick.lnk - d:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432] [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "d:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"= "d:\\WINDOWS\\system32\\PnkBstrA.exe"= "d:\\WINDOWS\\system32\\PnkBstrB.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"= "d:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault(tm)\\mohpa.exe"= "d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"= "d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"= "d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\proobj.exe"= "d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "d:\\Program Files\\LimeWire\\LimeWire.exe"= "d:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"= "d:\\Program Files\\uTorrent\\uTorrent.exe"= "d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "d:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [11.3.2009 20:19 159616] R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [11.3.2009 20:19 5248] R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256] R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360] R2 ekrn;ESET Service;d:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840] R3 WFIOCTL;WFIOCTL;d:\program files\WinFast\WFDTV\WFIOCTL.sys [27.6.2009 16:34 9446] S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\Google\Update\GoogleUpdate.exe [28.6.2009 18:30 133104] . Contents of the 'Scheduled Tasks' folder 2010-01-30 d:\windows\Tasks\AppleSoftwareUpdate.job - d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34] 2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30] 2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job - d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30] 2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003Core.job - d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33] 2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003UA.job - d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33] . . ------- Supplementary Scan ------- . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = <local> uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki... - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html Trusted Zone: bancaintesabeograd.com\online FF - ProfilePath - d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\ FF - component: d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-02-01 13:43 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(2996) d:\program files\ESET\ESET NOD32 Antivirus\eplgHooks.dll d:\windows\system32\msi.dll . ------------------------ Other Running Processes ------------------------ . d:\windows\system32\RUNDLL32.EXE d:\windows\RTHDCPL.EXE d:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe d:\program files\Java\jre6\bin\jqs.exe d:\program files\Nero\Nero8\Nero BackItUp\NBService.exe d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe d:\windows\system32\nvsvc32.exe d:\windows\system32\PnkBstrA.exe d:\windows\system32\PnkBstrB.exe d:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe d:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe d:\windows\system32\wdfmgr.exe d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe d:\program files\PC Connectivity Solution\ServiceLayer.exe d:\program files\Common Files\Nero\Lib\NMIndexingService.exe d:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe d:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2010-02-01 13:46:21 - machine was rebooted ComboFix-quarantined-files.txt 2010-02-01 12:46 ComboFix2.txt 2010-01-31 15:12 Pre-Run: 2.614.505.472 bytes free Post-Run: 2.466.963.456 bytes free - - End Of File - - 5BD33FB67E91C1E0E85B883E3057FF39 [ magna86 @ 01.02.2010. 14:57 ] @
that's it...
![]() Zapakuj ( zip-uj ili rar-uj ) ovaj folder C:\Qoobox i upload-uj ga preko ovog sajta: http://www.speedyshare.com/ link za download mi posalji na PP ........................................................................................... Onda... Klikni START >> RUN U liniju za unos teksta ukucaj "Combofix /Uninstall" i klikni OK ............................................................................................ Deinstaliraj i instaliraj najnoviju verziju Java Skini program JavaRa Kliknuti na Remove older versions Kada to zavrsi i izbaci log fajl, onda kliknuti na Search for updates odabrati donju opciju pa kliknuti na Search To ce odvesti na sajt sa koga treba skinuti i instalirati zadnju verziju Jave [ nekoooo @ 01.02.2010. 19:28 ] @
Uradjeno sve po uputstvu.
magna86, mnogo ti hvala na pomoci i ne znam kako da se oduzim. hvala jos jednom! [ magna86 @ 01.02.2010. 19:42 ] @
Copyright (C) 2001-2025 by www.elitesecurity.org. All rights reserved.
|