[ xman25 @ 27.05.2010. 17:24 ] @
Sumnjam da imam neki skriveni proces pa molim analizu HijackThis log file-a:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:18:17, on 27.5.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Windows\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Windows\VM305_STI.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Your Uninstaller 2010\urmain.exe
C:\Program Files\Your Uninstaller 2010\urmain.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Aca\Desktop\HiJackThis\Acika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/...=aus&qkw=%s&tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.rs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Windows Live pomagač za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Aca\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/con....1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia....ockwave/cabs/flash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Media Center Support Service (Jasmio.MediaCenter.Service) - Unknown owner - C:\Program Files\Jasmio\Media Center Support Service\Jasmio.MediaCenter.Service.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2010c\RpcAgentSrv.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

--
End of file - 9559 bytes
[ Aleksandar Maletic @ 27.05.2010. 17:27 ] @
Stikliraj samo ovo:

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)

...nista vise ja ovde ne vidim...kakve manifestacije imas, zasto si siguran da je prisutan malware?
[ xman25 @ 27.05.2010. 17:37 ] @
Primetio sam da mi zauzece procesora varira 0-30% a da mi nista nije aktivno. tj. bude npr. otvoren samo browser a ne surfujem.
[ Aleksandar Maletic @ 27.05.2010. 18:19 ] @
Mozda je browser u pitanju...pokusaj sa drugim da vidis da li ce biti isti simptomi...skini Dr.Web CureIt http://www.freedrweb.com/cureit/ , odradi prvo Express scan, ako nista ne nadje odradi i Complete scan, to ce malo potrajati...
[ xman25 @ 27.05.2010. 18:52 ] @
Odradio sam i sa njim, sve sam zivo proterao.
[ Aleksandar Maletic @ 27.05.2010. 19:24 ] @
Mislim da to nisu reakcije od malware-a, procesor bi u task-u skakao mnogo vise...pogledaj dobro startup, ocisti history itd...
[ magna86 @ 27.05.2010. 21:08 ] @
za pocetak deinstaliraj Google Chrome browser pa reci jel ima poboljsanja

edit: posle deinstalacije pokreni "wise registry cleaner" (imas portable verziju na officijalnom sajtu) i pocisti registry
[ xman25 @ 27.05.2010. 23:04 ] @
Odradio sve ali i dalje isto. evo sad mi je otvorena Mozilla (dosta tabova je otvoreno) i iskoriscenost cpu-a brzo dize i spusta i dodje i do 55%. A procesor nikakvu radnju ne obradjuje, osim sto je Mozilla otvorena. Ne znam da li je to normalno?
[ Aleksandar Maletic @ 27.05.2010. 23:11 ] @
Kada ti je vise tabova otvoreno normalno je da se opterecenje procesora poveca...da li ti procesor varira isto tako kada nista ne radis tj kada ne aktiviras nijednu aplikaciju?
[ xman25 @ 27.05.2010. 23:47 ] @
Izgleda da je sve ipak bilo samo do gomile otvorenih tabova. Bez pokretanja ikakve aplikacije cpu varira od 0-5%. Navika mi je da drzim uvek dosta otvorenih tabova jer mi je tako zgodno da se brzo krecem medju njima. Hvala svima na odgovorima.
[ Machiavelli... @ 28.05.2010. 17:14 ] @
ja koliko vidim imas

SpywareTerminatorShield
COMODO Internet Security
BitDefender 2010

Imas 3 antivirus/antispyware ja bi reko da oni uzimaju CPU. Posebno ako neko od ovih radi resident protection.
[ xman25 @ 29.05.2010. 00:31 ] @
SpywareTerminatorShield mi je samo anti spyware, bitdefender samo antivirus a COMODO Internet Security samo firewall.