|
![]() |
#1 |
Premium
Datum registracije: Apr 2006
Lokacija: Zagreb
Postovi: 60
|
Trojanci, virusi i glavobolja! Pomoć!
Imao sam hrpu trojanaca nedavno... Iako sam uklonio neke poput Quake-a i Zlob-a, ostalo ih je josh dosta... Pomagajte! Uz to, stalno mi iskače message na talijanskom nakon nekog prozora koji nestane za pola sekunde: Dialer - Nessun modem trovato, il programma sara terminato. WTF je to? Nod32 je za vrijeme skeniranja pronašao trojance Busky.AZ, Win32/QS.Downloader, i josh nesto... Navodno je to sve prema Nod32 počišćeno ili u karanteni. Skenirao sam i s Panda Active Scan-om... Panda je pak pronašla Vundo Trojan, koji Symantec-ov removal tool za Vundo nije pronasao... Ne znam što dalje... help please... Evo ispod hijack this logfile:
__________________
You know... War isn't tragedy. Detah of one man is tragedy, but deaths of millions are mere statistics. |
![]() |
![]() |
![]() |
#2 |
Premium
Datum registracije: Apr 2006
Lokacija: Zagreb
Postovi: 60
|
C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\DAEMON Tools\daemon.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe C:\WINDOWS\system32\WF2K.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\T-Com Antidialer\T-Com Antidialer.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\crypserv.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Eset\nod32.exe C:\Program Files\Windows NT\Accessories\WORDPAD.EXE C:\WINDOWS\system32\ishost.exe C:\WINDOWS\system32\ismini.exe C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe C:\WINDOWS\TEMP\win2F6.tmp.exe C:\WINDOWS\TEMP\idd2F8.tmp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\WinRAR\WinRAR.exe C:\DOCUME~1\VJEKOS~1\LOCALS~1\Temp\Rar$EX00.375\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {112650C4-0A01-5CFA-890E-03CB4BBF4C1D} - C:\WINDOWS\system32\ndptbzc.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {648592A3-44B7-9AF8-BACA-02859776A1CD} - C:\WINDOWS\system32\llkyzqd.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Safety Bar - {fbea0445-4c4a-4136-864a-c72a4a182a84} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing) O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [nTrayFw] "C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" O4 - HKLM\..\Run: [WinFoxV2] "C:\WINDOWS\system32\WF2K.EXE" Initial O4 - HKLM\..\Run: [WinFast2KLoadDefault] "rundll32.exe" C:\WINDOWS\system32\wf2kcpl.dll,DllLoadDefaultSettings O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [jrukc.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\jrukc.dll,rezxbg O4 - HKLM\..\Run: [tcomantidialerrun] "C:\Program Files\T-Com Antidialer\T-Com Antidialer.exe" O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll O9 - Extra button: Messenger {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CCS\Services\Tcpip\..\{A4DD7BAE-A058-4DC0-85F2-20D6CDFA4C27}: NameServer = 195.29.150.3 195.29.150.4 O17 - HKLM\System\CS1\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS2\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220 O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O20 - Winlogon Notify: winuns32 - C:\WINDOWS\SYSTEM32\winuns32.dll O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR2a\RpcDataSrv.exe O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR2a\RpcSandraSrv.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
__________________
You know... War isn't tragedy. Detah of one man is tragedy, but deaths of millions are mere statistics. |
![]() |
![]() |
|
|
Oglas
|
|
![]() |
#3 |
Premium
Datum registracije: Jan 2006
Lokacija: Samobor
Postovi: 4,204
|
skeniraj sa Spybot seach&destroy, Ad-aware, CWShreedder i kopiraj tu log od hijack this edit: jbmu kad ne citam do kraja... makni: O2 - BHO: (no name) - {112650C4-0A01-5CFA-890E-03CB4BBF4C1D} - C:\WINDOWS\system32\ndptbzc.dll O2 - BHO: (no name) - {648592A3-44B7-9AF8-BACA-02859776A1CD} - C:\WINDOWS\system32\llkyzqd.dl O3 - Toolbar: Safety Bar - {fbea0445-4c4a-4136-864a-c72a4a182a84} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing) O4 - HKLM\..\Run: [WinFast2KLoadDefault] "rundll32.exe" C:\WINDOWS\system32\wf2kcpl.dll,DllLoadDefaultSettings O4 - HKLM\..\Run: [jrukc.dll] "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\jrukc.dll,rezxbg O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O8 - Extra context menu item: &Search - http://kn.bar.need2find.com/KN/menusearch.html?p=KN ak neznas od cega je ova ip adresa makni: O17 - HKLM\System\CCS\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220 17 - HKLM\System\CS1\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220 O17 - HKLM\System\CS2\Services\Tcpip\..\{2C560CBE-8FE2-4143-BBF3-FF82BDBF338F}: NameServer = 208.67.222.222,208.67.220.220
__________________
|
![]() |
![]() |
![]() |
#4 |
Premium
Datum registracije: Apr 2006
Lokacija: Zagreb
Postovi: 60
|
__________________
You know... War isn't tragedy. Detah of one man is tragedy, but deaths of millions are mere statistics. |
![]() |
![]() |
![]() |
#5 |
Premium
Datum registracije: Apr 2006
Lokacija: Zagreb
Postovi: 60
|
Hvala! Jedino kaj sam n00b pa ne znam puno osnovnih stvari (: giljotin), jedno jednostavno pitanjce: Kak to maknut? U hijackthis-u?
__________________
You know... War isn't tragedy. Detah of one man is tragedy, but deaths of millions are mere statistics. |
![]() |
![]() |
![]() |
#7 |
Premium
Datum registracije: Apr 2006
Lokacija: Zagreb
Postovi: 60
|
__________________
You know... War isn't tragedy. Detah of one man is tragedy, but deaths of millions are mere statistics. |
![]() |
![]() |
![]() |
#8 |
PizzoZder
Datum registracije: Jan 2003
Lokacija: Umag
Postovi: 12,613
|
Prouci ova dva linka, usput rucno obrisi SVE *.tmp datoteke koje su se nagomilale u C:/windows/temp direktoriju. Sve ti je opisano ovdje: http://forum.pcekspert.com/showthrea...ighlight=nod32 http://forum.pcekspert.com/showthrea...ijanski+dialer
__________________
Prodajem kucu na klizistu.. Nije puno presla..... Member Of PC Ekspert 100+kg Demolition Squad NAJNOVIJE = Povoljno RAM..http://www.downloadmoreram.com/... tor i AMD kupili.... NOVO! Prodajem visokokvalitetni tropleteni hardverski konac za fixiranje coolera |
![]() |
![]() |
![]() |
#9 |
EMP moderator
Datum registracije: Apr 2005
Lokacija: Osijek
Postovi: 18,862
|
Zašto otvaraš novu temu kad si log mogao ovdje stavit, ccc...
__________________ "Kako su krojači novog svjetskog poretka uspjeli u tako kratko vrijeme slomiti intelektualne sposobnosti društva, uništiti kritičku svijest i ljudima nametnuti izvrnutu logiku?"
|
![]() |
![]() |
|
|
Oglas
|
|
![]() |
Uređivanje | |
|
|