Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Dva problema otvaranje particije i otvaranje usb-a

[es] :: Zaštita :: Dva problema otvaranje particije i otvaranje usb-a

[ Pregleda: 2276 | Odgovora: 11 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

Mr_Q

Član broj: 123690
Poruke: 141
*.gradiska.com.



Profil

icon Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 13:36 - pre 197 meseci
Kad otvorim My Computer i kad hoću da otvorim particiju C onda ne mogu otvoriti jer mi se pojavi ova slika:

http://img81.imageshack.us/my.php?image=windowsxpproblemod3.jpg

Kada otvorim USB preko My Computer pojavi mi se ova slika: http://img100.imageshack.us/my.php?image=usbwt8.jpg

Kako da to rešim?

Hvala unapred...

 
Odgovor na temu

Binary Mind
11040

Član broj: 28245
Poruke: 13289
*.adsl-1.sezampro.yu.



+3779 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 15:24 - pre 197 meseci
Pomocu HiJackThis!-a i Combofix-a... Pogledaj ovu temu da bi se upoznao sa onime sto treba da radis:

http://www.elitesecurity.org/t309447-Problem-sa-autorun-inf

Problem je slican, ali mozda ne i isti kao tvoj. Prvo skini HiJackThis! i uradi sken + okaci njegov log. Kad budes skinuo Combofix i poceo sa skenom ne diraj komp dok ne zavrsi. USB stick takodje treba da bude uboden u komp da bi probali da ga ocistimo pomocu Combofix-a. Posle okaci i Combofix-ov log ovde da vidim...
 
Odgovor na temu

Mr_Q

Član broj: 123690
Poruke: 141
*.gradiska.com.



Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 19:37 - pre 197 meseci
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:36:22 PM, on 2/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
C:\Program Files\Hard Drive Inspector\HDInspector.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Di recnik\Di.exe
C:\Program Files\My Lockbox\flockbox.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\pscript\Bin\PScript.exe
C:\Program Files\Winamp\winampa.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\Program Files\DNA\btdna.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\WINDOWS\system32\HDDSvc.exe
C:\WINDOWS\LogWatNT.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\xampp\mysql\bin\mysqld-nt.exe
C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\xampp\apache\bin\apache.exe
C:\Program Files\ErrorSmart\ErrorSmart.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Microsoft Office\Office12\VISIO.EXE
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Documents and Settings\Sormaz\My Documents\HiJackThis_v2.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 102.54.94.97 rhino.acme.com # source server
O1 - Hosts: 38.25.63.10 x.acme.com # x client host
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [StatusClient] C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [HDInspector.exe] C:\Program Files\Hard Drive Inspector\HDInspector.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
O4 - HKLM\..\Run: [Di dictionary] "C:\Program Files\Di recnik\Di.exe"
O4 - HKLM\..\Run: [flockbox] C:\Program Files\My Lockbox\flockbox.exe /a
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PageScript] C:\pscript\\Bin\PScript.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ErrorSmart] C:\Program Files\ErrorSmart\ErrorSmart.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ExtraDrivePro] C:\Program Files\Godlike Developers\Extra Drive Creator Pro\ExtraDrivePro.exe -x
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [WMI] C:\WINDOWS\system32\wmprvse.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Prevedi sa Di recnikom - C:\Program Files\Di recnik\diie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CC6687D-E97B-450B-A7F5-15F01F9FEDD8}: NameServer = 217.23.204.4 217.23.204.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{1CC6687D-E97B-450B-A7F5-15F01F9FEDD8}: NameServer = 217.23.204.4 217.23.204.5
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: DU Meter Service (DUMeterSvc) - Hagel Technologies Ltd - C:\Program Files\DU Meter\DUMeterSvc.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - c:\xampp\FileZillaFTP\FileZillaServer.exe
O23 - Service: HDD Information Service (HDDSvc) - AltrixSoft (http://www.altrixsoft.com/) - C:\WINDOWS\system32\HDDSvc.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINDOWS\LogWatNT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: mysql - Unknown owner - C:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 11051 bytes


Evo log od HiJackThis
 
Odgovor na temu

Mr_Q

Član broj: 123690
Poruke: 141
*.gradiska.com.



Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 20:05 - pre 197 meseci
Evo log od ComboFiX

ComboFix 08-02.05.3 - Sormaz 2008-02-07 20:52:52.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.168 [GMT 1:00]
Running from: C:\Documents and Settings\Sormaz\Desktop\ComboFix.exe
* Created a new restore point

[color=red]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\NSDriverr.sys
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\NSDriverr.sys
C:\WINDOWS\system32\wmprvse.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_NSDRIVERR
-------\NSDriverr


((((((((((((((((((((((((( Files Created from 2008-01-07 to 2008-02-07 )))))))))))))))))))))))))))))))
.

2008-02-07 16:12 . 2008-02-07 16:19 <DIR> d-------- C:\Program Files\SWFText
2008-02-07 15:39 . 2008-02-07 15:41 <DIR> d-------- C:\Program Files\AAALOGO
2008-02-07 12:27 . 2008-02-07 20:42 <DIR> d-------- C:\Program Files\mIRC
2008-02-07 12:14 . 2008-02-07 12:17 979,968 ---hs---- C:\WINDOWS\system32\70554DUMeter.exe
2008-02-07 12:14 . 2008-02-07 12:14 12,800 ---hs---- C:\WINDOWS\system32\53341crack.exe
2008-02-07 12:13 . 2008-02-07 12:14 <DIR> d-------- C:\Program Files\DU Meter
2008-02-07 12:13 . 2008-02-07 12:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hagel Technologies
2008-02-07 12:13 . 2008-02-07 12:13 1,871,512 ---hs---- C:\WINDOWS\system32\70554DUMeter-Install.exe
2008-02-07 12:13 . 2008-02-07 12:13 12,288 ---hs---- C:\WINDOWS\system32\53341install.exe
2008-02-07 07:14 . 2008-02-07 07:14 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Grisoft
2008-02-07 07:08 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-07 07:07 . 2008-02-07 07:07 110,592 --a------ C:\WINDOWS\system32\avgfwafu.dll
2008-02-07 06:09 . 2008-02-07 06:09 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-07 00:11 . 2008-02-07 10:27 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\AVG7
2008-02-07 00:11 . 2008-02-07 00:11 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\AVG7
2008-02-07 00:10 . 2008-02-07 08:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-07 00:01 . 2008-02-07 00:01 <DIR> d-------- C:\Program Files\MSECache
2008-02-06 23:58 . 2008-02-07 00:00 <DIR> d-------- C:\Program Files\Microsoft Small Business
2008-02-06 23:52 . 2008-02-06 23:55 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-02-06 22:59 . 2008-02-06 22:59 <DIR> d-------- C:\Program Files\Microsoft Works
2008-02-06 22:58 . 2008-02-06 22:58 <DIR> d-------- C:\Program Files\MSBuild
2008-02-06 22:56 . 2008-02-06 23:55 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-02-06 22:51 . 2008-02-06 22:51 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
2008-02-06 22:50 . 2008-02-06 22:57 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-02-06 22:00 . 2008-02-07 07:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-06 21:26 . 2008-02-06 21:29 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\ErrorSmart
2008-02-06 21:25 . 2008-02-07 12:22 <DIR> d-------- C:\Program Files\ErrorSmart
2008-02-04 23:03 . 2008-02-04 23:05 <DIR> d-------- C:\Program Files\Winamp
2008-02-04 23:03 . 2008-02-04 23:37 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Winamp
2008-02-04 00:01 . 2008-02-04 00:01 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Sony
2008-02-04 00:00 . 2008-02-04 00:00 <DIR> d-------- C:\Program Files\Vstplugins
2008-02-04 00:00 . 2008-02-04 00:00 <DIR> d-------- C:\Program Files\Sony
2008-02-03 23:57 . 2008-02-03 23:57 1,656 --a------ C:\WINDOWS\BPWIN20.INI
2008-02-03 23:12 . 2008-02-03 23:12 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Sony Setup
2008-02-03 23:11 . 2008-02-03 23:11 <DIR> d-------- C:\Program Files\Sony Setup
2008-02-03 19:01 . 2008-02-03 19:01 <DIR> d-------- C:\Program Files\Teleport Ultra
2008-02-03 16:19 . 2008-02-03 16:19 <DIR> d-------- C:\Program Files\Microsoft
2008-02-03 13:43 . 2008-02-03 13:43 <DIR> d-------- C:\Program Files\Lavasoft
2008-02-03 13:43 . 2008-02-03 13:43 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-03 13:42 . 2008-02-03 13:42 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-03 12:01 . 2008-02-03 12:03 32,256 --a------ C:\WINDOWS\system32\wmpns.exe
2008-02-02 12:47 . 2008-02-02 12:49 <DIR> d-------- C:\pp
2008-02-02 12:46 . 2005-12-06 23:24 4,510 --a------ C:\LIST.COM
2008-02-02 12:46 . 2008-02-02 12:46 3,784 --a------ C:\WINDOWS\system32\STATUS.ME
2008-02-02 12:44 . 2008-02-07 12:58 37 ---h----- C:\PSPath.ini
2008-01-31 23:44 . 2008-01-31 23:44 <DIR> d-------- C:\Program Files\MySpace
2008-01-31 23:44 . 2008-01-31 23:44 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\MySpace
2008-01-31 19:31 . 2008-01-31 19:31 <DIR> d-------- C:\Program Files\DBPix20
2008-01-31 17:07 . 2008-01-31 17:12 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\mIRC
2008-01-31 16:56 . 2008-01-31 16:56 <DIR> d-------- C:\No Name Script
2008-01-30 20:35 . 2008-01-30 20:35 <DIR> d-------- C:\_notes
2008-01-30 20:32 . 2008-01-30 20:33 <DIR> d-------- C:\Templates
2008-01-30 14:34 . 2008-01-30 14:34 <DIR> d-------- C:\sqlany50
2008-01-30 13:09 . 1996-02-20 04:02 326,656 --a------ C:\WINDOWS\system32\temp.001
2008-01-30 12:57 . 2008-01-30 12:57 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Corel
2008-01-30 12:57 . 2008-02-02 20:45 88 -r-hs---- C:\WINDOWS\system32\E6299C6BAF.sys
2008-01-30 12:57 . 2008-01-30 12:57 8 -r-hs---- C:\WINDOWS\system32\9D1945B6C5.sys
2008-01-30 12:55 . 2008-01-30 12:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-01-30 12:53 . 2008-01-30 12:53 <DIR> d-------- C:\Program Files\Common Files\Protexis
2008-01-30 12:52 . 2008-01-30 12:52 <DIR> d-------- C:\Program Files\Common Files\Corel
2008-01-30 12:52 . 2008-01-30 12:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Corel
2008-01-29 14:25 . 2008-02-02 20:46 2,516 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2008-01-29 14:20 . 2008-01-30 12:52 <DIR> d-------- C:\Program Files\Corel
2008-01-29 13:01 . 2003-05-22 16:44 670,203 -ra------ C:\WINDOWS\system32\drivers\Intels51.sys
2008-01-29 13:01 . 2001-08-17 13:57 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys
2008-01-29 13:01 . 2001-08-17 13:57 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-01-28 17:06 . 2008-01-30 14:35 70 --a------ C:\WINDOWS\wsql.ini
2008-01-28 17:05 . 1995-07-11 00:50 348,160 --a------ C:\WINDOWS\system32\mfc30.dll
2008-01-28 17:05 . 1996-01-15 07:12 334,016 --a------ C:\WINDOWS\system32\pbflt09.dll
2008-01-28 17:05 . 1996-01-15 07:12 222,928 --a------ C:\WINDOWS\system32\pbbas09.dll
2008-01-28 17:05 . 1994-08-16 19:00 210,944 --a------ C:\WINDOWS\system32\msvcrt10.dll
2008-01-28 17:05 . 1996-01-15 05:09 203,264 --a------ C:\WINDOWS\system32\pbutl09.dll
2008-01-28 17:05 . 1996-01-17 00:21 31,008 --a------ C:\WINDOWS\system32\ivtrn09.dll
2008-01-28 17:05 . 1997-09-11 23:00 26,340 --a------ C:\WINDOWS\system32\odbcinst.hlp
2008-01-28 17:05 . 1996-03-12 07:19 796 --a------ C:\WINDOWS\system32\ivpb.lic
2008-01-28 17:05 . 1997-09-11 23:00 244 --a------ C:\WINDOWS\system32\odbcinst.cnt
2008-01-28 17:05 . 1996-01-19 07:36 2 --a------ C:\WINDOWS\system32\pbdbc09.dll
2008-01-28 17:04 . 2008-01-28 17:04 <DIR> d-------- C:\WINDOWS\PSUNINST
2008-01-28 17:04 . 2005-07-30 11:56 97,816 --a------ C:\WINDOWS\system32\dbl50t.dll
2008-01-28 08:39 . 1996-02-20 04:02 326,656 --a------ C:\WINDOWS\system32\temp.000
2008-01-27 21:04 . 2008-01-27 21:04 <DIR> d-------- C:\Program Files\Firebird
2008-01-27 13:40 . 2008-01-27 13:40 <DIR> d-------- C:\Program Files\My Lockbox
2008-01-27 13:40 . 2007-12-13 20:13 17,264 --a------ C:\WINDOWS\system32\drivers\mprifl.sys
2008-01-25 23:44 . 2006-02-27 00:17 <DIR> d-------- C:\Swish_Templates
2008-01-25 23:44 . 2008-01-25 23:44 <DIR> d-------- C:\Program Files\SWiSHpresenter
2008-01-25 23:43 . 2008-01-25 23:44 <DIR> d-------- C:\Program Files\SWiSHmax
2008-01-25 16:43 . 2008-01-27 11:11 <DIR> d-------- C:\Program Files\Web Button Menu Maker
2008-01-22 13:46 . 2003-06-18 17:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-01-22 13:46 . 2008-02-06 23:49 856 --a------ C:\WINDOWS\ODBC.INI
2008-01-22 13:31 . 2008-01-22 13:31 <DIR> dr-h----- C:\MSOCache
2008-01-22 13:06 . 2008-01-22 13:08 <DIR> d-------- C:\Program Files\CDDVDDataRecovery
2008-01-22 13:06 . 2008-01-22 13:06 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\CyberLink
2008-01-20 19:36 . 2008-02-07 16:10 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-01-20 14:44 . 2008-02-04 22:57 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\Nokia Multimedia Player
2008-01-19 19:53 . 2008-01-20 14:54 <DIR> d-------- C:\Program Files\DC++
2008-01-19 19:42 . 2008-01-19 19:42 <DIR> d-------- C:\Program Files\Common Files\Skype
2008-01-19 19:42 . 2008-02-07 16:08 <DIR> d-------- C:\Documents and Settings\Sormaz\Application Data\skypePM
2008-01-19 19:42 . 2008-01-19 19:42 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-01-17 21:25 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-01-17 21:24 . 2008-01-17 21:24 <DIR> d--h----- C:\WINDOWS\$hf_mig$

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-08 13:51 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-19 02:47 8720384]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-07 07:06 219136]

R0 MPRIFL;MPRIFL;C:\WINDOWS\system32\DRIVERS\MPRIFL.SYS [2007-12-13 20:13]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2006-11-02 16:51]
R2 DUMeterSvc;DU Meter Service;C:\Program Files\DU Meter\DUMeterSvc.exe [2007-10-15 15:19]
R2 extradrv;Extra Driver;C:\WINDOWS\system32\DRIVERS\extradrv.sys [2005-11-05 12:44]
R2 LogWatch;Event Log Watch;C:\WINDOWS\LogWatNT.exe [2000-06-08 12:15]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" [2006-04-14 10:07]
R2 ramdrive;RAM Driver;C:\WINDOWS\system32\DRIVERS\ramdrive.sys [2005-11-05 12:44]
R3 Intels51;Intel(R) 536EP Modem;C:\WINDOWS\system32\DRIVERS\Intels51.sys [2003-05-22 16:44]
S3 SQLWriter;SQL Server VSS Writer;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2006-04-14 10:04]
S4 Apache2.2;Apache2.2;"C:\xampp\apache\bin\apache.exe" [2007-12-21 03:00]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00dd2a4c-d183-11dc-bd07-0018f3165390}]
\Shell\AutoRun\command - F:\d.com
\Shell\explore\Command - F:\d.com
\Shell\open\Command - F:\d.com

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e81d5fa-c44c-11dc-bcb8-0018f3165390}]
\Shell\AutoRun\command - F:\d.com
\Shell\explore\Command - F:\d.com
\Shell\open\Command - F:\d.com

.
Contents of the 'Scheduled Tasks' folder
"2008-02-07 12:01:45 C:\WINDOWS\Tasks\ErrorSmart Scheduled Scan.job"
- C:\Program Files\ErrorSmart\ErrorSmart.ex
- C:\Program Files\ErrorSmart.Sormaz+Runs ErrorSmart to optimize your registry.
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-07 20:59:00
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\DUMeterSvc]
"ImagePath"="C:\Program Files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\HDDSvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-02-07 21:02:32 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-07 20:02:28


Evo uspio sam da pomoću ovih programa popravim probleme da li se neće ti problemi javiti ponovo?
 
Odgovor na temu

Boris

Član broj: 82
Poruke: 450

ICQ: 100801505


+2 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 20:11 - pre 197 meseci
Kad vidim toliku listu vidim da nesto ne valja.

Skini combofix, pusti ga da odradi(restartuj ako zatrazi) i postuj nam log, ostavice ga u C:/ najverovatnije.
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
[::b0ris::]
 
Odgovor na temu

Binary Mind
11040

Član broj: 28245
Poruke: 13289
*.adsl-4.sezampro.yu.



+3779 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 22:21 - pre 197 meseci
Da li ti je USB flash uboden u neki USB port? Imas trojanaca za izvoz ukljucujuci i famozni amvo.exe :). Ne vidim da je USB flash skeniran. Kasnije cu krenuti sa analizom logova mada moze i neko drugi ako je zainteresovan. :)
 
Odgovor na temu

Mr_Q

Član broj: 123690
Poruke: 141
*.gradiska.com.



Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 22:49 - pre 197 meseci
Sad mi radi sve ok... Hvala
 
Odgovor na temu

Binary Mind
11040

Član broj: 28245
Poruke: 13289
*.adsl-4.sezampro.yu.



+3779 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 23:06 - pre 197 meseci
To sto ti sve radi ne znaci da si ociscen, ali kako hoces :)
 
Odgovor na temu

Binary Mind
11040

Član broj: 28245
Poruke: 13289
*.adsl-4.sezampro.yu.



+3779 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 23:10 - pre 197 meseci
Code:
O4 - HKCU\..\Run: [WMI] C:\WINDOWS\system32\wmprvse.exe


Ovo stikliraj u HiJackThis! i klikni fix checked... Sad cu da vidim Combofix pa javljam sta jos treba da radis. Inace ako je USB stick jos inficiran ponovice ti se isti problemi kad ga otvoris ako mozes...
 
Odgovor na temu

Boris

Član broj: 82
Poruke: 450

ICQ: 100801505


+2 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 23:35 - pre 197 meseci
@Mr_Q



C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\NSDriverr.sys
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\NSDriverr.sys
C:\WINDOWS\system32\wmprvse.exe


sacuvaces to kao "CFScript.txt" i prevuci ces na Combofix koji ce ponovo poceti da radi. Ne diraj nista dok radi pusti da se komp restartuje ako treba.


Posle toga sledece:

Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00dd2a4c-d183-11dc-bd07-0018f3165390}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e81d5fa-c44c-11dc-bcb8-0018f3165390}]

sacuvaces opet kao "CFScript.txt" i prevuci ces na Combofix koji ce ponovo poceti da radi. Ne diraj nista dok radi pusti da se komp restartuje ako treba.


Posle ponovo okaci novi HiJackThis! log i Combofix log.
[::b0ris::]
 
Odgovor na temu

Binary Mind
11040

Član broj: 28245
Poruke: 13289
*.adsl-4.sezampro.yu.



+3779 Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a07.02.2008. u 23:44 - pre 197 meseci
USB stick neka bude uboden posto autorun.inf fajl jos uvek moze biti na njemu. Skini SFScript.txt fajl koji je zakacen dole i prevuci ga na Combofix ikonu. Posle sacekaj da zavrsi i okaci nove HiJackThis! i Combofix logove.


Za USB stick mozes koristiti i Flash_Disinfector.exe koji mozes skinuti sa ovog linka:

http://www.techsupportforum.co...ols/sUBs/Flash_Disinfector.exe

Prati sve promptove i bice sve uredu. Vazno je da dezinfikujes USB stick jer ako je jos inficiran opet ces inficirati komp.
Prikačeni fajlovi
 
Odgovor na temu

Mr_Q

Član broj: 123690
Poruke: 141
*.gradiska.com.



Profil

icon Re: Dva problema otvaranje particije i otvaranje usb-a09.02.2008. u 11:00 - pre 197 meseci
Nemam sad problema valjda je sve ok sad javiću ako bude hvala u svakom slučaju
 
Odgovor na temu

[es] :: Zaštita :: Dva problema otvaranje particije i otvaranje usb-a

[ Pregleda: 2276 | Odgovora: 11 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.