Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Win32/PSW.OnLineGames.NRG Trojan HELP!

[es] :: Zaštita :: Win32/PSW.OnLineGames.NRG Trojan HELP!

[ Pregleda: 2558 | Odgovora: 14 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 16:09 - pre 201 meseci
Nod mi registruje Win32/PSW.OnLineGames.NRG Trojan
Ovo je log od Hijack:

Logfile of HijackThis v1.99.1
Scan saved at 1:53:57, on 16.10.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\StartupMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\regscan.exe
C:\Program Files\Electronic Arts\EA Downloader\Core.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\USER\DESKTOP\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09EB15FA-17D8-4D60-8598-3F549A848DF2} - C:\PROGRA~1\INTERN~1\PLUGINS\b54321.bho
O2 - BHO: (no name) - {48691221-F05C-4AB4-B9D0-50D6D36CC27F} - (no file)
O2 - BHO: (no name) - {581C5299-BEA6-4619-8218-BE539A98812A} - C:\Program Files\Internet Explorer\7v54321t.321
O2 - BHO: (no name) - {5935D8A5-DC70-4630-8C8C-3C629B67DE68} - C:\Program Files\Internet Explorer\7v54321t.321
O2 - BHO: (no name) - {6A1C6F99-5C00-41F2-99AE-44CE09DB5B6E} - C:\Program Files\Internet Explorer\7654321t.321
O2 - BHO: (no name) - {79058C97-6141-4E03-874B-0055FA21E36A} - C:\Program Files\Internet Explorer\ExploreMt.456
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AD862DC6-37FA-4D56-B7EA-59C2522A5FC4} - C:\Program Files\Internet Explorer\Explo2eMt.456
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [HBService32] System.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Regscan] C:\WINDOWS\system32\regscan.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsof...ogWebControl.cab?1222890190475
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/wi...t/wuweb_site.cab?1223387699223
O16 - DPF: {E cellSpacing=5 cellPadding=3 width=400} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{33F585CF-60A6-498E-A402-548D22698DBC}: NameServer = 80.74.160.38 80.74.160.12
O21 - SSODL: herkvgin.dll - {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F} - (no file)
O21 - SSODL: adsntzt.dll - {E0F3526A-4165-4589-80CD-50B6FBAC3BDA} - C:\WINDOWS\system32\adsntzt.dll
O21 - SSODL: mstimewd.dll - {65056902-6E7B-4bd7-95BA-688DB5FA5BEB} - (no file)
O21 - SSODL: ldadkduv.dll - {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F} - (no file)
O21 - SSODL: bootvidgj.dll - {D3112B69-A745-4805-874E-ABD480EA1299} - C:\WINDOWS\system32\bootvidgj.dll
O21 - SSODL: oetwmyap.dll - {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F} - (no file)
O21 - SSODL: pbrwvbze.dll - {21BE5FDF-D4CB-4850-AD99-21E68B50BF3F} - (no file)
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 17:29 - pre 201 meseci
Klikni desni klik na ikonicu Noda pored sata i izaberi Nod32 Control Center
Klikni na AMON iz Threat Protection
Destikliraj u desnom prozoru File system monitor (AMON) enabled.
Skini CF sa ovog linka
Pokreni Combofix i ne diraj prozor dok skenira.
Kad zavrsi postavi log koji ti izbaci ovde na forumu.(C:\ComboFix.txt)
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 19:39 - pre 201 meseci
ComboFix 08-10-16.08 - User 2008-10-17 20:23:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.195 [GMT 2:00]
Running from: C:\DOCUMENTS AND SETTINGS\USER\DESKTOP\ComboFix.exe
* Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Internet Explorer\PLUGINS\321Nt64.Jmp
C:\Program Files\Internet Explorer\PLUGINS\WinNt64.Jmp
C:\WINDOWS\IE4 Error Log.txt
C:\WINDOWS\jestertb.dll
C:\WINDOWS\system32\adsntzt.dll
C:\WINDOWS\system32\adsntzt.nls
C:\WINDOWS\system32\bootvidgj.dll
C:\WINDOWS\system32\bootvidgj.nls
C:\WINDOWS\system32\drivers\HBKernel32.sys
C:\WINDOWS\system32\HBmhly.dll
C:\WINDOWS\system32\mstimewd.nls
C:\WINDOWS\system32\regscan.exe
C:\WINDOWS\system32\sunesnk.exe
C:\WINDOWS\system32\Update.dat

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_HBKERNEL
-------\Legacy_HBKERNEL32
-------\Service_HBKernel32


((((((((((((((((((((((((( Files Created from 2008-09-17 to 2008-10-17 )))))))))))))))))))))))))))))))
.

2008-10-16 01:42 . 2008-10-16 01:42 <DIR> d-------- C:\Program Files\Common Files\Younexus
2008-10-14 22:44 . 2008-10-14 22:47 <DIR> d-------- C:\Program Files\Trojan Killer
2008-10-14 18:10 . 2008-10-17 18:00 <DIR> d-------- C:\Program Files\a2 free
2008-10-11 14:40 . 2008-10-11 14:40 <DIR> d-------- C:\Documents and Settings\User\Application Data\Lavasoft
2008-10-11 14:39 . 2008-10-11 14:39 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-07 22:39 . 2008-10-07 22:39 <DIR> d-------- C:\Program Files\IObit
2008-10-07 22:02 . 2008-10-07 22:02 <DIR> d-------- C:\Documents and Settings\User\Application Data\.bittorrent
2008-10-07 16:26 . 2008-10-07 18:04 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-10-06 19:11 . 2008-10-06 19:11 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-10-06 18:43 . 2008-10-06 18:43 <DIR> d-------- C:\Documents and Settings\User\Application Data\Talkback
2008-10-06 18:43 . 2008-10-06 18:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-06 18:32 . 2008-10-06 18:32 99,965 --a------ C:\WINDOWS\UninstallFirefox.exe
2008-10-06 18:31 . 2008-10-06 18:31 3,137 --a------ C:\WINDOWS\mozver.dat
2008-10-06 18:30 . 2008-10-06 18:30 <DIR> d-------- C:\Program Files\BitTorrent
2008-10-03 16:08 . 2008-10-03 16:08 <DIR> d-------- C:\Program Files\ActiveLaunch
2008-10-03 16:08 . 2008-10-03 16:14 <DIR> d-------- C:\Documents and Settings\User\Application Data\AL Data
2008-10-01 21:23 . 2008-10-01 21:23 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistributionOLD
2008-10-01 21:23 . 2008-07-18 22:10 45,768 --a------ C:\WINDOWS\system32\wups2.dll.old
2008-10-01 21:23 . 2008-07-18 22:10 33,992 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-10-01 21:23 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-10-01 21:23 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-10-01 21:23 . 2008-07-18 22:08 20,680 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-09-30 22:11 . 2008-09-30 22:10 300,048 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-09-30 22:11 . 2008-09-30 22:10 245,760 --a------ C:\WINDOWS\system32\imon.dll
2008-09-30 22:11 . 2008-09-30 22:10 114,688 --a------ C:\WINDOWS\system32\nms32.dll
2008-09-30 22:11 . 2008-09-30 22:11 442 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-09-30 22:10 . 2008-10-08 21:22 <DIR> d-------- C:\Program Files\ESET
2008-09-30 17:08 . 2008-09-30 17:24 <DIR> d-------- C:\Program Files\TweakNow RegCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-17 18:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 14:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-06 16:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-06 16:34 --------- d-----w C:\Program Files\ATI Technologies
2008-10-03 14:03 --------- d-----w C:\Program Files\Industry Giant 2
2008-10-03 14:02 --------- d-----w C:\Program Files\EA Games
2008-09-30 20:27 --------- d-----w C:\Program Files\3GP Player
2008-09-10 18:55 --------- d-----w C:\Program Files\Electronic Arts
2008-09-10 18:45 --------- d-----w C:\Program Files\EA SPORTS
2008-08-31 12:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-08-31 12:40 --------- d-----w C:\Program Files\IVT Corporation
2008-08-31 08:21 8,064 ----a-w C:\WINDOWS\rwrm.exe
2008-08-31 08:17 8,064 ----a-w C:\WINDOWS\ypqc.exe
2008-08-30 18:27 --------- d-----w C:\Program Files\LEGO Media
2008-08-10 18:24 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-08-01 05:40 9,928,704 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-08-01 04:58 253,952 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-08-01 04:33 425,984 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-08-01 04:32 311,296 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-08-01 04:23 184,320 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-08-01 04:23 143,360 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-08-01 04:22 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-08-01 04:22 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-08-01 04:22 143,360 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-08-01 04:21 573,440 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-08-01 04:19 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-08-01 04:10 3,917,568 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-08-01 03:59 2,183,552 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-08-01 03:46 48,640 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-08-01 03:42 376,832 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-08-01 03:40 35,328 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-08-01 03:40 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-08-01 03:39 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-08-01 03:34 561,152 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-07-31 19:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:08 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09EB15FA-17D8-4D60-8598-3F549A848DF2}]
2008-10-17 16:11 107008 --ahs---- C:\PROGRA~1\INTERN~1\PLUGINS\b54321.bho

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{581C5299-BEA6-4619-8218-BE539A98812A}]
2008-10-08 00:22 31369 --ahs---- C:\Program Files\Internet Explorer\7v54321t.321

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5935D8A5-DC70-4630-8C8C-3C629B67DE68}]
2008-10-08 00:22 31369 --ahs---- C:\Program Files\Internet Explorer\7v54321t.321

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}]
2008-10-08 00:20 30843 --ahs---- C:\Program Files\Internet Explorer\Explo2eMt.456

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-07 68856]
"EA Core"="C:\Program Files\Electronic Arts\EA Downloader\Core.exe" [2006-07-13 1851392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 128920]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [2007-04-03 4376328]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-07 29744]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-09-30 851968]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 C:\WINDOWS\StartupMonitor.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 C:\WINDOWS\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-07 113664]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-08-31 1044480]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 394856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}"= "C:\Program Files\Internet Explorer\Explo2eMt.456" [2008-10-08 30843]
"{5935D8A5-DC70-4630-8C8C-3C629B67DE68}"= "C:\Program Files\Internet Explorer\7v54321t.321" [2008-10-08 31369]
"{581C5299-BEA6-4619-8218-BE539A98812A}"= "C:\Program Files\Internet Explorer\7v54321t.321" [2008-10-08 31369]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.XVID"= xvid.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"D:\\Igre\\Firaxis Games\\Civilization4.exe"=
"C:\\Program Files\\BitTorrent\\btdownloadgui.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59833:TCP"= 59833:TCP:PORT_59833
"59981:TCP"= 59981:TCP:PORT_59981
"28358:TCP"= 28358:TCP:PORT_28358
"23205:TCP"= 23205:TCP:PORT_23205
"41363:TCP"= 41363:TCP:PORT_41363
"34216:TCP"= 34216:TCP:PORT_34216
"22605:TCP"= 22605:TCP:PORT_22605
"36975:TCP"= 36975:TCP:PORT_36975
"10249:TCP"= 10249:TCP:PORT_10249
"32706:TCP"= 32706:TCP:PORT_32706
"32305:TCP"= 32305:TCP:PORT_32305
"12703:TCP"= 12703:TCP:PORT_12703
"43328:TCP"= 43328:TCP:PORT_43328
"16036:TCP"= 16036:TCP:PORT_16036
"23387:TCP"= 23387:TCP:PORT_23387
"50586:TCP"= 50586:TCP:PORT_50586
"56838:TCP"= 56838:TCP:PORT_56838
"8439:TCP"= 8439:TCP:PORT_8439
"45551:TCP"= 45551:TCP:PORT_45551
"32605:TCP"= 32605:TCP:PORT_32605
"20289:TCP"= 20289:TCP:PORT_20289
"23680:TCP"= 23680:TCP:PORT_23680
"35178:TCP"= 35178:TCP:PORT_35178
"28333:TCP"= 28333:TCP:PORT_28333
"28653:TCP"= 28653:TCP:PORT_28653
"50585:TCP"= 50585:TCP:PORT_50585
"31146:TCP"= 31146:TCP:PORT_31146
"21142:TCP"= 21142:TCP:PORT_21142
"27840:TCP"= 27840:TCP:PORT_27840
"31911:TCP"= 31911:TCP:PORT_31911
"29487:TCP"= 29487:TCP:PORT_29487
"49991:TCP"= 49991:TCP:PORT_49991
"41625:TCP"= 41625:TCP:PORT_41625
"50513:TCP"= 50513:TCP:PORT_50513
"42476:TCP"= 42476:TCP:PORT_42476
"50504:TCP"= 50504:TCP:PORT_50504
"16820:TCP"= 16820:TCP:PORT_16820
"19409:TCP"= 19409:TCP:PORT_19409
"52600:TCP"= 52600:TCP:PORT_52600
"37936:TCP"= 37936:TCP:PORT_37936
"8951:TCP"= 8951:TCP:PORT_8951
"26458:TCP"= 26458:TCP:PORT_26458
"12008:TCP"= 12008:TCP:PORT_12008
"59231:TCP"= 59231:TCP:PORT_59231
"17233:TCP"= 17233:TCP:PORT_17233
"23754:TCP"= 23754:TCP:PORT_23754
"30562:TCP"= 30562:TCP:PORT_30562
"54996:TCP"= 54996:TCP:PORT_54996
"22689:TCP"= 22689:TCP:PORT_22689
"55675:TCP"= 55675:TCP:PORT_55675
"10051:TCP"= 10051:TCP:PORT_10051
"32564:TCP"= 32564:TCP:PORT_32564
"30148:TCP"= 30148:TCP:PORT_30148
"18225:TCP"= 18225:TCP:PORT_18225
"46008:TCP"= 46008:TCP:PORT_46008
"31839:TCP"= 31839:TCP:PORT_31839
"17176:TCP"= 17176:TCP:PORT_17176
"10793:TCP"= 10793:TCP:PORT_10793
"32013:TCP"= 32013:TCP:PORT_32013
"37528:TCP"= 37528:TCP:PORT_37528
"29117:TCP"= 29117:TCP:PORT_29117
"18956:TCP"= 18956:TCP:PORT_18956
"61811:TCP"= 61811:TCP:PORT_61811
"28623:TCP"= 28623:TCP:PORT_28623
"25704:TCP"= 25704:TCP:PORT_25704
"16040:TCP"= 16040:TCP:PORT_16040
"56711:TCP"= 56711:TCP:PORT_56711
"34633:TCP"= 34633:TCP:PORT_34633
"22743:TCP"= 22743:TCP:PORT_22743
"26103:TCP"= 26103:TCP:PORT_26103
"8290:TCP"= 8290:TCP:PORT_8290
"59376:TCP"= 59376:TCP:PORT_59376
"40305:TCP"= 40305:TCP:PORT_40305
"23386:TCP"= 23386:TCP:PORT_23386
"55183:TCP"= 55183:TCP:PORT_55183
"48273:TCP"= 48273:TCP:PORT_48273
"52852:TCP"= 52852:TCP:PORT_52852
"32576:TCP"= 32576:TCP:PORT_32576
"6776:TCP"= 6776:TCP:PORT_6776
"18632:TCP"= 18632:TCP:PORT_18632
"16535:TCP"= 16535:TCP:PORT_16535
"31281:TCP"= 31281:TCP:PORT_31281
"11475:TCP"= 11475:TCP:PORT_11475
"28981:TCP"= 28981:TCP:PORT_28981
"58183:TCP"= 58183:TCP:PORT_58183
"57980:TCP"= 57980:TCP:PORT_57980
"14822:TCP"= 14822:TCP:PORT_14822
"47059:TCP"= 47059:TCP:PORT_47059
"26731:TCP"= 26731:TCP:PORT_26731
"30265:TCP"= 30265:TCP:PORT_30265
"45350:TCP"= 45350:TCP:PORT_45350
"37393:TCP"= 37393:TCP:PORT_37393
"29698:TCP"= 29698:TCP:PORT_29698
"17793:TCP"= 17793:TCP:PORT_17793
"43090:TCP"= 43090:TCP:PORT_43090
"31198:TCP"= 31198:TCP:PORT_31198
"59246:TCP"= 59246:TCP:PORT_59246
"30680:TCP"= 30680:TCP:PORT_30680
"41835:TCP"= 41835:TCP:PORT_41835
"36738:TCP"= 36738:TCP:PORT_36738
"33910:TCP"= 33910:TCP:PORT_33910
"13198:TCP"= 13198:TCP:PORT_13198
"9597:TCP"= 9597:TCP:PORT_9597
"24548:TCP"= 24548:TCP:PORT_24548
"48199:TCP"= 48199:TCP:PORT_48199
"16835:TCP"= 16835:TCP:PORT_16835
"61335:TCP"= 61335:TCP:PORT_61335
"26046:TCP"= 26046:TCP:PORT_26046
"45616:TCP"= 45616:TCP:PORT_45616
"33845:TCP"= 33845:TCP:PORT_33845
"64851:TCP"= 64851:TCP:PORT_64851
"26513:TCP"= 26513:TCP:PORT_26513
"31310:TCP"= 31310:TCP:PORT_31310
"62875:TCP"= 62875:TCP:PORT_62875
"44517:TCP"= 44517:TCP:PORT_44517
"22646:TCP"= 22646:TCP:PORT_22646
"54437:TCP"= 54437:TCP:PORT_54437
"53413:TCP"= 53413:TCP:PORT_53413
"41677:TCP"= 41677:TCP:PORT_41677
"15055:TCP"= 15055:TCP:PORT_15055
"53748:TCP"= 53748:TCP:PORT_53748
"39700:TCP"= 39700:TCP:PORT_39700
"31068:TCP"= 31068:TCP:PORT_31068
"56677:TCP"= 56677:TCP:PORT_56677
"63570:TCP"= 63570:TCP:PORT_63570
"14531:TCP"= 14531:TCP:PORT_14531
"47123:TCP"= 47123:TCP:PORT_47123
"10683:TCP"= 10683:TCP:PORT_10683
"49244:TCP"= 49244:TCP:PORT_49244
"51438:TCP"= 51438:TCP:PORT_51438
"13231:TCP"= 13231:TCP:PORT_13231
"15697:TCP"= 15697:TCP:PORT_15697
"54908:TCP"= 54908:TCP:PORT_54908
"54431:TCP"= 54431:TCP:PORT_54431
"22631:TCP"= 22631:TCP:PORT_22631
"53291:TCP"= 53291:TCP:PORT_53291
"11401:TCP"= 11401:TCP:PORT_11401
"53298:TCP"= 53298:TCP:PORT_53298
"20311:TCP"= 20311:TCP:PORT_20311
"7814:TCP"= 7814:TCP:PORT_7814
"49807:TCP"= 49807:TCP:PORT_49807
"57495:TCP"= 57495:TCP:PORT_57495
"59805:TCP"= 59805:TCP:PORT_59805

R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-07-31 20616]
R2 GenPort;GenPort;C:\WINDOWS\system32\drivers\GenPort.sys [1997-10-08 4832]
R2 MapMem;MapMem;C:\WINDOWS\system32\drivers\MapMem.sys [1997-10-08 6816]
R2 Netmrn;Network Connerctions;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 NTRemap;NTRemap;C:\WINDOWS\system32\drivers\NTRemap.sys [1997-10-08 6336]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-07 29744]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 KProcWatch;KProcWatch;C:\WINDOWS\system32\drivers\KProcWatch.sys [ ]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Netmrn REG_MULTI_SZ Netmrn

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5feed3d4-17e4-11db-b102-806d6172696f}]
\Shell\AutoRun\command - E:\Setup.exe
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\x2gbkx5l.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://start.mozilla.org/firefox?client=firefox-a&rls=org.mozilla:en-US:official
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 20:28:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Completion time: 2008-10-17 20:30:56 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-17 18:30:50

Pre-Run: 6.816.952.320 bytes free
Post-Run: 6,801,690,624 bytes free

368
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 21:00 - pre 201 meseci
Code:
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09EB15FA-17D8-4D60-8598-3F549A848DF2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{581C5299-BEA6-4619-8218-BE539A98812A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5935D8A5-DC70-4630-8C8C-3C629B67DE68}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AD862DC6-37FA-4D56-B7EA-59C2522A5FC4}]


Ovako iskopiraj ovaj tekst u notepad i snimi ga na desktop kao CFScript, zatim ga levim tasterom misa prevuci na Combofix.
kad zavrsi postavi novi HijackThis log.
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 21:22 - pre 201 meseci
Nisam bas siguran da sam dobro odradio ali evo pogledaj!



Logfile of HijackThis v1.99.1
Scan saved at 22:19:40, on 17.10.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\StartupMonitor.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Electronic Arts\EA Downloader\Core.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\User\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09EB15FA-17D8-4D60-8598-3F549A848DF2} - C:\PROGRA~1\INTERN~1\PLUGINS\b54321.bho
O2 - BHO: (no name) - {581C5299-BEA6-4619-8218-BE539A98812A} - C:\Program Files\Internet Explorer\7v54321t.321
O2 - BHO: (no name) - {5935D8A5-DC70-4630-8C8C-3C629B67DE68} - C:\Program Files\Internet Explorer\7v54321t.321
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AD862DC6-37FA-4D56-B7EA-59C2522A5FC4} - C:\Program Files\Internet Explorer\Explo2eMt.456
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsof...ogWebControl.cab?1222890190475
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/wi...t/wuweb_site.cab?1223387699223
O16 - DPF: {E cellSpacing=5 cellPadding=3 width=400} -
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 21:33 - pre 201 meseci
Nesto nisi odradio kako treba, sta si uradio opisi mi ukratko i kazi da li imas jos problema i ako imas kakvih.
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 21:54 - pre 201 meseci
Nisam siguran da li treba tekst da sacuvam kao .txt file sa nazivom CFScript, sto sam i uradio, i da li treba prvo da otvorim Combo pa da ga prebacim? Nemam posebnih problema: kad nisam na netu explorer mi izbacuje poruku work ofline i cuje se zvuk za pop up u ne pravilnim intervalima.
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 22:15 - pre 201 meseci
To je trojanac Infostealer.Gampass i on je zaduzen za te popup poruke. Nesto je CF automatski obrisao, ostalo je ovo da uradis.
Raspakuj ovu skriptu na desktop i samo je prevuci na ikonicu ComboFixa, nista vise, nemoj da otvaras CF.
Prikačeni fajlovi
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 22:36 - pre 201 meseci
Dobio sam ovo:
ComboFix 08-10-16.08 - User 2008-10-17 23:27:07.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.177 [GMT 2:00]
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]

FILE ::
C:\Program Files\Internet Explorer\7v54321t.321
C:\Program Files\Internet Explorer\Explo2eMt.456
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Internet Explorer\7v54321t.321
C:\Program Files\Internet Explorer\Explo2eMt.456

.
((((((((((((((((((((((((( Files Created from 2008-09-17 to 2008-10-17 )))))))))))))))))))))))))))))))
.

2008-10-16 01:42 . 2008-10-16 01:42 <DIR> d-------- C:\Program Files\Common Files\Younexus
2008-10-14 22:44 . 2008-10-14 22:47 <DIR> d-------- C:\Program Files\Trojan Killer
2008-10-14 18:10 . 2008-10-17 18:00 <DIR> d-------- C:\Program Files\a2 free
2008-10-11 14:40 . 2008-10-11 14:40 <DIR> d-------- C:\Documents and Settings\User\Application Data\Lavasoft
2008-10-11 14:39 . 2008-10-11 14:39 <DIR> d-------- C:\Program Files\Lavasoft
2008-10-07 22:39 . 2008-10-07 22:39 <DIR> d-------- C:\Program Files\IObit
2008-10-07 22:02 . 2008-10-07 22:02 <DIR> d-------- C:\Documents and Settings\User\Application Data\.bittorrent
2008-10-07 16:26 . 2008-10-17 20:30 <DIR> d-------- C:\WINDOWS\system32\CatRoot2
2008-10-06 19:11 . 2008-10-06 19:11 <DIR> d--h----- C:\WINDOWS\$hf_mig$
2008-10-06 18:43 . 2008-10-06 18:43 <DIR> d-------- C:\Documents and Settings\User\Application Data\Talkback
2008-10-06 18:43 . 2008-10-06 18:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-10-06 18:32 . 2008-10-06 18:32 99,965 --a------ C:\WINDOWS\UninstallFirefox.exe
2008-10-06 18:31 . 2008-10-17 20:56 3,791 --a------ C:\WINDOWS\mozver.dat
2008-10-06 18:30 . 2008-10-06 18:30 <DIR> d-------- C:\Program Files\BitTorrent
2008-10-03 16:08 . 2008-10-03 16:08 <DIR> d-------- C:\Program Files\ActiveLaunch
2008-10-03 16:08 . 2008-10-03 16:14 <DIR> d-------- C:\Documents and Settings\User\Application Data\AL Data
2008-10-01 21:23 . 2008-10-01 21:23 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistributionOLD
2008-10-01 21:23 . 2008-07-18 22:10 45,768 --a------ C:\WINDOWS\system32\wups2.dll.old
2008-10-01 21:23 . 2008-07-18 22:10 33,992 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-10-01 21:23 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-10-01 21:23 . 2008-07-18 22:09 25,800 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-10-01 21:23 . 2008-07-18 22:08 20,680 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-09-30 22:11 . 2008-09-30 22:10 300,048 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-09-30 22:11 . 2008-09-30 22:10 245,760 --a------ C:\WINDOWS\system32\imon.dll
2008-09-30 22:11 . 2008-09-30 22:10 114,688 --a------ C:\WINDOWS\system32\nms32.dll
2008-09-30 22:11 . 2008-09-30 22:11 442 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-09-30 22:10 . 2008-10-08 21:22 <DIR> d-------- C:\Program Files\ESET
2008-09-30 17:08 . 2008-09-30 17:24 <DIR> d-------- C:\Program Files\TweakNow RegCleaner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-17 21:31 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-17 14:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-10-06 16:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-06 16:34 --------- d-----w C:\Program Files\ATI Technologies
2008-10-03 14:03 --------- d-----w C:\Program Files\Industry Giant 2
2008-10-03 14:02 --------- d-----w C:\Program Files\EA Games
2008-09-30 20:27 --------- d-----w C:\Program Files\3GP Player
2008-09-10 18:55 --------- d-----w C:\Program Files\Electronic Arts
2008-09-10 18:45 --------- d-----w C:\Program Files\EA SPORTS
2008-08-31 12:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-08-31 12:40 --------- d-----w C:\Program Files\IVT Corporation
2008-08-31 08:21 8,064 ----a-w C:\WINDOWS\rwrm.exe
2008-08-31 08:17 8,064 ----a-w C:\WINDOWS\ypqc.exe
2008-08-30 18:27 --------- d-----w C:\Program Files\LEGO Media
.

((((((((((((((((((((((((((((( snapshot@2008-10-17_20.30.31.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-04 18:24:00 3,695,008 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
+ 2008-10-04 18:24:00 235,936 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{09EB15FA-17D8-4D60-8598-3F549A848DF2}]
2008-10-17 22:31 107008 --ahs---- C:\PROGRA~1\INTERN~1\PLUGINS\b54321.bho

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-07 68856]
"EA Core"="C:\Program Files\Electronic Arts\EA Downloader\Core.exe" [2006-07-13 1851392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 128920]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.EXE" [2007-04-03 4376328]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-07 29744]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-09-30 851968]
"Run StartupMonitor"="StartupMonitor.exe" [2000-05-20 C:\WINDOWS\StartupMonitor.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-10-24 C:\WINDOWS\soundman.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 C:\WINDOWS\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-02-07 113664]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-08-31 1044480]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 394856]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.XVID"= xvid.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\DAP\\DAP.exe"=
"D:\\Igre\\Firaxis Games\\Civilization4.exe"=
"C:\\Program Files\\BitTorrent\\btdownloadgui.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59833:TCP"= 59833:TCP:PORT_59833
"59981:TCP"= 59981:TCP:PORT_59981
"28358:TCP"= 28358:TCP:PORT_28358
"23205:TCP"= 23205:TCP:PORT_23205
"41363:TCP"= 41363:TCP:PORT_41363
"34216:TCP"= 34216:TCP:PORT_34216
"22605:TCP"= 22605:TCP:PORT_22605
"36975:TCP"= 36975:TCP:PORT_36975
"10249:TCP"= 10249:TCP:PORT_10249
"32706:TCP"= 32706:TCP:PORT_32706
"32305:TCP"= 32305:TCP:PORT_32305
"12703:TCP"= 12703:TCP:PORT_12703
"43328:TCP"= 43328:TCP:PORT_43328
"16036:TCP"= 16036:TCP:PORT_16036
"23387:TCP"= 23387:TCP:PORT_23387
"50586:TCP"= 50586:TCP:PORT_50586
"56838:TCP"= 56838:TCP:PORT_56838
"8439:TCP"= 8439:TCP:PORT_8439
"45551:TCP"= 45551:TCP:PORT_45551
"32605:TCP"= 32605:TCP:PORT_32605
"20289:TCP"= 20289:TCP:PORT_20289
"23680:TCP"= 23680:TCP:PORT_23680
"35178:TCP"= 35178:TCP:PORT_35178
"28333:TCP"= 28333:TCP:PORT_28333
"28653:TCP"= 28653:TCP:PORT_28653
"50585:TCP"= 50585:TCP:PORT_50585
"31146:TCP"= 31146:TCP:PORT_31146
"21142:TCP"= 21142:TCP:PORT_21142
"27840:TCP"= 27840:TCP:PORT_27840
"31911:TCP"= 31911:TCP:PORT_31911
"29487:TCP"= 29487:TCP:PORT_29487
"49991:TCP"= 49991:TCP:PORT_49991
"41625:TCP"= 41625:TCP:PORT_41625
"50513:TCP"= 50513:TCP:PORT_50513
"42476:TCP"= 42476:TCP:PORT_42476
"50504:TCP"= 50504:TCP:PORT_50504
"16820:TCP"= 16820:TCP:PORT_16820
"19409:TCP"= 19409:TCP:PORT_19409
"52600:TCP"= 52600:TCP:PORT_52600
"37936:TCP"= 37936:TCP:PORT_37936
"8951:TCP"= 8951:TCP:PORT_8951
"26458:TCP"= 26458:TCP:PORT_26458
"12008:TCP"= 12008:TCP:PORT_12008
"59231:TCP"= 59231:TCP:PORT_59231
"17233:TCP"= 17233:TCP:PORT_17233
"23754:TCP"= 23754:TCP:PORT_23754
"30562:TCP"= 30562:TCP:PORT_30562
"54996:TCP"= 54996:TCP:PORT_54996
"22689:TCP"= 22689:TCP:PORT_22689
"55675:TCP"= 55675:TCP:PORT_55675
"10051:TCP"= 10051:TCP:PORT_10051
"32564:TCP"= 32564:TCP:PORT_32564
"30148:TCP"= 30148:TCP:PORT_30148
"18225:TCP"= 18225:TCP:PORT_18225
"46008:TCP"= 46008:TCP:PORT_46008
"31839:TCP"= 31839:TCP:PORT_31839
"17176:TCP"= 17176:TCP:PORT_17176
"10793:TCP"= 10793:TCP:PORT_10793
"32013:TCP"= 32013:TCP:PORT_32013
"37528:TCP"= 37528:TCP:PORT_37528
"29117:TCP"= 29117:TCP:PORT_29117
"18956:TCP"= 18956:TCP:PORT_18956
"61811:TCP"= 61811:TCP:PORT_61811
"28623:TCP"= 28623:TCP:PORT_28623
"25704:TCP"= 25704:TCP:PORT_25704
"16040:TCP"= 16040:TCP:PORT_16040
"56711:TCP"= 56711:TCP:PORT_56711
"34633:TCP"= 34633:TCP:PORT_34633
"22743:TCP"= 22743:TCP:PORT_22743
"26103:TCP"= 26103:TCP:PORT_26103
"8290:TCP"= 8290:TCP:PORT_8290
"59376:TCP"= 59376:TCP:PORT_59376
"40305:TCP"= 40305:TCP:PORT_40305
"23386:TCP"= 23386:TCP:PORT_23386
"55183:TCP"= 55183:TCP:PORT_55183
"48273:TCP"= 48273:TCP:PORT_48273
"52852:TCP"= 52852:TCP:PORT_52852
"32576:TCP"= 32576:TCP:PORT_32576
"6776:TCP"= 6776:TCP:PORT_6776
"18632:TCP"= 18632:TCP:PORT_18632
"16535:TCP"= 16535:TCP:PORT_16535
"31281:TCP"= 31281:TCP:PORT_31281
"11475:TCP"= 11475:TCP:PORT_11475
"28981:TCP"= 28981:TCP:PORT_28981
"58183:TCP"= 58183:TCP:PORT_58183
"57980:TCP"= 57980:TCP:PORT_57980
"14822:TCP"= 14822:TCP:PORT_14822
"47059:TCP"= 47059:TCP:PORT_47059
"26731:TCP"= 26731:TCP:PORT_26731
"30265:TCP"= 30265:TCP:PORT_30265
"45350:TCP"= 45350:TCP:PORT_45350
"37393:TCP"= 37393:TCP:PORT_37393
"29698:TCP"= 29698:TCP:PORT_29698
"17793:TCP"= 17793:TCP:PORT_17793
"43090:TCP"= 43090:TCP:PORT_43090
"31198:TCP"= 31198:TCP:PORT_31198
"59246:TCP"= 59246:TCP:PORT_59246
"30680:TCP"= 30680:TCP:PORT_30680
"41835:TCP"= 41835:TCP:PORT_41835
"36738:TCP"= 36738:TCP:PORT_36738
"33910:TCP"= 33910:TCP:PORT_33910
"13198:TCP"= 13198:TCP:PORT_13198
"9597:TCP"= 9597:TCP:PORT_9597
"24548:TCP"= 24548:TCP:PORT_24548
"48199:TCP"= 48199:TCP:PORT_48199
"16835:TCP"= 16835:TCP:PORT_16835
"61335:TCP"= 61335:TCP:PORT_61335
"26046:TCP"= 26046:TCP:PORT_26046
"45616:TCP"= 45616:TCP:PORT_45616
"33845:TCP"= 33845:TCP:PORT_33845
"64851:TCP"= 64851:TCP:PORT_64851
"26513:TCP"= 26513:TCP:PORT_26513
"31310:TCP"= 31310:TCP:PORT_31310
"62875:TCP"= 62875:TCP:PORT_62875
"44517:TCP"= 44517:TCP:PORT_44517
"22646:TCP"= 22646:TCP:PORT_22646
"54437:TCP"= 54437:TCP:PORT_54437
"53413:TCP"= 53413:TCP:PORT_53413
"41677:TCP"= 41677:TCP:PORT_41677
"15055:TCP"= 15055:TCP:PORT_15055
"53748:TCP"= 53748:TCP:PORT_53748
"39700:TCP"= 39700:TCP:PORT_39700
"31068:TCP"= 31068:TCP:PORT_31068
"56677:TCP"= 56677:TCP:PORT_56677
"63570:TCP"= 63570:TCP:PORT_63570
"14531:TCP"= 14531:TCP:PORT_14531
"47123:TCP"= 47123:TCP:PORT_47123
"10683:TCP"= 10683:TCP:PORT_10683
"49244:TCP"= 49244:TCP:PORT_49244
"51438:TCP"= 51438:TCP:PORT_51438
"13231:TCP"= 13231:TCP:PORT_13231
"15697:TCP"= 15697:TCP:PORT_15697
"54908:TCP"= 54908:TCP:PORT_54908
"54431:TCP"= 54431:TCP:PORT_54431
"22631:TCP"= 22631:TCP:PORT_22631
"53291:TCP"= 53291:TCP:PORT_53291
"11401:TCP"= 11401:TCP:PORT_11401
"53298:TCP"= 53298:TCP:PORT_53298
"20311:TCP"= 20311:TCP:PORT_20311
"7814:TCP"= 7814:TCP:PORT_7814
"49807:TCP"= 49807:TCP:PORT_49807
"57495:TCP"= 57495:TCP:PORT_57495
"59805:TCP"= 59805:TCP:PORT_59805

R0 BtHidBus;Bluetooth HID Bus Service;C:\WINDOWS\system32\Drivers\BtHidBus.sys [2008-07-31 20616]
R2 GenPort;GenPort;C:\WINDOWS\system32\drivers\GenPort.sys [1997-10-08 4832]
R2 MapMem;MapMem;C:\WINDOWS\system32\drivers\MapMem.sys [1997-10-08 6816]
R2 Netmrn;Network Connerctions;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
R2 NTRemap;NTRemap;C:\WINDOWS\system32\drivers\NTRemap.sys [1997-10-08 6336]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-07 29744]
S3 IvtBtBUs;IVT Bluetooth Bus Service;C:\WINDOWS\system32\Drivers\IvtBtBus.sys [2008-07-02 26248]
S3 KProcWatch;KProcWatch;C:\WINDOWS\system32\drivers\KProcWatch.sys [ ]
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 86368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Netmrn REG_MULTI_SZ Netmrn

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5feed3d4-17e4-11db-b102-806d6172696f}]
\Shell\AutoRun\command - E:\Setup.exe
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-17 23:31:58
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\WINDOWS\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\ESET\nod32krn.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Completion time: 2008-10-17 23:33:58 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-17 21:33:54
ComboFix2.txt 2008-10-17 20:19:01
ComboFix3.txt 2008-10-17 18:30:57

Pre-Run: 6.770.937.856 bytes free
Post-Run: 6,767,882,240 bytes free

318
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 22:51 - pre 201 meseci
Trebalo bi da je sada ok. pokreni sad Hijack This i stikliraj ove linije i klikni Fix

O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsof...ogWebControl.cab?1222890190475
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/wi...t/wuweb_site.cab?1223387699223
O16 - DPF: {E cellSpacing=5 cellPadding=3 width=400} -


Ako te interesuje imao si W32/Rbot-HA trojan backdoor, takodje gore pomenuti Infostealer.Gampass
Deinstaliraj Combofix Start> run> combofix /u ok, sacekaj da se deinstalacija zavrsi i posle ukljuci AV.

Javi da li je sve u redu.
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 23:27 - pre 201 meseci
Kako da deinstaliram Combo?
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 23:33 - pre 201 meseci
Klikni na Start - Run - ukucaj combofix /u ok, sacekaj da se deinstalacija zavrsi.
Pazi na razmak izmedju combofix i /
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.dialup.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 23:40 - pre 201 meseci
nece. ponovo ga pokrece!
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.yu.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!17.10.2008. u 23:46 - pre 201 meseci
Obriši folder C:\QooBox

Potrebno je resetovati System Restore:

* Control Panel > System: na System Restore tabu: čekiraj Turn off System Restore on all drives
*
* Control Panel > System: na System Restore tabu: dečekiraj Turn off System Restore on all drives

Gornji postupak će obrisati sadržaj System Restore foldera i kreirati novu, "čistu" tačku za oporavak sistema.

To je to...
 
Odgovor na temu

tatica
Mirko Lalovic
Pozega

Član broj: 197819
Poruke: 15
*.DIALUP-SMIN.neobee.net.



Profil

icon Re: Win32/PSW.OnLineGames.NRG Trojan HELP!18.10.2008. u 23:02 - pre 201 meseci
Extra! Uspeo SI! HVALA DO NEBA!
 
Odgovor na temu

[es] :: Zaštita :: Win32/PSW.OnLineGames.NRG Trojan HELP!

[ Pregleda: 2558 | Odgovora: 14 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.