Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

HijackThis log file - molim analizu

[es] :: Zaštita :: HijackThis log file - molim analizu

[ Pregleda: 2522 | Odgovora: 11 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon HijackThis log file - molim analizu27.05.2010. u 17:24 - pre 169 meseci
Sumnjam da imam neki skriveni proces pa molim analizu HijackThis log file-a:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:18:17, on 27.5.2010
Platform: Unknown Windows (WinNT 6.01.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe
C:\Windows\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2010\seccenter.exe
C:\Windows\VM305_STI.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Your Uninstaller 2010\urmain.exe
C:\Program Files\Your Uninstaller 2010\urmain.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Aca\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Aca\Desktop\HiJackThis\Acika.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/...=aus&qkw=%s&tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.rs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O2 - BHO: Windows Live pomagač za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2010\IEToolbar.dll
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2010\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2010\bdagent.exe"
O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\Aca\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/con....1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia....ockwave/cabs/flash/swflash.cab
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Acronis Nonstop Backup service (afcdpsrv) - Acronis - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe
O23 - Service: COMODO livePCsupport Service (CLPSLS) - COMODO - C:\Program Files\COMODO\COMODO livePCsupport\CLPSLS.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Media Center Support Service (Jasmio.MediaCenter.Service) - Unknown owner - C:\Program Files\Jasmio\Media Center Support Service\Jasmio.MediaCenter.Service.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\Program Files\OO Software\Defrag\oodag.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2010c\RpcAgentSrv.exe
O23 - Service: Sandboxie Service (SbieSvc) - tzuk - C:\Program Files\Sandboxie\SbieSvc.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2010\vsserv.exe

--
End of file - 9559 bytes
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 17:27 - pre 169 meseci
Stikliraj samo ovo:

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - (no file)

...nista vise ja ovde ne vidim...kakve manifestacije imas, zasto si siguran da je prisutan malware?
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 17:37 - pre 169 meseci
Primetio sam da mi zauzece procesora varira 0-30% a da mi nista nije aktivno. tj. bude npr. otvoren samo browser a ne surfujem.
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 18:19 - pre 169 meseci
Mozda je browser u pitanju...pokusaj sa drugim da vidis da li ce biti isti simptomi...skini Dr.Web CureIt http://www.freedrweb.com/cureit/ , odradi prvo Express scan, ako nista ne nadje odradi i Complete scan, to ce malo potrajati...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 18:52 - pre 169 meseci
Odradio sam i sa njim, sve sam zivo proterao.
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 19:24 - pre 169 meseci
Mislim da to nisu reakcije od malware-a, procesor bi u task-u skakao mnogo vise...pogledaj dobro startup, ocisti history itd...
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 21:08 - pre 169 meseci
za pocetak deinstaliraj Google Chrome browser pa reci jel ima poboljsanja

edit: posle deinstalacije pokreni "wise registry cleaner" (imas portable verziju na officijalnom sajtu) i pocisti registry
 
Odgovor na temu

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 23:04 - pre 169 meseci
Odradio sve ali i dalje isto. evo sad mi je otvorena Mozilla (dosta tabova je otvoreno) i iskoriscenost cpu-a brzo dize i spusta i dodje i do 55%. A procesor nikakvu radnju ne obradjuje, osim sto je Mozilla otvorena. Ne znam da li je to normalno?
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 23:11 - pre 169 meseci
Kada ti je vise tabova otvoreno normalno je da se opterecenje procesora poveca...da li ti procesor varira isto tako kada nista ne radis tj kada ne aktiviras nijednu aplikaciju?
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon Re: HijackThis log file - molim analizu27.05.2010. u 23:47 - pre 169 meseci
Izgleda da je sve ipak bilo samo do gomile otvorenih tabova. Bez pokretanja ikakve aplikacije cpu varira od 0-5%. Navika mi je da drzim uvek dosta otvorenih tabova jer mi je tako zgodno da se brzo krecem medju njima. Hvala svima na odgovorima.
 
Odgovor na temu

Machiavelli...
Đorđe Đokanović
IT Support Engineer II
www.amazon.com
Philadelphia

Član broj: 90589
Poruke: 672
*.hsd1.pa.comcast.net.

Sajt: www.linkedin.com/in/dorde..


+92 Profil

icon Re: HijackThis log file - molim analizu28.05.2010. u 17:14 - pre 169 meseci
ja koliko vidim imas

SpywareTerminatorShield
COMODO Internet Security
BitDefender 2010

Imas 3 antivirus/antispyware ja bi reko da oni uzimaju CPU. Posebno ako neko od ovih radi resident protection.

Having an idea is like being in a nutshell, but exchanging idea and collaborate
with
others is like being in infinite ocean of knowledge.
________________________________________________________________
____

Veruj u sebe. Ako ti neces, ko hoce?!

„Bolje živeti 100 godina kao milioner, nego sedam dana u bedi.“
 
Odgovor na temu

xman25

Član broj: 166173
Poruke: 41
*.dynamic.isp.telekom.rs.



+1 Profil

icon Re: HijackThis log file - molim analizu29.05.2010. u 00:31 - pre 169 meseci
SpywareTerminatorShield mi je samo anti spyware, bitdefender samo antivirus a COMODO Internet Security samo firewall.
 
Odgovor na temu

[es] :: Zaštita :: HijackThis log file - molim analizu

[ Pregleda: 2522 | Odgovora: 11 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.