Comodo Intrusions

poruka: 15
|
čitano: 5.140
|
moderatori: Lazarus Long, pirat, XXX-Man, DrNasty, vincimus
1
+/- sve poruke
ravni prikaz
starije poruke gore
14 godina
neaktivan
offline
Comodo Intrusions

Pogledao sam malo po opcijama Comoda i u firewall sekciji vidim da imam +40 blokiranih intrusiona iliti upada odnosno pokusaja,

razne ip adrese,nakon provjere,ima ih od Saudijske Arabije do Kanade.

Datumi su od 30.01.2011. pa do prije 2 minuta.

Idu minuta za minutom.

Comodo ih je sve blokirao.

 

Imam Aviru free,malwarebytes,superAntiSpywayre,CCleaner i sve to..raspored da mi se cisti komp svaki drugi dan.

 

Moze mi neko ovo pojasnit?

 

Moj PC  
0 0 hvala 0
15 godina
offline
Comodo Intrusions

Postaj log od hijackthis http://free.antivirus.com/hijackthis/ ovdje

 

da Bog da crk'o rock'n'roll, kad ga svako svira
Moj PC  
0 0 hvala 0
14 godina
neaktivan
offline
Comodo Intrusions

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:15:07, on 1.2.2011.
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Users\Forzuk\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files (x86)\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Internet Download Manager\IDMan.exe
C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IDM Helper - Disabled:{0055C089-8582-441B-A0BF-17B458C2A3A8} - (no file)
O2 - BHO: (no name) - Disabled:{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - Disabled:{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: (no name) - Disabled:{9030D464-4C02-4ABF-8ECC-5164760863C6} - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: GOM Player + Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATICustomerCare] "C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [googletalk] C:\Users\Forzuk\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9DD6B637-1F7F-462C-BF26-7CA3ADF7A09F}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs:  C:\Windows\SysWOW64\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Usluga Google ažuriranje (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8953 bytes

 

 

Imam sad preko 400 intrusiona,svi dolaze sa 3-4 iste IP adrese,po 50-ak komada,3-4 takve adrese,target su ili svchost.exe i system.

 

Moj PC  
0 0 hvala 0
15 godina
offline
Comodo Intrusions

fixaj ovog:     O3 - Toolbar: GOM Player + Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll

ostalo je sve u redu, stvarno neznam što bi moglo uzrokovati te intrusione, hijackthis kaže da nemaš ništa takvo pokrenuto/u memoriji

da Bog da crk'o rock'n'roll, kad ga svako svira
Moj PC  
0 0 hvala 0
14 godina
offline
Comodo Intrusions

Skeniraj s MBAM-om.Updatiraj prije skeniranja.

Piracy lives forever!!!
Moj PC  
0 0 hvala 0
16 godina
neaktivan
moderator
offline
RE: Comodo Intrusions
forzzuk kaže...

Logfile of Trend Micro HijackThis v2.0.4

 

  Pogledao sam na http://hijackthis.de/ i nemas virusa. Sto se tice raznih napadackih adresa samo ti mogu reci da se ne brines. Uzrok moze biti svasta od samo prozvanih hakera koji snifaju internet u potrazi za zarazenim racunalima (i time preuzeli kontrolu) do lose napisanih web skripta koje zele pristup tvojim fileovima.

 

dakle, nista narocito. Imam i ja ovakvih "napada". To su obicno "napadi" bazirani na neki propust u Windowsima

A programmer is just a tool which converts caffeine into code
16 godina
neaktivan
moderator
offline
Comodo Intrusions

@forzzuk

 

Ako ti je utjeha i ja ih imam. Ovakvih napada imam na tisuce u mom logu (Norton Internet Security 2011)

 

A programmer is just a tool which converts caffeine into code
 
0 0 hvala 1
14 godina
neaktivan
offline
Comodo Intrusions

hvala,jednostavno covjeka uhvati malo paranoja {#}

Pogotovo kad stalno čistim komp i pazim na te stvari.

Zanima me,sto bi bilo recimo da nemam Comodo (svi ga hvale).

 

Moj PC  
0 0 hvala 0
16 godina
neaktivan
moderator
offline
RE: Comodo Intrusions
forzzuk kaže...

hvala,jednostavno covjeka uhvati malo paranoja {#}

Pogotovo kad stalno čistim komp i pazim na te stvari.

Zanima me,sto bi bilo recimo da nemam Comodo (svi ga hvale).

 

  Ako je vrlo jaka varijabla ali stvari bi isle ovako. Ako bi nemao Comodo onda bi bio n00b i ne bi sada pricali ovdje o ovim napadima.

 

Dakle, najverojatno bi imao Windows Firewall koji je vrlo dobar i opet bio imao zastiti minus "paranoja" logova.

 

IMHO

 

Windows Firewall je vrlo dobar firewall koji se moze stelati do mile volje. Jedino lose je to sto nije "pregledan" za podesavanje pa nema grafickih dida mida...

 

...valjda ostavljaju mrvice i ostalima :)

A programmer is just a tool which converts caffeine into code
15 godina
neaktivan
offline
Comodo Intrusions

Imaš li statičku adresu ili dyndns?

 

Ako nemaš, ajd oprobaj restartati ruter i vidi hoće li promjeniti IP adresu. Ako promjeni i ako ti se nastave napadi, definitivno imaš problema s nečime na tvome računalu, čak možda i neki zero-day.

 

Ovako može biti da si posjetom na neku stranicu ostavio IP adresu, te sad gledaju kako da ti dođu glave.

Imamo televune, radivone, televizije, lektrika, lektrika, sva čuda, raj na zemlji brajo... Samo nemamo pisme, ni ognjišta ni smija... E!
 
0 0 hvala 0
14 godina
protjeran
offline
RE: Comodo Intrusions
Smooth Operator kaže...

Imaš li statičku adresu ili dyndns?

 

Ako nemaš, ajd oprobaj restartati ruter i vidi hoće li promjeniti IP adresu. Ako promjeni i ako ti se nastave napadi, definitivno imaš problema s nečime na tvome računalu, čak možda i neki zero-day.

 

Ovako može biti da si posjetom na neku stranicu ostavio IP adresu, te sad gledaju kako da ti dođu glave.

radikalni ekstremisti iz Egipta???!!!...{#}

14 godina
neaktivan
offline
Comodo Intrusions

5000 u 3 dana.

 

Moj PC  
0 0 hvala 0
13 godina
offline
RE: Comodo Intrusions
forzzuk kaže...

5000 u 3 dana.

 

Provjeri imaš li blokiran System (Firewall -> Network Security Policy -> Blocked Zones)?

the funniest thing about this particular signature is that by the time you realise it doesn't say anything it's too late to stop reading it
14 godina
neaktivan
offline
Comodo Intrusions

I ovo nemogu nikako maknut,nađe mi ga sa antispywareon kao 'unrecognised';windows\system32\MFPLAY.DLL

Moj PC  
0 0 hvala 0
15 godina
offline
Comodo Intrusions

Pogledaj malo ovdje

www.hrphotocontest.com
Moj PC  
0 0 hvala 0
1
Nova poruka
E-mail:
Lozinka:
 
vrh stranice