offline
- dugouho
- Novi MyCity građanin
- Pridružio: 08 Avg 2007
- Poruke: 26
|
Nisam siguran na što ste mislili kad ste rekli da će se pojaviti log i da ga iskopiram.Da li je to ovo?ComboFix 07-10-12.1 - Joçko 2007-10-11 23:23:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.148 [GMT 2:00]
Running from: C:\Documents and Settings\Joçko\My Documents\radna mapa\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\companion wizard\log.txt
C:\Program Files\Common Files\Companion Wizard\log.txt
C:\WA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\awtqo.exe
C:\WINDOWS\system32\dn305b4a81.dat
C:\WINDOWS\system32\kbddd5.dll
C:\WINDOWS\system32\mt_32.dll
C:\WINDOWS\system32\plus32.ocx
C:\WINDOWS\system32\tmp5C.tmp.dll
C:\WINDOWS\system32\tmp5C.tmp.dll
C:\WINDOWS\system32\tmpA5.tmp.dll
C:\WINDOWS\system32\tmpA5.tmp.dll
C:\WINDOWS\xhelper.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.
2007-10-11 23:22 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-11 18:16 <DIR> d-------- C:\Program Files\Security Task Manager
2007-10-11 18:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-10-11 11:37 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-09 06:51 <DIR> d-------- C:\My Downloads
2007-10-09 06:46 <DIR> d-------- C:\Program Files\Super Internet TV
2007-10-07 13:42 <DIR> d-------- C:\totalcmd
2007-10-07 13:42 545 --a------ C:\WINDOWS\UC.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\RAR.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\LHA.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\ARJ.PIF
2007-10-06 14:56 <DIR> d-------- C:\Program Files\DkZ Studio
2007-10-06 07:11 <DIR> d-------- C:\Program Files\WinUHA
2007-09-28 18:08 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-28 18:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 18:07 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-09-28 18:07 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-09-28 18:07 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-09-27 22:16 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-09-23 17:57 <DIR> d-------- C:\Program Files\TVAnts
2007-09-23 13:31 <DIR> d-------- C:\Program Files\ClocX
2007-09-22 19:00 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2007-09-20 20:59 <DIR> d-------- C:\WINDOWS\system32\Nexus Radio
2007-09-20 20:59 <DIR> d-------- C:\Program Files\Nexus_Radio
2007-09-20 20:59 <DIR> d-------- C:\Program Files\Nexus Radio
2007-09-20 20:59 <DIR> d-------- C:\My Recorded Files
2007-09-20 19:56 <DIR> d-------- C:\Program Files\Raven
2007-09-14 20:17 <DIR> d-------- C:\Program Files\D-Tools
2007-09-14 20:17 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-09-14 20:17 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-09-14 20:16 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-09-13 16:53 <DIR> d-------- C:\Program Files\Yahoo!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-11 16:10 5,767,168 ----a-w C:\Documents and Settings\Joško\ntuser.dat
2007-10-11 02:39 --------- d-----w C:\Program Files\Common Files\Real
2007-10-10 01:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-09 19:19 --------- d-----w C:\Program Files\SopCast
2007-10-09 04:56 --------- d-----w C:\Program Files\Real
2007-10-06 22:04 --------- d-----w C:\Program Files\Java
2007-10-05 03:10 --------- d-----w C:\Program Files\DivX
2007-09-30 14:05 --------- d-----w C:\Program Files\eMule
2007-09-28 16:07 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-09-28 16:07 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-09-28 16:07 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-09-28 16:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-09-28 16:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-09-28 16:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-28 16:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 16:05 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-28 16:05 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-28 16:05 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-09-28 16:05 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-09-28 16:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-09-28 16:05 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-09-28 16:05 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-09-28 16:05 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-09-28 01:24 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-09-28 01:13 --------- d-----w C:\Program Files\EA SPORTS
2007-09-28 01:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-27 21:34 --------- d-----w C:\Program Files\KONAMI
2007-09-27 12:16 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-25 20:04 --------- d-----w C:\Program Files\Total Video Converter
2007-09-23 16:01 --------- d-----w C:\Program Files\TVUPlayer
2007-09-09 07:56 --------- d-----w C:\Program Files\Common Files\Java
2007-09-07 02:57 --------- d-----w C:\Program Files\Setup
2007-09-06 20:54 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-06 20:45 --------- d-----w C:\Program Files\Activision
2007-09-04 19:51 --------- d-----w C:\Program Files\ratDVD
2007-08-30 04:27 --------- d-----w C:\Program Files\Webteh
2007-08-27 01:46 --------- d-----w C:\Program Files\Folder Icon Changer
2007-08-23 01:10 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-23 01:10 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-22 01:40 --------- d-----w C:\Program Files\Rainlendar2
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-20 03:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-08-17 23:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-08-17 23:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-08-16 17:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-08-15 19:15 --------- d-----w C:\Program Files\SlimTV
2007-08-08 02:52 164 ----a-w C:\install.dat
2007-08-04 19:23 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-28 14:59 17,120 ----a-w C:\WINDOWS\system32\awtsspq.dll
2007-07-19 22:57 267,112 ----a-w C:\WINDOWS\system32\xactengine2_9.dll
2007-07-19 22:54 18,280 ----a-w C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-19 22:48 77,160 ----a-w C:\DSETUP.dll
2007-07-19 22:48 503,144 ----a-w C:\DXSETUP.exe
2007-07-19 22:48 1,673,576 ----a-w C:\dsetup32.dll
2007-07-19 16:14 444,776 ----a-w C:\WINDOWS\system32\d3dx10_35.dll
2007-07-19 16:14 3,727,720 ----a-w C:\WINDOWS\system32\d3dx9_35.dll
2007-07-19 16:14 1,358,192 ----a-w C:\WINDOWS\system32\D3DCompiler_35.dll
2007-03-17 04:02 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0d8da04e-d7fe-4a03-bea8-1ee5d60ffe21}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
2007-09-29 15:28 1453080 --a------ C:\Program Files\Nexus_Radio\tbNex1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2462d2d8-b36e-44ab-84bf-c5a9383d2429}"= C:\Program Files\Nexus_Radio\tbNex1.dll [2007-09-29 15:28 1453080]
[HKEY_CLASSES_ROOT\CLSID\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2462D2D8-B36E-44AB-84BF-C5A9383D2429}"= C:\Program Files\Nexus_Radio\tbNex1.dll [2007-09-29 15:28 1453080]
[HKEY_CLASSES_ROOT\CLSID\{2462D2D8-B36E-44AB-84BF-C5A9383D2429}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 15:06]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 16:00 C:\WINDOWS\AGRSMMSG.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 21:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-09-14 09:45]
"RegistryMechanic"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [2005-01-26 11:04]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 12:12]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2007-04-15 08:31]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imagert]
imagert.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\awtsspq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup
R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys
S3 USB_RNDIS_51;T-Com MAXadsl modem (USB, NDIS);C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 Vl813;USB Filter;C:\WINDOWS\system32\DRIVERS\Vl813.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-09 07:00:00 C:\WINDOWS\Tasks\At10.job"
"2007-10-09 08:00:00 C:\WINDOWS\Tasks\At11.job"
"2007-10-09 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 15:00:00 C:\WINDOWS\Tasks\At18.job"
"2007-10-11 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 02:00:03 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 03:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 04:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-10 05:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 06:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 07:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 08:00:00 C:\WINDOWS\Tasks\At35.job"
"2007-10-09 09:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 10:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 11:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 12:00:00 C:\WINDOWS\Tasks\At39.job"
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 13:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 14:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 15:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 16:00:00 C:\WINDOWS\Tasks\At43.job"
"2007-10-11 17:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 18:00:01 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 19:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 20:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 21:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 02:00:03 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 03:00:01 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-09 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\7043s54v.exe
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-10-12 23:31:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-12 23:33:07 - machine was rebooted
.
--- E O F ---
Dopuna: 13 Okt 2007 18:32
Molim vas može li mi tko da odgovori na ovo pitanje:
Rećeno mi je da skinem ComboFix i da ga startujem i na kraju da kopiram log i ovdje da postavim i ja sam postavio ovo kao što se vidi u postu iznad samo nisam siguran da li sam dobro napravio.Može li mi reći tko da li sam ja dobro napravio ili sam možda nešto drugo trebao kopirati i postaviti.Razlog ovog mog pitanja je zbog tog što mi nitko nije odgovorio na ovaj moj prijašnji post pa se bojim da sam krivo napravio i da odgovor nikad neću doćekat.Znaći samo tražim da mi netko kaže jesam li dobro napravio u ovom mom postu iznad.
|