offline
- Pridružio: 13 Sep 2009
- Poruke: 97
|
Napisano: 25 Sep 2009 15:54
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
Sada cu da pokusam i sa ComboFix-om, pa cu javiti sta je bilo.
Dopuna: 25 Sep 2009 16:17
ComboFix 09-09-24.01 - Yugo 5.09.2009. 15:58.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.413 [GMT 2:00]
Running from: D:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Yugo\Application Data\Microsoft\Internet Explorer\Quick Launch\Advanced Virus Remover.lnk
c:\documents and settings\Yugo\Desktop\Advanced Virus Remover.lnk
c:\documents and settings\Yugo\Start Menu\Advanced Virus Remover.lnk
c:\program files\AdvancedVirusRemover
c:\program files\AdvancedVirusRemover\PAVRM.exe
c:\recycler\S-1-5-21-2624118270-5603507921-713645029-0608
c:\recycler\S-1-5-21-2624118270-5603507921-713645029-0608\Desktop.ini
c:\recycler\S-1-5-21-2624118270-5603507921-713645029-0608\wmiprvse.exe
c:\recycler\S-1-5-21-3727256006-6699103586-398626812-8126
c:\recycler\S-1-5-21-4167022408-0549548601-627578440-3621
c:\windows\system32\winhelper.dll
c:\windows\system32\winupdate.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-08-25 to 2009-09-25 )))))))))))))))))))))))))))))))
.
2009-09-25 10:25 . 2009-09-25 10:25 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-04 09:13 . 2009-03-21 19:39 -------- d-----w- c:\documents and settings\Yugo\Application Data\Skype
2009-09-04 09:11 . 2009-05-14 14:32 -------- d-----w- c:\documents and settings\Yugo\Application Data\DMCache
2009-08-22 20:00 . 2009-08-22 20:00 -------- d-----w- c:\documents and settings\Yugo\Application Data\Media Player Classic
2009-08-22 11:55 . 2008-11-13 09:04 120928 ----a-w- c:\documents and settings\Yugo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 07:58 . 2009-08-22 07:58 -------- d-----w- c:\program files\MSBuild
2009-08-22 07:58 . 2009-08-22 07:58 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2008-04-15 03:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2008-04-15 03:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 08:08 . 2008-04-15 03:00 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2007-08-14 01:54 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2008-04-15 03:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2008-04-15 03:00 17408 ----a-w- c:\windows\system32\corpol.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-15 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-15 169984]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-05-16 16862720]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [10.11.2008. 15:34 104456]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [10.11.2008. 15:34 92168]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [10.11.2008. 15:34 711240]
S3 GoogleDesktopManager-080708-050100;Google Desktop Manager 5.7.808.7150;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [13.11.2008. 10:59 24064]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1108&m=aoa150
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=1108&m=aoa150
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-09-25 16:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{728976f9-e55e-4c9d-9b7f-41fa7ea5b989}]
@Denied: (Full) (Everyone)
"Model"=dword:000000bd
"Therad"=dword:00000001
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,ca,eb,3f,c2,78,20,60,0a,d6,1e,06,c6,db,27,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):dc,93,ef,09,61,64,36,d0,40,ac,73,bf,14,93,43,4f,76,39,15,39,34,
b0,eb,c7,e0,58,3d,11,bd,b5,e4,24,0e,f2,a9,2d,fe,65,f3,98,00,00,00,00,00,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3888-)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\wdfmgr.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\docume~1\Yugo\LOCALS~1\temp\RtkBtMnt.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-09-25 16:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-25 14:13
Pre-Run: 144,107,233,280 bytes free
Post-Run: 144,455,639,040 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
132 --- E O F --- 2009-09-04 01:00
Mislim da sada sve radi lepo.
Hvala.
|