MSN virus

4

MSN virus

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 190
  • Gde živiš: Beograd

DDS (Ver_09-12-01.01) - NTFSx86
Run by Milan at 18:35:27,89 on sre 27.01.2010
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.1022.621 [GMT 1:00]

AV: avast! antivirus 4.8.1368 [VPS 100127-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\WinFast\WFDTV\DTVSchdl.exe
C:\WINDOWS\PixArt\PAC7302\Monitor.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinFast\WFDTV\WFWIZ.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Milan\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [Link mogu videti samo ulogovani korisnici]
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\rpbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live pomagač za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [WinFast Schedule] c:\program files\winfast\wfdtv\WFWIZ.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [IncrediMail] c:\program files\incredimail\bin\IncMail.exe /c
uRun: [Google Update] "c:\documents and settings\milan\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [WinFastDTV] c:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\milan\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - [Link mogu videti samo ulogovani korisnici]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [Link mogu videti samo ulogovani korisnici]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\milan\applic~1\mozilla\firefox\profiles\pg7bx94v.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\program files\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\milan\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2010-1-15 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-15 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2010-1-15 138680]
R3 ReallusionVirtualAudio;Reallusion Virtual Audio;c:\windows\system32\drivers\RLVrtAuCbl.sys [2010-1-15 31616]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2010-1-15 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2010-1-15 352920]

=============== Created Last 30 ================

2010-01-24 22:49:36 0 d-s---w- C:\ComboFix
2010-01-24 20:25:20 0 d-sha-r- C:\cmdcons
2010-01-24 20:24:12 98816 ----a-w- c:\windows\sed.exe
2010-01-24 20:24:12 77312 ----a-w- c:\windows\MBR.exe
2010-01-24 20:24:12 261632 ----a-w- c:\windows\PEV.exe
2010-01-24 20:24:12 161792 ----a-w- c:\windows\SWREG.exe
2010-01-24 20:00:21 0 d-----w- c:\windows\system32\wbem\Repository
2010-01-24 19:22:02 0 d-s---w- C:\ComboFix(2)
2010-01-24 13:12:11 0 d-----w- c:\program files\AxBx
2010-01-24 12:31:48 0 d-----w- c:\windows\pss
2010-01-23 16:42:34 0 d-----w- c:\program files\Microsoft
2010-01-23 16:42:18 0 d-----w- c:\program files\Windows Live SkyDrive
2010-01-23 16:34:02 0 d-----w- c:\windows\SxsCaPendDel
2010-01-23 16:33:18 0 d-----w- c:\windows\system32\appmgmt
2010-01-22 22:37:17 77824 ----a-r- c:\windows\system32\HPZIDS01.dll
2010-01-22 22:37:15 48128 ----a-w- c:\windows\system32\hpzll463.dll
2010-01-20 20:32:18 0 d-----w- c:\program files\vSoft
2010-01-18 18:45:19 0 d-----w- C:\My Web Sites
2010-01-18 18:11:12 0 d-----w- c:\program files\Free Hide Folder
2010-01-18 18:10:31 0 d-----w- c:\program files\WinHTTrack
2010-01-18 17:09:03 0 d-----w- C:\downloads
2010-01-18 17:09:03 0 d-----w- c:\docume~1\milan\applic~1\GrabPro
2010-01-18 17:04:58 0 d-----w- c:\windows\Lhsp
2010-01-18 17:04:43 0 d-----w- c:\program files\MyReader
2010-01-18 17:04:23 0 d-----w- c:\windows\speech
2010-01-18 16:58:02 0 d-----w- c:\program files\uTorrent
2010-01-18 16:56:55 0 d-----w- c:\docume~1\milan\applic~1\uTorrent
2010-01-16 12:18:14 3255 ----a-w- c:\windows\system32\wbem\Outlook_01ca96a5fa728f64.mof
2010-01-15 17:26:16 0 d-----w- c:\program files\NotePager Pro
2010-01-15 17:23:37 0 d-----w- c:\program files\Eggiz
2010-01-15 17:21:03 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-15 17:14:38 0 d-----r- c:\program files\Skype
2010-01-15 16:50:07 0 d-----w- c:\program files\IncrediMail
2010-01-15 16:50:07 0 d-----w- c:\docume~1\alluse~1\applic~1\IncrediMail
2010-01-15 16:50:07 0 d-----w- c:\docume~1\alluse~1\applic~1\IM
2010-01-15 16:47:24 0 d-----w- c:\program files\CCleaner
2010-01-15 16:46:42 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-01-15 16:46:41 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2010-01-15 16:46:41 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2010-01-15 16:46:37 0 d-----w- c:\windows\Logs
2010-01-15 16:46:00 0 d-----w- c:\program files\Winamp Detect
2010-01-15 16:42:02 14336 ----a-w- c:\program files\wmdmhelper.dll
2010-01-15 16:42:02 0 d-----w- c:\program files\templates
2010-01-15 16:42:01 712704 ----a-w- c:\program files\dtdr3260.dll
2010-01-15 16:42:01 651264 ----a-w- c:\program files\rjbres.dll
2010-01-15 16:42:01 36352 ----a-w- c:\program files\ierjplug.dll
2010-01-15 16:42:01 352256 ----a-w- c:\program files\rjdlg.dll
2010-01-15 16:42:01 19456 ----a-w- c:\program files\rjprog.dll
2010-01-15 16:42:01 139264 ----a-w- c:\program files\DUNZIP32.dll
2010-01-15 16:42:01 0 d-----w- c:\program files\Devices
2010-01-15 16:42:01 0 d-----w- c:\program files\CDBurning
2010-01-15 16:42:00 81920 ----a-w- c:\program files\tsasdk.dll
2010-01-15 16:42:00 6656 ----a-w- c:\program files\fixrjb.exe
2010-01-15 16:42:00 57344 ----a-w- c:\program files\tpasdk.dll
2010-01-15 16:42:00 41472 ----a-w- c:\program files\mmcdda32.dll
2010-01-15 16:42:00 19456 ----a-w- c:\program files\tnetdtct.dll
2010-01-15 16:41:59 43056 ----a-w- c:\program files\rpshellsearch.dll
2010-01-15 16:41:59 32768 ----a-w- c:\program files\rpwa3260.dll
2010-01-15 16:41:58 719360 ----a-w- c:\program files\dbghelp.dll
2010-01-15 16:41:58 65536 ----a-w- c:\program files\rjwmapln.dll
2010-01-15 16:41:58 329312 ----a-w- c:\program files\rpbrowserrecordplugin.dll
2010-01-15 16:41:58 0 d-----w- c:\program files\producer
2010-01-15 16:41:58 0 d-----w- c:\program files\browserrecord
2010-01-15 16:41:57 0 d-----w- c:\program files\plugins
2010-01-15 16:41:55 53248 ----a-w- c:\program files\rpau3260.dll
2010-01-15 16:41:55 480 ----a-w- c:\program files\keys.dat
2010-01-15 16:41:53 112168 ----a-w- c:\program files\rdsf3260.dll
2010-01-15 16:41:53 102400 ----a-w- c:\program files\HXAudioDeviceHook.dll
2010-01-15 16:41:53 0 d-----w- c:\program files\Netscape6
2010-01-15 16:41:53 0 d-----w- c:\program files\DataCache
2010-01-15 16:41:52 86016 ----a-w- c:\program files\rpplugprot.dll
2010-01-15 16:41:52 63016 ----a-w- c:\program files\rpshell.dll
2010-01-15 16:41:52 50 ----a-w- c:\program files\strs23.dat
2010-01-15 16:41:52 13 ----a-w- c:\program files\strs26.dat
2010-01-15 16:41:52 1030 ----a-w- c:\program files\autoplaylist.dat
2010-01-15 16:41:52 0 d-----w- c:\program files\library
2010-01-15 16:41:51 7168 ----a-w- c:\program files\realjbox.exe
2010-01-15 16:41:51 14888 ----a-w- c:\program files\rphelperapp.exe
2010-01-15 16:41:51 0 d-----w- c:\program files\rpplugins
2010-01-15 16:41:50 0 d-----w- c:\program files\common files\xing shared
2010-01-15 16:41:49 0 d-----w- c:\program files\converter
2010-01-15 16:41:40 222728 ----a-w- c:\program files\realplay.exe
2010-01-15 16:41:40 0 d-----w- c:\program files\Setup
2010-01-15 16:41:39 198208 ----a-w- c:\program files\RecordingManager.exe
2010-01-15 16:41:38 0 d-----w- c:\program files\common files\Real
2010-01-15 16:36:46 0 d-----w- c:\docume~1\milan\applic~1\Malwarebytes
2010-01-15 16:36:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-15 16:36:41 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-15 16:36:41 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-15 16:36:41 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-15 16:14:40 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-01-15 11:17:06 0 d-----w- c:\program files\common files\ODBC
2010-01-15 11:17:03 0 d-----w- c:\program files\common files\SpeechEngines
2010-01-15 11:16:38 0 d-----r- c:\documents and settings\all users\Documents
2010-01-15 10:31:11 0 d-sh--w- c:\documents and settings\all users\DRM
2010-01-15 10:30:54 0 d--h--w- c:\program files\WindowsUpdate
2010-01-15 10:30:24 0 d-----w- c:\program files\common files\MSSoap
2010-01-15 10:28:59 0 d-----w- c:\program files\Online Services
2010-01-15 10:28:52 0 d-----w- c:\program files\Messenger
2010-01-15 10:28:49 0 d-----w- c:\program files\MSN Gaming Zone
2010-01-15 10:28:18 0 d-----w- c:\program files\Windows NT
2010-01-15 00:34:35 0 d-----w- c:\program files\common files\Windows Live
2010-01-15 00:26:50 0 d-----w- c:\program files\Microsoft Visual Studio 8
2010-01-15 00:08:57 0 d-----w- c:\program files\Reallusion
2010-01-15 00:08:57 0 d-----w- c:\program files\common files\Reallusion
2010-01-15 00:07:32 0 d-----w- c:\program files\common files\Eye 312
2010-01-15 00:07:28 0 d-----w- c:\program files\common files\Pac7302
2010-01-14 23:48:30 0 d-----w- c:\docume~1\alluse~1\applic~1\ArcSoft
2010-01-14 23:48:23 0 d-----w- c:\program files\common files\Ulead Systems
2010-01-14 23:48:01 0 d-----w- c:\program files\WinFast
2010-01-14 23:46:14 0 d-----w- c:\program files\Leadtek Research Inc
2010-01-14 23:34:43 0 d-----w- c:\program files\My Company Name
2010-01-14 23:30:59 0 d-----w- c:\program files\common files\ATI Technologies
2010-01-14 23:27:12 0 d-----w- c:\program files\ATI Technologies
2010-01-14 23:17:15 0 d-----w- c:\program files\Realtek

==================== Find3M ====================

2010-01-15 16:42:01 2851 ----a-w- c:\program files\cdroms.cfg
2010-01-15 10:29:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-15 00:54:04 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-14 23:23:58 15600 ----a-w- c:\windows\gdrv.sys
2010-01-14 23:17:09 315392 ----a-w- c:\windows\HideWin.exe

============= FINISH: 18:35:37,76 ===============

[Link mogu videti samo ulogovani korisnici]



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

Ima li nekih problema?



offline
  • Pridružio: 28 Feb 2009
  • Poruke: 190
  • Gde živiš: Beograd

Za sad sve deluje ok. Bar se nadam Very Happy

Htedoh samo da pitam sta sa fajlom(ikonicom) infocard.exe.back koja mi stoji na desktopu i sa folderom Qoobox u Win.Exploreru,ako se secam to mi do sad nije bilo?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

infocard.exe.back obrisi rucno.

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 190
  • Gde živiš: Beograd

Uradio sam ovo za deinstalaciju combofixa.Medjutim na desktopu mi jos uvek stoji.A takodje i u win.exploreru i to u dva foldera kao i ovaj qoobox.

Evo i slike




offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8652
  • Gde živiš: Novi Beograd

Obrisi onda sve te foldere i fajlove rucno.

offline
  • Pridružio: 28 Feb 2009
  • Poruke: 190
  • Gde živiš: Beograd

Ok Zavrsio sam.

Hvala puno za pomoc Very Happy

Ko je trenutno na forumu
 

Ukupno su 1637 korisnika na forumu :: 94 registrovanih, 6 sakrivenih i 1537 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: aca018, Aco_GM, alex71, Atomski čoban, bakovaca, Bojan198527, Botovac, Branko Matić, brufen, cavatina, Cirkon, coaaco, cole77, colji, DaliborVukadinovic, darkojovxp, DavidA, deLacy, desmeki, Dimitrise93, Django777, Djokislav, DonRumataEstorski, doom83, Dukelander, dunavzed, Frunze, Gaga_89, gost321, h8propaganda, hajduk1911, ikan, Imperator_Aleksandr_lll, Iskander, Jadranko1969, jaka013, joca83, jodzula, Kajzer Soze, kalens021, Kalu128338, kaput21, karevski, Kenanjoz, KizJ, Knovakov, komsija1, Kubovac, laganini123, laurusri, Lelemood, Leonov, leopard83, LostInSpaceandTime, Lošmi, luka35, Makky, Marko Marković, mačković, mikrimaus, milenko crazy north, Miler88, milos.cbr, Miškić, morava_01, nikolapetkovic, nixos, NklJov123, nnovakis, opt1, pacika, procesor, Resnica, RiV, Rogan33, S.Palestinac, Sass Drake, Sharpshooter, Smiljkovich, sovanova95, StankoVrankovic, Stefan M, stegonosa, strn, t84dar, TangoSix, tomigun, Tumansky, vaci, Velibor Radoja, Vlad000, Vlada78, XBMC, Zastava