Pomoc!!!

2

Pomoc!!!

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

ComboFix 07-12-21.4 - dmitko 2007-12-22 12:28:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.64 [GMT 1:00]
Running from: D:\Documents and Settings\dmitko\My Documents\Programi\ComboFix.exe
Command switches used :: D:\Documents and Settings\dmitko\My Documents\Programi\CFScript.txt
* Created a new restore point

FILE
D:\WINDOWS\Qxe85.sys
D:\WINDOWS\system32\abmorgku.ini
D:\WINDOWS\system32\cbwnquxx.ini
D:\WINDOWS\system32\csbhbimu.ini
D:\WINDOWS\system32\dlduusrn.ini
D:\WINDOWS\system32\eagxbwne.ini
D:\WINDOWS\system32\eoslriix.ini
D:\WINDOWS\system32\fkgwiixu.ini
D:\WINDOWS\system32\gbghqqcb.ini
D:\WINDOWS\system32\gbrkghjy.ini
D:\WINDOWS\system32\hcjfuqwn.ini
D:\WINDOWS\system32\hnrtbtsr.ini
D:\WINDOWS\system32\inuafavy.ini
D:\WINDOWS\system32\jfrscxqi.ini
D:\WINDOWS\system32\jilnn.tmp2
D:\WINDOWS\system32\jqsiaarq.ini
D:\WINDOWS\system32\ljwqgubq.ini
D:\WINDOWS\system32\nfenxfdj.ini
D:\WINDOWS\system32\nnlij.dll
D:\WINDOWS\system32\nuvbicak.ini
D:\WINDOWS\system32\nuynrsnd.ini
D:\WINDOWS\system32\odecsmfb.ini
D:\WINDOWS\system32\rjnnwcen.dll
D:\WINDOWS\system32\saehnvgj.ini
D:\WINDOWS\system32\sakmbjhk.ini
D:\WINDOWS\system32\tixvkalc.ini
D:\WINDOWS\system32\vbwbrohq.ini
D:\WINDOWS\system32\wihstsha.ini
D:\WINDOWS\system32\wnpmcs.exe
D:\WINDOWS\system32\xeymlsou.ini
D:\WINDOWS\system32\xnyonwxd.dll
D:\WINDOWS\system32\yaywwwv.dll
D:\WINDOWS\system32\ybpktavb.ini
D:\WINDOWS\system32\ylwhnivo.ini
D:\WINDOWS\system32\ymkegvty.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\VundoFix Backups
D:\VundoFix Backups\abbynskx.exe.bad
D:\VundoFix Backups\aehrqyeq.exe.bad
D:\VundoFix Backups\ahssnqle.exe.bad
D:\VundoFix Backups\arceeere.dll.bad
D:\VundoFix Backups\bbdidyxh.ini2.bad
D:\VundoFix Backups\bbdidyxh.tmp.bad
D:\VundoFix Backups\bjaonylj.exe.bad
D:\VundoFix Backups\bmvsapmx.dll.bad
D:\VundoFix Backups\bsugnjph.dll.bad
D:\VundoFix Backups\bufdeknk.dll.bad
D:\VundoFix Backups\buftrrer.exe.bad
D:\VundoFix Backups\bulforpk.exe.bad
D:\VundoFix Backups\byxvstt.dll.bad
D:\VundoFix Backups\byxxyax.dll.bad
D:\VundoFix Backups\cgqkivdm.dll.bad
D:\VundoFix Backups\ctfewxlr.exe.bad
D:\VundoFix Backups\cvfmgdts.dll.bad
D:\VundoFix Backups\ddcaaxw.dll.bad
D:\VundoFix Backups\ddcbcyw.dll.bad
D:\VundoFix Backups\dftujuvw.exe.bad
D:\VundoFix Backups\dhqjtcot.dll.bad
D:\VundoFix Backups\diptaqkx.exe.bad
D:\VundoFix Backups\dksinswl.dll.bad
D:\VundoFix Backups\dlvfdhxj.exe.bad
D:\VundoFix Backups\durmitva.exe.bad
D:\VundoFix Backups\efccdbx.dll.bad
D:\VundoFix Backups\efryokfn.exe.bad
D:\VundoFix Backups\elcantrj.exe.bad
D:\VundoFix Backups\eltdyxsl.exe.bad
D:\VundoFix Backups\eljqahac.exe.bad
D:\VundoFix Backups\erladjul.dll.bad
D:\VundoFix Backups\erqccepe.dll.bad
D:\VundoFix Backups\etcmiyeq.exe.bad
D:\VundoFix Backups\eujwmpdq.dll.bad
D:\VundoFix Backups\euohfcua.exe.bad
D:\VundoFix Backups\fhcbkmom.dll.bad
D:\VundoFix Backups\fkoqcxvh.dll.bad
D:\VundoFix Backups\flatoklk.dll.bad
D:\VundoFix Backups\fodlrbli.exe.bad
D:\VundoFix Backups\fojmrqkd.dll.bad
D:\VundoFix Backups\fqcthuge.exe.bad
D:\VundoFix Backups\frhtxhin.dll.bad
D:\VundoFix Backups\ftrlkotl.exe.bad
D:\VundoFix Backups\fymkyajy.exe.bad
D:\VundoFix Backups\gcibaevb.exe.bad
D:\VundoFix Backups\gekubmfl.dll.bad
D:\VundoFix Backups\ghexibvp.exe.bad
D:\VundoFix Backups\gpqqpjpp.dll.bad
D:\VundoFix Backups\grfxqbes.dll.bad
D:\VundoFix Backups\gwxvgxvr.dll.bad
D:\VundoFix Backups\haftkuhh.exe.bad
D:\VundoFix Backups\hggddeb.dll.bad
D:\VundoFix Backups\hgghecb.dll.bad
D:\VundoFix Backups\hkjecvmw.exe.bad
D:\VundoFix Backups\hnxojvop.exe.bad
D:\VundoFix Backups\hsjqqsfn.dll.bad
D:\VundoFix Backups\hvxcqokf.ini.bad
D:\VundoFix Backups\hxydidbb.dll.bad
D:\VundoFix Backups\iesprpac.exe.bad
D:\VundoFix Backups\iifcddb.dll.bad
D:\VundoFix Backups\iifdedb.dll.bad
D:\VundoFix Backups\iiffecb.dll.bad
D:\VundoFix Backups\ilqmclid.exe.bad
D:\VundoFix Backups\iqapjyno.dll.bad
D:\VundoFix Backups\iqbcmmvv.dll.bad
D:\VundoFix Backups\ivhhkdtj.exe.bad
D:\VundoFix Backups\jgaoiwuw.exe.bad
D:\VundoFix Backups\jgevafpt.exe.bad
D:\VundoFix Backups\jgiedtye.exe.bad
D:\VundoFix Backups\jlmsluhp.exe.bad
D:\VundoFix Backups\jmscciwu.dll.bad
D:\VundoFix Backups\jqbgnjmc.exe.bad
D:\VundoFix Backups\jrxtyjed.exe.bad
D:\VundoFix Backups\jswocnvd.exe.bad
D:\VundoFix Backups\jxmilhaq.exe.bad
D:\VundoFix Backups\jyannjiu.dll.bad
D:\VundoFix Backups\kacibvun.dll.bad
D:\VundoFix Backups\khfdeff.dll.bad
D:\VundoFix Backups\kiljhtxt.exe.bad
D:\VundoFix Backups\kniwiiym.dll.bad
D:\VundoFix Backups\knyncmie.exe.bad
D:\VundoFix Backups\ktpjotqd.exe.bad
D:\VundoFix Backups\lhcaswkq.exe.bad
D:\VundoFix Backups\lnebdilm.dll.bad
D:\VundoFix Backups\lujdalre.ini.bad
D:\VundoFix Backups\luosnwol.exe.bad
D:\VundoFix Backups\maqyasru.exe.bad
D:\VundoFix Backups\mlnfjdxd.dll.bad
D:\VundoFix Backups\morceksk.dll.bad
D:\VundoFix Backups\nnlij.dll.bad
D:\VundoFix Backups\nnlljih.dll.bad
D:\VundoFix Backups\nrsuudld.dll.bad
D:\VundoFix Backups\nucsmgoj.exe.bad
D:\VundoFix Backups\nwqufjch.dll.bad
D:\VundoFix Backups\nyqebdlm.exe.bad
D:\VundoFix Backups\ofngmepc.exe.bad
D:\VundoFix Backups\oohqkvpe.exe.bad
D:\VundoFix Backups\opnkkhf.dll.bad
D:\VundoFix Backups\oqwusfsj.exe.bad
D:\VundoFix Backups\ountstka.exe.bad
D:\VundoFix Backups\ovinhwly.dll.bad
D:\VundoFix Backups\owfyyqlg.dll.bad
D:\VundoFix Backups\paclxvvk.exe.bad
D:\VundoFix Backups\paecpirv.exe.bad
D:\VundoFix Backups\pjyryfie.exe.bad
D:\VundoFix Backups\pmnnmmn.dll.bad
D:\VundoFix Backups\pnvwnkov.exe.bad
D:\VundoFix Backups\pocpywpw.exe.bad
D:\VundoFix Backups\poghddco.exe.bad
D:\VundoFix Backups\ppjpqqpg.ini.bad
D:\VundoFix Backups\pqngtnah.exe.bad
D:\VundoFix Backups\pqpjqrpf.exe.bad
D:\VundoFix Backups\prpppraj.exe.bad
D:\VundoFix Backups\qbugqwjl.dll.bad
D:\VundoFix Backups\qcavotex.exe.bad
D:\VundoFix Backups\qcqqpqmj.exe.bad
D:\VundoFix Backups\qsipmaxt.exe.bad
D:\VundoFix Backups\rayxxhvp.exe.bad
D:\VundoFix Backups\rstbtrnh.dll.bad
D:\VundoFix Backups\ruvqcaqk.dll.bad
D:\VundoFix Backups\rwghixnj.exe.bad
D:\VundoFix Backups\rymyxppx.exe.bad
D:\VundoFix Backups\sebqxfrg.ini.bad
D:\VundoFix Backups\sfmjlnsc.exe.bad
D:\VundoFix Backups\sfumsefo.exe.bad
D:\VundoFix Backups\sokrutwv.dll.bad
D:\VundoFix Backups\ssqnnmn.dll.bad
D:\VundoFix Backups\ssqpqqo.dll.bad
D:\VundoFix Backups\stxistig.exe.bad
D:\VundoFix Backups\sxmgullq.dll.bad
D:\VundoFix Backups\tcayvlcg.exe.bad
D:\VundoFix Backups\tchjwwlj.exe.bad
D:\VundoFix Backups\tkehyadc.exe.bad
D:\VundoFix Backups\toctjqhd.ini.bad
D:\VundoFix Backups\twosmwwf.dll.bad
D:\VundoFix Backups\tyfgwdck.exe.bad
D:\VundoFix Backups\uamvbvkf.exe.bad
D:\VundoFix Backups\ujxuxleh.dll.bad
D:\VundoFix Backups\ukgromba.dll.bad
D:\VundoFix Backups\ukiwwwch.exe.bad
D:\VundoFix Backups\umibhbsc.dll.bad
D:\VundoFix Backups\uoslmyex.dll.bad
D:\VundoFix Backups\urqnoom.dll.bad
D:\VundoFix Backups\urqpqrq.dll.bad
D:\VundoFix Backups\ursqrqp.dll.bad
D:\VundoFix Backups\uslmrqyj.exe.bad
D:\VundoFix Backups\uwnoeqdi.exe.bad
D:\VundoFix Backups\uxiiwgkf.dll.bad
D:\VundoFix Backups\viryuhes.exe.bad
D:\VundoFix Backups\vtusppn.dll.bad
D:\VundoFix Backups\vvunlsps.dll.bad
D:\VundoFix Backups\vwapncsc.dll.bad
D:\VundoFix Backups\wdympjlw.exe.bad
D:\VundoFix Backups\wersdjxt.dll.bad
D:\VundoFix Backups\wjimegvv.exe.bad
D:\VundoFix Backups\wjkyrraa.exe.bad
D:\VundoFix Backups\woqbboxp.exe.bad
D:\VundoFix Backups\wqweafdy.dll.bad
D:\VundoFix Backups\wrsgcjjl.exe.bad
D:\VundoFix Backups\wuojjmby.exe.bad
D:\VundoFix Backups\wwbussty.exe.bad
D:\VundoFix Backups\xaogpkkx.exe.bad
D:\VundoFix Backups\xiirlsoe.dll.bad
D:\VundoFix Backups\xxuqnwbc.dll.bad
D:\VundoFix Backups\yglbtpmv.exe.bad
D:\VundoFix Backups\yhssauue.exe.bad
D:\VundoFix Backups\yjhgkrbg.dll.bad
D:\VundoFix Backups\yofemrkp.dll.bad
D:\VundoFix Backups\yohyvqor.exe.bad
D:\VundoFix Backups\ypvyudbm.exe.bad
D:\VundoFix Backups\ytvgekmy.dll.bad
D:\VundoFix Backups\yuceaacd.exe.bad
D:\VundoFix Backups\yvafauni.dll.bad
D:\VundoFix Backups\yvmkxdsn.exe.bad
D:\WINDOWS\Qxe85.sys
D:\WINDOWS\system32\abmorgku.ini
D:\WINDOWS\system32\cbwnquxx.ini
D:\WINDOWS\system32\csbhbimu.ini
D:\WINDOWS\system32\dlduusrn.ini
D:\WINDOWS\system32\eagxbwne.ini
D:\WINDOWS\system32\eoslriix.ini
D:\WINDOWS\system32\fkgwiixu.ini
D:\WINDOWS\system32\gbghqqcb.ini
D:\WINDOWS\system32\gbrkghjy.ini
D:\WINDOWS\system32\hcjfuqwn.ini
D:\WINDOWS\system32\hnrtbtsr.ini
D:\WINDOWS\system32\inuafavy.ini
D:\WINDOWS\system32\jfrscxqi.ini
D:\WINDOWS\system32\jilnn.tmp2
D:\WINDOWS\system32\jqsiaarq.ini
D:\WINDOWS\system32\ljwqgubq.ini
D:\WINDOWS\system32\nfenxfdj.ini
D:\WINDOWS\system32\nuvbicak.ini
D:\WINDOWS\system32\nuynrsnd.ini
D:\WINDOWS\system32\odecsmfb.ini
D:\WINDOWS\system32\rjnnwcen.dll
D:\WINDOWS\system32\saehnvgj.ini
D:\WINDOWS\system32\sakmbjhk.ini
D:\WINDOWS\system32\tixvkalc.ini
D:\WINDOWS\system32\vbwbrohq.ini
D:\WINDOWS\system32\wihstsha.ini
D:\WINDOWS\system32\wnpmcs.exe
D:\WINDOWS\system32\xeymlsou.ini
D:\WINDOWS\system32\xnyonwxd.dll
D:\WINDOWS\system32\xnyonwxd.dllbox
D:\WINDOWS\system32\yaywwwv.dll
D:\WINDOWS\system32\ybpktavb.ini
D:\WINDOWS\system32\ylwhnivo.ini
D:\WINDOWS\system32\ymkegvty.ini

Dopuna: 22 Dec 2007 12:50

.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.

2007-12-22 02:04 . 2007-12-22 02:04 7,168 --a------ D:\WINDOWS\system32\windows
2007-12-18 22:41 . 2007-12-18 22:41 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2007-12-18 22:41 . 2007-12-18 22:41 1,409 --a------ D:\WINDOWS\QTFont.for
2007-12-18 00:37 . 1999-11-12 21:49 294,912 --a------ D:\WINDOWS\system32\iviaudio.ax
2007-12-18 00:37 . 2000-05-07 22:08 34,816 --a------ D:\WINDOWS\system32\mpgaudio.ax
2007-12-18 00:37 . 2002-05-21 17:14 4,286 --a------ D:\WINDOWS\system32\divx.ico
2007-12-18 00:33 . 2007-12-18 00:33 <DIR> d-------- D:\Program Files\The Playa
2007-12-18 00:33 . 2007-12-18 00:33 <DIR> d-------- D:\Program Files\DivXCodec
2007-12-18 00:10 . 2007-12-18 00:15 <DIR> d-------- D:\Program Files\ACE Mega CoDecS Pack
2007-12-17 12:09 . 2007-12-17 12:09 <DIR> d-------- D:\Program Files\Trend Micro
2007-12-16 19:48 . 2007-12-18 22:40 <DIR> d-------- D:\Program Files\MicroDVD
2007-12-16 19:47 . 2001-01-24 03:28 412,160 -ra------ D:\WINDOWS\system32\DivXc32.dll
2007-12-16 19:47 . 2000-12-21 15:40 300,544 -ra------ D:\WINDOWS\system32\l3codeca.acm
2007-12-16 19:47 . 2000-12-29 13:58 287,744 -ra------ D:\WINDOWS\system32\DivXa32.acm
2007-12-16 19:47 . 2000-12-21 15:34 239,616 -ra------ D:\WINDOWS\system32\DivX_c32.ax
2007-12-16 19:47 . 2001-01-24 03:05 121,856 -ra------ D:\WINDOWS\system32\Mp3cnfg.cpl
2007-12-16 19:47 . 2001-01-24 03:12 19,456 -ra------ D:\WINDOWS\system32\Mp3cnfg.exe
2007-12-15 01:30 . 2007-12-14 17:12 57,662 --a------ D:\WINDOWS\system32\fx.exe
2007-12-15 01:30 . 2004-03-05 07:01 31,232 --a------ D:\WINDOWS\system32\pv.exe
2007-12-15 01:19 . 2007-12-15 01:19 23,392 --a------ D:\WINDOWS\system32\nscompat.tlb
2007-12-15 01:19 . 2007-12-15 01:19 16,832 --a------ D:\WINDOWS\system32\amcompat.tlb
2007-12-13 21:15 . 2007-12-14 20:31 <DIR> d-------- D:\Program Files\eMule
2007-12-13 21:02 . 2007-12-13 21:02 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Avira
2007-12-13 18:25 . 2007-12-18 22:21 <DIR> d-------- D:\Program Files\SuperCleaner
2007-12-13 00:41 . 2007-03-08 00:51 9,336 --------- D:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-13 00:40 . 2007-03-08 00:51 129,784 --a------ D:\WINDOWS\system32\pxafs.dll
2007-12-13 00:40 . 2007-03-08 00:51 9,464 --------- D:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-12 01:18 . 2007-12-12 01:18 <DIR> d-------- D:\Program Files\Windows Live
2007-12-12 01:18 . 2007-12-12 20:33 <DIR> d-------- D:\Program Files\MessengerDiscovery
2007-12-12 01:18 . 2004-03-09 00:00 212,240 --a------ D:\WINDOWS\system32\richtx32.OCX
2007-12-12 01:18 . 2004-03-09 00:00 124,688 --a------ D:\WINDOWS\system32\MSWINSCK.ocx
2007-12-11 00:08 . 2007-12-13 18:34 <DIR> d-------- D:\Program Files\Engineering Power Tools - v1.9.6
2007-12-11 00:08 . 1997-01-16 00:00 958,224 --a------ D:\WINDOWS\system32\MSCHART.OCX
2007-12-11 00:08 . 2004-03-09 00:00 609,824 --a------ D:\WINDOWS\system32\COMCTL32.ocx
2007-12-11 00:08 . 1997-01-14 00:00 519,680 --a------ D:\WINDOWS\system32\DBGRID32.OCX
2007-12-11 00:08 . 1998-06-24 00:00 164,144 --a------ D:\WINDOWS\system32\COMCT232.OCX
2007-12-11 00:08 . 1997-01-16 00:00 71,680 --a------ D:\WINDOWS\ST5UNST.EXE
2007-12-11 00:08 . 1997-01-16 00:00 29,696 --a------ D:\WINDOWS\system32\VB5StKit.dll
2007-12-06 18:39 . 2007-12-21 21:37 <DIR> d-------- D:\Documents and Settings\dmitko\Application Data\U3
2007-12-03 16:19 . 2007-12-14 20:28 <DIR> d-------- D:\Program Files\Windows Media Connect 2
2007-12-03 16:16 . 2007-12-03 16:16 <DIR> d-------- D:\WINDOWS\system32\LogFiles
2007-12-03 16:16 . 2007-12-03 16:18 <DIR> d-------- D:\WINDOWS\system32\drivers\UMDF
2007-12-02 23:42 . 2007-12-07 11:26 <DIR> d-------- D:\Program Files\Macrogaming
2007-12-02 20:36 . 2001-11-30 19:05 131,072 --a------ D:\WINDOWS\system32\dzip32.dll
2007-12-02 20:36 . 2001-11-30 19:05 110,592 --a------ D:\WINDOWS\system32\dunzip32.dll
2007-12-02 20:35 . 2007-12-02 20:36 <DIR> d-------- D:\Program Files\Windows Media Bonus Pack for Windows XP
2007-11-24 20:48 . 2007-12-05 00:16 <DIR> d-------- D:\Program Files\MySpace
2007-11-24 20:48 . 2007-11-24 20:48 <DIR> d-------- D:\Documents and Settings\dmitko\Application Data\MySpace

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 23:19 --------- d-----w D:\Program Files\QuickTime
2007-12-17 22:58 --------- d-----w D:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-16 18:42 --------- d-----w D:\Program Files\DivX
2007-12-13 17:34 --------- d-----w D:\Documents and Settings\dmitko\Application Data\Azureus
2007-12-13 16:51 --------- d-----w D:\Program Files\MSN Messenger
2007-12-13 14:47 --------- d-----w D:\Program Files\Windows Live Toolbar
2007-12-13 14:46 --------- d-----w D:\Program Files\Winamp
2007-12-02 22:37 --------- d-----w D:\Program Files\Opera
2007-11-19 13:50 --------- d-----w D:\Program Files\Common Files\Adobe
2007-11-18 19:53 --------- d-----w D:\Documents and Settings\All Users\Application Data\Barbie Fashion Show
2007-11-14 23:28 --------- d-----w D:\Documents and Settings\dmitko\Application Data\Apple Computer
2007-11-14 17:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-14 17:21 --------- d-----w D:\Program Files\Apple Software Update
2007-11-14 17:21 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2007-11-13 10:25 20,480 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 00:37 --------- d-----w D:\Documents and Settings\All Users\Application Data\ESET
2007-11-08 19:57 --------- d-----w D:\Program Files\MT882
2007-11-08 19:51 155,995 ----a-w D:\WINDOWS\java\Packages\KFLNLFDR.ZIP
2007-11-08 19:31 --------- d-----w D:\Program Files\Kaspersky Lab
2007-11-08 18:20 --------- d-----w D:\Program Files\CCleaner
2007-11-05 11:06 30,728 ----a-w D:\WINDOWS\system32\drivers\epfwtdir.sys
2007-11-05 11:04 33,800 ----a-w D:\WINDOWS\system32\drivers\eamon.sys
2007-11-05 11:04 27,656 ----a-w D:\WINDOWS\system32\drivers\easdrv.sys
2007-10-31 18:03 --------- d-----w D:\Program Files\MSXML 4.0
2007-10-31 15:52 45,056 ----a-w D:\WINDOWS\NCUNINST.EXE
2007-10-30 19:36 --------- d-----w D:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-30 18:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-30 15:18 --------- d-----w D:\Documents and Settings\dmitko\Application Data\SumatraPDF
2001-11-23 04:08 712,704 ----a-w D:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((( snapshot@2007-12-22_ 2.44.37.91 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-04 00:54]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"Sony Ericsson PC Suite"="D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"egui"="D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-05 12:05]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2007-12-18 00:20]

R1 easdrv;easdrv;D:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-11-05 12:04]
R1 epfwtdir;epfwtdir;D:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-05 12:06]
R2 eamon;EAMON;D:\WINDOWS\system32\DRIVERS\eamon.sys [2007-11-05 12:04]
R3 iadusb;MT882;D:\WINDOWS\system32\DRIVERS\glauiad.sys [2006-03-20 08:32]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);D:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 20:34]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;D:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2006-11-25 12:29]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;D:\WINDOWS\system32\DRIVERS\k510mdm.sys [2006-11-25 12:29]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);D:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-11-25 12:29]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;D:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-11-25 12:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 16:46:05 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-12-22 12:41:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 12:44:31 - machine was rebooted
D:\ComboFix2.txt ... 2007-12-22 02:46
.
2007-12-22 02:03:37 --- E O F ---



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pošalji mi sledeće file-ove:

D:\WINDOWS\system32\fx.exe
D:\WINDOWS\system32\pv.exe


Upload link: [Link mogu videti samo ulogovani korisnici]



Restartuj PC i postavi svež HijackThis log.



offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Fileovi uploadovani..

Dopuna: 22 Dec 2007 15:25

Logfile of HijackThis v1.99.1
Scan saved at 15:21:29, on 22.12.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\WgaTray.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Common Files\Teleca Shared\Generic.exe
D:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
D:\Documents and Settings\dmitko\My Documents\Programi\tr3.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Search - [Link mogu videti samo ulogovani korisnici]
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {E72CFC93-BAE3-8D60-85D1-129993AAC8B9} (UImageUploader Class) - [Link mogu videti samo ulogovani korisnici]
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pronađi i obriši:

D:\WINDOWS\system32\fx.exe
D:\WINDOWS\system32\pv.exe

C:\QooBox\ (ceo folder)


-------------------------------------------------------------------------------------


Pokreni HijackThis, skeniraj i čekiraj sledeće linije:

O8 - Extra context menu item: &Search - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - [Link mogu videti samo ulogovani korisnici]

Klikni Fix Checked.


-------------------------------------------------------------------------------------


Iskljucivanje System Restore-a

Na Desktopu, desni klik na My Computer.
Odaberite Properties.
Odaberite System Restore tab.
Stiklirajte Turn off System Restore.
Kliknite na dugme Apply.
Kliknite na dugme OK.



Restartuj kompjuter.


Ukljucivanje System Restore-a

Na Desktopu, desni klik na My Computer.
Odaberite Properties.
Odaberite System Restore tab.
Destiklirajte Turn off System Restore.
Kliknite na dugme Apply.
Kliknite na dugme OK.


-------------------------------------------------------------------------------------


Kakvo je sada stanje? Primećuješ li neke probleme?

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Mnogo ste mi pomogli hvala, sada mi komp radi dosta bolje, mada jos uvek imam problem da mi se usred rada ubaguje i prestane da reaguje, moram da ga restartuje na power, mada taj problem verovatno i nema veze sa malwareom...
Hvala u svakom slucaju, najbolji ste, a da li sada imate neku generalnu preporuku za mene kako u buducnosti da se zastitim od malwarea?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Što se tiče malware-a - ovde ga vše nema.

Što se tiče pomenutog problema, mnogo toga može da ga prouzrokuje (obrati pažnju na temperature komponenti, probaj reinstalirati driver-e, itd).

Kako se zaštititi? Nažalost, nema 100% pouzdanog metoda.
Prosto, treba da koristiš zaštitni softver i da budeš ''oprezan'' surfer.


Pozdrav...

Ko je trenutno na forumu
 

Ukupno su 1261 korisnika na forumu :: 292 registrovanih, 22 sakrivenih i 947 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -III-, -Max-, 015, 33 bren, _stipa_, A.R.Chafee.Jr., advokat84, AK - 230, alberto, aleksandarbl, AleksandarV, aleph_one, alternator, amaterSRB, anbeast, Andrija357, Antoni S, Arhiv, Aska, Asparagus, atmel, Avalon015, avijacija, babaroga, bakovaca, bambulic, Banovo Brdo, Batko.VD.65, bb929, belov, berste23, bestguarder, black venom, Bo96, bojan581, bojan_t, bojank, bojankrstc, Bokiboks, Boris BM, Boris.A, Boris90, Boroš, BORUTUS, Bozjidar87, Brabant, BradaRS, brandža84, Brot, Bubimir, bukefal, C-Gun, cakija, CCCP, cekic, Chainsaw, chichabg, Cicumile, cifra, Citalac, Clouseau, Crazzer, cuvarkuca, cvalex, cvele130, cvrle312, dacanaldo, DalmatinacMF, dankisha, darkkran, Darko8, delboy, Denaya, DezurniOperativni, Df410, Dixtrix, Django777, djordjemiklusev, DJUNTA, Djuza, dmarx1, dnr, dolinalima, Draganeli, draganl, Dragon Order, DrNeoCortex, dunavzed, Dusko Nikolin, Dzoni2412, Dzuki, Džekson, Electron, feanor, fokac, Gaga_89, gajca1977, gasha, gmlale, gobrad, goxin, gregorxix, grenadir, GrobarPovratak, grunff2, Hans Gajger, HrcAk47, ikan, Imperator_Aleksandr_lll, In_hero, Inner-Cell, invictuss, Ivan Germanovic, ivan1973, ivan_8282, Jablan, Jakonjveliki, jalos, Jan, Jeremiah, Jerry Drake, jodzula, Jonbonjovi, Jovan.D, Jozo74, K a s p e r, Kajzer_Soze, Kalem, Kaponi, Kichma, Kobrim, Koce, kokodakalo, komsija1, Koridor, kozhedub, krkalon, Krusarac, Kubovac, kunktator, kuntakinte, lacko, ladro, lima, livada123, luja, M74AB3, madun123, Makarid, maksi007, Mane88, MareMarkic, marko.markovic, MarkoDzimi, markolopin, matrix_1, maxim_von_burdengate, mačković, MB120mm, mercedesamg, Mi lao shu, Might is Right, Mihailo Gazdić, Miki 84, milanpetkovicv, milenko crazy north, milikonst, milivoje_vatrogasac, Milovan Dinic, Milun24, mishkooo, mist-mist, Misterrno, Mitch22, mkukoleca, mm1811, mnn2, Moldovan, moldway, monomah, Mrav Obrad, museum, Myamoto Musashi, Mzee, Naj-Turs, neko iz mase, NemanjaCG, nenad81, Nmr, Ognjen D., Orc, orfanel, OsmatracIzDosade, ozzy, paja69, PantR, pavle_pzs, PedjaDikovic, pein, Pekman, Perudin_92, Phaeton, pisac12, PlayerOne, Podgoritza, Podljub, Posmatrac77OKB, Povratak1912, precan, Primus17, Privrednik, proka89, Pururin, radovanstojkov023, RajkoB, raster12, Razdroid, reader, RiV, royst33, RS28, Sevetar, shadower78, shaja1, Sharpshooter, Simon simonović, Simonsen23, Sin Boskic, Sioux7674, Sky diver 29, Slingshot, Smajser, SMF, Smiljkovich, Sone1983, Speer, Srna, ssekir75, stagezin, stalja, StepskiVuk, stevo svinja, stibium51, Stojan Mrsavi, Stoorb, styg, Su 57, svnedelja, synergia, t84dar, tanakadzo, Tandrčak, TBoy, TheBeastOfMG, tomo2, Tribal, trinitrotoluen, troki1971, Tunguska55, v82, vaci, Valter071, VanZan, vathra, VBoss, vdeki, veljkovicdani, Viceroy, vladaa012, vladd, vladivostok, VNVK, VOŽD, vrlenija, W123, WELJKO, x011, xAlex2, yip314, yiyi, zastavnik, zbazin, zdrebac, zemljanin, ZetaMan, zexon, Zmaj Tolak, zmajognjeniivan, Zoran1959, Zrcalo, zule2, Zvrk