Pomoc!!!

2

Pomoc!!!

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

ComboFix 07-12-21.4 - dmitko 2007-12-22 12:28:24.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.64 [GMT 1:00]
Running from: D:\Documents and Settings\dmitko\My Documents\Programi\ComboFix.exe
Command switches used :: D:\Documents and Settings\dmitko\My Documents\Programi\CFScript.txt
* Created a new restore point

FILE
D:\WINDOWS\Qxe85.sys
D:\WINDOWS\system32\abmorgku.ini
D:\WINDOWS\system32\cbwnquxx.ini
D:\WINDOWS\system32\csbhbimu.ini
D:\WINDOWS\system32\dlduusrn.ini
D:\WINDOWS\system32\eagxbwne.ini
D:\WINDOWS\system32\eoslriix.ini
D:\WINDOWS\system32\fkgwiixu.ini
D:\WINDOWS\system32\gbghqqcb.ini
D:\WINDOWS\system32\gbrkghjy.ini
D:\WINDOWS\system32\hcjfuqwn.ini
D:\WINDOWS\system32\hnrtbtsr.ini
D:\WINDOWS\system32\inuafavy.ini
D:\WINDOWS\system32\jfrscxqi.ini
D:\WINDOWS\system32\jilnn.tmp2
D:\WINDOWS\system32\jqsiaarq.ini
D:\WINDOWS\system32\ljwqgubq.ini
D:\WINDOWS\system32\nfenxfdj.ini
D:\WINDOWS\system32\nnlij.dll
D:\WINDOWS\system32\nuvbicak.ini
D:\WINDOWS\system32\nuynrsnd.ini
D:\WINDOWS\system32\odecsmfb.ini
D:\WINDOWS\system32\rjnnwcen.dll
D:\WINDOWS\system32\saehnvgj.ini
D:\WINDOWS\system32\sakmbjhk.ini
D:\WINDOWS\system32\tixvkalc.ini
D:\WINDOWS\system32\vbwbrohq.ini
D:\WINDOWS\system32\wihstsha.ini
D:\WINDOWS\system32\wnpmcs.exe
D:\WINDOWS\system32\xeymlsou.ini
D:\WINDOWS\system32\xnyonwxd.dll
D:\WINDOWS\system32\yaywwwv.dll
D:\WINDOWS\system32\ybpktavb.ini
D:\WINDOWS\system32\ylwhnivo.ini
D:\WINDOWS\system32\ymkegvty.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\VundoFix Backups
D:\VundoFix Backups\abbynskx.exe.bad
D:\VundoFix Backups\aehrqyeq.exe.bad
D:\VundoFix Backups\ahssnqle.exe.bad
D:\VundoFix Backups\arceeere.dll.bad
D:\VundoFix Backups\bbdidyxh.ini2.bad
D:\VundoFix Backups\bbdidyxh.tmp.bad
D:\VundoFix Backups\bjaonylj.exe.bad
D:\VundoFix Backups\bmvsapmx.dll.bad
D:\VundoFix Backups\bsugnjph.dll.bad
D:\VundoFix Backups\bufdeknk.dll.bad
D:\VundoFix Backups\buftrrer.exe.bad
D:\VundoFix Backups\bulforpk.exe.bad
D:\VundoFix Backups\byxvstt.dll.bad
D:\VundoFix Backups\byxxyax.dll.bad
D:\VundoFix Backups\cgqkivdm.dll.bad
D:\VundoFix Backups\ctfewxlr.exe.bad
D:\VundoFix Backups\cvfmgdts.dll.bad
D:\VundoFix Backups\ddcaaxw.dll.bad
D:\VundoFix Backups\ddcbcyw.dll.bad
D:\VundoFix Backups\dftujuvw.exe.bad
D:\VundoFix Backups\dhqjtcot.dll.bad
D:\VundoFix Backups\diptaqkx.exe.bad
D:\VundoFix Backups\dksinswl.dll.bad
D:\VundoFix Backups\dlvfdhxj.exe.bad
D:\VundoFix Backups\durmitva.exe.bad
D:\VundoFix Backups\efccdbx.dll.bad
D:\VundoFix Backups\efryokfn.exe.bad
D:\VundoFix Backups\elcantrj.exe.bad
D:\VundoFix Backups\eltdyxsl.exe.bad
D:\VundoFix Backups\eljqahac.exe.bad
D:\VundoFix Backups\erladjul.dll.bad
D:\VundoFix Backups\erqccepe.dll.bad
D:\VundoFix Backups\etcmiyeq.exe.bad
D:\VundoFix Backups\eujwmpdq.dll.bad
D:\VundoFix Backups\euohfcua.exe.bad
D:\VundoFix Backups\fhcbkmom.dll.bad
D:\VundoFix Backups\fkoqcxvh.dll.bad
D:\VundoFix Backups\flatoklk.dll.bad
D:\VundoFix Backups\fodlrbli.exe.bad
D:\VundoFix Backups\fojmrqkd.dll.bad
D:\VundoFix Backups\fqcthuge.exe.bad
D:\VundoFix Backups\frhtxhin.dll.bad
D:\VundoFix Backups\ftrlkotl.exe.bad
D:\VundoFix Backups\fymkyajy.exe.bad
D:\VundoFix Backups\gcibaevb.exe.bad
D:\VundoFix Backups\gekubmfl.dll.bad
D:\VundoFix Backups\ghexibvp.exe.bad
D:\VundoFix Backups\gpqqpjpp.dll.bad
D:\VundoFix Backups\grfxqbes.dll.bad
D:\VundoFix Backups\gwxvgxvr.dll.bad
D:\VundoFix Backups\haftkuhh.exe.bad
D:\VundoFix Backups\hggddeb.dll.bad
D:\VundoFix Backups\hgghecb.dll.bad
D:\VundoFix Backups\hkjecvmw.exe.bad
D:\VundoFix Backups\hnxojvop.exe.bad
D:\VundoFix Backups\hsjqqsfn.dll.bad
D:\VundoFix Backups\hvxcqokf.ini.bad
D:\VundoFix Backups\hxydidbb.dll.bad
D:\VundoFix Backups\iesprpac.exe.bad
D:\VundoFix Backups\iifcddb.dll.bad
D:\VundoFix Backups\iifdedb.dll.bad
D:\VundoFix Backups\iiffecb.dll.bad
D:\VundoFix Backups\ilqmclid.exe.bad
D:\VundoFix Backups\iqapjyno.dll.bad
D:\VundoFix Backups\iqbcmmvv.dll.bad
D:\VundoFix Backups\ivhhkdtj.exe.bad
D:\VundoFix Backups\jgaoiwuw.exe.bad
D:\VundoFix Backups\jgevafpt.exe.bad
D:\VundoFix Backups\jgiedtye.exe.bad
D:\VundoFix Backups\jlmsluhp.exe.bad
D:\VundoFix Backups\jmscciwu.dll.bad
D:\VundoFix Backups\jqbgnjmc.exe.bad
D:\VundoFix Backups\jrxtyjed.exe.bad
D:\VundoFix Backups\jswocnvd.exe.bad
D:\VundoFix Backups\jxmilhaq.exe.bad
D:\VundoFix Backups\jyannjiu.dll.bad
D:\VundoFix Backups\kacibvun.dll.bad
D:\VundoFix Backups\khfdeff.dll.bad
D:\VundoFix Backups\kiljhtxt.exe.bad
D:\VundoFix Backups\kniwiiym.dll.bad
D:\VundoFix Backups\knyncmie.exe.bad
D:\VundoFix Backups\ktpjotqd.exe.bad
D:\VundoFix Backups\lhcaswkq.exe.bad
D:\VundoFix Backups\lnebdilm.dll.bad
D:\VundoFix Backups\lujdalre.ini.bad
D:\VundoFix Backups\luosnwol.exe.bad
D:\VundoFix Backups\maqyasru.exe.bad
D:\VundoFix Backups\mlnfjdxd.dll.bad
D:\VundoFix Backups\morceksk.dll.bad
D:\VundoFix Backups\nnlij.dll.bad
D:\VundoFix Backups\nnlljih.dll.bad
D:\VundoFix Backups\nrsuudld.dll.bad
D:\VundoFix Backups\nucsmgoj.exe.bad
D:\VundoFix Backups\nwqufjch.dll.bad
D:\VundoFix Backups\nyqebdlm.exe.bad
D:\VundoFix Backups\ofngmepc.exe.bad
D:\VundoFix Backups\oohqkvpe.exe.bad
D:\VundoFix Backups\opnkkhf.dll.bad
D:\VundoFix Backups\oqwusfsj.exe.bad
D:\VundoFix Backups\ountstka.exe.bad
D:\VundoFix Backups\ovinhwly.dll.bad
D:\VundoFix Backups\owfyyqlg.dll.bad
D:\VundoFix Backups\paclxvvk.exe.bad
D:\VundoFix Backups\paecpirv.exe.bad
D:\VundoFix Backups\pjyryfie.exe.bad
D:\VundoFix Backups\pmnnmmn.dll.bad
D:\VundoFix Backups\pnvwnkov.exe.bad
D:\VundoFix Backups\pocpywpw.exe.bad
D:\VundoFix Backups\poghddco.exe.bad
D:\VundoFix Backups\ppjpqqpg.ini.bad
D:\VundoFix Backups\pqngtnah.exe.bad
D:\VundoFix Backups\pqpjqrpf.exe.bad
D:\VundoFix Backups\prpppraj.exe.bad
D:\VundoFix Backups\qbugqwjl.dll.bad
D:\VundoFix Backups\qcavotex.exe.bad
D:\VundoFix Backups\qcqqpqmj.exe.bad
D:\VundoFix Backups\qsipmaxt.exe.bad
D:\VundoFix Backups\rayxxhvp.exe.bad
D:\VundoFix Backups\rstbtrnh.dll.bad
D:\VundoFix Backups\ruvqcaqk.dll.bad
D:\VundoFix Backups\rwghixnj.exe.bad
D:\VundoFix Backups\rymyxppx.exe.bad
D:\VundoFix Backups\sebqxfrg.ini.bad
D:\VundoFix Backups\sfmjlnsc.exe.bad
D:\VundoFix Backups\sfumsefo.exe.bad
D:\VundoFix Backups\sokrutwv.dll.bad
D:\VundoFix Backups\ssqnnmn.dll.bad
D:\VundoFix Backups\ssqpqqo.dll.bad
D:\VundoFix Backups\stxistig.exe.bad
D:\VundoFix Backups\sxmgullq.dll.bad
D:\VundoFix Backups\tcayvlcg.exe.bad
D:\VundoFix Backups\tchjwwlj.exe.bad
D:\VundoFix Backups\tkehyadc.exe.bad
D:\VundoFix Backups\toctjqhd.ini.bad
D:\VundoFix Backups\twosmwwf.dll.bad
D:\VundoFix Backups\tyfgwdck.exe.bad
D:\VundoFix Backups\uamvbvkf.exe.bad
D:\VundoFix Backups\ujxuxleh.dll.bad
D:\VundoFix Backups\ukgromba.dll.bad
D:\VundoFix Backups\ukiwwwch.exe.bad
D:\VundoFix Backups\umibhbsc.dll.bad
D:\VundoFix Backups\uoslmyex.dll.bad
D:\VundoFix Backups\urqnoom.dll.bad
D:\VundoFix Backups\urqpqrq.dll.bad
D:\VundoFix Backups\ursqrqp.dll.bad
D:\VundoFix Backups\uslmrqyj.exe.bad
D:\VundoFix Backups\uwnoeqdi.exe.bad
D:\VundoFix Backups\uxiiwgkf.dll.bad
D:\VundoFix Backups\viryuhes.exe.bad
D:\VundoFix Backups\vtusppn.dll.bad
D:\VundoFix Backups\vvunlsps.dll.bad
D:\VundoFix Backups\vwapncsc.dll.bad
D:\VundoFix Backups\wdympjlw.exe.bad
D:\VundoFix Backups\wersdjxt.dll.bad
D:\VundoFix Backups\wjimegvv.exe.bad
D:\VundoFix Backups\wjkyrraa.exe.bad
D:\VundoFix Backups\woqbboxp.exe.bad
D:\VundoFix Backups\wqweafdy.dll.bad
D:\VundoFix Backups\wrsgcjjl.exe.bad
D:\VundoFix Backups\wuojjmby.exe.bad
D:\VundoFix Backups\wwbussty.exe.bad
D:\VundoFix Backups\xaogpkkx.exe.bad
D:\VundoFix Backups\xiirlsoe.dll.bad
D:\VundoFix Backups\xxuqnwbc.dll.bad
D:\VundoFix Backups\yglbtpmv.exe.bad
D:\VundoFix Backups\yhssauue.exe.bad
D:\VundoFix Backups\yjhgkrbg.dll.bad
D:\VundoFix Backups\yofemrkp.dll.bad
D:\VundoFix Backups\yohyvqor.exe.bad
D:\VundoFix Backups\ypvyudbm.exe.bad
D:\VundoFix Backups\ytvgekmy.dll.bad
D:\VundoFix Backups\yuceaacd.exe.bad
D:\VundoFix Backups\yvafauni.dll.bad
D:\VundoFix Backups\yvmkxdsn.exe.bad
D:\WINDOWS\Qxe85.sys
D:\WINDOWS\system32\abmorgku.ini
D:\WINDOWS\system32\cbwnquxx.ini
D:\WINDOWS\system32\csbhbimu.ini
D:\WINDOWS\system32\dlduusrn.ini
D:\WINDOWS\system32\eagxbwne.ini
D:\WINDOWS\system32\eoslriix.ini
D:\WINDOWS\system32\fkgwiixu.ini
D:\WINDOWS\system32\gbghqqcb.ini
D:\WINDOWS\system32\gbrkghjy.ini
D:\WINDOWS\system32\hcjfuqwn.ini
D:\WINDOWS\system32\hnrtbtsr.ini
D:\WINDOWS\system32\inuafavy.ini
D:\WINDOWS\system32\jfrscxqi.ini
D:\WINDOWS\system32\jilnn.tmp2
D:\WINDOWS\system32\jqsiaarq.ini
D:\WINDOWS\system32\ljwqgubq.ini
D:\WINDOWS\system32\nfenxfdj.ini
D:\WINDOWS\system32\nuvbicak.ini
D:\WINDOWS\system32\nuynrsnd.ini
D:\WINDOWS\system32\odecsmfb.ini
D:\WINDOWS\system32\rjnnwcen.dll
D:\WINDOWS\system32\saehnvgj.ini
D:\WINDOWS\system32\sakmbjhk.ini
D:\WINDOWS\system32\tixvkalc.ini
D:\WINDOWS\system32\vbwbrohq.ini
D:\WINDOWS\system32\wihstsha.ini
D:\WINDOWS\system32\wnpmcs.exe
D:\WINDOWS\system32\xeymlsou.ini
D:\WINDOWS\system32\xnyonwxd.dll
D:\WINDOWS\system32\xnyonwxd.dllbox
D:\WINDOWS\system32\yaywwwv.dll
D:\WINDOWS\system32\ybpktavb.ini
D:\WINDOWS\system32\ylwhnivo.ini
D:\WINDOWS\system32\ymkegvty.ini

Dopuna: 22 Dec 2007 12:50

.
((((((((((((((((((((((((( Files Created from 2007-11-22 to 2007-12-22 )))))))))))))))))))))))))))))))
.

2007-12-22 02:04 . 2007-12-22 02:04 7,168 --a------ D:\WINDOWS\system32\windows
2007-12-18 22:41 . 2007-12-18 22:41 54,156 --ah----- D:\WINDOWS\QTFont.qfn
2007-12-18 22:41 . 2007-12-18 22:41 1,409 --a------ D:\WINDOWS\QTFont.for
2007-12-18 00:37 . 1999-11-12 21:49 294,912 --a------ D:\WINDOWS\system32\iviaudio.ax
2007-12-18 00:37 . 2000-05-07 22:08 34,816 --a------ D:\WINDOWS\system32\mpgaudio.ax
2007-12-18 00:37 . 2002-05-21 17:14 4,286 --a------ D:\WINDOWS\system32\divx.ico
2007-12-18 00:33 . 2007-12-18 00:33 <DIR> d-------- D:\Program Files\The Playa
2007-12-18 00:33 . 2007-12-18 00:33 <DIR> d-------- D:\Program Files\DivXCodec
2007-12-18 00:10 . 2007-12-18 00:15 <DIR> d-------- D:\Program Files\ACE Mega CoDecS Pack
2007-12-17 12:09 . 2007-12-17 12:09 <DIR> d-------- D:\Program Files\Trend Micro
2007-12-16 19:48 . 2007-12-18 22:40 <DIR> d-------- D:\Program Files\MicroDVD
2007-12-16 19:47 . 2001-01-24 03:28 412,160 -ra------ D:\WINDOWS\system32\DivXc32.dll
2007-12-16 19:47 . 2000-12-21 15:40 300,544 -ra------ D:\WINDOWS\system32\l3codeca.acm
2007-12-16 19:47 . 2000-12-29 13:58 287,744 -ra------ D:\WINDOWS\system32\DivXa32.acm
2007-12-16 19:47 . 2000-12-21 15:34 239,616 -ra------ D:\WINDOWS\system32\DivX_c32.ax
2007-12-16 19:47 . 2001-01-24 03:05 121,856 -ra------ D:\WINDOWS\system32\Mp3cnfg.cpl
2007-12-16 19:47 . 2001-01-24 03:12 19,456 -ra------ D:\WINDOWS\system32\Mp3cnfg.exe
2007-12-15 01:30 . 2007-12-14 17:12 57,662 --a------ D:\WINDOWS\system32\fx.exe
2007-12-15 01:30 . 2004-03-05 07:01 31,232 --a------ D:\WINDOWS\system32\pv.exe
2007-12-15 01:19 . 2007-12-15 01:19 23,392 --a------ D:\WINDOWS\system32\nscompat.tlb
2007-12-15 01:19 . 2007-12-15 01:19 16,832 --a------ D:\WINDOWS\system32\amcompat.tlb
2007-12-13 21:15 . 2007-12-14 20:31 <DIR> d-------- D:\Program Files\eMule
2007-12-13 21:02 . 2007-12-13 21:02 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Avira
2007-12-13 18:25 . 2007-12-18 22:21 <DIR> d-------- D:\Program Files\SuperCleaner
2007-12-13 00:41 . 2007-03-08 00:51 9,336 --------- D:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-12-13 00:40 . 2007-03-08 00:51 129,784 --a------ D:\WINDOWS\system32\pxafs.dll
2007-12-13 00:40 . 2007-03-08 00:51 9,464 --------- D:\WINDOWS\system32\drivers\cdralw2k.sys
2007-12-12 01:18 . 2007-12-12 01:18 <DIR> d-------- D:\Program Files\Windows Live
2007-12-12 01:18 . 2007-12-12 20:33 <DIR> d-------- D:\Program Files\MessengerDiscovery
2007-12-12 01:18 . 2004-03-09 00:00 212,240 --a------ D:\WINDOWS\system32\richtx32.OCX
2007-12-12 01:18 . 2004-03-09 00:00 124,688 --a------ D:\WINDOWS\system32\MSWINSCK.ocx
2007-12-11 00:08 . 2007-12-13 18:34 <DIR> d-------- D:\Program Files\Engineering Power Tools - v1.9.6
2007-12-11 00:08 . 1997-01-16 00:00 958,224 --a------ D:\WINDOWS\system32\MSCHART.OCX
2007-12-11 00:08 . 2004-03-09 00:00 609,824 --a------ D:\WINDOWS\system32\COMCTL32.ocx
2007-12-11 00:08 . 1997-01-14 00:00 519,680 --a------ D:\WINDOWS\system32\DBGRID32.OCX
2007-12-11 00:08 . 1998-06-24 00:00 164,144 --a------ D:\WINDOWS\system32\COMCT232.OCX
2007-12-11 00:08 . 1997-01-16 00:00 71,680 --a------ D:\WINDOWS\ST5UNST.EXE
2007-12-11 00:08 . 1997-01-16 00:00 29,696 --a------ D:\WINDOWS\system32\VB5StKit.dll
2007-12-06 18:39 . 2007-12-21 21:37 <DIR> d-------- D:\Documents and Settings\dmitko\Application Data\U3
2007-12-03 16:19 . 2007-12-14 20:28 <DIR> d-------- D:\Program Files\Windows Media Connect 2
2007-12-03 16:16 . 2007-12-03 16:16 <DIR> d-------- D:\WINDOWS\system32\LogFiles
2007-12-03 16:16 . 2007-12-03 16:18 <DIR> d-------- D:\WINDOWS\system32\drivers\UMDF
2007-12-02 23:42 . 2007-12-07 11:26 <DIR> d-------- D:\Program Files\Macrogaming
2007-12-02 20:36 . 2001-11-30 19:05 131,072 --a------ D:\WINDOWS\system32\dzip32.dll
2007-12-02 20:36 . 2001-11-30 19:05 110,592 --a------ D:\WINDOWS\system32\dunzip32.dll
2007-12-02 20:35 . 2007-12-02 20:36 <DIR> d-------- D:\Program Files\Windows Media Bonus Pack for Windows XP
2007-11-24 20:48 . 2007-12-05 00:16 <DIR> d-------- D:\Program Files\MySpace
2007-11-24 20:48 . 2007-11-24 20:48 <DIR> d-------- D:\Documents and Settings\dmitko\Application Data\MySpace

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-17 23:19 --------- d-----w D:\Program Files\QuickTime
2007-12-17 22:58 --------- d-----w D:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-12-16 18:42 --------- d-----w D:\Program Files\DivX
2007-12-13 17:34 --------- d-----w D:\Documents and Settings\dmitko\Application Data\Azureus
2007-12-13 16:51 --------- d-----w D:\Program Files\MSN Messenger
2007-12-13 14:47 --------- d-----w D:\Program Files\Windows Live Toolbar
2007-12-13 14:46 --------- d-----w D:\Program Files\Winamp
2007-12-02 22:37 --------- d-----w D:\Program Files\Opera
2007-11-19 13:50 --------- d-----w D:\Program Files\Common Files\Adobe
2007-11-18 19:53 --------- d-----w D:\Documents and Settings\All Users\Application Data\Barbie Fashion Show
2007-11-14 23:28 --------- d-----w D:\Documents and Settings\dmitko\Application Data\Apple Computer
2007-11-14 17:22 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-14 17:21 --------- d-----w D:\Program Files\Apple Software Update
2007-11-14 17:21 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2007-11-13 10:25 20,480 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys
2007-11-09 00:37 --------- d-----w D:\Documents and Settings\All Users\Application Data\ESET
2007-11-08 19:57 --------- d-----w D:\Program Files\MT882
2007-11-08 19:51 155,995 ----a-w D:\WINDOWS\java\Packages\KFLNLFDR.ZIP
2007-11-08 19:31 --------- d-----w D:\Program Files\Kaspersky Lab
2007-11-08 18:20 --------- d-----w D:\Program Files\CCleaner
2007-11-05 11:06 30,728 ----a-w D:\WINDOWS\system32\drivers\epfwtdir.sys
2007-11-05 11:04 33,800 ----a-w D:\WINDOWS\system32\drivers\eamon.sys
2007-11-05 11:04 27,656 ----a-w D:\WINDOWS\system32\drivers\easdrv.sys
2007-10-31 18:03 --------- d-----w D:\Program Files\MSXML 4.0
2007-10-31 15:52 45,056 ----a-w D:\WINDOWS\NCUNINST.EXE
2007-10-30 19:36 --------- d-----w D:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-10-30 18:03 --------- d-----w D:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-30 15:18 --------- d-----w D:\Documents and Settings\dmitko\Application Data\SumatraPDF
2001-11-23 04:08 712,704 ----a-w D:\WINDOWS\inf\OTHER\AUDIO3D.DLL
.

((((((((((((((((((((((((((((( snapshot@2007-12-22_ 2.44.37.91 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"swg"="D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-04 00:54]
"MsnMsgr"="D:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="D:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"Sony Ericsson PC Suite"="D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"egui"="D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2007-11-05 12:05]
"QuickTime Task"="D:\WINDOWS\system32\qttask.exe" [2007-12-18 00:20]

R1 easdrv;easdrv;D:\WINDOWS\system32\DRIVERS\easdrv.sys [2007-11-05 12:04]
R1 epfwtdir;epfwtdir;D:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2007-11-05 12:06]
R2 eamon;EAMON;D:\WINDOWS\system32\DRIVERS\eamon.sys [2007-11-05 12:04]
R3 iadusb;MT882;D:\WINDOWS\system32\DRIVERS\glauiad.sys [2006-03-20 08:32]
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);D:\WINDOWS\system32\DRIVERS\k510bus.sys [2006-02-17 20:34]
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;D:\WINDOWS\system32\DRIVERS\k510mdfl.sys [2006-11-25 12:29]
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;D:\WINDOWS\system32\DRIVERS\k510mdm.sys [2006-11-25 12:29]
S3 k510mgmt;Sony Ericsson K510 USB WMC Device Management Drivers (WDM);D:\WINDOWS\system32\DRIVERS\k510mgmt.sys [2006-11-25 12:29]
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;D:\WINDOWS\system32\DRIVERS\k510obex.sys [2006-11-25 12:29]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

.
Contents of the 'Scheduled Tasks' folder
"2007-12-07 16:46:05 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2007-12-22 12:41:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-22 12:44:31 - machine was rebooted
D:\ComboFix2.txt ... 2007-12-22 02:46
.
2007-12-22 02:03:37 --- E O F ---

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pošalji mi sledeće file-ove:

D:\WINDOWS\system32\fx.exe
D:\WINDOWS\system32\pv.exe


Upload link: http://www.mycity.rs/ambulanta-upload.php



Restartuj PC i postavi svež HijackThis log.

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Fileovi uploadovani..

Dopuna: 22 Dec 2007 15:25

Logfile of HijackThis v1.99.1
Scan saved at 15:21:29, on 22.12.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\system32\WgaTray.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\Program Files\Common Files\Teleca Shared\Generic.exe
D:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
D:\Documents and Settings\dmitko\My Documents\Programi\tr3.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - D:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [QuickTime Task] "D:\WINDOWS\system32\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &Search - edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxpt407YYYU
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.exe.imgfarm.com/images/nocache/funwebpro.....0.15-3.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
O16 - DPF: {E72CFC93-BAE3-8D60-85D1-129993AAC8B9} (UImageUploader Class) - perfspot.com/u/UImageUploaderXP.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - D:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pronađi i obriši:

D:\WINDOWS\system32\fx.exe
D:\WINDOWS\system32\pv.exe

C:\QooBox\ (ceo folder)


-------------------------------------------------------------------------------------


Pokreni HijackThis, skeniraj i čekiraj sledeće linije:

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxpt407YYYU
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebpro.....0.15-3.cab

Klikni Fix Checked.


-------------------------------------------------------------------------------------


Iskljucivanje System Restore-a

Na Desktopu, desni klik na My Computer.
Odaberite Properties.
Odaberite System Restore tab.
Stiklirajte Turn off System Restore.
Kliknite na dugme Apply.
Kliknite na dugme OK.



Restartuj kompjuter.


Ukljucivanje System Restore-a

Na Desktopu, desni klik na My Computer.
Odaberite Properties.
Odaberite System Restore tab.
Destiklirajte Turn off System Restore.
Kliknite na dugme Apply.
Kliknite na dugme OK.


-------------------------------------------------------------------------------------


Kakvo je sada stanje? Primećuješ li neke probleme?

offline
  • Pridružio: 03 Dec 2007
  • Poruke: 26

Mnogo ste mi pomogli hvala, sada mi komp radi dosta bolje, mada jos uvek imam problem da mi se usred rada ubaguje i prestane da reaguje, moram da ga restartuje na power, mada taj problem verovatno i nema veze sa malwareom...
Hvala u svakom slucaju, najbolji ste, a da li sada imate neku generalnu preporuku za mene kako u buducnosti da se zastitim od malwarea?

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Što se tiče malware-a - ovde ga vše nema.

Što se tiče pomenutog problema, mnogo toga može da ga prouzrokuje (obrati pažnju na temperature komponenti, probaj reinstalirati driver-e, itd).

Kako se zaštititi? Nažalost, nema 100% pouzdanog metoda.
Prosto, treba da koristiš zaštitni softver i da budeš ''oprezan'' surfer.


Pozdrav...

Ko je trenutno na forumu
 

Ukupno su 866 korisnika na forumu :: 18 registrovanih, 3 sakrivenih i 845 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, A.R.Chafee.Jr., Boris90, comi_pfc, laki_bb, loon123, Marko Marković, Mixelotti, mnn2, operniki, procesor, raketaš, stegonosa, uruk, wolverined4, wulfy, yrraf, zdrebac