Pomoc, izgleda malware!

3

Pomoc, izgleda malware!

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Ovako:

kompjuter na kome ces da skines sledeci program potrebno je da ugasis Antivirus pa onda da ga skines.

Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]


--------------------------

I onda pre nego sto prebacis ComboFix na lap-top iskljucices Aviru po sledecem uputstvu:

Klikni desnim tasterom na Avira ikonicu ( ) u donjem, desnom uglu ekrana i deštikliraj AntiVir Guard Enable.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • Pridružio: 23 Mar 2008
  • Poruke: 68

ComboFix 08-12-30.02 - Freezing Cool 2008-12-31 22:48:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2584 [GMT 1:00]
Running from: c:\documents and settings\Freezing Cool\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.

2008-12-31 22:27 . 2008-12-31 22:38 <DIR> d-------- c:\program files\Garena
2008-12-31 22:26 . 2008-12-31 22:26 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\InstallShield
2008-12-31 22:19 . 2008-12-31 22:23 139,264 --a------ c:\windows\War3Unin.exe
2008-12-31 22:19 . 2008-12-31 22:24 55,201 --a------ c:\windows\War3Unin.dat
2008-12-31 22:19 . 2008-12-31 22:23 2,829 --a------ c:\windows\War3Unin.pif
2008-12-31 22:16 . 2008-12-31 22:42 <DIR> d-------- c:\program files\Warcraft III
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\program files\Avira
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\Malwarebytes
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-31 20:52 . 2008-12-31 20:52 <DIR> d-------- c:\program files\ChessBase
2008-12-31 20:52 . 2008-12-31 21:02 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\ChessBase
2008-12-31 20:31 . 2008-12-31 20:32 <DIR> d-------- c:\program files\Counter-Strike 1.6 V35
2008-12-31 19:27 . 2008-12-31 19:27 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\DivX
2008-12-31 16:56 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-31 16:16 . 2008-12-31 22:27 <DIR> d-------- c:\program files\FlashGet
2008-12-31 15:31 . 2008-12-31 15:31 <DIR> d---s---- c:\documents and settings\Freezing Cool\UserData
2008-12-31 09:42 . 2008-12-31 09:43 164 --a------ c:\windows\wcx_ftp.ini
2008-12-31 04:05 . 2008-12-31 04:05 <DIR> d-------- c:\documents and settings\Freezing Cool\Contacts
2008-12-31 04:02 . 2004-08-04 00:10 85,376 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2008-12-31 04:02 . 2004-08-04 00:10 19,328 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2008-12-31 04:02 . 2004-08-04 00:10 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2008-12-31 04:02 . 2004-08-04 01:56 16,384 --a------ c:\windows\system32\ipsink.ax
2008-12-31 04:02 . 2004-08-04 00:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2008-12-31 04:02 . 2004-08-03 23:58 7,552 --a------ c:\windows\system32\drivers\MSKSSRV.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2008-12-31 04:02 . 2004-08-03 23:58 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2008-12-31 04:02 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a--c--- c:\windows\system32\dllcache\usbui.dll
2008-12-31 04:00 . 2001-08-17 14:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 21:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 20:48 --------- d-----w c:\program files\AdVantage
2008-12-31 19:30 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer
2008-12-31 18:27 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Ahead
2008-12-31 02:48 --------- d-----w c:\program files\Google
2008-12-31 02:45 --------- d-----w c:\program files\Winamp
2008-12-31 02:45 --------- d-----w c:\program files\Real
2008-12-31 02:45 --------- d-----w c:\program files\MSN Messenger
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\xing shared
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\Real
2008-12-31 02:45 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Winamp
2008-12-31 02:43 --------- d-----w c:\program files\Realtek
2008-12-31 02:41 315,392 ----a-w c:\windows\HideWin.exe
2008-12-31 02:38 --------- d-----w c:\program files\Webteh
2008-12-31 02:38 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer Pro
2008-12-31 02:37 --------- d-----w c:\program files\Nero
2008-12-31 02:37 --------- d-----w c:\program files\Common Files\Ahead
2008-12-31 02:36 --------- d-----w c:\program files\DIFX
2008-12-31 02:26 --------- d-----w c:\program files\Intel
2008-12-31 02:25 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-31 02:08 --------- d-----w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-18 8433664]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-31 185784]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2007-05-18 c:\windows\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 c:\windows\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 c:\windows\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Counter-Strike 1.6 V35\\hl.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=

R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-12-31 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-12-31 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-12-31 41217]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys []

*Newly Created Service* - ANTIVIRMAILSERVICE
*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - ANTIVIRWEBSERVICE
*Newly Created Service* - AVESERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
*Newly Created Service* - BTHSERV
*Newly Created Service* - MBAMSWISSARMY
*Newly Created Service* - PROCEXP90
*Newly Created Service* - WS2IFSL
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
MSConfigStartUp-AdVantage - c:\program files\AdVantage\AdVantage.exe


.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: avsda.dll
FF - ProfilePath - c:\documents and settings\Freezing Cool\Application Data\Mozilla\Firefox\Profiles\klvdcp6g.default\
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-12-31 22:48:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

Evo ComboFix logfile-a:

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-31 22:49:39
ComboFix-quarantined-files.txt 2008-12-31 21:49:29

Pre-Run: 65,937,338,368 bytes free
Post-Run: 66,296,676,352 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

150



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Ostatak posla radicemo sutra u Novoj 2009. godini!

Sad odoh da djuskam i pijem.


Pozzzz

offline
  • Pridružio: 23 Mar 2008
  • Poruke: 68

OK. Srecna Nova 2009. Smile I lepo se provedi, ja sam zakasnio da uzmem kartu gde idu svi moji drugari jer nisam bio kuci poslednje 2 nedelje :S Ali nije mi lose kuci uz internet i sampanjac i vino Very Happy

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Iskljuci Aviru:

Otvoriti Notepad i iskopirati sledeci tekst:

Folder::
c:\program files\AdVantage


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 23 Mar 2008
  • Poruke: 68

ComboFix 08-12-30.02 - Freezing Cool 2009-01-01 3:47:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2585 [GMT 1:00]
Running from: c:\documents and settings\Freezing Cool\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Freezing Cool\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\AdVantage
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome.manifest
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\advantage.png
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\contents.rdf
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\overlay.js
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\overlay.xul
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\vssver2.scc
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\locale\en-US\overlay.dtd
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\locale\en-US\vssver2.scc
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\components\IMeMedia_FF.xpt
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\install.rdf
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\vssver2.scc
c:\program files\AdVantage\AdVantage.cch
c:\program files\AdVantage\AdVantage.db
c:\program files\AdVantage\AdVantage.htm
c:\program files\AdVantage\AdVUninst.exe
c:\program files\AdVantage\ffext.mod
c:\program files\AdVantage\user.db

.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.

2008-12-31 23:34 . 2008-12-31 23:45 <DIR> d-------- c:\program files\TalismanOnline
2008-12-31 22:27 . 2009-01-01 01:18 <DIR> d-------- c:\program files\Garena
2008-12-31 22:26 . 2008-12-31 22:26 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\InstallShield
2008-12-31 22:19 . 2008-12-31 22:23 139,264 --a------ c:\windows\War3Unin.exe
2008-12-31 22:19 . 2008-12-31 22:24 55,201 --a------ c:\windows\War3Unin.dat
2008-12-31 22:19 . 2008-12-31 22:23 2,829 --a------ c:\windows\War3Unin.pif
2008-12-31 22:16 . 2009-01-01 02:08 <DIR> d-------- c:\program files\Warcraft III
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\program files\Avira
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\Malwarebytes
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-31 20:52 . 2008-12-31 20:52 <DIR> d-------- c:\program files\ChessBase
2008-12-31 20:52 . 2008-12-31 21:02 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\ChessBase
2008-12-31 20:31 . 2008-12-31 20:32 <DIR> d-------- c:\program files\Counter-Strike 1.6 V35
2008-12-31 19:27 . 2008-12-31 19:27 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\DivX
2008-12-31 16:56 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-31 16:16 . 2008-12-31 22:27 <DIR> d-------- c:\program files\FlashGet
2008-12-31 15:31 . 2008-12-31 15:31 <DIR> d---s---- c:\documents and settings\Freezing Cool\UserData
2008-12-31 09:42 . 2008-12-31 09:43 164 --a------ c:\windows\wcx_ftp.ini
2008-12-31 04:05 . 2008-12-31 04:05 <DIR> d-------- c:\documents and settings\Freezing Cool\Contacts
2008-12-31 04:02 . 2004-08-04 00:10 85,376 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2008-12-31 04:02 . 2004-08-04 00:10 19,328 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2008-12-31 04:02 . 2004-08-04 00:10 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2008-12-31 04:02 . 2004-08-04 01:56 16,384 --a------ c:\windows\system32\ipsink.ax
2008-12-31 04:02 . 2004-08-04 00:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2008-12-31 04:02 . 2004-08-03 23:58 7,552 --a------ c:\windows\system32\drivers\MSKSSRV.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2008-12-31 04:02 . 2004-08-03 23:58 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2008-12-31 04:02 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a--c--- c:\windows\system32\dllcache\usbui.dll
2008-12-31 04:00 . 2001-08-17 14:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 21:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 19:30 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer
2008-12-31 18:27 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Ahead
2008-12-31 02:48 --------- d-----w c:\program files\Google
2008-12-31 02:45 --------- d-----w c:\program files\Winamp
2008-12-31 02:45 --------- d-----w c:\program files\Real
2008-12-31 02:45 --------- d-----w c:\program files\MSN Messenger
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\xing shared
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\Real
2008-12-31 02:45 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Winamp
2008-12-31 02:43 --------- d-----w c:\program files\Realtek
2008-12-31 02:41 315,392 ----a-w c:\windows\HideWin.exe
2008-12-31 02:38 --------- d-----w c:\program files\Webteh
2008-12-31 02:38 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer Pro
2008-12-31 02:37 --------- d-----w c:\program files\Nero
2008-12-31 02:37 --------- d-----w c:\program files\Common Files\Ahead
2008-12-31 02:36 --------- d-----w c:\program files\DIFX
2008-12-31 02:26 --------- d-----w c:\program files\Intel
2008-12-31 02:25 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-31 02:08 --------- d-----w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-04 19:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
+ 2007-02-22 22:41:12 304,544 ----a-w c:\windows\Downloaded Program Files\MessengerStatsPAClient.dll
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
+ 2009-01-01 01:14:41 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-12-31 21:44:30 28,095 ----a-w c:\windows\system32\nvModes.dat
+ 2009-01-01 01:15:43 28,095 ----a-w c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-18 8433664]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-31 185784]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2007-05-18 c:\windows\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 c:\windows\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 c:\windows\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Counter-Strike 1.6 V35\\hl.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=

R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-12-31 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-12-31 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-12-31 41217]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys []

*Newly Created Service* - ANTIVIRMAILSERVICE
*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - ANTIVIRWEBSERVICE
*Newly Created Service* - AVESERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
*Newly Created Service* - BTHSERV
*Newly Created Service* - CATCHME
*Newly Created Service* - MBAMSWISSARMY
*Newly Created Service* - PROCEXP90
*Newly Created Service* - WS2IFSL
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: avsda.dll
FF - ProfilePath - c:\documents and settings\Freezing Cool\Application Data\Mozilla\Firefox\Profiles\klvdcp6g.default\
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-01 03:48:33
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-01-01 3:49:10
ComboFix-quarantined-files.txt 2009-01-01 02:49:04
ComboFix2.txt 2008-12-31 21:49:40

Pre-Run: 65,674,731,520 bytes free
Post-Run: 65,666,117,632 bytes free

181

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Da li ima ikakvog poboljsanja?

offline
  • Pridružio: 23 Mar 2008
  • Poruke: 68

Pa za sad radi kako treba, videcemo dal mu jos nesto fali. Hvala puno. Ako nesto pocne da radi kako ne treba (ali mislim da nece) pusticu ti PM.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Jel radi wireless?

offline
  • Pridružio: 23 Mar 2008
  • Poruke: 68

Na to sam nacisto zaboravio. Sad sam pokusao i ne radi i dalje. Nece da nadje ni jednu mrezu. Samo pise "No wireless networks were found in range". Prosle nedelje je hvatao oko 7-8 nemoguce sad da nema nijedna. Mozda je i moguce al mi je to sumnjivo...

Ko je trenutno na forumu
 

Ukupno su 4576 korisnika na forumu :: 51 registrovanih, 8 sakrivenih i 4517 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 04bokibole, 10x10.9, 357magnum, aramis s, Ares12356, Aristotle2002, Asteker, Belac91, blankspace, blue, branko7, bukefal, CHARLIE JA., crnirocko, cvrle312, damirZR, Djokislav, Dogma21, Draganeli, Dzuki, Flanker-G, Georgius, goxin, GrammaticalAnalysis, howyesno, Jose, Kajzer Soze, Kriglord, lacko, leopard83, lord sir giga, Marko Marković, marko.markovic, Medojed, mikrimaus, mile.ilic75, Njubara, nnnnnnnnnn, PlayerOne, Roksi, royst33, ruma, Sirius, Tihi86, Trimi68, Vaske8990, vathra, Vlada78, vuksa72, XBMC, Zec