|
|
|
Poslao: 31 Dec 2008 22:56
|
offline
- Pridružio: 23 Mar 2008
- Poruke: 68
|
ComboFix 08-12-30.02 - Freezing Cool 2008-12-31 22:48:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2584 [GMT 1:00]
Running from: c:\documents and settings\Freezing Cool\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.
2008-12-31 22:27 . 2008-12-31 22:38 <DIR> d-------- c:\program files\Garena
2008-12-31 22:26 . 2008-12-31 22:26 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\InstallShield
2008-12-31 22:19 . 2008-12-31 22:23 139,264 --a------ c:\windows\War3Unin.exe
2008-12-31 22:19 . 2008-12-31 22:24 55,201 --a------ c:\windows\War3Unin.dat
2008-12-31 22:19 . 2008-12-31 22:23 2,829 --a------ c:\windows\War3Unin.pif
2008-12-31 22:16 . 2008-12-31 22:42 <DIR> d-------- c:\program files\Warcraft III
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\program files\Avira
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\Malwarebytes
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-31 20:52 . 2008-12-31 20:52 <DIR> d-------- c:\program files\ChessBase
2008-12-31 20:52 . 2008-12-31 21:02 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\ChessBase
2008-12-31 20:31 . 2008-12-31 20:32 <DIR> d-------- c:\program files\Counter-Strike 1.6 V35
2008-12-31 19:27 . 2008-12-31 19:27 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\DivX
2008-12-31 16:56 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-31 16:16 . 2008-12-31 22:27 <DIR> d-------- c:\program files\FlashGet
2008-12-31 15:31 . 2008-12-31 15:31 <DIR> d---s---- c:\documents and settings\Freezing Cool\UserData
2008-12-31 09:42 . 2008-12-31 09:43 164 --a------ c:\windows\wcx_ftp.ini
2008-12-31 04:05 . 2008-12-31 04:05 <DIR> d-------- c:\documents and settings\Freezing Cool\Contacts
2008-12-31 04:02 . 2004-08-04 00:10 85,376 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2008-12-31 04:02 . 2004-08-04 00:10 19,328 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2008-12-31 04:02 . 2004-08-04 00:10 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2008-12-31 04:02 . 2004-08-04 01:56 16,384 --a------ c:\windows\system32\ipsink.ax
2008-12-31 04:02 . 2004-08-04 00:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2008-12-31 04:02 . 2004-08-03 23:58 7,552 --a------ c:\windows\system32\drivers\MSKSSRV.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2008-12-31 04:02 . 2004-08-03 23:58 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2008-12-31 04:02 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a--c--- c:\windows\system32\dllcache\usbui.dll
2008-12-31 04:00 . 2001-08-17 14:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 21:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 20:48 --------- d-----w c:\program files\AdVantage
2008-12-31 19:30 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer
2008-12-31 18:27 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Ahead
2008-12-31 02:48 --------- d-----w c:\program files\Google
2008-12-31 02:45 --------- d-----w c:\program files\Winamp
2008-12-31 02:45 --------- d-----w c:\program files\Real
2008-12-31 02:45 --------- d-----w c:\program files\MSN Messenger
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\xing shared
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\Real
2008-12-31 02:45 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Winamp
2008-12-31 02:43 --------- d-----w c:\program files\Realtek
2008-12-31 02:41 315,392 ----a-w c:\windows\HideWin.exe
2008-12-31 02:38 --------- d-----w c:\program files\Webteh
2008-12-31 02:38 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer Pro
2008-12-31 02:37 --------- d-----w c:\program files\Nero
2008-12-31 02:37 --------- d-----w c:\program files\Common Files\Ahead
2008-12-31 02:36 --------- d-----w c:\program files\DIFX
2008-12-31 02:26 --------- d-----w c:\program files\Intel
2008-12-31 02:25 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-31 02:08 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-18 8433664]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-31 185784]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2007-05-18 c:\windows\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 c:\windows\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 c:\windows\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Counter-Strike 1.6 V35\\hl.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-12-31 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-12-31 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-12-31 41217]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys []
*Newly Created Service* - ANTIVIRMAILSERVICE
*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - ANTIVIRWEBSERVICE
*Newly Created Service* - AVESERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
*Newly Created Service* - BTHSERV
*Newly Created Service* - MBAMSWISSARMY
*Newly Created Service* - PROCEXP90
*Newly Created Service* - WS2IFSL
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
MSConfigStartUp-AdVantage - c:\program files\AdVantage\AdVantage.exe
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: avsda.dll
FF - ProfilePath - c:\documents and settings\Freezing Cool\Application Data\Mozilla\Firefox\Profiles\klvdcp6g.default\
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-12-31 22:48:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
Evo ComboFix logfile-a:
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-12-31 22:49:39
ComboFix-quarantined-files.txt 2008-12-31 21:49:29
Pre-Run: 65,937,338,368 bytes free
Post-Run: 66,296,676,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
150
|
|
|
|
|
|
|
Poslao: 31 Dec 2008 23:12
|
offline
- helen1

- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8657
- Gde živiš: Novi Beograd
|
Ostatak posla radicemo sutra u Novoj 2009. godini!
Sad odoh da djuskam i pijem.
Pozzzz
|
|
|
|
|
|
|
Poslao: 31 Dec 2008 23:39
|
offline
- Pridružio: 23 Mar 2008
- Poruke: 68
|
OK. Srecna Nova 2009. I lepo se provedi, ja sam zakasnio da uzmem kartu gde idu svi moji drugari jer nisam bio kuci poslednje 2 nedelje :S Ali nije mi lose kuci uz internet i sampanjac i vino
|
|
|
|
|
|
|
Poslao: 01 Jan 2009 02:43
|
offline
- helen1

- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8657
- Gde živiš: Novi Beograd
|
Iskljuci Aviru:
Otvoriti Notepad i iskopirati sledeci tekst:
Folder::
c:\program files\AdVantage
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
|
|
|
|
|
|
|
Poslao: 01 Jan 2009 03:54
|
offline
- Pridružio: 23 Mar 2008
- Poruke: 68
|
ComboFix 08-12-30.02 - Freezing Cool 2009-01-01 3:47:45.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3071.2585 [GMT 1:00]
Running from: c:\documents and settings\Freezing Cool\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Freezing Cool\Desktop\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AdVantage
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome.manifest
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\advantage.png
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\contents.rdf
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\overlay.js
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\overlay.xul
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\content\vssver2.scc
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\locale\en-US\overlay.dtd
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\chrome\locale\en-US\vssver2.scc
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\components\IMeMedia_FF.xpt
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\components\MeMedia_FF.dll
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\install.js
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\install.rdf
c:\program files\AdVantage\{A89AED22-9133-424c-88E7-C8235C5FF302}\vssver2.scc
c:\program files\AdVantage\AdVantage.cch
c:\program files\AdVantage\AdVantage.db
c:\program files\AdVantage\AdVantage.htm
c:\program files\AdVantage\AdVUninst.exe
c:\program files\AdVantage\ffext.mod
c:\program files\AdVantage\user.db
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2008-12-31 23:34 . 2008-12-31 23:45 <DIR> d-------- c:\program files\TalismanOnline
2008-12-31 22:27 . 2009-01-01 01:18 <DIR> d-------- c:\program files\Garena
2008-12-31 22:26 . 2008-12-31 22:26 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\InstallShield
2008-12-31 22:19 . 2008-12-31 22:23 139,264 --a------ c:\windows\War3Unin.exe
2008-12-31 22:19 . 2008-12-31 22:24 55,201 --a------ c:\windows\War3Unin.dat
2008-12-31 22:19 . 2008-12-31 22:23 2,829 --a------ c:\windows\War3Unin.pif
2008-12-31 22:16 . 2009-01-01 02:08 <DIR> d-------- c:\program files\Warcraft III
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\program files\Avira
2008-12-31 21:44 . 2008-12-31 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\Malwarebytes
2008-12-31 21:28 . 2008-12-31 21:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-31 20:52 . 2008-12-31 20:52 <DIR> d-------- c:\program files\ChessBase
2008-12-31 20:52 . 2008-12-31 21:02 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\ChessBase
2008-12-31 20:31 . 2008-12-31 20:32 <DIR> d-------- c:\program files\Counter-Strike 1.6 V35
2008-12-31 19:27 . 2008-12-31 19:27 <DIR> d-------- c:\documents and settings\Freezing Cool\Application Data\DivX
2008-12-31 16:56 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-31 16:16 . 2008-12-31 22:27 <DIR> d-------- c:\program files\FlashGet
2008-12-31 15:31 . 2008-12-31 15:31 <DIR> d---s---- c:\documents and settings\Freezing Cool\UserData
2008-12-31 09:42 . 2008-12-31 09:43 164 --a------ c:\windows\wcx_ftp.ini
2008-12-31 04:05 . 2008-12-31 04:05 <DIR> d-------- c:\documents and settings\Freezing Cool\Contacts
2008-12-31 04:02 . 2004-08-04 00:10 85,376 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2008-12-31 04:02 . 2004-08-04 00:10 19,328 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2008-12-31 04:02 . 2004-08-04 00:10 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2008-12-31 04:02 . 2004-08-04 01:56 16,384 --a------ c:\windows\system32\ipsink.ax
2008-12-31 04:02 . 2004-08-04 00:10 15,360 --a------ c:\windows\system32\drivers\StreamIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2008-12-31 04:02 . 2004-08-04 00:10 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2008-12-31 04:02 . 2004-08-03 23:58 7,552 --a------ c:\windows\system32\drivers\MSKSSRV.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2008-12-31 04:02 . 2004-08-03 23:58 5,376 --a------ c:\windows\system32\drivers\MSPCLOCK.sys
2008-12-31 04:02 . 2004-08-03 23:58 4,992 --a------ c:\windows\system32\drivers\MSPQM.sys
2008-12-31 04:02 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-12-31 04:00 . 2004-08-04 00:56 74,240 --a--c--- c:\windows\system32\dllcache\usbui.dll
2008-12-31 04:00 . 2001-08-17 14:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-31 21:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-31 19:30 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer
2008-12-31 18:27 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Ahead
2008-12-31 02:48 --------- d-----w c:\program files\Google
2008-12-31 02:45 --------- d-----w c:\program files\Winamp
2008-12-31 02:45 --------- d-----w c:\program files\Real
2008-12-31 02:45 --------- d-----w c:\program files\MSN Messenger
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\xing shared
2008-12-31 02:45 --------- d-----w c:\program files\Common Files\Real
2008-12-31 02:45 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\Winamp
2008-12-31 02:43 --------- d-----w c:\program files\Realtek
2008-12-31 02:41 315,392 ----a-w c:\windows\HideWin.exe
2008-12-31 02:38 --------- d-----w c:\program files\Webteh
2008-12-31 02:38 --------- d-----w c:\documents and settings\Freezing Cool\Application Data\BSplayer Pro
2008-12-31 02:37 --------- d-----w c:\program files\Nero
2008-12-31 02:37 --------- d-----w c:\program files\Common Files\Ahead
2008-12-31 02:36 --------- d-----w c:\program files\DIFX
2008-12-31 02:26 --------- d-----w c:\program files\Intel
2008-12-31 02:25 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-31 02:08 --------- d-----w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-04 19:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
+ 2007-02-22 22:41:12 304,544 ----a-w c:\windows\Downloaded Program Files\MessengerStatsPAClient.dll
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
+ 2009-01-01 01:14:41 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-12-31 21:44:30 28,095 ----a-w c:\windows\system32\nvModes.dat
+ 2009-01-01 01:15:43 28,095 ----a-w c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2002-12-31 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-18 8433664]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-31 185784]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" [2008-06-12 266497]
"nwiz"="nwiz.exe" [2007-05-18 c:\windows\system32\nwiz.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2006-06-29 c:\windows\AGRSMMSG.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-10-16 c:\windows\RTHDCPL.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
"vidc.hfyu"= huffyuv.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Counter-Strike 1.6 V35\\hl.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
R2 AntiVirMailService;Avira AntiVir Premium MailGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\avmailc.exe" [2008-12-31 164097]
R2 antivirwebservice;Avira AntiVir Premium WebGuard;"c:\program files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE" [2008-12-31 258305]
R2 AVEService;Avira AntiVir Premium MailGuard helper service;"c:\program files\Avira\AntiVir PersonalEdition Premium\avesvc.exe" [2008-12-31 41217]
R3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys []
*Newly Created Service* - ANTIVIRMAILSERVICE
*Newly Created Service* - ANTIVIRSCHEDULER
*Newly Created Service* - ANTIVIRSERVICE
*Newly Created Service* - ANTIVIRWEBSERVICE
*Newly Created Service* - AVESERVICE
*Newly Created Service* - AVGIO
*Newly Created Service* - AVGNTFLT
*Newly Created Service* - AVIPBB
*Newly Created Service* - BTHSERV
*Newly Created Service* - CATCHME
*Newly Created Service* - MBAMSWISSARMY
*Newly Created Service* - PROCEXP90
*Newly Created Service* - WS2IFSL
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: avsda.dll
FF - ProfilePath - c:\documents and settings\Freezing Cool\Application Data\Mozilla\Firefox\Profiles\klvdcp6g.default\
FF - plugin: c:\windows\system32\C2MP\npdivx32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-01 03:48:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-01-01 3:49:10
ComboFix-quarantined-files.txt 2009-01-01 02:49:04
ComboFix2.txt 2008-12-31 21:49:40
Pre-Run: 65,674,731,520 bytes free
Post-Run: 65,666,117,632 bytes free
181
|
|
|
|
|
|
|
Poslao: 01 Jan 2009 08:51
|
offline
- helen1

- Anti Malware Fighter
Rank 2
- Pridružio: 27 Avg 2005
- Poruke: 8657
- Gde živiš: Novi Beograd
|
Da li ima ikakvog poboljsanja?
|
|
|
|
|
|
|
Poslao: 01 Jan 2009 13:09
|
offline
- Pridružio: 23 Mar 2008
- Poruke: 68
|
Pa za sad radi kako treba, videcemo dal mu jos nesto fali. Hvala puno. Ako nesto pocne da radi kako ne treba (ali mislim da nece) pusticu ti PM.
|
|
|
|
|
|
|
|
|
Poslao: 01 Jan 2009 13:19
|
offline
- Pridružio: 23 Mar 2008
- Poruke: 68
|
Na to sam nacisto zaboravio. Sad sam pokusao i ne radi i dalje. Nece da nadje ni jednu mrezu. Samo pise "No wireless networks were found in range". Prosle nedelje je hvatao oko 7-8 nemoguce sad da nema nijedna. Mozda je i moguce al mi je to sumnjivo...
|
|
|
|
|
|