Potrebna pomoc

Potrebna pomoc

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2633
  • Gde živiš: Milan, Italy

Poz.... Drugu mi je zarazen komp pa ako moze pomoc evo loga........

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:09:29, on 27.10.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\713xRMT.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\PixelView\ADTVScheduleAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\WindowsUpdate.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Desktop\Adis\TR3.exe..exe

R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15C26CC7-2A06-4F38-8281-59E038964ED7} - C:\WINDOWS\system32\urqRKATj.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMT.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Windows Update] WindowsUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [stupid creative poll axis] C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [d85e20a8] rundll32.exe "C:\WINDOWS\system32\boqwnujy.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [Fork Meow] C:\DOCUME~1\ADIS~1.HOM\APPLIC~1\FREECA~1\FindInterDvd.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: PixelView Schedule Agent.lnk = C:\Program Files\PixelView\ADTVScheduleAgent.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D1C7546-B46D-4571-8BE8-A1521831291F}: NameServer = 195.66.163.225 79.143.98.35
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: iifddbbb - C:\WINDOWS\SYSTEM32\iifddbbb.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

--
End of file - 11178 bytes

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Poz...



* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.




Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2633
  • Gde živiš: Milan, Italy

ComboFix 08-10-27.01 - adis 2008-10-27 23:01:08.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.336 [GMT 1:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\ps.bat
C:\WINDOWS\admintxt.txt
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\bdrmmffm.exe
C:\WINDOWS\system32\boqwnujy.dll
C:\WINDOWS\system32\cbXRklJC.dll
C:\WINDOWS\system32\cisobdav.ini
C:\WINDOWS\system32\hgGvvusS.dll
C:\WINDOWS\system32\hgGwTnli.dll
C:\WINDOWS\system32\iifddbbb.dll
C:\WINDOWS\system32\jTAKRqru.ini
C:\WINDOWS\system32\jTAKRqru.ini2
C:\WINDOWS\system32\jtejyybr.ini
C:\WINDOWS\system32\lejqgdqk.ini
C:\WINDOWS\system32\ljJAQIaW.dll
C:\WINDOWS\system32\ljJBuRIA.dll
C:\WINDOWS\system32\ljJYOFVL.dll
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\system32\nnnnnMCV.dll
C:\WINDOWS\system32\pnuldcon.exe
C:\WINDOWS\system32\spkynrfg.exe
C:\WINDOWS\system32\urqRKATj.dll
C:\WINDOWS\system32\xxyyxvsp.dll
C:\WINDOWS\system32\yayvTjjG.dll
C:\WINDOWS\system32\yjunwqob.ini
C:\WINDOWS\windowsupdate.exe
D:\Autorun.inf
D:\ps.bat
E:\Autorun.inf
E:\ps.bat

.
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.

2008-10-22 22:55 . 2008-10-22 22:55 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia Multimedia Player
2008-10-22 18:28 . 2008-10-22 18:29 <DIR> d-------- C:\Program Files\Winamp
2008-10-22 18:28 . 2008-10-22 21:34 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Winamp
2008-10-22 18:28 . 2007-03-08 00:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-10-22 18:28 . 2007-03-08 00:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-22 18:28 . 2007-03-08 00:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-21 20:44 . 2008-10-21 20:44 <DIR> d-------- C:\Program Files\free cast
2008-10-14 13:35 . 2008-10-14 13:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Wildfire
2008-10-14 13:35 . 2008-10-14 13:35 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-10-14 13:31 . 2008-10-14 13:32 <DIR> d-------- C:\Program Files\Crimsonland
2008-10-14 13:27 . 2008-10-14 13:27 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-10-14 13:27 . 2008-10-14 13:28 <DIR> d-------- C:\Program Files\Jets N Guns
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-07 12:49 . 2008-10-22 23:46 <DIR> d-------- C:\Program Files\Achilles-Script 4.5 White
2008-10-06 10:32 . 2008-10-06 10:32 0 --a------ C:\WINDOWS\mngui.INI
2008-10-06 10:03 . 2006-11-30 14:14 97,088 -ra------ C:\WINDOWS\system32\drivers\se45mdm.sys
2008-10-06 10:03 . 2006-11-30 14:14 90,800 -ra------ C:\WINDOWS\system32\drivers\se45unic.sys
2008-10-06 10:03 . 2006-11-30 14:14 88,624 -ra------ C:\WINDOWS\system32\drivers\se45mgmt.sys
2008-10-06 10:03 . 2006-11-30 14:14 86,432 -ra------ C:\WINDOWS\system32\drivers\se45obex.sys
2008-10-06 10:03 . 2006-11-30 14:13 61,536 -ra------ C:\WINDOWS\system32\drivers\se45bus.sys
2008-10-06 10:03 . 2006-11-30 14:14 18,704 -ra------ C:\WINDOWS\system32\drivers\se45nd5.sys
2008-10-06 10:03 . 2006-11-30 14:14 9,360 -ra------ C:\WINDOWS\system32\drivers\se45mdfl.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cmnt.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cm.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45whnt.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45wh.sys
2008-10-06 10:03 . 2006-11-30 14:14 4,128 -ra------ C:\WINDOWS\system32\drivers\se45cr.sys
2008-10-06 10:01 . 2008-10-06 10:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Teleca
2008-10-06 10:00 . 2008-10-06 10:00 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:55 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Teleca
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Ericsson
2008-10-06 09:54 . 2008-10-06 09:54 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-30 15:27 . 2008-09-30 15:27 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\WebApplication1
2008-09-30 13:39 . 2008-09-30 13:38 100,484 -r-hs---- C:\tknapl.exe
2008-09-30 00:42 . 2008-09-30 00:47 <DIR> d-------- C:\Program Files\netbeans-5.5
2008-09-29 23:59 . 2008-10-27 18:26 <DIR> d-------- C:\Program Files\RegVac Registry Cleaner
2008-09-29 23:58 . 2008-10-27 19:07 <DIR> d-------- C:\Program Files\A1Click Ultra PC Cleaner
2008-09-29 12:52 . 2008-09-29 12:52 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-09-29 12:52 . 2008-10-14 20:20 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\f2fIntermediate
2008-09-28 21:46 . 2008-10-21 20:45 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
2008-09-28 21:45 . 2008-10-21 20:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast
2008-09-28 17:35 . 2008-09-28 17:35 <DIR> d-------- C:\Program Files\Sun
2008-09-28 17:34 . 2008-06-10 01:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-28 17:32 . 2008-09-30 00:48 <DIR> d-------- C:\Program Files\Java
2008-09-28 17:22 . 2008-10-27 22:47 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-28 16:49 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Phone Browser
2008-09-28 14:40 . 2008-10-15 09:03 <DIR> d---s---- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\UserData
2008-09-28 00:00 . 2008-09-27 13:19 90,749,456 --a------ C:\178.13_geforce_winxp_32bit_english_whql.exe
2008-09-27 23:59 . 2008-09-27 23:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\SonicStage
2008-09-27 23:59 . 2008-09-27 13:46 331,805,736 --a------ C:\windowsxp-kb936929-sp3-x86-enu_c81472f7eeea2eca421e116cd4c03e2300ebfde4.exe
2008-09-27 23:35 . 2008-10-15 09:02 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\new clas
2008-09-27 23:34 . 2008-09-27 23:35 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\bluej
2008-09-27 23:34 . 2008-09-27 23:34 <DIR> d-------- C:\BlueJ
2008-09-27 22:50 . 2008-09-27 22:50 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\GUIFormExamples
2008-09-27 22:38 . 2008-09-27 22:38 <DIR> d-------- C:\WINDOWS\Sun
2008-09-27 21:58 . 2008-10-26 17:46 <DIR> d-------- C:\Webcam Recordings
2008-09-27 21:14 . 2008-09-29 18:05 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Contacts
2008-09-27 21:01 . 2008-09-27 21:01 268 --ah----- C:\sqmdata14.sqm
2008-09-27 21:01 . 2008-09-27 21:01 244 --ah----- C:\sqmnoopt14.sqm
2008-09-27 21:00 . 2008-09-27 21:00 244 --ah----- C:\sqmnoopt13.sqm
2008-09-27 21:00 . 2008-09-27 21:00 232 --ah----- C:\sqmdata13.sqm
2008-09-27 20:59 . 2008-09-27 20:59 244 --ah----- C:\sqmnoopt12.sqm
2008-09-27 20:59 . 2008-09-27 20:59 232 --ah----- C:\sqmdata12.sqm
2008-09-27 20:56 . 2008-09-27 20:56 244 --ah----- C:\sqmnoopt11.sqm
2008-09-27 20:56 . 2008-09-27 20:56 244 --ah----- C:\sqmnoopt10.sqm
2008-09-27 20:56 . 2008-09-27 20:56 232 --ah----- C:\sqmdata11.sqm
2008-09-27 20:56 . 2008-09-27 20:56 232 --ah----- C:\sqmdata10.sqm
2008-09-27 20:55 . 2008-09-27 20:55 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-27 20:43 . 2008-09-27 20:43 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\.netbeans
2008-09-27 20:12 . 2008-09-27 20:12 244 --ah----- C:\sqmnoopt09.sqm
2008-09-27 20:12 . 2008-09-27 20:12 232 --ah----- C:\sqmdata09.sqm
2008-09-27 20:08 . 2008-09-27 20:08 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-27 20:08 . 2008-10-27 22:53 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-09-27 20:08 . 2008-10-27 23:18 5,793,568 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-27 20:08 . 2008-09-27 20:08 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-27 20:08 . 2008-10-27 23:14 89,084 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-27 20:08 . 2008-09-27 20:08 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-27 20:08 . 2008-10-27 23:18 45,856 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-27 20:08 . 2008-10-27 23:14 7,364 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-27 20:07 . 2008-09-27 20:07 244 --ah----- C:\sqmnoopt08.sqm
2008-09-27 20:07 . 2008-09-27 20:07 232 --ah----- C:\sqmdata08.sqm
2008-09-27 20:03 . 2008-09-27 20:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-27 20:00 . 2008-09-27 20:00 244 --ah----- C:\sqmnoopt07.sqm
2008-09-27 20:00 . 2008-09-27 20:00 232 --ah----- C:\sqmdata07.sqm
2008-09-27 19:59 . 2008-09-27 19:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-09-27 19:57 . 2000-05-22 09:58 647,872 --a------ C:\WINDOWS\system32\Mscomct2.ocx
2008-09-27 19:57 . 1999-10-11 02:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2008-09-27 19:55 . 2008-09-27 19:57 <DIR> d-------- C:\Program Files\Creative
2008-09-27 19:55 . 2008-10-07 21:10 <DIR> d-------- C:\Media
2008-09-27 19:52 . 2003-06-18 16:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-09-27 19:52 . 2008-09-27 19:52 376 --a------ C:\WINDOWS\ODBC.INI
2008-09-27 19:50 . 2004-08-03 22:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-27 19:42 . 2008-09-27 19:44 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-09-27 19:30 . 2004-03-09 00:00 1,081,616 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-09-27 19:16 . 2008-09-27 19:16 <DIR> dr-h----- C:\MSOCache
2008-09-27 19:15 . 2008-09-27 19:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-09-27 19:15 . 2008-09-27 19:16 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Nokia
2008-09-27 19:14 . 2008-09-27 19:15 <DIR> d-------- C:\Program Files\DIFX
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-09-27 19:14 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\PC Suite
2008-09-27 19:14 . 2007-02-22 09:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-09-27 19:14 . 2007-02-22 09:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-09-27 19:14 . 2007-02-22 09:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-09-27 19:14 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-09-27 19:14 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-09-27 19:14 . 2007-02-22 09:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-09-27 19:13 . 2008-09-27 19:13 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-09-27 19:11 . 2008-09-27 19:11 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\CyberLink
2008-09-27 19:10 . 2008-09-27 19:10 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-09-27 19:10 . 2001-03-08 17:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-09-27 19:09 . 2008-09-27 19:10 <DIR> d-------- C:\Program Files\CyberLink
2008-09-27 19:05 . 2008-10-26 17:46 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-27 19:03 . 2008-09-27 19:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nero
2008-09-27 18:59 . 2008-10-07 22:05 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-09-27 18:59 . 2004-03-08 23:00 609,824 --a------ C:\WINDOWS\system32\COMCTL32.ocx
2008-09-27 18:59 . 2004-03-08 23:00 212,240 --a------ C:\WINDOWS\system32\richtx32.OCX
2008-09-27 18:59 . 2004-03-08 21:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX
2008-09-27 18:59 . 2004-03-08 23:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 16:04 155,995 ----a-w C:\WINDOWS\java\Packages\9BRBTNJF.ZIP
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL" [2008-09-27 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-09-27 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 15360]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"Fork Meow"="C:\DOCUME~1\ADIS~1.HOM\APPLIC~1\FREECA~1\FindInterDvd.exe" [2008-10-21 499200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 86016]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"TV Card Remote Control Device Monitor"="C:\WINDOWS\713xRMT.exe" [2007-09-13 466944]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-27 29744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"stupid creative poll axis"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe" [2008-10-25 536576]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-08 227856]
"nwiz"="nwiz.exe" [2005-12-10 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-09-27 295606]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
PixelView Schedule Agent.lnk - C:\Program Files\PixelView\ADTVScheduleAgent.exe [2008-09-27 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2002-12-31 14336]
R3 3xHybrid;SAA713x TV Card Service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-10-24 907520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\tdi.sys [2002-12-31 18560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-27 29744]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2008-09-27 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]

2008-10-27 C:\WINDOWS\Tasks\A3409A69918B1969.job
- c:\docume~1\adis~1.hom\applic~1\freeca~1\For vga multi.exe [2008-10-21 20:46]
.
- - - - ORPHANS REMOVED - - - -

BHO-{2D610010-DE60-4E83-A3FE-06CC1DF3AE74} - C:\WINDOWS\system32\urqRKATj.dll
BHO-{79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll
HKLM-Run-d85e20a8 - C:\WINDOWS\system32\boqwnujy.dll
HKLM-Run-RegistryMechanic - (no file)
ShellExecuteHooks-{79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Mozilla\Firefox\Profiles\f9n71fc3.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 23:15:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\DOCUME~1\ADIS~1.HOM\LOCALS~1\Temp\RGI2.tmp

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
.
**************************************************************************
.
Completion time: 2008-10-27 23:25:30 - machine was rebooted [adis]
ComboFix-quarantined-files.txt 2008-10-27 22:25:24

Pre-Run: 20,720,537,600 bytes free
Post-Run: 20,894,285,824 bytes free

283

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Uploaduj file: C:\WINDOWS\system32\drivers\tdi.sys

Upload link: http://www.mycity.rs/ambulanta-upload.php


-------------------------------------------------------------------------------------



Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job

Folder::
C:\Program Files\free cast
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fork Meow"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stupid creative poll axis"=-



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2633
  • Gde živiš: Milan, Italy

Upload je uspjesan.... evo loga..........



ComboFix 08-10-27.01 - adis 2008-10-28 21:34:29.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.328 [GMT 1:00]
Command switches used :: C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\0
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\bfxbpteb.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\FindInterDvd.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\For vga multi.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\Funk Ante Axis Iso.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\xfdltsqi.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\Store team.exe
C:\Program Files\free cast
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-22 22:55 . 2008-10-22 22:55 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia Multimedia Player
2008-10-22 18:28 . 2008-10-22 18:29 <DIR> d-------- C:\Program Files\Winamp
2008-10-22 18:28 . 2008-10-22 21:34 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Winamp
2008-10-22 18:28 . 2007-03-08 00:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-10-22 18:28 . 2007-03-08 00:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-22 18:28 . 2007-03-08 00:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-14 13:35 . 2008-10-14 13:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Wildfire
2008-10-14 13:35 . 2008-10-14 13:35 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-10-14 13:31 . 2008-10-14 13:32 <DIR> d-------- C:\Program Files\Crimsonland
2008-10-14 13:27 . 2008-10-14 13:27 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-10-14 13:27 . 2008-10-14 13:28 <DIR> d-------- C:\Program Files\Jets N Guns
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-07 12:49 . 2008-10-22 23:46 <DIR> d-------- C:\Program Files\Achilles-Script 4.5 White
2008-10-06 10:32 . 2008-10-06 10:32 0 --a------ C:\WINDOWS\mngui.INI
2008-10-06 10:03 . 2006-11-30 14:14 97,088 -ra------ C:\WINDOWS\system32\drivers\se45mdm.sys
2008-10-06 10:03 . 2006-11-30 14:14 90,800 -ra------ C:\WINDOWS\system32\drivers\se45unic.sys
2008-10-06 10:03 . 2006-11-30 14:14 88,624 -ra------ C:\WINDOWS\system32\drivers\se45mgmt.sys
2008-10-06 10:03 . 2006-11-30 14:14 86,432 -ra------ C:\WINDOWS\system32\drivers\se45obex.sys
2008-10-06 10:03 . 2006-11-30 14:13 61,536 -ra------ C:\WINDOWS\system32\drivers\se45bus.sys
2008-10-06 10:03 . 2006-11-30 14:14 18,704 -ra------ C:\WINDOWS\system32\drivers\se45nd5.sys
2008-10-06 10:03 . 2006-11-30 14:14 9,360 -ra------ C:\WINDOWS\system32\drivers\se45mdfl.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cmnt.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cm.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45whnt.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45wh.sys
2008-10-06 10:03 . 2006-11-30 14:14 4,128 -ra------ C:\WINDOWS\system32\drivers\se45cr.sys
2008-10-06 10:01 . 2008-10-06 10:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Teleca
2008-10-06 10:00 . 2008-10-06 10:00 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:55 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Teleca
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Ericsson
2008-10-06 09:54 . 2008-10-06 09:54 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-30 15:27 . 2008-09-30 15:27 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\WebApplication1
2008-09-30 00:42 . 2008-09-30 00:47 <DIR> d-------- C:\Program Files\netbeans-5.5
2008-09-29 23:59 . 2008-10-27 18:26 <DIR> d-------- C:\Program Files\RegVac Registry Cleaner
2008-09-29 23:58 . 2008-10-27 19:07 <DIR> d-------- C:\Program Files\A1Click Ultra PC Cleaner
2008-09-29 12:52 . 2008-09-29 12:52 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-09-29 12:52 . 2008-10-14 20:20 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\f2fIntermediate
2008-09-28 17:35 . 2008-09-28 17:35 <DIR> d-------- C:\Program Files\Sun
2008-09-28 17:34 . 2008-06-10 01:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-28 17:32 . 2008-09-30 00:48 <DIR> d-------- C:\Program Files\Java
2008-09-28 17:22 . 2008-10-27 22:47 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-28 16:49 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Phone Browser
2008-09-28 14:40 . 2008-10-15 09:03 <DIR> d---s---- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\UserData
2008-09-28 00:00 . 2008-09-27 13:19 90,749,456 --a------ C:\178.13_geforce_winxp_32bit_english_whql.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 20:39 56,608 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-28 20:39 5,951,264 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-28 20:32 90,620 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-28 20:32 8,252 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-28 20:15 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-10-15 08:00 --------- d-----w C:\Documents and Settings\adis\Application Data\Azureus
2008-10-07 21:05 --------- d-----w C:\Program Files\MessengerDiscovery
2008-09-28 20:45 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-28 15:49 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\PC Suite
2008-09-27 22:59 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Corporation
2008-09-27 20:46 --------- d-----w C:\Program Files\Google
2008-09-27 20:06 --------- d-----w C:\Program Files\Windows Live
2008-09-27 19:08 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-27 19:08 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-27 19:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-27 19:03 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-27 18:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-09-27 18:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-27 18:57 --------- d-----w C:\Program Files\Creative
2008-09-27 18:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-09-27 18:16 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-09-27 18:16 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia
2008-09-27 18:15 --------- d-----w C:\Program Files\DIFX
2008-09-27 18:14 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-09-27 18:14 --------- d-----w C:\Program Files\Nokia
2008-09-27 18:14 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-27 18:14 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-27 18:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-09-27 18:11 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\CyberLink
2008-09-27 18:10 --------- d-----w C:\Program Files\CyberLink
2008-09-27 18:10 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-09-27 18:03 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nero
2008-09-27 17:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-09-27 17:51 --------- d-----w C:\Program Files\Sony Corporation
2008-09-27 17:51 --------- d-----w C:\Program Files\Sony
2008-09-27 17:51 --------- d-----w C:\Program Files\Common Files\Sony Shared
2008-09-27 17:49 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Corporation
2008-09-27 17:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-27 17:45 --------- d-----w C:\Program Files\PixelView
2008-09-27 17:40 --------- d-----w C:\Program Files\SiSLan
2008-09-27 17:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2008-09-27 16:12 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-09-27 16:12 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-27 16:12 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\TuneUp Software
2008-09-27 16:04 155,995 ----a-w C:\WINDOWS\java\Packages\9BRBTNJF.ZIP
2008-09-27 16:02 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-09-27 15:04 --------- d-----w C:\Documents and Settings\adis\Application Data\Nero
2008-09-27 15:03 --------- d-----w C:\Program Files\Common Files\Nero
2008-09-27 15:01 --------- d-----w C:\Program Files\Nero
2008-09-27 14:54 --------- d-----w C:\Program Files\AskTBar
2008-09-27 14:52 --------- d-----w C:\Program Files\Circle Developement
2008-09-27 14:48 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-27 14:48 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-09-27 14:48 --------- d-----w C:\Program Files\Common Files\L&H
2008-09-27 14:47 --------- d-----w C:\Program Files\Microsoft Works
2008-09-27 14:44 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-09-27 14:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-27 14:35 --------- d-----w C:\Program Files\Azureus
2008-09-27 14:34 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-27 14:32 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-27 14:21 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-27 14:17 --------- d-----w C:\Program Files\Common Files\Java
2008-09-27 14:10 --------- d-----w C:\Program Files\Analog Devices
2008-09-27 14:02 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-27 12:46 331,805,736 ----a-w C:\windowsxp-kb936929-sp3-x86-enu_c81472f7eeea2eca421e116cd4c03e2300ebfde4.exe
2008-09-22 06:39 98,533 --sh--r C:\rdsfk.com
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL" [2008-09-27 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-09-27 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 15360]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 86016]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"TV Card Remote Control Device Monitor"="C:\WINDOWS\713xRMT.exe" [2007-09-13 466944]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-27 29744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"nwiz"="nwiz.exe" [2005-12-10 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-09-27 295606]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
PixelView Schedule Agent.lnk - C:\Program Files\PixelView\ADTVScheduleAgent.exe [2008-09-27 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2002-12-31 14336]
R3 3xHybrid;SAA713x TV Card Service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-10-24 907520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\tdi.sys [2002-12-31 18560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-27 29744]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2008-09-27 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 21:39:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-28 21:41:24
ComboFix-quarantined-files.txt 2008-10-28 20:41:21
ComboFix2.txt 2008-10-27 22:25:32

Pre-Run: 20,819,046,400 bytes free
Post-Run: 20,803,514,368 bytes free

222

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

C:\Program Files\Circle Developement <--- ovo pokušaj da deinstaliraš; ako nije moguće, obriši kompletan folder.


C:\Program Files\MessengerDiscovery <--- ovo je, kao što ti već pomenuh, adware.



Jedan od trojanaca koji su ovde bili prisutni, je instaliran uz ovo:

C:\Program Files\Messenger Plus! Live



Imaj to na umu kada idući put budeš nekom preporučivao korišćenje tih programa.





Anyway... Ovo je sada čisto.
Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore



Toliko od mene...

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2633
  • Gde živiš: Milan, Italy

Pa ono na mom kompu mogu da se izborim sa MSN plus i messenger discoveru live.... tako da mi ne smetaju... al imacu to na umu.. Smile


Hvala puno za pomoc Smile

Ko je trenutno na forumu
 

Ukupno su 974 korisnika na forumu :: 57 registrovanih, 9 sakrivenih i 908 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Arahne, Arsenije, Atomski čoban, awathorn, babaroga, Bobrock1, Boris90, botta, Brana01, brundo65, cemix, Dannyboy, DH, Djokkinen, Dukelander, Fog of War, Frunze, haris1913, ikan, Imba Dakula, Insan, Ivan Campo, JOntra, Karla, kolateralnasteta, krca73, Kruger, Krusarac, Leonov, Mercury, mgolub, Mi lao shu, MiGac, mikki jons, mile23, Mitraljeta, nebidrag, Nemanja.M, Niko Bitan, Nobunaga, opt1, pein, Pohovani_00, Polemarchoi, raptorsi, S-lash, Sale.S, Srpska zauvjek, synergia, Trpe Grozni, trutcina, Tvrtko I, zlatkoa987, Zlikowsky, Zmaj001, |_MeD_|