Potrebna pomoc

Potrebna pomoc

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2630
  • Gde živiš: Milan, Italy

Poz.... Drugu mi je zarazen komp pa ako moze pomoc evo loga........

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:09:29, on 27.10.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\713xRMT.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\PixelView\ADTVScheduleAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\WindowsUpdate.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Desktop\Adis\TR3.exe..exe

R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15C26CC7-2A06-4F38-8281-59E038964ED7} - C:\WINDOWS\system32\urqRKATj.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\2.bin\ASKTBAR.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [TV Card Remote Control Device Monitor] C:\WINDOWS\713xRMT.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Windows Update] WindowsUpdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [stupid creative poll axis] C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [d85e20a8] rundll32.exe "C:\WINDOWS\system32\boqwnujy.dll",b
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
O4 - HKCU\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKCU\..\Run: [Fork Meow] C:\DOCUME~1\ADIS~1.HOM\APPLIC~1\FREECA~1\FindInterDvd.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe
O4 - Global Startup: PixelView Schedule Agent.lnk = C:\Program Files\PixelView\ADTVScheduleAgent.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{6D1C7546-B46D-4571-8BE8-A1521831291F}: NameServer = 195.66.163.225 79.143.98.35
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: iifddbbb - C:\WINDOWS\SYSTEM32\iifddbbb.dll
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

--
End of file - 11178 bytes

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Poz...



* Klikni desnim tasterom na Kaspersky ikonicu ( ) u donjem, desnom uglu ekrana i izaberi Pause Protection.
* U prozoru koji se otvori, izaberi By User Request.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.




Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2630
  • Gde živiš: Milan, Italy

ComboFix 08-10-27.01 - adis 2008-10-27 23:01:08.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.336 [GMT 1:00]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
C:\ps.bat
C:\WINDOWS\admintxt.txt
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\bdrmmffm.exe
C:\WINDOWS\system32\boqwnujy.dll
C:\WINDOWS\system32\cbXRklJC.dll
C:\WINDOWS\system32\cisobdav.ini
C:\WINDOWS\system32\hgGvvusS.dll
C:\WINDOWS\system32\hgGwTnli.dll
C:\WINDOWS\system32\iifddbbb.dll
C:\WINDOWS\system32\jTAKRqru.ini
C:\WINDOWS\system32\jTAKRqru.ini2
C:\WINDOWS\system32\jtejyybr.ini
C:\WINDOWS\system32\lejqgdqk.ini
C:\WINDOWS\system32\ljJAQIaW.dll
C:\WINDOWS\system32\ljJBuRIA.dll
C:\WINDOWS\system32\ljJYOFVL.dll
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\system32\nnnnnMCV.dll
C:\WINDOWS\system32\pnuldcon.exe
C:\WINDOWS\system32\spkynrfg.exe
C:\WINDOWS\system32\urqRKATj.dll
C:\WINDOWS\system32\xxyyxvsp.dll
C:\WINDOWS\system32\yayvTjjG.dll
C:\WINDOWS\system32\yjunwqob.ini
C:\WINDOWS\windowsupdate.exe
D:\Autorun.inf
D:\ps.bat
E:\Autorun.inf
E:\ps.bat

.
((((((((((((((((((((((((( Files Created from 2008-09-27 to 2008-10-27 )))))))))))))))))))))))))))))))
.

2008-10-22 22:55 . 2008-10-22 22:55 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia Multimedia Player
2008-10-22 18:28 . 2008-10-22 18:29 <DIR> d-------- C:\Program Files\Winamp
2008-10-22 18:28 . 2008-10-22 21:34 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Winamp
2008-10-22 18:28 . 2007-03-08 00:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-10-22 18:28 . 2007-03-08 00:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-22 18:28 . 2007-03-08 00:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-21 20:44 . 2008-10-21 20:44 <DIR> d-------- C:\Program Files\free cast
2008-10-14 13:35 . 2008-10-14 13:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Wildfire
2008-10-14 13:35 . 2008-10-14 13:35 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-10-14 13:31 . 2008-10-14 13:32 <DIR> d-------- C:\Program Files\Crimsonland
2008-10-14 13:27 . 2008-10-14 13:27 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-10-14 13:27 . 2008-10-14 13:28 <DIR> d-------- C:\Program Files\Jets N Guns
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-07 12:49 . 2008-10-22 23:46 <DIR> d-------- C:\Program Files\Achilles-Script 4.5 White
2008-10-06 10:32 . 2008-10-06 10:32 0 --a------ C:\WINDOWS\mngui.INI
2008-10-06 10:03 . 2006-11-30 14:14 97,088 -ra------ C:\WINDOWS\system32\drivers\se45mdm.sys
2008-10-06 10:03 . 2006-11-30 14:14 90,800 -ra------ C:\WINDOWS\system32\drivers\se45unic.sys
2008-10-06 10:03 . 2006-11-30 14:14 88,624 -ra------ C:\WINDOWS\system32\drivers\se45mgmt.sys
2008-10-06 10:03 . 2006-11-30 14:14 86,432 -ra------ C:\WINDOWS\system32\drivers\se45obex.sys
2008-10-06 10:03 . 2006-11-30 14:13 61,536 -ra------ C:\WINDOWS\system32\drivers\se45bus.sys
2008-10-06 10:03 . 2006-11-30 14:14 18,704 -ra------ C:\WINDOWS\system32\drivers\se45nd5.sys
2008-10-06 10:03 . 2006-11-30 14:14 9,360 -ra------ C:\WINDOWS\system32\drivers\se45mdfl.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cmnt.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cm.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45whnt.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45wh.sys
2008-10-06 10:03 . 2006-11-30 14:14 4,128 -ra------ C:\WINDOWS\system32\drivers\se45cr.sys
2008-10-06 10:01 . 2008-10-06 10:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Teleca
2008-10-06 10:00 . 2008-10-06 10:00 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:55 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Teleca
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Ericsson
2008-10-06 09:54 . 2008-10-06 09:54 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-30 15:27 . 2008-09-30 15:27 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\WebApplication1
2008-09-30 13:39 . 2008-09-30 13:38 100,484 -r-hs---- C:\tknapl.exe
2008-09-30 00:42 . 2008-09-30 00:47 <DIR> d-------- C:\Program Files\netbeans-5.5
2008-09-29 23:59 . 2008-10-27 18:26 <DIR> d-------- C:\Program Files\RegVac Registry Cleaner
2008-09-29 23:58 . 2008-10-27 19:07 <DIR> d-------- C:\Program Files\A1Click Ultra PC Cleaner
2008-09-29 12:52 . 2008-09-29 12:52 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-09-29 12:52 . 2008-10-14 20:20 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\f2fIntermediate
2008-09-28 21:46 . 2008-10-21 20:45 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
2008-09-28 21:45 . 2008-10-21 20:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast
2008-09-28 17:35 . 2008-09-28 17:35 <DIR> d-------- C:\Program Files\Sun
2008-09-28 17:34 . 2008-06-10 01:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-28 17:32 . 2008-09-30 00:48 <DIR> d-------- C:\Program Files\Java
2008-09-28 17:22 . 2008-10-27 22:47 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-28 16:49 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Phone Browser
2008-09-28 14:40 . 2008-10-15 09:03 <DIR> d---s---- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\UserData
2008-09-28 00:00 . 2008-09-27 13:19 90,749,456 --a------ C:\178.13_geforce_winxp_32bit_english_whql.exe
2008-09-27 23:59 . 2008-09-27 23:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\SonicStage
2008-09-27 23:59 . 2008-09-27 13:46 331,805,736 --a------ C:\windowsxp-kb936929-sp3-x86-enu_c81472f7eeea2eca421e116cd4c03e2300ebfde4.exe
2008-09-27 23:35 . 2008-10-15 09:02 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\new clas
2008-09-27 23:34 . 2008-09-27 23:35 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\bluej
2008-09-27 23:34 . 2008-09-27 23:34 <DIR> d-------- C:\BlueJ
2008-09-27 22:50 . 2008-09-27 22:50 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\GUIFormExamples
2008-09-27 22:38 . 2008-09-27 22:38 <DIR> d-------- C:\WINDOWS\Sun
2008-09-27 21:58 . 2008-10-26 17:46 <DIR> d-------- C:\Webcam Recordings
2008-09-27 21:14 . 2008-09-29 18:05 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Contacts
2008-09-27 21:01 . 2008-09-27 21:01 268 --ah----- C:\sqmdata14.sqm
2008-09-27 21:01 . 2008-09-27 21:01 244 --ah----- C:\sqmnoopt14.sqm
2008-09-27 21:00 . 2008-09-27 21:00 244 --ah----- C:\sqmnoopt13.sqm
2008-09-27 21:00 . 2008-09-27 21:00 232 --ah----- C:\sqmdata13.sqm
2008-09-27 20:59 . 2008-09-27 20:59 244 --ah----- C:\sqmnoopt12.sqm
2008-09-27 20:59 . 2008-09-27 20:59 232 --ah----- C:\sqmdata12.sqm
2008-09-27 20:56 . 2008-09-27 20:56 244 --ah----- C:\sqmnoopt11.sqm
2008-09-27 20:56 . 2008-09-27 20:56 244 --ah----- C:\sqmnoopt10.sqm
2008-09-27 20:56 . 2008-09-27 20:56 232 --ah----- C:\sqmdata11.sqm
2008-09-27 20:56 . 2008-09-27 20:56 232 --ah----- C:\sqmdata10.sqm
2008-09-27 20:55 . 2008-09-27 20:55 0 --a------ C:\WINDOWS\nsreg.dat
2008-09-27 20:43 . 2008-09-27 20:43 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\.netbeans
2008-09-27 20:12 . 2008-09-27 20:12 244 --ah----- C:\sqmnoopt09.sqm
2008-09-27 20:12 . 2008-09-27 20:12 232 --ah----- C:\sqmdata09.sqm
2008-09-27 20:08 . 2008-09-27 20:08 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-09-27 20:08 . 2008-10-27 22:53 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-09-27 20:08 . 2008-10-27 23:18 5,793,568 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-27 20:08 . 2008-09-27 20:08 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-09-27 20:08 . 2008-10-27 23:14 89,084 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-27 20:08 . 2008-09-27 20:08 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-09-27 20:08 . 2008-10-27 23:18 45,856 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-09-27 20:08 . 2008-10-27 23:14 7,364 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-09-27 20:07 . 2008-09-27 20:07 244 --ah----- C:\sqmnoopt08.sqm
2008-09-27 20:07 . 2008-09-27 20:07 232 --ah----- C:\sqmdata08.sqm
2008-09-27 20:03 . 2008-09-27 20:03 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-27 20:00 . 2008-09-27 20:00 244 --ah----- C:\sqmnoopt07.sqm
2008-09-27 20:00 . 2008-09-27 20:00 232 --ah----- C:\sqmdata07.sqm
2008-09-27 19:59 . 2008-09-27 19:59 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-09-27 19:57 . 2000-05-22 09:58 647,872 --a------ C:\WINDOWS\system32\Mscomct2.ocx
2008-09-27 19:57 . 1999-10-11 02:00 41,984 --------- C:\WINDOWS\Ctregrun.exe
2008-09-27 19:55 . 2008-09-27 19:57 <DIR> d-------- C:\Program Files\Creative
2008-09-27 19:55 . 2008-10-07 21:10 <DIR> d-------- C:\Media
2008-09-27 19:52 . 2003-06-18 16:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-09-27 19:52 . 2008-09-27 19:52 376 --a------ C:\WINDOWS\ODBC.INI
2008-09-27 19:50 . 2004-08-03 22:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-09-27 19:42 . 2008-09-27 19:44 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-09-27 19:30 . 2004-03-09 00:00 1,081,616 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-09-27 19:16 . 2008-09-27 19:16 <DIR> dr-h----- C:\MSOCache
2008-09-27 19:15 . 2008-09-27 19:16 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-09-27 19:15 . 2008-09-27 19:16 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Nokia
2008-09-27 19:14 . 2008-09-27 19:15 <DIR> d-------- C:\Program Files\DIFX
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Common Files\PCSuite
2008-09-27 19:14 . 2008-09-27 19:14 <DIR> d-------- C:\Program Files\Common Files\Nokia
2008-09-27 19:14 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\PC Suite
2008-09-27 19:14 . 2007-02-22 09:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2008-09-27 19:14 . 2007-02-22 09:15 90,624 --a------ C:\WINDOWS\system32\nmwcdcls.dll
2008-09-27 19:14 . 2007-02-22 09:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2008-09-27 19:14 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2008-09-27 19:14 . 2007-02-22 09:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2008-09-27 19:14 . 2007-02-22 09:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2008-09-27 19:13 . 2008-09-27 19:13 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-09-27 19:11 . 2008-09-27 19:11 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\CyberLink
2008-09-27 19:10 . 2008-09-27 19:10 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-09-27 19:10 . 2001-03-08 17:30 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2008-09-27 19:09 . 2008-09-27 19:10 <DIR> d-------- C:\Program Files\CyberLink
2008-09-27 19:05 . 2008-10-26 17:46 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-09-27 19:03 . 2008-09-27 19:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nero
2008-09-27 18:59 . 2008-10-07 22:05 <DIR> d-------- C:\Program Files\MessengerDiscovery
2008-09-27 18:59 . 2004-03-08 23:00 609,824 --a------ C:\WINDOWS\system32\COMCTL32.ocx
2008-09-27 18:59 . 2004-03-08 23:00 212,240 --a------ C:\WINDOWS\system32\richtx32.OCX
2008-09-27 18:59 . 2004-03-08 21:00 152,848 --a------ C:\WINDOWS\system32\comdlg32.OCX
2008-09-27 18:59 . 2004-03-08 23:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 16:04 155,995 ----a-w C:\WINDOWS\java\Packages\9BRBTNJF.ZIP
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL" [2008-09-27 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-09-27 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 15360]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"Fork Meow"="C:\DOCUME~1\ADIS~1.HOM\APPLIC~1\FREECA~1\FindInterDvd.exe" [2008-10-21 499200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 86016]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"TV Card Remote Control Device Monitor"="C:\WINDOWS\713xRMT.exe" [2007-09-13 466944]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-27 29744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"stupid creative poll axis"="C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe" [2008-10-25 536576]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2008-02-08 227856]
"nwiz"="nwiz.exe" [2005-12-10 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-09-27 295606]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
PixelView Schedule Agent.lnk - C:\Program Files\PixelView\ADTVScheduleAgent.exe [2008-09-27 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2002-12-31 14336]
R3 3xHybrid;SAA713x TV Card Service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-10-24 907520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\tdi.sys [2002-12-31 18560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-27 29744]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2008-09-27 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]

2008-10-27 C:\WINDOWS\Tasks\A3409A69918B1969.job
- c:\docume~1\adis~1.hom\applic~1\freeca~1\For vga multi.exe [2008-10-21 20:46]
.
- - - - ORPHANS REMOVED - - - -

BHO-{2D610010-DE60-4E83-A3FE-06CC1DF3AE74} - C:\WINDOWS\system32\urqRKATj.dll
BHO-{79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll
HKLM-Run-d85e20a8 - C:\WINDOWS\system32\boqwnujy.dll
HKLM-Run-RegistryMechanic - (no file)
ShellExecuteHooks-{79117664-7A50-429C-B3AF-6CDF9E1886CE} - C:\WINDOWS\system32\iifddbbb.dll


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Mozilla\Firefox\Profiles\f9n71fc3.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - www.google.com
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-27 23:15:41
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\DOCUME~1\ADIS~1.HOM\LOCALS~1\Temp\RGI2.tmp

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
.
**************************************************************************
.
Completion time: 2008-10-27 23:25:30 - machine was rebooted [adis]
ComboFix-quarantined-files.txt 2008-10-27 22:25:24

Pre-Run: 20,720,537,600 bytes free
Post-Run: 20,894,285,824 bytes free

283

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Uploaduj file: C:\WINDOWS\system32\drivers\tdi.sys

Upload link: http://www.mycity.rs/ambulanta-upload.php


-------------------------------------------------------------------------------------



Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job

Folder::
C:\Program Files\free cast
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Fork Meow"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stupid creative poll axis"=-



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2630
  • Gde živiš: Milan, Italy

Upload je uspjesan.... evo loga..........



ComboFix 08-10-27.01 - adis 2008-10-28 21:34:29.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.328 [GMT 1:00]
Command switches used :: C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\0
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\bfxbpteb.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\FindInterDvd.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\For vga multi.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\Funk Ante Axis Iso.exe
C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\free cast\xfdltsqi.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\HOLE MEDIA.exe
C:\Documents and Settings\All Users.WINDOWS\Application Data\Memo save stupid creative\Store team.exe
C:\Program Files\free cast
C:\tknapl.exe
C:\WINDOWS\Tasks\A3409A69918B1969.job

.
((((((((((((((((((((((((( Files Created from 2008-09-28 to 2008-10-28 )))))))))))))))))))))))))))))))
.

2008-10-22 22:55 . 2008-10-22 22:55 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia Multimedia Player
2008-10-22 18:28 . 2008-10-22 18:29 <DIR> d-------- C:\Program Files\Winamp
2008-10-22 18:28 . 2008-10-22 21:34 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Winamp
2008-10-22 18:28 . 2007-03-08 00:51 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2008-10-22 18:28 . 2007-03-08 00:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-22 18:28 . 2007-03-08 00:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-14 13:35 . 2008-10-14 13:46 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Wildfire
2008-10-14 13:35 . 2008-10-14 13:35 4,096 --a------ C:\WINDOWS\d3dx.dat
2008-10-14 13:31 . 2008-10-14 13:32 <DIR> d-------- C:\Program Files\Crimsonland
2008-10-14 13:27 . 2008-10-14 13:27 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-10-14 13:27 . 2008-10-14 13:28 <DIR> d-------- C:\Program Files\Jets N Guns
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-10-10 16:44 . 2004-08-03 22:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-10-07 12:49 . 2008-10-22 23:46 <DIR> d-------- C:\Program Files\Achilles-Script 4.5 White
2008-10-06 10:32 . 2008-10-06 10:32 0 --a------ C:\WINDOWS\mngui.INI
2008-10-06 10:03 . 2006-11-30 14:14 97,088 -ra------ C:\WINDOWS\system32\drivers\se45mdm.sys
2008-10-06 10:03 . 2006-11-30 14:14 90,800 -ra------ C:\WINDOWS\system32\drivers\se45unic.sys
2008-10-06 10:03 . 2006-11-30 14:14 88,624 -ra------ C:\WINDOWS\system32\drivers\se45mgmt.sys
2008-10-06 10:03 . 2006-11-30 14:14 86,432 -ra------ C:\WINDOWS\system32\drivers\se45obex.sys
2008-10-06 10:03 . 2006-11-30 14:13 61,536 -ra------ C:\WINDOWS\system32\drivers\se45bus.sys
2008-10-06 10:03 . 2006-11-30 14:14 18,704 -ra------ C:\WINDOWS\system32\drivers\se45nd5.sys
2008-10-06 10:03 . 2006-11-30 14:14 9,360 -ra------ C:\WINDOWS\system32\drivers\se45mdfl.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cmnt.sys
2008-10-06 10:03 . 2006-11-30 14:13 6,240 -ra------ C:\WINDOWS\system32\drivers\se45cm.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45whnt.sys
2008-10-06 10:03 . 2006-11-30 14:14 5,872 -ra------ C:\WINDOWS\system32\drivers\se45wh.sys
2008-10-06 10:03 . 2006-11-30 14:14 4,128 -ra------ C:\WINDOWS\system32\drivers\se45cr.sys
2008-10-06 10:01 . 2008-10-06 10:03 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Teleca
2008-10-06 10:00 . 2008-10-06 10:00 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:55 <DIR> d-------- C:\Program Files\Sony Ericsson
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Teleca Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Program Files\Common Files\Sony Ericsson Shared
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Teleca
2008-10-06 09:55 . 2008-10-06 09:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Ericsson
2008-10-06 09:54 . 2008-10-06 09:54 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-09-30 15:27 . 2008-09-30 15:27 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\WebApplication1
2008-09-30 00:42 . 2008-09-30 00:47 <DIR> d-------- C:\Program Files\netbeans-5.5
2008-09-29 23:59 . 2008-10-27 18:26 <DIR> d-------- C:\Program Files\RegVac Registry Cleaner
2008-09-29 23:58 . 2008-10-27 19:07 <DIR> d-------- C:\Program Files\A1Click Ultra PC Cleaner
2008-09-29 12:52 . 2008-09-29 12:52 <DIR> d--hs---- C:\WINDOWS\ftpcache
2008-09-29 12:52 . 2008-10-14 20:20 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\f2fIntermediate
2008-09-28 17:35 . 2008-09-28 17:35 <DIR> d-------- C:\Program Files\Sun
2008-09-28 17:34 . 2008-06-10 01:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-28 17:32 . 2008-09-30 00:48 <DIR> d-------- C:\Program Files\Java
2008-09-28 17:22 . 2008-10-27 22:47 <DIR> d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-28 16:49 . 2008-09-28 16:49 <DIR> d-------- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Phone Browser
2008-09-28 14:40 . 2008-10-15 09:03 <DIR> d---s---- C:\Documents and Settings\adis.HOME-F0B0CEB3AD\UserData
2008-09-28 00:00 . 2008-09-27 13:19 90,749,456 --a------ C:\178.13_geforce_winxp_32bit_english_whql.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-28 20:39 56,608 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-28 20:39 5,951,264 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-28 20:32 90,620 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-28 20:32 8,252 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-28 20:15 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-10-15 08:00 --------- d-----w C:\Documents and Settings\adis\Application Data\Azureus
2008-10-07 21:05 --------- d-----w C:\Program Files\MessengerDiscovery
2008-09-28 20:45 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-28 15:49 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\PC Suite
2008-09-27 22:59 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Sony Corporation
2008-09-27 20:46 --------- d-----w C:\Program Files\Google
2008-09-27 20:06 --------- d-----w C:\Program Files\Windows Live
2008-09-27 19:08 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-09-27 19:08 85,860 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2008-09-27 19:08 --------- d-----w C:\Program Files\Kaspersky Lab
2008-09-27 19:03 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab Setup Files
2008-09-27 18:59 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
2008-09-27 18:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-27 18:57 --------- d-----w C:\Program Files\Creative
2008-09-27 18:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\FLEXnet
2008-09-27 18:16 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Suite
2008-09-27 18:16 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nokia
2008-09-27 18:15 --------- d-----w C:\Program Files\DIFX
2008-09-27 18:14 --------- d-----w C:\Program Files\PC Connectivity Solution
2008-09-27 18:14 --------- d-----w C:\Program Files\Nokia
2008-09-27 18:14 --------- d-----w C:\Program Files\Common Files\PCSuite
2008-09-27 18:14 --------- d-----w C:\Program Files\Common Files\Nokia
2008-09-27 18:13 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Installations
2008-09-27 18:11 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\CyberLink
2008-09-27 18:10 --------- d-----w C:\Program Files\CyberLink
2008-09-27 18:10 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-09-27 18:03 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\Nero
2008-09-27 17:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Nero
2008-09-27 17:51 --------- d-----w C:\Program Files\Sony Corporation
2008-09-27 17:51 --------- d-----w C:\Program Files\Sony
2008-09-27 17:51 --------- d-----w C:\Program Files\Common Files\Sony Shared
2008-09-27 17:49 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Sony Corporation
2008-09-27 17:48 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-09-27 17:45 --------- d-----w C:\Program Files\PixelView
2008-09-27 17:40 --------- d-----w C:\Program Files\SiSLan
2008-09-27 17:36 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\nView_Profiles
2008-09-27 16:12 --------- d-----w C:\Program Files\TuneUp Utilities 2007
2008-09-27 16:12 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-09-27 16:12 --------- d-----w C:\Documents and Settings\adis.HOME-F0B0CEB3AD\Application Data\TuneUp Software
2008-09-27 16:04 155,995 ----a-w C:\WINDOWS\java\Packages\9BRBTNJF.ZIP
2008-09-27 16:02 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\WinZip
2008-09-27 15:04 --------- d-----w C:\Documents and Settings\adis\Application Data\Nero
2008-09-27 15:03 --------- d-----w C:\Program Files\Common Files\Nero
2008-09-27 15:01 --------- d-----w C:\Program Files\Nero
2008-09-27 14:54 --------- d-----w C:\Program Files\AskTBar
2008-09-27 14:52 --------- d-----w C:\Program Files\Circle Developement
2008-09-27 14:48 --------- d-----w C:\Program Files\Microsoft.NET
2008-09-27 14:48 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-09-27 14:48 --------- d-----w C:\Program Files\Common Files\L&H
2008-09-27 14:47 --------- d-----w C:\Program Files\Microsoft Works
2008-09-27 14:44 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2008-09-27 14:44 --------- d-----w C:\Program Files\Common Files\Adobe
2008-09-27 14:35 --------- d-----w C:\Program Files\Azureus
2008-09-27 14:34 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-09-27 14:32 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-27 14:21 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-09-27 14:17 --------- d-----w C:\Program Files\Common Files\Java
2008-09-27 14:10 --------- d-----w C:\Program Files\Analog Devices
2008-09-27 14:02 --------- d-----w C:\Program Files\microsoft frontpage
2008-09-27 12:46 331,805,736 ----a-w C:\windowsxp-kb936929-sp3-x86-enu_c81472f7eeea2eca421e116cd4c03e2300ebfde4.exe
2008-09-22 06:39 98,533 --sh--r C:\rdsfk.com
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL" [2008-09-27 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-09-27 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2002-12-31 15360]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-10 7311360]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-12-10 86016]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 98304]
"TV Card Remote Control Device Monitor"="C:\WINDOWS\713xRMT.exe" [2007-09-13 466944]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-07 30208]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-27 29744]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 487424]
"nwiz"="nwiz.exe" [2005-12-10 C:\WINDOWS\system32\nwiz.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-09-27 295606]
Adobe Acrobat Synchronizer.lnk - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-22 734872]
PixelView Schedule Agent.lnk - C:\Program Files\PixelView\ADTVScheduleAgent.exe [2008-09-27 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codec"= l3codecp.acm

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R2 UxTuneUp;TuneUp Design Expansion;C:\WINDOWS\System32\svchost.exe [2002-12-31 14336]
R3 3xHybrid;SAA713x TV Card Service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2007-10-24 907520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 AVPsys;AVPsys;C:\WINDOWS\system32\drivers\tdi.sys [2002-12-31 18560]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-27 29744]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2008-09-27 C:\WINDOWS\Tasks\1-Click Maintenance.job
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe [2006-12-19 15:53]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-28 21:39:31
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-28 21:41:24
ComboFix-quarantined-files.txt 2008-10-28 20:41:21
ComboFix2.txt 2008-10-27 22:25:32

Pre-Run: 20,819,046,400 bytes free
Post-Run: 20,803,514,368 bytes free

222

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

C:\Program Files\Circle Developement <--- ovo pokušaj da deinstaliraš; ako nije moguće, obriši kompletan folder.


C:\Program Files\MessengerDiscovery <--- ovo je, kao što ti već pomenuh, adware.



Jedan od trojanaca koji su ovde bili prisutni, je instaliran uz ovo:

C:\Program Files\Messenger Plus! Live



Imaj to na umu kada idući put budeš nekom preporučivao korišćenje tih programa.





Anyway... Ovo je sada čisto.
Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore



Toliko od mene...

offline
  • 100%Milanista
  • Information Technology
  • Pridružio: 23 Avg 2008
  • Poruke: 2630
  • Gde živiš: Milan, Italy

Pa ono na mom kompu mogu da se izborim sa MSN plus i messenger discoveru live.... tako da mi ne smetaju... al imacu to na umu.. Smile


Hvala puno za pomoc Smile

Ko je trenutno na forumu
 

Ukupno su 706 korisnika na forumu :: 28 registrovanih, 5 sakrivenih i 673 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., ALBION101, Apok, djordje92sm, dragoljub11987, dragon986, ILGromovnik, Insan, ivan979, kybonacci, Lieutenant, MiG-29M2, MiGac, Mixelotti, mnn2, mushroom, nemkea71, nenad81, pavle_pzs, pein, proleter373, ruso, sovanova95, Steeeefan, stegonosa, stug, vathra, vlvl