Problem sa 2 virusa. pomoc

2

Problem sa 2 virusa. pomoc

offline
  • Pridružio: 18 Jul 2008
  • Poruke: 115
  • Gde živiš: Majur

Ipak hvala sad ne javlja za taj virus, ako jos bude smaralo radicu sys Smile
Hvala.



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

we^control ::Ipak hvala sad ne javlja za taj virus, ako jos bude smaralo radicu sys Smile
Hvala.


Ali nismo gotovi Smile

Kako god ti hoces.



offline
  • Pridružio: 18 Jul 2008
  • Poruke: 115
  • Gde živiš: Majur

uradio sam opet ako nije nista drugacije nema veze.


ComboFix 09-02-27.02 - Aleksandar 2009-02-28 23:12:30.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.735.352 [GMT 1:00]
Running from: c:\documents and settings\Aleksandar\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aleksandar\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 )))))))))))))))))))))))))))))))
.

2009-02-28 19:33 . 2009-02-28 19:37 <DIR> d-------- C:\USBNoRisk
2009-02-23 19:00 . 2009-02-23 19:01 <DIR> d-------- c:\program files\Hewlett-Packard
2009-02-15 22:09 . 2001-11-01 16:24 731,355,136 --a------ C:\YoungDebutants.vob
2009-02-07 20:36 . 2009-02-07 20:36 <DIR> d-------- c:\windows\Sun
2009-02-07 00:10 . 2009-02-07 00:10 <DIR> d-------- c:\documents and settings\Aleksandar\Application Data\Nokia
2009-02-05 21:25 . 2009-02-05 21:25 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-02-05 20:34 . 2009-02-28 23:13 <DIR> d-------- c:\program files\Achilles-Script 5.0 Black
2009-02-03 00:56 . 2009-02-03 00:56 <DIR> d-------- c:\program files\Java
2009-02-03 00:56 . 2009-02-03 00:56 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-03 00:56 . 2009-02-03 00:56 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-01 19:27 . 2009-02-01 19:27 1,077,336 -r--s---- c:\windows\system32\MSCOMCTL.OCX
2009-02-01 19:27 . 2009-02-01 19:27 140,488 -r------- c:\windows\system32\COMDLG32.OCX
2009-01-31 21:51 . 2009-01-31 21:51 <DIR> d-------- c:\program files\AVG
2009-01-29 20:17 . 2009-01-29 20:17 <DIR> d-------- c:\program files\Uniblue
2009-01-29 20:17 . 2009-01-29 20:17 <DIR> d-------- c:\documents and settings\Aleksandar\Application Data\Uniblue
2009-01-29 20:03 . 2009-01-29 20:04 <DIR> d-------- c:\program files\Common Files\PC Tools
2009-01-29 20:03 . 2008-07-28 12:29 160,792 --a------ c:\windows\system32\drivers\pctfw2.sys
2009-01-29 20:03 . 2008-08-25 12:36 81,288 --a------ c:\windows\system32\drivers\iksyssec.sys
2009-01-29 20:03 . 2008-08-25 12:36 66,952 --a------ c:\windows\system32\drivers\iksysflt.sys
2009-01-29 20:03 . 2008-08-25 12:36 40,840 --a------ c:\windows\system32\drivers\ikfilesec.sys
2009-01-29 20:03 . 2008-06-02 16:19 29,576 --a------ c:\windows\system32\drivers\kcom.sys
2009-01-29 18:09 . 2004-05-26 15:08 7,296 -r------- c:\windows\system32\drivers\EIO.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 21:49 --------- d-----w c:\program files\Professional §©®ÎÞt v.4 Black
2009-02-19 20:12 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-19 17:20 --------- d-----w c:\program files\Spyware Doctor
2009-02-15 12:42 --------- d-----w c:\program files\FlashGet
2009-02-05 20:05 --------- d-----w c:\program files\Counter-Strike
2009-02-01 18:05 2,079 ----a-w c:\windows\system32\M1achardks.dll
2009-01-24 22:22 4,100 ----a-w c:\windows\system32\hdvirffo.dll
2009-01-24 18:21 20,747 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-01-24 18:20 --------- d-----w c:\program files\Gigabyte
2009-01-22 21:21 --------- d-----w c:\program files\D-Tools
2009-01-21 17:18 --------- d-----w c:\documents and settings\Aleksandar\Application Data\Ahead
2009-01-21 17:11 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-21 17:11 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2009-01-21 17:09 --------- d-----w c:\program files\Common Files\Ahead
2009-01-21 17:07 --------- d-----w c:\program files\Nero
2009-01-21 17:07 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-01-20 21:35 --------- d-----w c:\program files\Valve
2009-01-20 17:21 --------- d-----w c:\program files\PC Tools Internet Security
2009-01-20 17:21 --------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-01-19 23:58 --------- d-----w c:\program files\EASEUS
2009-01-19 17:16 --------- d-----w c:\program files\Windows Live
2009-01-18 20:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PCToolsSpamMonitorPlus
2009-01-18 20:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PCToolsFirewallPlus
2009-01-17 17:26 729,088 ----a-w c:\windows\iun6002.exe
2009-01-15 23:14 --------- d-----w c:\program files\MSN Messenger
2009-01-15 23:14 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-14 15:37 --------- d-----w c:\program files\Common Files\Windows Live
2009-01-14 15:30 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PC Tools
2009-01-14 03:37 --------- d-----w c:\program files\Your Uninstaller 2008
2009-01-14 03:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\URSoft
2009-01-12 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-01-12 03:27 --------- d-----w c:\documents and settings\Aleksandar\Application Data\TeamViewer
2009-01-12 01:56 --------- d-----w c:\program files\Common Files\NSV
2009-01-10 21:37 --------- d-----w c:\program files\ATI Technologies
2009-01-10 14:22 --------- d-----w c:\program files\Lavalys
2008-12-28 13:37 --------- d-----w c:\documents and settings\Aleksandar\Application Data\ESET
2008-12-28 13:36 --------- d-----w c:\program files\ESET
2008-12-28 13:36 --------- d-----w c:\documents and settings\All Users\Application Data\ESET
2008-12-28 13:36 --------- d-----w c:\documents and settings\Aleksandar\Application Data\Winamp
2008-12-28 13:32 --------- d-----w c:\program files\Winamp
2008-04-14 04:42 263,168 --sh--r c:\windows\system32\SetPoints.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"Microsoft Update"="SetPoints.exe" [2008-04-14 c:\windows\system32\SetPoints.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft Update"="SetPoints.exe" [2008-04-14 c:\windows\system32\SetPoints.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 c:\windows\system32\narrator.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
GN-WP01GS Utility.lnk - c:\program files\Gigabyte\Gigabyte WP01GS Wireless PCI Adapter SoftAP\Installer\WINXP\RaUI.exe [2009-01-24 720896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-09-25 10:29 2007088 c:\program files\FlashGet\flashget.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2002-11-19 14:01 46592 c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTPreset]
--a------ 2004-02-24 20:17 45056 c:\windows\system32\VTPreset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Professional §©®ÎÞt v.4 Black\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\FlashGet\\FlashGet.exe"=

R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-01-29 160792]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-29 356920]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [2002-01-01 5824]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
TCP: {4BE5F4F9-5C64-42B2-9692-AAE6652B8F71} = 10.5.0.100,10.5.0.200
FF - ProfilePath - c:\documents and settings\Aleksandar\Application Data\Mozilla\Firefox\Profiles\bxxmtu1l.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-28 23:14:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(652)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
Completion time: 2009-02-28 23:15:52
ComboFix-quarantined-files.txt 2009-02-28 22:15:49
ComboFix2.txt 2009-02-28 20:27:01
ComboFix3.txt 2009-02-28 17:44:11

Pre-Run: 1,043,025,920 bytes free
Post-Run: 1,031,573,504 bytes free

161 --- E O F --- 2009-01-19 02:04:50

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Vidim da imas i Spyware doctora, javlja li on nesto prilikom pokusaja prevlacenja CFScripte?

offline
  • Pridružio: 18 Jul 2008
  • Poruke: 115
  • Gde živiš: Majur

on je iskljucen ali combofix javi kao da je nasao spywaredoc nesto i ima samo da se klikne ok i onda nastavi dalje.....

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Skini odavde skriptu na Desktop pa je prevuci:

[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 18 Jul 2008
  • Poruke: 115
  • Gde živiš: Majur

ComboFix 09-02-27.02 - Aleksandar 2009-03-01 17:08:53.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.735.415 [GMT 1:00]
Running from: c:\documents and settings\Aleksandar\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Aleksandar\Desktop\CFScript.txt
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated)
FW: ESET Personal firewall *enabled*
* Created a new restore point

FILE ::
c:\windows\system32\SetPoints.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\SetPoints.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-01 to 2009-03-01 )))))))))))))))))))))))))))))))
.

2009-02-28 19:33 . 2009-02-28 19:37 <DIR> d-------- C:\USBNoRisk
2009-02-23 19:00 . 2009-02-23 19:01 <DIR> d-------- c:\program files\Hewlett-Packard
2009-02-15 22:09 . 2001-11-01 16:24 731,355,136 --a------ C:\YoungDebutants.vob
2009-02-07 20:36 . 2009-02-07 20:36 <DIR> d-------- c:\windows\Sun
2009-02-07 00:10 . 2009-02-07 00:10 <DIR> d-------- c:\documents and settings\Aleksandar\Application Data\Nokia
2009-02-05 21:25 . 2009-02-05 21:25 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
2009-02-05 20:34 . 2009-02-28 23:25 <DIR> d-------- c:\program files\Achilles-Script 5.0 Black
2009-02-03 00:56 . 2009-02-03 00:56 <DIR> d-------- c:\program files\Java
2009-02-03 00:56 . 2009-02-03 00:56 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-03 00:56 . 2009-02-03 00:56 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-01 19:27 . 2009-02-01 19:27 1,077,336 -r--s---- c:\windows\system32\MSCOMCTL.OCX
2009-02-01 19:27 . 2009-02-01 19:27 140,488 -r------- c:\windows\system32\COMDLG32.OCX

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-24 21:49 --------- d-----w c:\program files\Professional §©®ÎÞt v.4 Black
2009-02-19 20:12 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-19 17:20 --------- d-----w c:\program files\Spyware Doctor
2009-02-15 12:42 --------- d-----w c:\program files\FlashGet
2009-02-05 20:05 --------- d-----w c:\program files\Counter-Strike
2009-02-01 18:05 2,079 ----a-w c:\windows\system32\M1achardks.dll
2009-01-31 20:51 --------- d-----w c:\program files\AVG
2009-01-29 19:17 --------- d-----w c:\program files\Uniblue
2009-01-29 19:17 --------- d-----w c:\documents and settings\Aleksandar\Application Data\Uniblue
2009-01-29 19:04 --------- d-----w c:\program files\Common Files\PC Tools
2009-01-24 22:22 4,100 ----a-w c:\windows\system32\hdvirffo.dll
2009-01-24 18:21 20,747 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-01-24 18:20 --------- d-----w c:\program files\Gigabyte
2009-01-22 21:21 --------- d-----w c:\program files\D-Tools
2009-01-21 17:18 --------- d-----w c:\documents and settings\Aleksandar\Application Data\Ahead
2009-01-21 17:11 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-21 17:11 --------- d-----w c:\documents and settings\All Users\Application Data\Ahead
2009-01-21 17:09 --------- d-----w c:\program files\Common Files\Ahead
2009-01-21 17:07 --------- d-----w c:\program files\Nero
2009-01-21 17:07 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2009-01-20 21:35 --------- d-----w c:\program files\Valve
2009-01-20 17:21 --------- d-----w c:\program files\PC Tools Internet Security
2009-01-20 17:21 --------- d-----w c:\documents and settings\All Users\Application Data\PC Tools
2009-01-19 23:58 --------- d-----w c:\program files\EASEUS
2009-01-19 17:16 --------- d-----w c:\program files\Windows Live
2009-01-18 20:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PCToolsSpamMonitorPlus
2009-01-18 20:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PCToolsFirewallPlus
2009-01-17 17:26 729,088 ----a-w c:\windows\iun6002.exe
2009-01-15 23:14 --------- d-----w c:\program files\MSN Messenger
2009-01-15 23:14 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-14 15:37 --------- d-----w c:\program files\Common Files\Windows Live
2009-01-14 15:30 --------- d-----w c:\documents and settings\Aleksandar\Application Data\PC Tools
2009-01-14 03:37 --------- d-----w c:\program files\Your Uninstaller 2008
2009-01-14 03:32 --------- d-----w c:\documents and settings\Aleksandar\Application Data\URSoft
2009-01-12 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-01-12 03:27 --------- d-----w c:\documents and settings\Aleksandar\Application Data\TeamViewer
2009-01-12 01:56 --------- d-----w c:\program files\Common Files\NSV
2009-01-10 21:37 --------- d-----w c:\program files\ATI Technologies
2009-01-10 14:22 --------- d-----w c:\program files\Lavalys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2007-12-21 1443072]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 c:\windows\system32\narrator.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
GN-WP01GS Utility.lnk - c:\program files\Gigabyte\Gigabyte WP01GS Wireless PCI Adapter SoftAP\Installer\WINXP\RaUI.exe [2009-01-24 720896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.l3fhg"= mp3fhg.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
--a------ 2004-08-22 17:05 81920 c:\program files\D-Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
--a------ 2007-09-25 10:29 2007088 c:\program files\FlashGet\flashget.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 05:42 1695232 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:54 5674352 c:\program files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2002-11-19 14:01 46592 c:\windows\SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTPreset]
--a------ 2004-02-24 20:17 45056 c:\windows\system32\VTPreset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Valve\\hl.exe"=
"c:\\Program Files\\Professional §©®ÎÞt v.4 Black\\mirc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\FlashGet\\FlashGet.exe"=

R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2009-01-29 160792]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2007-12-21 468224]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-29 356920]
S3 Asushwio;Asushwio;c:\windows\system32\drivers\ASUSHWIO.SYS [2002-01-01 5824]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
LSP: c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
TCP: {4BE5F4F9-5C64-42B2-9692-AAE6652B8F71} = 10.5.0.100,10.5.0.200
FF - ProfilePath - c:\documents and settings\Aleksandar\Application Data\Mozilla\Firefox\Profiles\bxxmtu1l.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-03-01 17:10:42
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(652)
c:\program files\Common Files\PC Tools\LSP\PCTLsp.dll
.
Completion time: 2009-03-01 17:12:17
ComboFix-quarantined-files.txt 2009-03-01 16:12:12
ComboFix2.txt 2009-02-28 22:15:54
ComboFix3.txt 2009-02-28 20:27:01
ComboFix4.txt 2009-02-28 17:44:11

Pre-Run: 1,201,815,552 bytes free
Post-Run: 1,190,187,008 bytes free

153 --- E O F --- 2009-01-19 02:04:50

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Sad je dobro, pre nesto ti nisi dobro sacuvao.

Kako sad radi komp?

offline
  • Pridružio: 18 Jul 2008
  • Poruke: 115
  • Gde živiš: Majur

Veoma dobro! problem je u tome sto mi je moj hdd crkao i sad sam nesto podataka najvaznijih sacuvao na jednom od 40 i to pocelo da zeza a ne mogu da radim sys podaci mi trebaju.
a ako sad kod nekog kod koga sam stavljao moj fles je l' preslo ovo i ako ja ubacim kod njega sta mislis hoce li se meni opet vratiti?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8657
  • Gde živiš: Novi Beograd

Moguce je da ce ti se opet vratiti infekcija na tvoj flash.

Uradi ovo jos:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 2532 korisnika na forumu :: 66 registrovanih, 8 sakrivenih i 2458 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 100jan, 357magnum, alternator, Asteker, brandža84, Bubimir, celik, Cirkon, crazydkure, djboj, Djokkinen, draganl, dragoljub11987, DrNeoCortex, Duce, Electron, FileFinder, Fliper, gajasvi, Giskard, Haris, HrcAk47, ibssa, igorkozar83, IQ116, jalos, Jonbonjovi, Kadzo, Kolimator, M74AB3, MagicniHerpes, marsi, MB120mm, Metanoja, mgolub, milanpb, Milometer, MiroslavD, Moldovan, nenorodjo, nnnnnnnnnn, nsharambasa, Pauljxxx, pobeda, precan, predragc, procesor, proka89, repac, SamoGledam, Sevatar, Smiljkovich, Spinosa, Srki98, Tastatura ratnik, vathra, vrgudinac, vukan0799, Webb, Yekaterinburg, Zanimljivo, ZetaMan, Zgembo78, zmajbre, Zoca, Zorge