Problem sa Virusom

2

Problem sa Virusom

offline
  • Pridružio: 15 Nov 2008
  • Poruke: 273
  • Gde živiš: Podgorica

Napisano: 01 Nov 2009 0:23

ComboFix 09-10-30.01 - SINIŠA 11/01/2009 0:15.7.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.199 [GMT 1:00]
Running from: c:\documents and settings\SINIŠA\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\SINIŠA\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))))
.

2014-11-20 14:37 . 2014-11-20 14:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-10-14 17:45 . 2009-10-14 17:45 -------- d-----w- C:\PRIMATRON
2009-10-14 17:16 . 2009-10-14 17:16 -------- d-----w- c:\program files\Common Files\Corel
2009-10-14 17:15 . 2009-10-14 17:15 -------- d-----w- c:\program files\Corel
2009-10-13 19:59 . 2009-10-14 17:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
2009-10-04 09:00 . 2009-10-04 09:15 -------- dc-h--w- c:\documents and settings\All Users\Application Data\~0
2009-10-04 08:50 . 2007-02-13 04:56 38480 ------w- c:\windows\system32\IJRMF.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 20:09 . 2008-11-21 21:59 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-31 17:17 . 2008-11-10 12:10 -------- d-----w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2009-10-28 21:04 . 2007-01-13 18:17 -------- d-----w- c:\program files\mIRC
2009-10-26 19:22 . 2009-10-13 20:02 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-10-14 17:38 . 2009-10-13 20:02 88 --sh--r- c:\documents and settings\All Users\Application Data\E5041DF6BC.sys
2009-10-13 19:43 . 2007-02-15 19:58 3764 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-13 16:12 . 2009-09-06 14:42 -------- d-----w- c:\program files\IGEMS_R8
2009-10-07 21:23 . 2009-04-01 20:52 943920 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-10-04 09:37 . 2008-05-28 21:42 -------- d-----w- c:\program files\Canon
2009-10-04 08:19 . 2006-12-21 14:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-27 07:35 . 2009-09-27 07:35 -------- d-----w- c:\documents and settings\All Users\Application Data\VMLakiraona
2009-09-22 18:34 . 2009-09-22 18:34 -------- d-----w- c:\documents and settings\All Users\Application Data\IsolatedStorage
2009-09-13 11:43 . 2009-09-13 11:12 -------- d-----w- c:\program files\BumpTop
2009-09-05 21:28 . 2009-09-05 21:28 -------- d-----w- c:\program files\Switch Off
2009-08-14 14:20 . 2009-08-13 20:25 738304 ----a-w- c:\windows\GPInstall.exe
2009-08-12 10:50 . 2009-08-18 17:47 21192 ----a-w- c:\windows\system32\dopdfmn6.dll
2009-08-12 10:50 . 2009-08-18 17:47 18632 ----a-w- c:\windows\system32\dopdfmi6.dll
2006-11-22 18:07 . 2007-02-15 19:58 88 --sh--r- c:\windows\system32\590D0E0B75.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-07-21 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-02-04 23975720]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-29 39408]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\documents and settings\SINIŠA\Application Data\iolo\

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Alcohol Soft\\Alcohol 120\\AxCmd.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"c:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"c:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [4/20/2008 10:27 PM 13696]
S3 AMDMSRIO;AMDMSRIO;\??\c:\docume~1\SINIA~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys --> c:\docume~1\SINIA~1\LOCALS~1\Temp\{55638DD9-D5A9-11D3-B74B-204C4F4F5020}\AMDMSRIO.sys [?]
S3 SmartKeyDriver;SmartKeyDriver;c:\program files\MSI\SmartKey\SMemory.sys [12/30/2006 6:45 PM 8676]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - FWTCRPOG
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - fwtcrpog
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder

2009-10-31 c:\windows\Tasks\User_Feed_Synchronization-{32124A26-D946-4D64-BDA6-4278B39C2005}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-11-01 00:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1177238915-1004336348-839522115-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\S-1-5-21-1177238915-1004336348-839522115-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1FEF7500-86C3-9C7A-A2F8-D1C7658849CA}*]
"jagjdjmpeenllkaojpod"=hex:62,61,69,67,00,00
"iagmhhpcfgdmpnckcc"=hex:6b,61,68,64,6d,69,63,6a,6e,6c,61,69,70,6f,6f,64,6e,6a,
6f,66,63,6c,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(736)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3832)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-31 0:22
ComboFix-quarantined-files.txt 2009-10-31 23:21
ComboFix2.txt 2009-10-31 22:52

Pre-Run: 21,099,786,240 bytes free
Post-Run: 21,089,673,216 bytes free

- - End Of File - - 85C7FECEF2D748230C1933253DEA1073

Dopuna: 01 Nov 2009 0:24





Dopuna: 01 Nov 2009 0:25

treba li sta jos. ? Sta dalje?

Dopuna: 01 Nov 2009 0:50

instalirao sam AVG
Puno HVALAAA...



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

OK. Još samo ovo:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.



offline
  • Pridružio: 15 Nov 2008
  • Poruke: 273
  • Gde živiš: Podgorica

Reci mi samo jos ovo kako da ne izlazi ovo u donjem desnom uglu i sta treba da je upaljeno a sta ne?


offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Na drugoj slici, sa leve strane, postoji opcija Change the way Security Center alerts me - tu možeš isključiti obaveštenja.



Takođe, poželjno je da aktiviraš Windows-ov firewall (Control Panel > Windows Firewall: On (recommended)).

Ko je trenutno na forumu
 

Ukupno su 1407 korisnika na forumu :: 297 registrovanih, 18 sakrivenih i 1092 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -Max-, 015, 33 bren, _stipa_, Ageofloneliness, AK - 230, akaherz994, aleksandar1888, aleksandarbl, ALEKSICMILE, alternator, annon, aramis s, Arsenije, AS, asdfjklc, Aska, ast13, Asteker, Avalon015, babaroga, Baltimor, BaneM75, Batko.VD.65, bavar357, bax0904, Baždaranac, bbogdan, beki76, berste23, Betta, Bobrock1, Bodin86, Bojcca, bojcistv, Boris.A, boromir, BOXRR, branko7, BrcakRS, Bubimir, BUDDAR70, BWG, C-Gun, CCCP, cebam, celt, ceman, Chainsaw, Cicumile, cifra, CikaKURE, Clouseau, Coficab, Comyymoc, Cp6uH, crnogorac, cvrle312, cyprus, darcaud, darios, darkkran, Darth Malak, dd201176, DeerHunter, dejan1972, DejanSt, dejoglina, dekan.m, Del70, DENIRO, Despot Đurađ, Dinarid, Djole3621, DJUNTA, Djuro2000, Dorcolac, dragan_mig31, DragoslavS, Drugard72, dukikan, dule10savic, dulleo, Dungorth, Dzoni2412, Dzumanga, Džekson, El-Komadante, Ercomero, feanor, flash12, Flotikius, Fulcrum, GazdaDjoka, geo.dule, Geran136, GH69, Gheljda, glados, gobrad, goran.vvv, grenadir, Grochow, Hans Gajger, Homislav, HrcAk47, hrkaz, ikan, Insan, j-22orao, Jakonjveliki, Jan, Jaxupa, Jaz, Jecmendo, Jeremiah, Joco Skljoco, jopicus, Jozo74, K a s p e r, Kajzer Soze, keyz, kikisp, knutveliki, Kobrim, kojotuzamku, kolle.the.kid, kondenzator, kovacicbozo, krasta, Kruger, Kure126-7, kybonacci, lacko, lafa008, lakson001, Lelemood, Leonov, Lester Freamon, Levi, Litostroton, Lotus, luja, luka35, Magistar78, Maja_581, Makarid, maksi007, malimedo01, Mane88, Marko1238, MaschinenPistole, mat, MB120mm, medaTT, mercedesamg, Metanoja, mgolub, Miki281, Milan A. Nikolic, milan124, Miletić Zoran, Mille Qravela, Milos1987, miodrag, miroslav milanović, misaru, mix1, Miškić, Mićko, mnn2, Moldovan, moldway, Mozgonja, mrvica78, Murko, mux, Ne doznajem se u oružje, neko iz mase, Nemanja Opalić, Nemanja.M, NemanjaCG, Neutral-M, nikoladim, nixos, nnovakis, novator, obsidian, orfanel, OtacMakarije, ozzy, Paklenica, Panter, pein, Pekman, Permaldar, Petar888, Pilence, pisac12, PlayerOne, Poslovni broj, Povratak1912, precan, Primus17, Prle90, Qvazimodo, Radio operater, radoznao, raster12, Remarqe, repac, Resnica, Ripanjac, Rothmans, royst33, sabros, Samo gledam, sekretar, Semberija, Sharpshooter, ShtagodShtagod, sickmouse, sisi, Skakac7, Smiljkovich, snikolic, Solunac na steroidima, Sone0883, sovanova95, spektorsky, Srle993, ssekir75, stalja, StalniPromatrač, StankoVrankovic, starlights, stegonosa, steksi, Su 57, superwhy, suponik, suton, Szigetwar, t84dar, Tajpan, Tandrčak, Tankosić, Tas011, TBoy, tmanda323, trinitrotoluen, trpche, trutcina, tvlada, ujke, umpah-pah, uruk, US_Rank_0, vathra, Vatreni Zmaj, vazduh, Velibor Radoja, Veljko™, vensla, vidra boy, vidra1, Vl veliki, Vlada78, vladetije, Vladko, vladnik321, vlado3399, vladom6, vlahale, vlajkox, voja64, Vrač, Vujkeu, vuk77, vukovi, vuksa72, Wepp, x011, x9, Yekaterinburg, Zander, zdrebac, Zeljo980, zemljanin, zil10, Zorge, Zrcalo, zule2, Zvone, Zvrk, zzeljko, ZZZ