Racunar se sam restartuje

2

Racunar se sam restartuje

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

ComboFix 09-01-16.02 - bosko 2009-01-19 21:39:25.3 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1033.18.1022.377 [GMT 1:00]
Running from: c:\users\bosko\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\users\All Users\CyberLink
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\programdata\CyberLink
2009-01-18 23:02 . 2009-01-18 23:02 <DIR> d-------- c:\users\bosko\AppData\Roaming\CyberLink
2009-01-18 22:57 . 2009-01-19 20:13 <DIR> d-------- c:\program files\CyberLink
2009-01-18 22:57 . 2003-04-23 18:29 221,215 --------- c:\windows\System32\Divxdec.ax
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI Technologies
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI
2009-01-18 14:10 . 2009-01-18 14:10 <DIR> d-------- C:\ATI
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\users\bosko\AppData\Roaming\IObit
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\program files\CCleaner
2009-01-18 03:20 . 2009-01-19 19:52 <DIR> d-------- c:\users\bosko\AppData\Roaming\Nero
2009-01-18 03:05 . 2009-01-18 03:05 4,767 --a------ c:\windows\Irremote.ini
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\users\All Users\Nero
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\programdata\Nero
2009-01-18 02:50 . 2009-01-18 03:19 <DIR> d-------- c:\program files\Common Files\Nero
2009-01-17 23:38 . 2009-01-17 23:38 <DIR> d-------- c:\program files\AskTBar
2009-01-17 22:26 . 2009-01-17 22:26 <DIR> d-------- c:\users\bosko\AppData\Roaming\skypePM
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\programdata\ezsidmv.dat
2009-01-17 22:25 . 2009-01-17 22:25 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-17 12:34 . 2008-11-26 18:17 51,792 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2009-01-14 22:07 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-05 00:10 . 2009-01-05 00:10 <DIR> d-------- c:\program files\RegCure
2009-01-05 00:10 . 2009-01-05 00:13 <DIR> d-------- c:\program files\Disk Cleaner
2008-12-27 23:52 . 2007-04-09 13:23 28,040 --a------ c:\windows\System32\mdimon.dll
2008-12-27 23:52 . 2008-12-27 23:52 376 --a------ c:\windows\ODBC.INI
2008-12-27 23:50 . 2008-12-27 23:50 <DIR> d-------- c:\program files\Common Files\L&H
2008-12-27 23:49 . 2008-12-27 23:49 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\Stationery
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\MEDIA
2008-12-27 23:48 . 2008-12-27 23:49 <DIR> d-------- C:\CLIPART
2008-12-27 23:47 . 2008-12-27 23:50 <DIR> d-------- C:\Templates
2008-12-27 23:47 . 2009-01-14 22:40 <DIR> d-------- C:\OFFICE11
2008-12-25 22:35 . 2008-12-25 23:24 <DIR> d-------- c:\program files\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\users\All Users\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\programdata\Quark
2008-12-23 03:47 . 2008-12-23 03:47 138,240 --a------ c:\windows\System32\drivers\Rtlh86.sys
2008-12-23 03:47 . 2008-12-23 03:47 10,240 --a------ c:\windows\System32\RtNicProp32.dll
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\users\All Users\PC Drivers HeadQuarters
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\programdata\PC Drivers HeadQuarters
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\program files\PC Drivers HeadQuarters

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 19:14 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-19 19:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-19 14:31 --------- d-----w c:\programdata\Microsoft Help
2009-01-19 14:19 --------- d-----w c:\programdata\Google Updater
2009-01-18 03:15 --------- d-----w c:\users\bosko\AppData\Roaming\uTorrent
2009-01-18 03:15 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-01-18 03:15 --------- d-----w c:\program files\ICQ
2009-01-18 03:15 --------- d-----w c:\program files\AWR
2009-01-18 03:14 --------- d-----w c:\program files\YouTube Downloader
2009-01-18 02:30 --------- d-----w c:\program files\IObit
2009-01-18 02:05 --------- d-----w c:\program files\Nero
2009-01-17 23:56 --------- d-----w c:\program files\FlashGet
2009-01-17 22:06 --------- d-----w c:\program files\Common Files\Ahead
2009-01-17 21:32 --------- d-----w c:\users\bosko\AppData\Roaming\Skype
2009-01-17 21:25 --------- d-----w c:\programdata\Skype
2009-01-17 21:25 --------- d-----w c:\program files\Skype
2009-01-14 21:41 --------- d-----w c:\program files\Windows Mail
2008-12-29 16:43 --------- d-----w c:\program files\Microsoft Works
2008-12-22 14:16 --------- d-----w c:\program files\Opera
2008-12-17 23:40 --------- d-----w c:\program files\Restorer2000 Pro
2008-12-17 22:39 --------- d-----w c:\users\bosko\AppData\Roaming\Cimaware
2008-12-17 22:34 --------- d-----w c:\program files\Cimaware
2008-12-14 23:05 --------- d-----w c:\program files\Google
2008-12-11 14:01 --------- d-----w c:\users\bosko\AppData\Roaming\Xilisoft Corporation
2008-12-11 14:01 --------- d-----w c:\program files\Xilisoft
2008-12-03 21:14 --------- d-----w c:\program files\WMR11
2008-12-03 21:13 --------- d-----w c:\program files\Replay Media Catcher
2008-12-01 20:15 --------- d-----w c:\program files\MSXML 4.0
2008-11-27 13:39 --------- d-----w c:\program files\ABBYY FineReader 9.0
2008-11-27 13:35 --------- d-----w c:\program files\Common Files\ABBYY
2008-11-27 12:51 --------- d-----w c:\program files\HP
2008-11-27 01:22 --------- d-----w c:\program files\Hewlett-Packard
2008-11-24 17:15 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-24 17:15 --------- d-----w c:\program files\Adobe Media Player
2008-11-21 22:07 --------- d-----w c:\program files\Odigo
2008-11-21 15:55 --------- d-----w c:\users\bosko\AppData\Roaming\DMCache
2008-11-17 16:07 323,584 ----a-w c:\windows\System32\AUDIOGENIE2.DLL
2008-11-17 16:07 237,568 ----a-w c:\windows\System32\rmc_rtspdl.dll
2008-11-17 16:07 156,672 ----a-w c:\windows\System32\rmc_fixasf.exe
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-29 02:21 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll
2008-10-29 02:20 331,776 ----a-w c:\windows\System32\atipdlxx.dll
2008-10-29 02:20 262,144 ----a-w c:\windows\System32\Oemdspif.dll
2008-10-29 02:20 159,744 ----a-w c:\windows\System32\atitmmxx.dll
2008-10-29 02:19 43,520 ----a-w c:\windows\System32\ati2edxx.dll
2008-10-29 02:19 274,432 ----a-w c:\windows\System32\Ati2evxx.dll
2008-10-29 02:18 712,704 ----a-w c:\windows\System32\Ati2evxx.exe
2008-10-29 02:03 3,955,712 ----a-w c:\windows\System32\atiumdag.dll
2008-10-29 01:47 10,629,120 ----a-w c:\windows\System32\atioglxx.dll
2008-10-29 01:41 4,730,880 ----a-w c:\windows\System32\atiumdva.dll
2008-10-29 01:27 54,272 ----a-w c:\windows\System32\atiadlxx.dll
2008-10-29 01:27 50,688 ----a-w c:\windows\System32\amdpcom32.dll
2008-10-23 22:01 410,976 ----a-w c:\windows\System32\deploytk.dll
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\System32\atibrtmon.exe
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-01 21:04 174 --sha-w c:\program files\desktop.ini
2006-11-01 23:30 87,552 ----a-w c:\users\bosko\BootSect.exe
.

((((((((((((((((((((((((((((( snapshot@2009-01-16_22.55.58.71 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-19 20:26:56 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-01-18 14:00:25 51,200 ----a-w c:\windows\inf\infpub.dat
- 2008-12-19 20:26:55 86,016 ----a-w c:\windows\inf\infstor.dat
+ 2009-01-18 14:00:25 86,016 ----a-w c:\windows\inf\infstor.dat
- 2008-12-19 20:26:56 86,016 ----a-w c:\windows\inf\infstrng.dat
+ 2009-01-18 14:00:25 86,016 ----a-w c:\windows\inf\infstrng.dat
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\ARPPRODUCTICON.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut2_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut3_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut4_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut5_4DEA5338A7B840A3B51CDC742625BF49.exe
- 2008-12-17 23:04:57 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-19 14:30:14 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-16 21:53:53 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-19 18:44:56 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-19 18:44:56 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-01-16 21:53:54 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-19 18:44:14 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-11-26 17:21:30 1,236,208 ----a-w c:\windows\System32\aswBoot.exe
- 2008-04-28 19:09:10 172,033 ----a-w c:\windows\System32\atiicdxx.dat
+ 2008-08-14 17:42:21 176,214 ----a-w c:\windows\System32\atiicdxx.dat
+ 2008-11-26 17:15:10 97,480 ----a-w c:\windows\System32\AvastSS.scr
- 2009-01-16 21:04:01 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-16 21:04:01 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-19 18:46:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-16 21:04:01 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-26 17:17:25 20,560 ----a-w c:\windows\System32\drivers\aswFsBlk.sys
+ 2008-11-26 17:16:29 23,152 ----a-w c:\windows\System32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 ----a-w c:\windows\System32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 ----a-w c:\windows\System32\drivers\aswTdi.sys
- 2008-06-03 00:34:04 49,152 ----a-w c:\windows\System32\drivers\ati2erec.dll
+ 2008-10-29 01:10:39 53,248 ----a-w c:\windows\System32\drivers\ati2erec.dll
- 2008-06-03 04:22:56 3,695,104 ----a-w c:\windows\System32\drivers\atikmdag.sys
+ 2008-10-29 03:11:48 4,017,152 ----a-w c:\windows\System32\drivers\atikmdag.sys
+ 2008-10-29 01:27:54 50,688 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\amdpcom32.dll
+ 2008-10-29 02:19:54 43,520 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ati2edxx.dll
+ 2008-10-29 01:10:39 53,248 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ati2erec.dll
+ 2008-10-29 02:19:41 274,432 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Ati2evxx.dll
+ 2008-10-29 02:18:23 712,704 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Ati2evxx.exe
+ 2008-10-29 01:27:30 54,272 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiadlxx.dll
+ 2008-10-21 17:51:43 118,784 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atibrtmon.exe
+ 2008-10-29 02:21:55 425,984 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIDEMGX.dll
+ 2008-10-29 02:09:23 2,243,584 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atidxx32.dll
+ 2008-08-14 17:42:21 176,214 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiicdxx.dat
+ 2008-10-29 03:11:48 4,017,152 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atikmdag.sys
+ 2008-10-21 16:40:00 45,056 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIODCLI.exe
+ 2008-10-21 16:40:00 81,920 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIODE.exe
+ 2008-10-29 01:47:29 10,629,120 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atioglxx.dll
+ 2008-10-29 02:20:18 331,776 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atipdlxx.dll
+ 2008-10-29 02:20:31 159,744 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atitmmxx.dll
+ 2008-10-29 02:03:13 3,955,712 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdag.dll
+ 2008-10-29 01:41:09 3,107,788 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdva.dat
+ 2008-10-29 01:41:46 4,730,880 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdva.dll
+ 2008-10-29 02:20:07 262,144 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Oemdspif.dll
+ 2008-12-23 02:47:52 138,240 ----a-w c:\windows\System32\DriverStore\FileRepository\netrtx32.inf_72ee8a5d\Rtlh86.sys
+ 2008-12-23 02:47:52 10,240 ----a-w c:\windows\System32\DriverStore\FileRepository\netrtx32.inf_72ee8a5d\RtNicProp32.dll
- 2004-07-26 14:16:10 1,568,768 ----a-w c:\windows\System32\imagX7.dll
+ 2008-07-04 09:23:36 1,757,184 ----a-w c:\windows\System32\imagX7.dll
- 2004-07-26 14:16:10 476,320 ----a-w c:\windows\System32\imagXpr7.dll
+ 2008-07-04 09:23:38 497,296 ----a-w c:\windows\System32\imagXpr7.dll
- 2004-07-26 14:16:10 262,144 ----a-w c:\windows\System32\imagXR7.dll
+ 2008-07-04 09:23:42 258,048 ----a-w c:\windows\System32\imagXR7.dll
- 2004-07-26 14:16:10 471,040 ----a-w c:\windows\System32\imagXRA7.dll
+ 2008-07-04 09:23:46 802,816 ----a-w c:\windows\System32\imagXRA7.dll
- 2009-01-16 21:44:41 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-01-19 18:49:35 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-16 21:44:41 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-01-19 18:49:35 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-14 21:39:08 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-01-17 22:08:16 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2004-07-09 06:43:56 364,544 ----a-w c:\windows\System32\TwnLib4.dll
+ 2006-03-17 14:49:46 368,640 ----a-w c:\windows\System32\twnlib4.dll
- 2009-01-16 21:41:38 4,790 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
+ 2009-01-19 18:45:06 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
- 2009-01-16 16:32:27 4,170 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1001_UserData.bin
+ 2009-01-19 16:18:27 4,556 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1001_UserData.bin
- 2009-01-16 21:41:38 54,174 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-19 18:45:06 56,900 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-13 02:15:47 5,162 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-01-18 14:02:04 5,162 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-01-16 21:41:37 32,130 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-18 19:43:05 34,102 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-01-16 15:43:57 233,576 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-01-18 13:00:17 238,024 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-01-14 21:07:24 106,545,790 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-17 22:07:26 106,550,609 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-17 22:07:22 1,233,920 ----a-w c:\windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d\msxml4.dll
+ 2009-01-17 22:07:25 82,432 ----a-w c:\windows\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\msxml4r.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-17 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-18 227840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"snpstd2"="c:\windows\vsnpstd2.exe" [2007-04-13 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 06:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
--a------ 2007-03-20 13:36 36864 c:\windows\RaidTool\xInsIDE.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
--a------ 2003-10-14 17:36 38984 c:\progra~1\ICQ\ICQNet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-11-06 09:27 200704 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-18 22:33 1233920 c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-07 14:31 21633320 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
--a------ 2007-04-13 12:52 307200 c:\windows\vsnpstd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-03-29 11:29 3276800 c:\program files\Analog Devices\SoundMAX\SoundMAX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2007-04-02 23:32 1261568 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-10-23 23:01 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-23 22:38 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2008-01-18 22:36 2153472 c:\windows\System32\oobefldr.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{67B60EAD-3C77-49AC-90F8-9288200869D1}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5A7EE9E4-6788-4535-AC41-76500635EA39}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FA2F8F5B-ED90-4ADE-9C88-CDEF7FEEA73D}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5E991B1D-B1FA-40F7-B13E-4A7E9916DD41}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D14867AD-22F7-4750-ABF2-D0A685B66C69}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B5109571-B5B3-456A-B589-3DDD29B10494}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{CE2178AB-774D-4D48-A37A-C1FE0F7A3A3E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EFE1FA44-6686-4E23-B969-0F0C30CCB140}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{26BA0090-0487-4DAB-BD06-213A5E5D1DA6}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= UDP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"UDP Query User{CEA48B16-DFD1-4FAA-AD15-97DCD03C428D}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= TCP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"TCP Query User{43CB0764-00DD-412B-9F85-6BFBCEDC46CD}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{62614483-3CC9-468D-98F7-D951B75BEEA0}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5226F6FB-9A3D-491C-8E66-500D4A7EB2EE}c:\\program files\\icq\\icq.exe"= UDP:c:\program files\icq\icq.exe:ICQ
"UDP Query User{AC6E884A-8372-46E9-9869-18A80E2EAC16}c:\\program files\\icq\\icq.exe"= TCP:c:\program files\icq\icq.exe:ICQ
"TCP Query User{7E8A6F46-D485-404D-86F0-43ECEBC71C9E}c:\\program files\\internet download manager\\idman.exe"= UDP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"UDP Query User{C49491B4-1CDD-4152-9F9D-13F57D0961D7}c:\\program files\\internet download manager\\idman.exe"= TCP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"TCP Query User{ACED7AD6-DCAF-49F4-AFF2-BCE31D061E9B}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{5CC8D909-E25D-4D62-A9AA-9A914511D029}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{46C1624D-DEC6-45BA-8C6D-F74E4B3CFC08}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{216DA21D-E274-4F46-A0F0-35377379AC80}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{A81602BD-5283-4337-ABCD-DC87055B218A}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{3A951DDA-27EF-44BA-AB10-BB4FDF408DFC}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{98DCE7C0-D1F9-4D4E-AE25-ABAFC19D9A3B}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{738405EB-A673-401B-948B-2567FA87F1E5}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-01-17 111184]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-01-17 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-01-17 51792]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S4 gupdate1c95e4056d7d8d0;Google Update Service (gupdate1c95e4056d7d8d0);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 119280]
.
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 00:04]

2009-01-17 c:\windows\Tasks\hrwczpfw.job
- c:\windows\system32\rundll32.exe [2006-11-02 10:45]

2009-01-19 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-18 c:\windows\Tasks\User_Feed_Synchronization-{84B48C1F-F902-4578-81EB-EFCD09CA99E9}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\office11\EXCEL.EXE/3000
TCP: {3C9F5F5F-6B83-485F-B823-C8415F8338CF} = 195.66.160.1 195.66.160.2
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-19 21:42:04
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):d3,27,c3,a7,a7,60,b9,10,17,1d,4d,2f,e5,7b,01,6c,e6,58,89,51,fe,
e3,7f,8b,2a,fc,7d,7f,a3,5d,0c,ee,d4,c5,dd,c2,8c,7f,9c,ad,00,00,00,00,00,00,\

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{fc939414-aa92-4118-afd8-d2fae174aa82}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000145
"Therad"=dword:0000001e
.
Completion time: 2009-01-19 21:43:47
ComboFix-quarantined-files.txt 2009-01-19 20:43:44
ComboFix2.txt 2009-01-16 22:50:41
ComboFix3.txt 2009-01-16 21:57:10

Pre-Run: 48.852.910.080 bytes free
Post-Run: 48,847,826,944 bytes free

343 --- E O F --- 2009-01-19 19:12:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Klikni desnim tasterom na sledeći file: c:\windows\Tasks\hrwczpfw.job i izaberi opciju Properties.

Otvoriće se prozor - iskopiraj ovde ono što se nalazi unutar Run polja.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

Otvoriće se prozor - iskopiraj ovde ono što se nalazi unutar Run polja.??? meni je na srpskom..

Dopuna: 19 Jan 2009 23:41



Dopuna: 19 Jan 2009 23:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Napravi screenshotove i ostale dve kartice (tab-a).

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Zamolio bih te da obrišeš trenutnu verziju ComboFix-a koju imaš, skineš novu sa gornjih linkova i postaviš još jedan log.

U principu, ne bih rekao da na tvom kompjuteru postoji aktivan malware, no svejedno bih želeo da odradimo još jednu proveru.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

vazi..hvala ti na trudu

Dopuna: 20 Jan 2009 23:31

ComboFix 09-01-19.05 - bosko 2009-01-20 23:24:59.4 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1033.18.1022.414 [GMT 1:00]
Running from: c:\users\bosko\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\hrwczpfw.job

.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-20 00:46 . 2009-01-20 00:46 <DIR> d-------- c:\users\bosko\AppData\Roaming\GRETECH
2009-01-20 00:46 . 2009-01-20 00:46 <DIR> d-------- c:\program files\GRETECH
2009-01-20 00:22 . 2009-01-20 00:24 <DIR> d-------- c:\program files\The KMPlayer
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\users\All Users\CyberLink
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\programdata\CyberLink
2009-01-18 23:02 . 2009-01-18 23:02 <DIR> d-------- c:\users\bosko\AppData\Roaming\CyberLink
2009-01-18 22:57 . 2009-01-19 20:13 <DIR> d-------- c:\program files\CyberLink
2009-01-18 22:57 . 2003-04-23 18:29 221,215 --------- c:\windows\System32\Divxdec.ax
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI Technologies
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI
2009-01-18 14:10 . 2009-01-18 14:10 <DIR> d-------- C:\ATI
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\users\bosko\AppData\Roaming\IObit
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\program files\CCleaner
2009-01-18 03:20 . 2009-01-19 19:52 <DIR> d-------- c:\users\bosko\AppData\Roaming\Nero
2009-01-18 03:05 . 2009-01-18 03:05 4,767 --a------ c:\windows\Irremote.ini
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\users\All Users\Nero
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\programdata\Nero
2009-01-18 02:50 . 2009-01-18 03:19 <DIR> d-------- c:\program files\Common Files\Nero
2009-01-17 23:38 . 2009-01-17 23:38 <DIR> d-------- c:\program files\AskTBar
2009-01-17 22:26 . 2009-01-17 22:26 <DIR> d-------- c:\users\bosko\AppData\Roaming\skypePM
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\programdata\ezsidmv.dat
2009-01-17 22:25 . 2009-01-17 22:25 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-17 12:34 . 2008-11-26 18:17 51,792 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2009-01-14 22:07 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-05 00:10 . 2009-01-05 00:10 <DIR> d-------- c:\program files\RegCure
2009-01-05 00:10 . 2009-01-05 00:13 <DIR> d-------- c:\program files\Disk Cleaner
2008-12-27 23:52 . 2007-04-09 13:23 28,040 --a------ c:\windows\System32\mdimon.dll
2008-12-27 23:52 . 2008-12-27 23:52 376 --a------ c:\windows\ODBC.INI
2008-12-27 23:50 . 2008-12-27 23:50 <DIR> d-------- c:\program files\Common Files\L&H
2008-12-27 23:49 . 2008-12-27 23:49 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\Stationery
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\MEDIA
2008-12-27 23:48 . 2008-12-27 23:49 <DIR> d-------- C:\CLIPART
2008-12-27 23:47 . 2008-12-27 23:50 <DIR> d-------- C:\Templates
2008-12-27 23:47 . 2009-01-14 22:40 <DIR> d-------- C:\OFFICE11
2008-12-25 22:35 . 2008-12-25 23:24 <DIR> d-------- c:\program files\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\users\All Users\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\programdata\Quark
2008-12-23 03:47 . 2008-12-23 03:47 138,240 --a------ c:\windows\System32\drivers\Rtlh86.sys
2008-12-23 03:47 . 2008-12-23 03:47 10,240 --a------ c:\windows\System32\RtNicProp32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-20 21:47 --------- d-----w c:\programdata\Google Updater
2009-01-19 23:43 --------- d-----w c:\users\bosko\AppData\Roaming\uTorrent
2009-01-19 19:14 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-19 19:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-19 14:31 --------- d-----w c:\programdata\Microsoft Help
2009-01-18 03:15 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-01-18 03:15 --------- d-----w c:\program files\ICQ
2009-01-18 03:15 --------- d-----w c:\program files\AWR
2009-01-18 03:14 --------- d-----w c:\program files\YouTube Downloader
2009-01-18 02:30 --------- d-----w c:\program files\IObit
2009-01-18 02:05 --------- d-----w c:\program files\Nero
2009-01-17 23:56 --------- d-----w c:\program files\FlashGet
2009-01-17 22:06 --------- d-----w c:\program files\Common Files\Ahead
2009-01-17 21:32 --------- d-----w c:\users\bosko\AppData\Roaming\Skype
2009-01-17 21:25 --------- d-----w c:\programdata\Skype
2009-01-17 21:25 --------- d-----w c:\program files\Skype
2009-01-14 21:41 --------- d-----w c:\program files\Windows Mail
2008-12-29 16:43 --------- d-----w c:\program files\Microsoft Works
2008-12-22 14:16 --------- d-----w c:\program files\Opera
2008-12-19 19:59 --------- d-----w c:\programdata\PC Drivers HeadQuarters
2008-12-19 19:59 --------- d-----w c:\program files\PC Drivers HeadQuarters
2008-12-17 23:40 --------- d-----w c:\program files\Restorer2000 Pro
2008-12-17 22:39 --------- d-----w c:\users\bosko\AppData\Roaming\Cimaware
2008-12-17 22:34 --------- d-----w c:\program files\Cimaware
2008-12-14 23:05 --------- d-----w c:\program files\Google
2008-12-11 14:01 --------- d-----w c:\users\bosko\AppData\Roaming\Xilisoft Corporation
2008-12-11 14:01 --------- d-----w c:\program files\Xilisoft
2008-12-03 21:14 --------- d-----w c:\program files\WMR11
2008-12-03 21:13 --------- d-----w c:\program files\Replay Media Catcher
2008-12-01 20:15 --------- d-----w c:\program files\MSXML 4.0
2008-11-27 13:39 --------- d-----w c:\program files\ABBYY FineReader 9.0
2008-11-27 13:35 --------- d-----w c:\program files\Common Files\ABBYY
2008-11-27 12:51 --------- d-----w c:\program files\HP
2008-11-27 01:22 --------- d-----w c:\program files\Hewlett-Packard
2008-11-24 17:15 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-24 17:15 --------- d-----w c:\program files\Adobe Media Player
2008-11-21 22:07 --------- d-----w c:\program files\Odigo
2008-11-21 15:55 --------- d-----w c:\users\bosko\AppData\Roaming\DMCache
2008-11-17 16:07 323,584 ----a-w c:\windows\System32\AUDIOGENIE2.DLL
2008-11-17 16:07 237,568 ----a-w c:\windows\System32\rmc_rtspdl.dll
2008-11-17 16:07 156,672 ----a-w c:\windows\System32\rmc_fixasf.exe
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-29 02:21 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll
2008-10-29 02:20 331,776 ----a-w c:\windows\System32\atipdlxx.dll
2008-10-29 02:20 262,144 ----a-w c:\windows\System32\Oemdspif.dll
2008-10-29 02:20 159,744 ----a-w c:\windows\System32\atitmmxx.dll
2008-10-29 02:19 43,520 ----a-w c:\windows\System32\ati2edxx.dll
2008-10-29 02:19 274,432 ----a-w c:\windows\System32\Ati2evxx.dll
2008-10-29 02:18 712,704 ----a-w c:\windows\System32\Ati2evxx.exe
2008-10-29 02:03 3,955,712 ----a-w c:\windows\System32\atiumdag.dll
2008-10-29 01:47 10,629,120 ----a-w c:\windows\System32\atioglxx.dll
2008-10-29 01:41 4,730,880 ----a-w c:\windows\System32\atiumdva.dll
2008-10-29 01:27 54,272 ----a-w c:\windows\System32\atiadlxx.dll
2008-10-29 01:27 50,688 ----a-w c:\windows\System32\amdpcom32.dll
2008-10-23 22:01 410,976 ----a-w c:\windows\System32\deploytk.dll
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\System32\atibrtmon.exe
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-01 21:04 174 --sha-w c:\program files\desktop.ini
2006-11-01 23:30 87,552 ----a-w c:\users\bosko\BootSect.exe
.

((((((((((((((((((((((((((((( snapshot_2009-01-19_21.42.35,20 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-20 21:39:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-01-20 21:39:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-19 18:44:56 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-20 21:41:43 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-01-19 18:44:14 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 21:41:04 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 21:41:04 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-20 21:46:34 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-19 18:46:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-20 21:46:34 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-20 21:46:34 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-16 21:51:56 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-01-20 22:24:53 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-01-19 18:49:35 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-01-20 21:46:35 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-19 18:49:35 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-01-20 21:46:35 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-19 18:45:06 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
+ 2009-01-20 21:42:02 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
- 2009-01-19 18:45:06 56,900 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 21:42:02 56,940 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-18 19:43:05 34,102 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 21:42:00 34,176 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-17 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-18 227840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"snpstd2"="c:\windows\vsnpstd2.exe" [2007-04-13 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 06:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
--a------ 2007-03-20 13:36 36864 c:\windows\RaidTool\xInsIDE.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
--a------ 2003-10-14 17:36 38984 c:\progra~1\ICQ\ICQNet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-11-06 09:27 200704 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-18 22:33 1233920 c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-07 14:31 21633320 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
--a------ 2007-04-13 12:52 307200 c:\windows\vsnpstd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-03-29 11:29 3276800 c:\program files\Analog Devices\SoundMAX\SoundMAX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2007-04-02 23:32 1261568 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-10-23 23:01 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-23 22:38 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2008-01-18 22:36 2153472 c:\windows\System32\oobefldr.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{67B60EAD-3C77-49AC-90F8-9288200869D1}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5A7EE9E4-6788-4535-AC41-76500635EA39}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FA2F8F5B-ED90-4ADE-9C88-CDEF7FEEA73D}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5E991B1D-B1FA-40F7-B13E-4A7E9916DD41}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D14867AD-22F7-4750-ABF2-D0A685B66C69}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B5109571-B5B3-456A-B589-3DDD29B10494}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{CE2178AB-774D-4D48-A37A-C1FE0F7A3A3E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EFE1FA44-6686-4E23-B969-0F0C30CCB140}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{26BA0090-0487-4DAB-BD06-213A5E5D1DA6}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= UDP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"UDP Query User{CEA48B16-DFD1-4FAA-AD15-97DCD03C428D}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= TCP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"TCP Query User{43CB0764-00DD-412B-9F85-6BFBCEDC46CD}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{62614483-3CC9-468D-98F7-D951B75BEEA0}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5226F6FB-9A3D-491C-8E66-500D4A7EB2EE}c:\\program files\\icq\\icq.exe"= UDP:c:\program files\icq\icq.exe:ICQ
"UDP Query User{AC6E884A-8372-46E9-9869-18A80E2EAC16}c:\\program files\\icq\\icq.exe"= TCP:c:\program files\icq\icq.exe:ICQ
"TCP Query User{7E8A6F46-D485-404D-86F0-43ECEBC71C9E}c:\\program files\\internet download manager\\idman.exe"= UDP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"UDP Query User{C49491B4-1CDD-4152-9F9D-13F57D0961D7}c:\\program files\\internet download manager\\idman.exe"= TCP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"TCP Query User{ACED7AD6-DCAF-49F4-AFF2-BCE31D061E9B}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{5CC8D909-E25D-4D62-A9AA-9A914511D029}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{46C1624D-DEC6-45BA-8C6D-F74E4B3CFC08}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{216DA21D-E274-4F46-A0F0-35377379AC80}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{A81602BD-5283-4337-ABCD-DC87055B218A}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{3A951DDA-27EF-44BA-AB10-BB4FDF408DFC}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{98DCE7C0-D1F9-4D4E-AE25-ABAFC19D9A3B}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{738405EB-A673-401B-948B-2567FA87F1E5}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-01-17 111184]
R3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-01-17 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-01-17 51792]
S4 gupdate1c95e4056d7d8d0;Google Update Service (gupdate1c95e4056d7d8d0);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 119280]
.
Contents of the 'Scheduled Tasks' folder

2009-01-20 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 00:04]

2009-01-20 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-19 c:\windows\Tasks\User_Feed_Synchronization-{84B48C1F-F902-4578-81EB-EFCD09CA99E9}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\office11\EXCEL.EXE/3000
TCP: {3C9F5F5F-6B83-485F-B823-C8415F8338CF} = 195.66.160.1 195.66.160.2
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-20 23:26:44
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):d3,27,c3,a7,a7,60,b9,10,17,1d,4d,2f,e5,7b,01,6c,e6,58,89,51,fe,
e3,7f,8b,2a,fc,7d,7f,a3,5d,0c,ee,d4,c5,dd,c2,8c,7f,9c,ad,00,00,00,00,00,00,\

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{fc939414-aa92-4118-afd8-d2fae174aa82}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000145
"Therad"=dword:0000001e
.
Completion time: 2009-01-20 23:28:29
ComboFix-quarantined-files.txt 2009-01-20 22:28:27
ComboFix2.txt 2009-01-19 20:43:49
ComboFix3.txt 2009-01-16 22:50:41
ComboFix4.txt 2009-01-16 21:57:10

Pre-Run: 46.612.353.024 bytes free
Post-Run: 46,373,416,960 bytes free

281 --- E O F --- 2009-01-19 19:12:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ovde stvarno više nema ni traga malware-u.

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore




To je ono što ja mogu da uradim. Dalje savete možeš potražiti u forumu Windows.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

ok..hvala ti i veliki pozdrav

Ko je trenutno na forumu
 

Ukupno su 917 korisnika na forumu :: 66 registrovanih, 5 sakrivenih i 846 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3028 - dana 22 Nov 2019 07:47

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: axa, babaroga, baki60, brundo65, chaky962, Cvijo_ue, Davor Kondic, Dimitrise93, djonsule, Drug pukovnik, dule10savic, Gabriel182, Georgius2, Gibli, GreenMan, hyla, ILGromovnik, Insan, ivance95, ivica976, kalens021, Kinkou, kosticmilanko, Kubovac, Lieutenant, lord sir giga, majorgaspar, mandicdamir245, mean_machine, MegaVLAdaR, mige2, Mihajlo, Milan A. Nikolic, Miskohd, moldway, nemkea71, Parker2, pein, PrintZip, r77adder, raykan, rkekoke, rovac, SAA fan, sakota79, Sale.S, Shomy2, Sirius, snop, sosko, Sr.Stat., SsssssNOVI, stug, Taso2, USSVoyager, Van, vasa.93, vathra, VJ, vjetar, vobo, voja64, wizzardone, xandar, zexoni, 1107