Racunar se sam restartuje

2

Racunar se sam restartuje

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

ComboFix 09-01-16.02 - bosko 2009-01-19 21:39:25.3 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1033.18.1022.377 [GMT 1:00]
Running from: c:\users\bosko\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.

2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\users\All Users\CyberLink
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\programdata\CyberLink
2009-01-18 23:02 . 2009-01-18 23:02 <DIR> d-------- c:\users\bosko\AppData\Roaming\CyberLink
2009-01-18 22:57 . 2009-01-19 20:13 <DIR> d-------- c:\program files\CyberLink
2009-01-18 22:57 . 2003-04-23 18:29 221,215 --------- c:\windows\System32\Divxdec.ax
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI Technologies
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI
2009-01-18 14:10 . 2009-01-18 14:10 <DIR> d-------- C:\ATI
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\users\bosko\AppData\Roaming\IObit
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\program files\CCleaner
2009-01-18 03:20 . 2009-01-19 19:52 <DIR> d-------- c:\users\bosko\AppData\Roaming\Nero
2009-01-18 03:05 . 2009-01-18 03:05 4,767 --a------ c:\windows\Irremote.ini
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\users\All Users\Nero
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\programdata\Nero
2009-01-18 02:50 . 2009-01-18 03:19 <DIR> d-------- c:\program files\Common Files\Nero
2009-01-17 23:38 . 2009-01-17 23:38 <DIR> d-------- c:\program files\AskTBar
2009-01-17 22:26 . 2009-01-17 22:26 <DIR> d-------- c:\users\bosko\AppData\Roaming\skypePM
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\programdata\ezsidmv.dat
2009-01-17 22:25 . 2009-01-17 22:25 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-17 12:34 . 2008-11-26 18:17 51,792 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2009-01-14 22:07 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-05 00:10 . 2009-01-05 00:10 <DIR> d-------- c:\program files\RegCure
2009-01-05 00:10 . 2009-01-05 00:13 <DIR> d-------- c:\program files\Disk Cleaner
2008-12-27 23:52 . 2007-04-09 13:23 28,040 --a------ c:\windows\System32\mdimon.dll
2008-12-27 23:52 . 2008-12-27 23:52 376 --a------ c:\windows\ODBC.INI
2008-12-27 23:50 . 2008-12-27 23:50 <DIR> d-------- c:\program files\Common Files\L&H
2008-12-27 23:49 . 2008-12-27 23:49 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\Stationery
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\MEDIA
2008-12-27 23:48 . 2008-12-27 23:49 <DIR> d-------- C:\CLIPART
2008-12-27 23:47 . 2008-12-27 23:50 <DIR> d-------- C:\Templates
2008-12-27 23:47 . 2009-01-14 22:40 <DIR> d-------- C:\OFFICE11
2008-12-25 22:35 . 2008-12-25 23:24 <DIR> d-------- c:\program files\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\users\All Users\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\programdata\Quark
2008-12-23 03:47 . 2008-12-23 03:47 138,240 --a------ c:\windows\System32\drivers\Rtlh86.sys
2008-12-23 03:47 . 2008-12-23 03:47 10,240 --a------ c:\windows\System32\RtNicProp32.dll
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\users\All Users\PC Drivers HeadQuarters
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\programdata\PC Drivers HeadQuarters
2008-12-19 20:59 . 2008-12-19 20:59 <DIR> d-------- c:\program files\PC Drivers HeadQuarters

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 19:14 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-19 19:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-19 14:31 --------- d-----w c:\programdata\Microsoft Help
2009-01-19 14:19 --------- d-----w c:\programdata\Google Updater
2009-01-18 03:15 --------- d-----w c:\users\bosko\AppData\Roaming\uTorrent
2009-01-18 03:15 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-01-18 03:15 --------- d-----w c:\program files\ICQ
2009-01-18 03:15 --------- d-----w c:\program files\AWR
2009-01-18 03:14 --------- d-----w c:\program files\YouTube Downloader
2009-01-18 02:30 --------- d-----w c:\program files\IObit
2009-01-18 02:05 --------- d-----w c:\program files\Nero
2009-01-17 23:56 --------- d-----w c:\program files\FlashGet
2009-01-17 22:06 --------- d-----w c:\program files\Common Files\Ahead
2009-01-17 21:32 --------- d-----w c:\users\bosko\AppData\Roaming\Skype
2009-01-17 21:25 --------- d-----w c:\programdata\Skype
2009-01-17 21:25 --------- d-----w c:\program files\Skype
2009-01-14 21:41 --------- d-----w c:\program files\Windows Mail
2008-12-29 16:43 --------- d-----w c:\program files\Microsoft Works
2008-12-22 14:16 --------- d-----w c:\program files\Opera
2008-12-17 23:40 --------- d-----w c:\program files\Restorer2000 Pro
2008-12-17 22:39 --------- d-----w c:\users\bosko\AppData\Roaming\Cimaware
2008-12-17 22:34 --------- d-----w c:\program files\Cimaware
2008-12-14 23:05 --------- d-----w c:\program files\Google
2008-12-11 14:01 --------- d-----w c:\users\bosko\AppData\Roaming\Xilisoft Corporation
2008-12-11 14:01 --------- d-----w c:\program files\Xilisoft
2008-12-03 21:14 --------- d-----w c:\program files\WMR11
2008-12-03 21:13 --------- d-----w c:\program files\Replay Media Catcher
2008-12-01 20:15 --------- d-----w c:\program files\MSXML 4.0
2008-11-27 13:39 --------- d-----w c:\program files\ABBYY FineReader 9.0
2008-11-27 13:35 --------- d-----w c:\program files\Common Files\ABBYY
2008-11-27 12:51 --------- d-----w c:\program files\HP
2008-11-27 01:22 --------- d-----w c:\program files\Hewlett-Packard
2008-11-24 17:15 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-24 17:15 --------- d-----w c:\program files\Adobe Media Player
2008-11-21 22:07 --------- d-----w c:\program files\Odigo
2008-11-21 15:55 --------- d-----w c:\users\bosko\AppData\Roaming\DMCache
2008-11-17 16:07 323,584 ----a-w c:\windows\System32\AUDIOGENIE2.DLL
2008-11-17 16:07 237,568 ----a-w c:\windows\System32\rmc_rtspdl.dll
2008-11-17 16:07 156,672 ----a-w c:\windows\System32\rmc_fixasf.exe
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-29 02:21 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll
2008-10-29 02:20 331,776 ----a-w c:\windows\System32\atipdlxx.dll
2008-10-29 02:20 262,144 ----a-w c:\windows\System32\Oemdspif.dll
2008-10-29 02:20 159,744 ----a-w c:\windows\System32\atitmmxx.dll
2008-10-29 02:19 43,520 ----a-w c:\windows\System32\ati2edxx.dll
2008-10-29 02:19 274,432 ----a-w c:\windows\System32\Ati2evxx.dll
2008-10-29 02:18 712,704 ----a-w c:\windows\System32\Ati2evxx.exe
2008-10-29 02:03 3,955,712 ----a-w c:\windows\System32\atiumdag.dll
2008-10-29 01:47 10,629,120 ----a-w c:\windows\System32\atioglxx.dll
2008-10-29 01:41 4,730,880 ----a-w c:\windows\System32\atiumdva.dll
2008-10-29 01:27 54,272 ----a-w c:\windows\System32\atiadlxx.dll
2008-10-29 01:27 50,688 ----a-w c:\windows\System32\amdpcom32.dll
2008-10-23 22:01 410,976 ----a-w c:\windows\System32\deploytk.dll
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\System32\atibrtmon.exe
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-01 21:04 174 --sha-w c:\program files\desktop.ini
2006-11-01 23:30 87,552 ----a-w c:\users\bosko\BootSect.exe
.

((((((((((((((((((((((((((((( snapshot@2009-01-16_22.55.58.71 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-19 20:26:56 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-01-18 14:00:25 51,200 ----a-w c:\windows\inf\infpub.dat
- 2008-12-19 20:26:55 86,016 ----a-w c:\windows\inf\infstor.dat
+ 2009-01-18 14:00:25 86,016 ----a-w c:\windows\inf\infstor.dat
- 2008-12-19 20:26:56 86,016 ----a-w c:\windows\inf\infstrng.dat
+ 2009-01-18 14:00:25 86,016 ----a-w c:\windows\inf\infstrng.dat
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\ARPPRODUCTICON.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut2_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut3_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut4_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2009-01-18 13:27:14 9,158 ----a-r c:\windows\Installer\{8BCD9811-1084-4941-0222-F993DB70F182}\NewShortcut5_4DEA5338A7B840A3B51CDC742625BF49.exe
- 2008-12-17 23:04:57 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-19 14:30:14 217,864 ----a-r c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-16 21:53:53 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-19 18:44:56 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-19 18:44:56 262,144 ---ha-w c:\windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2009-01-16 21:53:54 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-19 18:44:14 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-11-26 17:21:30 1,236,208 ----a-w c:\windows\System32\aswBoot.exe
- 2008-04-28 19:09:10 172,033 ----a-w c:\windows\System32\atiicdxx.dat
+ 2008-08-14 17:42:21 176,214 ----a-w c:\windows\System32\atiicdxx.dat
+ 2008-11-26 17:15:10 97,480 ----a-w c:\windows\System32\AvastSS.scr
- 2009-01-16 21:04:01 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-16 21:04:01 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-19 18:46:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-16 21:04:01 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-26 17:17:25 20,560 ----a-w c:\windows\System32\drivers\aswFsBlk.sys
+ 2008-11-26 17:16:29 23,152 ----a-w c:\windows\System32\drivers\aswRdr.sys
+ 2008-11-26 17:17:36 111,184 ----a-w c:\windows\System32\drivers\aswSP.sys
+ 2008-11-26 17:16:38 50,864 ----a-w c:\windows\System32\drivers\aswTdi.sys
- 2008-06-03 00:34:04 49,152 ----a-w c:\windows\System32\drivers\ati2erec.dll
+ 2008-10-29 01:10:39 53,248 ----a-w c:\windows\System32\drivers\ati2erec.dll
- 2008-06-03 04:22:56 3,695,104 ----a-w c:\windows\System32\drivers\atikmdag.sys
+ 2008-10-29 03:11:48 4,017,152 ----a-w c:\windows\System32\drivers\atikmdag.sys
+ 2008-10-29 01:27:54 50,688 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\amdpcom32.dll
+ 2008-10-29 02:19:54 43,520 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ati2edxx.dll
+ 2008-10-29 01:10:39 53,248 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ati2erec.dll
+ 2008-10-29 02:19:41 274,432 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Ati2evxx.dll
+ 2008-10-29 02:18:23 712,704 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Ati2evxx.exe
+ 2008-10-29 01:27:30 54,272 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiadlxx.dll
+ 2008-10-21 17:51:43 118,784 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atibrtmon.exe
+ 2008-10-29 02:21:55 425,984 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIDEMGX.dll
+ 2008-10-29 02:09:23 2,243,584 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atidxx32.dll
+ 2008-08-14 17:42:21 176,214 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiicdxx.dat
+ 2008-10-29 03:11:48 4,017,152 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atikmdag.sys
+ 2008-10-21 16:40:00 45,056 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIODCLI.exe
+ 2008-10-21 16:40:00 81,920 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\ATIODE.exe
+ 2008-10-29 01:47:29 10,629,120 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atioglxx.dll
+ 2008-10-29 02:20:18 331,776 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atipdlxx.dll
+ 2008-10-29 02:20:31 159,744 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atitmmxx.dll
+ 2008-10-29 02:03:13 3,955,712 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdag.dll
+ 2008-10-29 01:41:09 3,107,788 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdva.dat
+ 2008-10-29 01:41:46 4,730,880 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\atiumdva.dll
+ 2008-10-29 02:20:07 262,144 ----a-w c:\windows\System32\DriverStore\FileRepository\cl_70229.inf_b3b9bd90\B_71400\Oemdspif.dll
+ 2008-12-23 02:47:52 138,240 ----a-w c:\windows\System32\DriverStore\FileRepository\netrtx32.inf_72ee8a5d\Rtlh86.sys
+ 2008-12-23 02:47:52 10,240 ----a-w c:\windows\System32\DriverStore\FileRepository\netrtx32.inf_72ee8a5d\RtNicProp32.dll
- 2004-07-26 14:16:10 1,568,768 ----a-w c:\windows\System32\imagX7.dll
+ 2008-07-04 09:23:36 1,757,184 ----a-w c:\windows\System32\imagX7.dll
- 2004-07-26 14:16:10 476,320 ----a-w c:\windows\System32\imagXpr7.dll
+ 2008-07-04 09:23:38 497,296 ----a-w c:\windows\System32\imagXpr7.dll
- 2004-07-26 14:16:10 262,144 ----a-w c:\windows\System32\imagXR7.dll
+ 2008-07-04 09:23:42 258,048 ----a-w c:\windows\System32\imagXR7.dll
- 2004-07-26 14:16:10 471,040 ----a-w c:\windows\System32\imagXRA7.dll
+ 2008-07-04 09:23:46 802,816 ----a-w c:\windows\System32\imagXRA7.dll
- 2009-01-16 21:44:41 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-01-19 18:49:35 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-16 21:44:41 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-01-19 18:49:35 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-14 21:39:08 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-01-17 22:08:16 6,553,600 ----a-w c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2004-07-09 06:43:56 364,544 ----a-w c:\windows\System32\TwnLib4.dll
+ 2006-03-17 14:49:46 368,640 ----a-w c:\windows\System32\twnlib4.dll
- 2009-01-16 21:41:38 4,790 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
+ 2009-01-19 18:45:06 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
- 2009-01-16 16:32:27 4,170 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1001_UserData.bin
+ 2009-01-19 16:18:27 4,556 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1001_UserData.bin
- 2009-01-16 21:41:38 54,174 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-19 18:45:06 56,900 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-13 02:15:47 5,162 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-01-18 14:02:04 5,162 ----a-w c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2009-01-16 21:41:37 32,130 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-18 19:43:05 34,102 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2009-01-16 15:43:57 233,576 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-01-18 13:00:17 238,024 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-01-14 21:07:24 106,545,790 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-17 22:07:26 106,550,609 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-01-17 22:07:22 1,233,920 ----a-w c:\windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d\msxml4.dll
+ 2009-01-17 22:07:25 82,432 ----a-w c:\windows\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6\msxml4r.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-17 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-18 227840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"snpstd2"="c:\windows\vsnpstd2.exe" [2007-04-13 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 06:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
--a------ 2007-03-20 13:36 36864 c:\windows\RaidTool\xInsIDE.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
--a------ 2003-10-14 17:36 38984 c:\progra~1\ICQ\ICQNet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-11-06 09:27 200704 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-18 22:33 1233920 c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-07 14:31 21633320 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
--a------ 2007-04-13 12:52 307200 c:\windows\vsnpstd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-03-29 11:29 3276800 c:\program files\Analog Devices\SoundMAX\SoundMAX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2007-04-02 23:32 1261568 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-10-23 23:01 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-23 22:38 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2008-01-18 22:36 2153472 c:\windows\System32\oobefldr.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{67B60EAD-3C77-49AC-90F8-9288200869D1}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5A7EE9E4-6788-4535-AC41-76500635EA39}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FA2F8F5B-ED90-4ADE-9C88-CDEF7FEEA73D}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5E991B1D-B1FA-40F7-B13E-4A7E9916DD41}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D14867AD-22F7-4750-ABF2-D0A685B66C69}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B5109571-B5B3-456A-B589-3DDD29B10494}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{CE2178AB-774D-4D48-A37A-C1FE0F7A3A3E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EFE1FA44-6686-4E23-B969-0F0C30CCB140}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{26BA0090-0487-4DAB-BD06-213A5E5D1DA6}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= UDP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"UDP Query User{CEA48B16-DFD1-4FAA-AD15-97DCD03C428D}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= TCP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"TCP Query User{43CB0764-00DD-412B-9F85-6BFBCEDC46CD}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{62614483-3CC9-468D-98F7-D951B75BEEA0}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5226F6FB-9A3D-491C-8E66-500D4A7EB2EE}c:\\program files\\icq\\icq.exe"= UDP:c:\program files\icq\icq.exe:ICQ
"UDP Query User{AC6E884A-8372-46E9-9869-18A80E2EAC16}c:\\program files\\icq\\icq.exe"= TCP:c:\program files\icq\icq.exe:ICQ
"TCP Query User{7E8A6F46-D485-404D-86F0-43ECEBC71C9E}c:\\program files\\internet download manager\\idman.exe"= UDP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"UDP Query User{C49491B4-1CDD-4152-9F9D-13F57D0961D7}c:\\program files\\internet download manager\\idman.exe"= TCP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"TCP Query User{ACED7AD6-DCAF-49F4-AFF2-BCE31D061E9B}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{5CC8D909-E25D-4D62-A9AA-9A914511D029}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{46C1624D-DEC6-45BA-8C6D-F74E4B3CFC08}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{216DA21D-E274-4F46-A0F0-35377379AC80}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{A81602BD-5283-4337-ABCD-DC87055B218A}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{3A951DDA-27EF-44BA-AB10-BB4FDF408DFC}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{98DCE7C0-D1F9-4D4E-AE25-ABAFC19D9A3B}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{738405EB-A673-401B-948B-2567FA87F1E5}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-01-17 111184]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-01-17 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-01-17 51792]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S4 gupdate1c95e4056d7d8d0;Google Update Service (gupdate1c95e4056d7d8d0);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 119280]
.
Contents of the 'Scheduled Tasks' folder

2009-01-19 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 00:04]

2009-01-17 c:\windows\Tasks\hrwczpfw.job
- c:\windows\system32\rundll32.exe [2006-11-02 10:45]

2009-01-19 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-18 c:\windows\Tasks\User_Feed_Synchronization-{84B48C1F-F902-4578-81EB-EFCD09CA99E9}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Ahead\Lib\NeroCheck.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\office11\EXCEL.EXE/3000
TCP: {3C9F5F5F-6B83-485F-B823-C8415F8338CF} = 195.66.160.1 195.66.160.2
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-19 21:42:04
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):d3,27,c3,a7,a7,60,b9,10,17,1d,4d,2f,e5,7b,01,6c,e6,58,89,51,fe,
e3,7f,8b,2a,fc,7d,7f,a3,5d,0c,ee,d4,c5,dd,c2,8c,7f,9c,ad,00,00,00,00,00,00,\

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{fc939414-aa92-4118-afd8-d2fae174aa82}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000145
"Therad"=dword:0000001e
.
Completion time: 2009-01-19 21:43:47
ComboFix-quarantined-files.txt 2009-01-19 20:43:44
ComboFix2.txt 2009-01-16 22:50:41
ComboFix3.txt 2009-01-16 21:57:10

Pre-Run: 48.852.910.080 bytes free
Post-Run: 48,847,826,944 bytes free

343 --- E O F --- 2009-01-19 19:12:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Klikni desnim tasterom na sledeći file: c:\windows\Tasks\hrwczpfw.job i izaberi opciju Properties.

Otvoriće se prozor - iskopiraj ovde ono što se nalazi unutar Run polja.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

Otvoriće se prozor - iskopiraj ovde ono što se nalazi unutar Run polja.??? meni je na srpskom..

Dopuna: 19 Jan 2009 23:41



Dopuna: 19 Jan 2009 23:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Napravi screenshotove i ostale dve kartice (tab-a).

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Zamolio bih te da obrišeš trenutnu verziju ComboFix-a koju imaš, skineš novu sa gornjih linkova i postaviš još jedan log.

U principu, ne bih rekao da na tvom kompjuteru postoji aktivan malware, no svejedno bih želeo da odradimo još jednu proveru.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

vazi..hvala ti na trudu

Dopuna: 20 Jan 2009 23:31

ComboFix 09-01-19.05 - bosko 2009-01-20 23:24:59.4 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1250.1.1033.18.1022.414 [GMT 1:00]
Running from: c:\users\bosko\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Tasks\hrwczpfw.job

.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-20 00:46 . 2009-01-20 00:46 <DIR> d-------- c:\users\bosko\AppData\Roaming\GRETECH
2009-01-20 00:46 . 2009-01-20 00:46 <DIR> d-------- c:\program files\GRETECH
2009-01-20 00:22 . 2009-01-20 00:24 <DIR> d-------- c:\program files\The KMPlayer
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\users\All Users\CyberLink
2009-01-19 20:13 . 2009-01-19 20:13 <DIR> d-------- c:\programdata\CyberLink
2009-01-18 23:02 . 2009-01-18 23:02 <DIR> d-------- c:\users\bosko\AppData\Roaming\CyberLink
2009-01-18 22:57 . 2009-01-19 20:13 <DIR> d-------- c:\program files\CyberLink
2009-01-18 22:57 . 2003-04-23 18:29 221,215 --------- c:\windows\System32\Divxdec.ax
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI Technologies
2009-01-18 14:11 . 2009-01-18 14:11 <DIR> d-------- c:\program files\ATI
2009-01-18 14:10 . 2009-01-18 14:10 <DIR> d-------- C:\ATI
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\users\bosko\AppData\Roaming\IObit
2009-01-18 03:30 . 2009-01-18 03:30 <DIR> d-------- c:\program files\CCleaner
2009-01-18 03:20 . 2009-01-19 19:52 <DIR> d-------- c:\users\bosko\AppData\Roaming\Nero
2009-01-18 03:05 . 2009-01-18 03:05 4,767 --a------ c:\windows\Irremote.ini
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\users\All Users\Nero
2009-01-18 02:50 . 2009-01-18 02:58 <DIR> d-------- c:\programdata\Nero
2009-01-18 02:50 . 2009-01-18 03:19 <DIR> d-------- c:\program files\Common Files\Nero
2009-01-17 23:38 . 2009-01-17 23:38 <DIR> d-------- c:\program files\AskTBar
2009-01-17 22:26 . 2009-01-17 22:26 <DIR> d-------- c:\users\bosko\AppData\Roaming\skypePM
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\users\All Users\ezsidmv.dat
2009-01-17 22:26 . 2009-01-17 22:26 56 --ah----- c:\programdata\ezsidmv.dat
2009-01-17 22:25 . 2009-01-17 22:25 <DIR> d-------- c:\program files\Common Files\Skype
2009-01-17 12:34 . 2008-11-26 18:17 51,792 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2009-01-14 22:07 . 2008-12-16 03:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-05 00:10 . 2009-01-05 00:10 <DIR> d-------- c:\program files\RegCure
2009-01-05 00:10 . 2009-01-05 00:13 <DIR> d-------- c:\program files\Disk Cleaner
2008-12-27 23:52 . 2007-04-09 13:23 28,040 --a------ c:\windows\System32\mdimon.dll
2008-12-27 23:52 . 2008-12-27 23:52 376 --a------ c:\windows\ODBC.INI
2008-12-27 23:50 . 2008-12-27 23:50 <DIR> d-------- c:\program files\Common Files\L&H
2008-12-27 23:49 . 2008-12-27 23:49 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\Stationery
2008-12-27 23:48 . 2008-12-27 23:48 <DIR> d-------- C:\MEDIA
2008-12-27 23:48 . 2008-12-27 23:49 <DIR> d-------- C:\CLIPART
2008-12-27 23:47 . 2008-12-27 23:50 <DIR> d-------- C:\Templates
2008-12-27 23:47 . 2009-01-14 22:40 <DIR> d-------- C:\OFFICE11
2008-12-25 22:35 . 2008-12-25 23:24 <DIR> d-------- c:\program files\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\users\All Users\Quark
2008-12-25 22:28 . 2008-12-25 22:29 <DIR> d-------- c:\programdata\Quark
2008-12-23 03:47 . 2008-12-23 03:47 138,240 --a------ c:\windows\System32\drivers\Rtlh86.sys
2008-12-23 03:47 . 2008-12-23 03:47 10,240 --a------ c:\windows\System32\RtNicProp32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-20 21:47 --------- d-----w c:\programdata\Google Updater
2009-01-19 23:43 --------- d-----w c:\users\bosko\AppData\Roaming\uTorrent
2009-01-19 19:14 --------- d-----w c:\program files\Common Files\InstallShield
2009-01-19 19:13 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-19 14:31 --------- d-----w c:\programdata\Microsoft Help
2009-01-18 03:15 --------- d-----w c:\program files\Wireless WEP Key Password Spy
2009-01-18 03:15 --------- d-----w c:\program files\ICQ
2009-01-18 03:15 --------- d-----w c:\program files\AWR
2009-01-18 03:14 --------- d-----w c:\program files\YouTube Downloader
2009-01-18 02:30 --------- d-----w c:\program files\IObit
2009-01-18 02:05 --------- d-----w c:\program files\Nero
2009-01-17 23:56 --------- d-----w c:\program files\FlashGet
2009-01-17 22:06 --------- d-----w c:\program files\Common Files\Ahead
2009-01-17 21:32 --------- d-----w c:\users\bosko\AppData\Roaming\Skype
2009-01-17 21:25 --------- d-----w c:\programdata\Skype
2009-01-17 21:25 --------- d-----w c:\program files\Skype
2009-01-14 21:41 --------- d-----w c:\program files\Windows Mail
2008-12-29 16:43 --------- d-----w c:\program files\Microsoft Works
2008-12-22 14:16 --------- d-----w c:\program files\Opera
2008-12-19 19:59 --------- d-----w c:\programdata\PC Drivers HeadQuarters
2008-12-19 19:59 --------- d-----w c:\program files\PC Drivers HeadQuarters
2008-12-17 23:40 --------- d-----w c:\program files\Restorer2000 Pro
2008-12-17 22:39 --------- d-----w c:\users\bosko\AppData\Roaming\Cimaware
2008-12-17 22:34 --------- d-----w c:\program files\Cimaware
2008-12-14 23:05 --------- d-----w c:\program files\Google
2008-12-11 14:01 --------- d-----w c:\users\bosko\AppData\Roaming\Xilisoft Corporation
2008-12-11 14:01 --------- d-----w c:\program files\Xilisoft
2008-12-03 21:14 --------- d-----w c:\program files\WMR11
2008-12-03 21:13 --------- d-----w c:\program files\Replay Media Catcher
2008-12-01 20:15 --------- d-----w c:\program files\MSXML 4.0
2008-11-27 13:39 --------- d-----w c:\program files\ABBYY FineReader 9.0
2008-11-27 13:35 --------- d-----w c:\program files\Common Files\ABBYY
2008-11-27 12:51 --------- d-----w c:\program files\HP
2008-11-27 01:22 --------- d-----w c:\program files\Hewlett-Packard
2008-11-24 17:15 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-11-24 17:15 --------- d-----w c:\program files\Adobe Media Player
2008-11-21 22:07 --------- d-----w c:\program files\Odigo
2008-11-21 15:55 --------- d-----w c:\users\bosko\AppData\Roaming\DMCache
2008-11-17 16:07 323,584 ----a-w c:\windows\System32\AUDIOGENIE2.DLL
2008-11-17 16:07 237,568 ----a-w c:\windows\System32\rmc_rtspdl.dll
2008-11-17 16:07 156,672 ----a-w c:\windows\System32\rmc_fixasf.exe
2008-11-01 03:44 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 ----a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 ----a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 06:29 2,927,104 ----a-w c:\windows\explorer.exe
2008-10-29 02:21 425,984 ----a-w c:\windows\System32\ATIDEMGX.dll
2008-10-29 02:20 331,776 ----a-w c:\windows\System32\atipdlxx.dll
2008-10-29 02:20 262,144 ----a-w c:\windows\System32\Oemdspif.dll
2008-10-29 02:20 159,744 ----a-w c:\windows\System32\atitmmxx.dll
2008-10-29 02:19 43,520 ----a-w c:\windows\System32\ati2edxx.dll
2008-10-29 02:19 274,432 ----a-w c:\windows\System32\Ati2evxx.dll
2008-10-29 02:18 712,704 ----a-w c:\windows\System32\Ati2evxx.exe
2008-10-29 02:03 3,955,712 ----a-w c:\windows\System32\atiumdag.dll
2008-10-29 01:47 10,629,120 ----a-w c:\windows\System32\atioglxx.dll
2008-10-29 01:41 4,730,880 ----a-w c:\windows\System32\atiumdva.dll
2008-10-29 01:27 54,272 ----a-w c:\windows\System32\atiadlxx.dll
2008-10-29 01:27 50,688 ----a-w c:\windows\System32\amdpcom32.dll
2008-10-23 22:01 410,976 ----a-w c:\windows\System32\deploytk.dll
2008-10-22 03:57 241,152 ----a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-22 01:22 2,048 ----a-w c:\windows\System32\tzres.dll
2008-10-21 17:51 118,784 ----a-w c:\windows\System32\atibrtmon.exe
2008-10-21 05:25 296,960 ----a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 ----a-w c:\windows\System32\connect.dll
2008-10-01 21:04 174 --sha-w c:\program files\desktop.ini
2006-11-01 23:30 87,552 ----a-w c:\users\bosko\BootSect.exe
.

((((((((((((((((((((((((((((( snapshot_2009-01-19_21.42.35,20 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-01-20 21:39:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-19 18:42:34 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-01-20 21:39:31 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-01-19 18:44:56 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-01-20 21:41:43 262,144 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2009-01-19 18:44:14 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 21:41:04 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-01-20 21:41:04 262,144 ---ha-w c:\windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-20 21:46:34 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-19 18:46:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-20 21:46:34 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-19 18:46:38 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-20 21:46:34 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-16 21:51:56 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-01-20 22:24:53 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2009-01-19 18:49:35 101,052 ----a-w c:\windows\System32\perfc009.dat
+ 2009-01-20 21:46:35 101,052 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-19 18:49:35 586,980 ----a-w c:\windows\System32\perfh009.dat
+ 2009-01-20 21:46:35 586,980 ----a-w c:\windows\System32\perfh009.dat
- 2009-01-19 18:45:06 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
+ 2009-01-20 21:42:02 5,448 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1829870228-2469409553-779331432-1000_UserData.bin
- 2009-01-19 18:45:06 56,900 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 21:42:02 56,940 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-18 19:43:05 34,102 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-01-20 21:42:00 34,176 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-01-17 57344]

[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"="c:\windows\system32\msconfig.exe" [2008-01-18 227840]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"snpstd2"="c:\windows\vsnpstd2.exe" [2007-04-13 307200]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 21:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2007-08-24 06:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X IDE Setup]
--a------ 2007-03-20 13:36 36864 c:\windows\RaidTool\xInsIDE.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mirabilis ICQ]
--a------ 2003-10-14 17:36 38984 c:\progra~1\ICQ\ICQNet.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-11-06 09:27 200704 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2008-01-18 22:33 1233920 c:\program files\Windows Sidebar\sidebar.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra------ 2008-11-07 14:31 21633320 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SNPSTD2]
--a------ 2007-04-13 12:52 307200 c:\windows\vsnpstd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
--a------ 2007-03-29 11:29 3276800 c:\program files\Analog Devices\SoundMAX\SoundMAX.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2007-04-02 23:32 1261568 c:\program files\Analog Devices\Core\smax4pnp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-10-23 23:01 136600 c:\program files\Java\jre6\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-10-23 22:38 180269 c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-18 22:38 1008184 c:\program files\Windows Defender\MSASCui.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2008-01-18 22:36 2153472 c:\windows\System32\oobefldr.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{67B60EAD-3C77-49AC-90F8-9288200869D1}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{5A7EE9E4-6788-4535-AC41-76500635EA39}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{FA2F8F5B-ED90-4ADE-9C88-CDEF7FEEA73D}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5E991B1D-B1FA-40F7-B13E-4A7E9916DD41}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{D14867AD-22F7-4750-ABF2-D0A685B66C69}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B5109571-B5B3-456A-B589-3DDD29B10494}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{CE2178AB-774D-4D48-A37A-C1FE0F7A3A3E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EFE1FA44-6686-4E23-B969-0F0C30CCB140}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{26BA0090-0487-4DAB-BD06-213A5E5D1DA6}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= UDP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"UDP Query User{CEA48B16-DFD1-4FAA-AD15-97DCD03C428D}c:\\users\\bosko\\appdata\\local\\yahoo!\\messenger for vista\\yahoo.messenger.ymapp.exe"= TCP:c:\users\bosko\appdata\local\yahoo!\messenger for vista\yahoo.messenger.ymapp.exe:yahoo.messenger.ymapp.exe
"TCP Query User{43CB0764-00DD-412B-9F85-6BFBCEDC46CD}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{62614483-3CC9-468D-98F7-D951B75BEEA0}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{5226F6FB-9A3D-491C-8E66-500D4A7EB2EE}c:\\program files\\icq\\icq.exe"= UDP:c:\program files\icq\icq.exe:ICQ
"UDP Query User{AC6E884A-8372-46E9-9869-18A80E2EAC16}c:\\program files\\icq\\icq.exe"= TCP:c:\program files\icq\icq.exe:ICQ
"TCP Query User{7E8A6F46-D485-404D-86F0-43ECEBC71C9E}c:\\program files\\internet download manager\\idman.exe"= UDP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"UDP Query User{C49491B4-1CDD-4152-9F9D-13F57D0961D7}c:\\program files\\internet download manager\\idman.exe"= TCP:c:\program files\internet download manager\idman.exe:Internet Download Manager (IDM)
"TCP Query User{ACED7AD6-DCAF-49F4-AFF2-BCE31D061E9B}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{5CC8D909-E25D-4D62-A9AA-9A914511D029}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{46C1624D-DEC6-45BA-8C6D-F74E4B3CFC08}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{216DA21D-E274-4F46-A0F0-35377379AC80}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{A81602BD-5283-4337-ABCD-DC87055B218A}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{3A951DDA-27EF-44BA-AB10-BB4FDF408DFC}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"{98DCE7C0-D1F9-4D4E-AE25-ABAFC19D9A3B}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{738405EB-A673-401B-948B-2567FA87F1E5}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype

R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [2009-01-17 111184]
R3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
R4 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;c:\program files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 660768]
R4 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [2009-01-17 20560]
R4 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [2009-01-17 51792]
S4 gupdate1c95e4056d7d8d0;Google Update Service (gupdate1c95e4056d7d8d0);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 119280]
.
Contents of the 'Scheduled Tasks' folder

2009-01-20 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-15 00:04]

2009-01-20 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-05 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-04-21 22:21]

2009-01-19 c:\windows\Tasks\User_Feed_Synchronization-{84B48C1F-F902-4578-81EB-EFCD09CA99E9}.job
- c:\windows\system32\msfeedssync.exe [2008-01-18 22:33]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\office11\EXCEL.EXE/3000
TCP: {3C9F5F5F-6B83-485F-B823-C8415F8338CF} = 195.66.160.1 195.66.160.2
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-01-20 23:26:44
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):d3,27,c3,a7,a7,60,b9,10,17,1d,4d,2f,e5,7b,01,6c,e6,58,89,51,fe,
e3,7f,8b,2a,fc,7d,7f,a3,5d,0c,ee,d4,c5,dd,c2,8c,7f,9c,ad,00,00,00,00,00,00,\

[HKEY_USERS\S-1-5-21-1829870228-2469409553-779331432-1000_Classes\CLSID\{fc939414-aa92-4118-afd8-d2fae174aa82}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000145
"Therad"=dword:0000001e
.
Completion time: 2009-01-20 23:28:29
ComboFix-quarantined-files.txt 2009-01-20 22:28:27
ComboFix2.txt 2009-01-19 20:43:49
ComboFix3.txt 2009-01-16 22:50:41
ComboFix4.txt 2009-01-16 21:57:10

Pre-Run: 46.612.353.024 bytes free
Post-Run: 46,373,416,960 bytes free

281 --- E O F --- 2009-01-19 19:12:43

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ovde stvarno više nema ni traga malware-u.

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore




To je ono što ja mogu da uradim. Dalje savete možeš potražiti u forumu Windows.

offline
  • Pridružio: 17 Jun 2008
  • Poruke: 11

ok..hvala ti i veliki pozdrav

Ko je trenutno na forumu
 

Ukupno su 516 korisnika na forumu :: 59 registrovanih, 6 sakrivenih i 451 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 1567 - dana 15 Jul 2016 19:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, _commandos_, _Petar, A.R.Chafee.Jr., acatomic2, Aleksandar Tomić, aleksandar_tatic, aludjekic, Andrija357, aramis s, Arhiv, awathorn, bobeNS, celik, Cobi026, CUCLA70, darkstar101, dzenan_y, Filodendron, FOX2, havoc995, ivan979, ivica976, Jethro, JOntra2, krkalon, Kubovac, kunktator, Ljuba011, Logic005, lovac12, Lošmi, ltcolonel, Mali Veseljak, MarKhan, Mercury, mikrimaus, milimoj, miodrag2, Perko91, rovac, ruseskij, sekretar, Skijavoneska, Skywhaler, smorovic, Srki94, SsssssNOVI, Stija zmija, Taso, theNedjeljko, trutcina, vespa nikola, Viceroy, Vlada1389, voja64, Warhawk, Wrangler2, yrraf