[bobby]Virusi :(

1

[bobby]Virusi :(

offline
  • boksi  Male
  • Ugledni građanin
  • Pridružio: 11 Jun 2008
  • Poruke: 474

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:07:06 PM, on 11/15/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Documents and Settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\TEMP\tempo-DC3.tmp
C:\Documents and Settings\Boris\Desktop\New Folder\TR3.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD3542EA-3674-47E2-BE2A-6F5640FFEADA}: NameServer = 85.255.112.184;85.255.112.67
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 6461 bytes

Dopuna: 15 Nov 2008 19:14



Nije mi jasno sto avast kad nadje virus nece da ga obrise?

Dopuna: 15 Nov 2008 21:16

Ima li neko da pomogne riknuce mi komp help

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • boksi  Male
  • Ugledni građanin
  • Pridružio: 11 Jun 2008
  • Poruke: 474

ComboFix 08-11-13.02 - Boris 2008-11-15 22:24:36.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.27 [GMT 1:00]
Running from: c:\documents and settings\Boris\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\autorun.inf
c:\documents and settings\Boris\Favorites\Cheap Pharmacy Online.url
c:\documents and settings\Boris\Favorites\Search Online.url
c:\documents and settings\Boris\Favorites\SMS TRAP.url
c:\documents and settings\Boris\Favorites\VIP Casino.url
c:\documents and settings\Boris\Start Menu\Cheap Pharmacy Online.url
c:\documents and settings\Boris\Start Menu\Search Online.url
c:\documents and settings\Boris\Start Menu\SMS TRAP.url
c:\documents and settings\Boris\Start Menu\VIP Casino.url
C:\resycled
c:\resycled\boot.com
c:\windows\k.txt
c:\windows\system32\c.ico
c:\windows\system32\kdifu.exe
c:\windows\system32\m.ico
c:\windows\system32\p.ico
c:\windows\system32\s.ico
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2008-10-15 to 2008-11-15 )))))))))))))))))))))))))))))))
.

2008-11-15 22:31 . 2008-11-15 22:31 <DIR> dr-hs---- C:\resycled
2008-11-15 21:39 . 2008-11-15 21:39 <DIR> d-------- c:\documents and settings\Boris\Application Data\ArcaBit
2008-11-15 19:23 . <DIR> c:\windows\LastGood.Tmp
2008-11-15 18:59 . 2008-11-15 18:59 27,904 --a------ c:\windows\system32\drivers\ndisprot.sys
2008-11-15 00:35 . 2008-11-15 00:35 <DIR> d-------- c:\windows\Sun
2008-11-13 10:32 . 2008-11-13 10:32 <DIR> d-------- c:\documents and settings\Boris\Application Data\Thinstall
2008-11-12 23:17 . 2008-11-12 23:17 137,344 --a------ c:\windows\system32\drivers\hwpsgt.sys
2008-11-12 23:17 . 2008-11-12 23:17 9,472 --a------ c:\windows\system32\drivers\lemsgt.sys
2008-11-12 15:16 . 2008-11-12 15:16 0 --a------ c:\windows\nsreg.dat
2008-11-12 14:34 . 2008-11-12 14:34 242,196 ---h----- C:\TREEINFO.WC
2008-11-11 17:12 . 2008-11-11 17:12 <DIR> d-------- c:\program files\Free PDF to Word Doc Converter
2008-11-11 17:03 . 2008-11-11 17:03 <DIR> d-------- c:\windows\PrimoPDF4
2008-11-11 17:03 . 2006-12-11 22:12 176,235 --a------ c:\windows\system32\Primomonnt.dll
2008-11-06 14:33 . 2008-11-06 14:33 <DIR> d-------- c:\program files\Small Rockets
2008-11-06 14:33 . 2008-11-06 14:33 405,504 --a------ c:\windows\system32\srkey.exe
2008-11-06 14:25 . 2008-11-06 14:25 <DIR> d-------- C:\My Games
2008-11-06 12:18 . 2008-11-12 16:02 <DIR> d-------- c:\program files\SweetIM
2008-11-06 12:18 . 2008-11-12 16:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\SweetIM
2008-11-01 19:53 . 2008-11-15 16:07 <DIR> d-------- c:\documents and settings\Boris\Application Data\skypePM
2008-11-01 19:53 . 2008-11-01 19:53 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-11-01 19:52 . 2008-11-01 19:52 <DIR> d-------- c:\program files\Common Files\Skype
2008-10-27 23:40 . 2008-11-15 19:29 <DIR> d-------- c:\windows\BDOSCAN8
2008-10-27 23:19 . 2008-10-27 23:20 <DIR> d-------- c:\documents and settings\Boris\Application Data\Desktopicon
2008-10-27 20:24 . 2008-10-27 20:24 8,704 --a------ c:\windows\system32\sv.exe
2008-10-20 20:28 . 2008-10-20 20:28 <DIR> d-------- c:\windows\system32\xlib254.dll
2008-10-20 20:28 . 2008-10-20 20:28 <DIR> d-------- c:\windows\system32\append.dll
2008-10-20 20:04 . 2008-11-08 13:59 <DIR> d-------- c:\program files\Ubi Soft Games
2008-10-20 18:38 . 2008-10-20 18:38 <DIR> d-------- c:\documents and settings\Boris\Temp
2008-10-18 13:33 . 2003-09-15 10:54 155,648 --a------ c:\windows\system32\setuplib.dll
2008-10-18 13:33 . 2002-08-28 14:35 73,728 --a------ c:\windows\system32\waitwnd.exe
2008-10-17 18:36 . 2008-10-17 18:36 87 --a------ c:\windows\cdplayer.ini
2008-10-16 19:17 . 2008-04-09 09:37 93,268 --a------ c:\windows\VGAsetup.ini
2008-10-16 19:16 . 2008-10-16 19:16 <DIR> d-------- c:\program files\sisagp
2008-10-16 19:16 . 2008-10-16 19:17 <DIR> d-------- c:\program files\SiS VGA Utilities V3.84
2008-10-16 19:16 . 2006-03-22 20:53 337,320 --a------ c:\windows\difxapi.dll
2008-10-16 19:16 . 2006-04-12 18:35 208,896 --a------ c:\windows\Progress.exe
2008-10-16 19:16 . 2008-03-20 17:58 65,536 --------- c:\windows\system32\SiSHook.dll
2008-10-16 19:16 . 2006-04-28 08:56 49,152 --a------ c:\windows\InstFunc.exe
2008-10-16 19:16 . 2008-03-20 17:56 12,288 --a------ c:\windows\InstFunc.dll
2008-10-16 18:47 . 2008-03-20 17:57 262,144 --a------ c:\windows\system32\sistray.exe
2008-10-16 18:47 . 2004-09-03 14:35 184,320 --------- c:\windows\system32\SiSApCom.dll
2008-10-16 18:47 . 2008-03-20 17:57 110,592 --------- c:\windows\system32\TVMode.dll
2008-10-16 18:30 . 2008-10-16 18:30 <DIR> d-------- c:\documents and settings\Boris\Application Data\FarStone
2008-10-16 18:28 . 2008-10-16 18:28 <DIR> d-------- c:\program files\FarStone
2008-10-16 18:28 . 2008-10-16 18:28 5,501 --a------ c:\windows\system32\rtclcmg32.dll
2008-10-16 18:10 . 2008-11-06 13:34 <DIR> d-------- c:\program files\Call of Duty

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 21:31 --------- d-----w c:\documents and settings\Boris\Application Data\Skype
2008-11-15 14:33 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-12 15:03 --------- d-----w c:\program files\Yahoo!
2008-11-12 15:01 --------- d-----w c:\program files\Opera
2008-11-12 14:56 --------- d-----w c:\program files\Google
2008-11-12 14:55 --------- d-----w c:\program files\GameSpy Arcade
2008-11-12 14:55 --------- d-----w c:\program files\ffdshow
2008-11-07 09:42 --------- d-----w c:\program files\mIRC
2008-11-06 13:25 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-06 13:25 --------- d-----w c:\program files\Real
2008-10-30 11:00 --------- d-----w c:\program files\Mv2Player
2008-10-28 00:20 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-18 10:18 --------- d-----w c:\documents and settings\Boris\Application Data\Gearbox Software
2008-10-14 14:44 12,528 ----a-w c:\windows\system32\drivers\secdrv.sys
2008-10-14 14:15 --------- d-----w c:\program files\WinISO
2008-10-13 20:44 --------- d-----w c:\program files\EA GAMES
2008-10-13 19:58 --------- d-----w c:\program files\PowerISO
2008-10-08 13:37 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-10-03 12:37 --------- d-----w c:\program files\Ubisoft
2008-10-02 09:32 --------- d-----w c:\documents and settings\Boris\Application Data\Smith Micro
2008-10-02 09:28 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-01 16:26 --------- d-----w c:\program files\Nival Interactive
2008-09-26 18:41 --------- d-----w c:\documents and settings\Boris\Application Data\Media Player Classic
2008-09-24 11:15 --------- d-----w c:\program files\Common Files\Nero
2008-09-24 11:13 --------- d-----w c:\program files\Nero
2008-09-24 11:13 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-09-24 11:03 --------- d-----w c:\program files\Common Files\Ahead
2008-09-24 11:03 --------- d-----w c:\program files\Ahead
2008-09-05 08:22 158,456 ------w c:\windows\system32\pxwma.dll
2008-09-02 16:09 4,608 ----a-w c:\windows\system32\w95inf32.dll
2008-09-02 16:09 2,272 ----a-w c:\windows\system32\w95inf16.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-05 185896]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SiSPower"="SiSPower.dll" [2008-03-20 c:\windows\system32\SiSPower.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.XVID"= xvid.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-10-23 13:18 202024 c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-05 17:51 133104 c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2008-09-02 19:41 190024 c:\program files\MessengerPlus! 3\MsgPlus.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:06 1667584 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 07:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 13:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-07-07 08:34 167936 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Repair Wizard Scheduler]
--a------ 2007-05-21 05:04 393728 c:\program files\SmartPCTools\Registry Repair Wizard\RCHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 2008-10-08 12:12 111928 c:\program files\SweetIM\Messenger\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-09-02 19:55 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-04 00:02 36352 c:\program files\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-05 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-05 20560]
S3 Ndisprot;ArcNet NDIS Protocol Driver;\??\c:\windows\system32\drivers\Ndisprot.sys [2008-11-15 27904]
S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;c:\windows\system32\DRIVERS\sisnicxp.sys [2008-09-02 32768]
S4 cdawdm;CDAWDM;c:\windows\system32\DRIVERS\CDAWDM.sys []
.
Contents of the 'Scheduled Tasks' folder

2008-11-15 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-05 17:51]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKLM-Run-c:\windows\system32\kdifu.exe - c:\windows\system32\kdifu.exe
MSConfigStartUp-MsnMsgr - ~c:\program files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-TrojanScanner - c:\program files\Trojan Remover\Trjscan.exe
MSConfigStartUp-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Boris\Application Data\Mozilla\Firefox\Profiles\i0axvmw1.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
FF -: plugin - c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\1.2.131.25\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-15 22:34:04
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\Crypserv.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2008-11-15 22:44:00 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-15 21:43:36

Pre-Run: 4,640,698,368 bytes free
Post-Run: 6,521,847,808 bytes free

243

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Daj mi sledeci fajl na proveru:
c:\windows\system32\sv.exe

Uploaduj ga preko sledece forme:
http://www.mycity.rs/ambulanta-upload.php
Javi kada uradis upload.

Deinstaliraj Ares P2P program, ume da destabilizuje ceo sistem.

offline
  • boksi  Male
  • Ugledni građanin
  • Pridružio: 11 Jun 2008
  • Poruke: 474

c:\windows\system32\sv.exe

Obrisao je avast ovaj fajl pokazao ga kao Trojan horse

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Napravi nove HijackThis i ComboFix logove, pa ih postavi da ih pregledam.

offline
  • boksi  Male
  • Ugledni građanin
  • Pridružio: 11 Jun 2008
  • Poruke: 474

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:10 PM, on 11/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Boris\Desktop\New Folder\TR3.exe..exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {3D8700FB-86A4-4CB4-B738-6F0FC016AC7D} (MainControl Class) - http://arcaonline.arcabit.com/ArcaOnline.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 6623 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Treba mi i nov ComboFix log.

offline
  • boksi  Male
  • Ugledni građanin
  • Pridružio: 11 Jun 2008
  • Poruke: 474

ComboFix 08-11-14.01 - Boris 2008-11-16 20:44:49.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.26 [GMT 1:00]
Running from: c:\documents and settings\Boris\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\resycled

.
((((((((((((((((((((((((( Files Created from 2008-10-16 to 2008-11-16 )))))))))))))))))))))))))))))))
.

2008-11-15 22:52 . 2008-11-16 00:00 <DIR> d-------- c:\documents and settings\Boris\.housecall6.6
2008-11-15 21:39 . 2008-11-15 21:39 <DIR> d-------- c:\documents and settings\Boris\Application Data\ArcaBit
2008-11-15 18:59 . 2008-11-15 18:59 27,904 --a------ c:\windows\system32\drivers\ndisprot.sys
2008-11-15 00:35 . 2008-11-15 00:35 <DIR> d-------- c:\windows\Sun
2008-11-13 10:32 . 2008-11-13 10:32 <DIR> d-------- c:\documents and settings\Boris\Application Data\Thinstall
2008-11-12 23:17 . 2008-11-12 23:17 137,344 --a------ c:\windows\system32\drivers\hwpsgt.sys
2008-11-12 23:17 . 2008-11-12 23:17 9,472 --a------ c:\windows\system32\drivers\lemsgt.sys
2008-11-12 15:16 . 2008-11-12 15:16 0 --a------ c:\windows\nsreg.dat
2008-11-12 14:34 . 2008-11-12 14:34 242,196 ---h----- C:\TREEINFO.WC
2008-11-11 17:12 . 2008-11-11 17:12 <DIR> d-------- c:\program files\Free PDF to Word Doc Converter
2008-11-11 17:03 . 2008-11-11 17:03 <DIR> d-------- c:\windows\PrimoPDF4
2008-11-11 17:03 . 2006-12-11 22:12 176,235 --a------ c:\windows\system32\Primomonnt.dll
2008-11-06 14:33 . 2008-11-06 14:33 <DIR> d-------- c:\program files\Small Rockets
2008-11-06 14:33 . 2008-11-06 14:33 405,504 --a------ c:\windows\system32\srkey.exe
2008-11-06 14:25 . 2008-11-06 14:25 <DIR> d-------- C:\My Games
2008-11-06 12:18 . 2008-11-12 16:02 <DIR> d-------- c:\program files\SweetIM
2008-11-06 12:18 . 2008-11-12 16:02 <DIR> d-------- c:\documents and settings\All Users\Application Data\SweetIM
2008-11-01 19:53 . 2008-11-16 16:08 <DIR> d-------- c:\documents and settings\Boris\Application Data\skypePM
2008-11-01 19:53 . 2008-11-01 19:53 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-11-01 19:52 . 2008-11-01 19:52 <DIR> d-------- c:\program files\Common Files\Skype
2008-10-27 23:40 . 2008-11-15 19:29 <DIR> d-------- c:\windows\BDOSCAN8
2008-10-27 23:19 . 2008-10-27 23:20 <DIR> d-------- c:\documents and settings\Boris\Application Data\Desktopicon
2008-10-20 20:28 . 2008-10-20 20:28 <DIR> d-------- c:\windows\system32\xlib254.dll
2008-10-20 20:28 . 2008-10-20 20:28 <DIR> d-------- c:\windows\system32\append.dll
2008-10-20 20:04 . 2008-11-08 13:59 <DIR> d-------- c:\program files\Ubi Soft Games
2008-10-20 18:38 . 2008-10-20 18:38 <DIR> d-------- c:\documents and settings\Boris\Temp
2008-10-18 13:33 . 2003-09-15 10:54 155,648 --a------ c:\windows\system32\setuplib.dll
2008-10-18 13:33 . 2002-08-28 14:35 73,728 --a------ c:\windows\system32\waitwnd.exe
2008-10-17 18:36 . 2008-10-17 18:36 87 --a------ c:\windows\cdplayer.ini
2008-10-16 19:17 . 2008-04-09 09:37 93,268 --a------ c:\windows\VGAsetup.ini
2008-10-16 19:16 . 2008-10-16 19:16 <DIR> d-------- c:\program files\sisagp
2008-10-16 19:16 . 2008-10-16 19:17 <DIR> d-------- c:\program files\SiS VGA Utilities V3.84
2008-10-16 19:16 . 2006-03-22 20:53 337,320 --a------ c:\windows\difxapi.dll
2008-10-16 19:16 . 2006-04-12 18:35 208,896 --a------ c:\windows\Progress.exe
2008-10-16 19:16 . 2008-03-20 17:58 65,536 --------- c:\windows\system32\SiSHook.dll
2008-10-16 19:16 . 2006-04-28 08:56 49,152 --a------ c:\windows\InstFunc.exe
2008-10-16 19:16 . 2008-03-20 17:56 12,288 --a------ c:\windows\InstFunc.dll
2008-10-16 18:47 . 2008-03-20 17:57 262,144 --a------ c:\windows\system32\sistray.exe
2008-10-16 18:47 . 2004-09-03 14:35 184,320 --------- c:\windows\system32\SiSApCom.dll
2008-10-16 18:47 . 2008-03-20 17:57 110,592 --------- c:\windows\system32\TVMode.dll
2008-10-16 18:30 . 2008-10-16 18:30 <DIR> d-------- c:\documents and settings\Boris\Application Data\FarStone
2008-10-16 18:28 . 2008-10-16 18:28 <DIR> d-------- c:\program files\FarStone
2008-10-16 18:28 . 2008-10-16 18:28 5,501 --a------ c:\windows\system32\rtclcmg32.dll
2008-10-16 18:10 . 2008-11-06 13:34 <DIR> d-------- c:\program files\Call of Duty

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-16 19:37 --------- d-----w c:\documents and settings\Boris\Application Data\Skype
2008-11-16 15:34 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-11-12 15:03 --------- d-----w c:\program files\Yahoo!
2008-11-12 15:01 --------- d-----w c:\program files\Opera
2008-11-12 14:56 --------- d-----w c:\program files\Google
2008-11-12 14:55 --------- d-----w c:\program files\GameSpy Arcade
2008-11-12 14:55 --------- d-----w c:\program files\ffdshow
2008-11-07 09:42 --------- d-----w c:\program files\mIRC
2008-11-06 13:25 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-06 13:25 --------- d-----w c:\program files\Real
2008-10-30 11:00 --------- d-----w c:\program files\Mv2Player
2008-10-28 00:20 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-10-18 10:18 --------- d-----w c:\documents and settings\Boris\Application Data\Gearbox Software
2008-10-14 14:44 12,528 ----a-w c:\windows\system32\drivers\secdrv.sys
2008-10-14 14:15 --------- d-----w c:\program files\WinISO
2008-10-13 20:44 --------- d-----w c:\program files\EA GAMES
2008-10-13 19:58 --------- d-----w c:\program files\PowerISO
2008-10-08 13:37 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-10-03 12:37 --------- d-----w c:\program files\Ubisoft
2008-10-02 09:32 --------- d-----w c:\documents and settings\Boris\Application Data\Smith Micro
2008-10-02 09:28 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-01 16:26 --------- d-----w c:\program files\Nival Interactive
2008-09-26 18:41 --------- d-----w c:\documents and settings\Boris\Application Data\Media Player Classic
2008-09-24 11:15 --------- d-----w c:\program files\Common Files\Nero
2008-09-24 11:13 --------- d-----w c:\program files\Nero
2008-09-24 11:13 --------- d-----w c:\documents and settings\All Users\Application Data\Nero
2008-09-24 11:03 --------- d-----w c:\program files\Common Files\Ahead
2008-09-24 11:03 --------- d-----w c:\program files\Ahead
2008-09-05 08:22 158,456 ------w c:\windows\system32\pxwma.dll
2008-09-02 16:09 4,608 ----a-w c:\windows\system32\w95inf32.dll
2008-09-02 16:09 2,272 ----a-w c:\windows\system32\w95inf16.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-09-05 185896]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"SiSPower"="SiSPower.dll" [2008-03-20 c:\windows\system32\SiSPower.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"vidc.XVID"= xvid.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BlueSoleil.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BlueSoleil.lnk
backup=c:\windows\pss\BlueSoleil.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-10-23 13:18 202024 c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-05 17:51 133104 c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2008-09-02 19:41 190024 c:\program files\MessengerPlus! 3\MsgPlus.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-08-04 00:06 1667584 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-09-20 07:51 1836328 c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 13:57 153136 c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-07-07 08:34 167936 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Registry Repair Wizard Scheduler]
--a------ 2007-05-21 05:04 393728 c:\program files\SmartPCTools\Registry Repair Wizard\RCHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
-ra------ 2008-10-08 12:12 111928 c:\program files\SweetIM\Messenger\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-09-02 19:55 39408 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2008-08-04 00:02 36352 c:\program files\Winamp\winampa.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\EA GAMES\\MOHAA\\MOHAA.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-05 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-05 20560]
S3 Ndisprot;ArcNet NDIS Protocol Driver;\??\c:\windows\system32\drivers\Ndisprot.sys [2008-11-15 27904]
S3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;c:\windows\system32\DRIVERS\sisnicxp.sys [2008-09-02 32768]
S4 cdawdm;CDAWDM;c:\windows\system32\DRIVERS\CDAWDM.sys []
.
Contents of the 'Scheduled Tasks' folder

2008-11-16 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-05 17:51]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Boris\Application Data\Mozilla\Firefox\Profiles\i0axvmw1.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
FF -: plugin - c:\documents and settings\Boris\Local Settings\Application Data\Google\Update\1.2.131.25\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-16 20:49:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\Crypserv.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
.
**************************************************************************
.
Completion time: 2008-11-16 20:59:25 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-16 19:59:05

Pre-Run: 6,532,796,416 bytes free
Post-Run: 6,540,546,048 bytes free

217

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Rekao bih da je sada sve cisto.
Ima li jos kakvih vidljivih simptoma?

Ko je trenutno na forumu
 

Ukupno su 625 korisnika na forumu :: 9 registrovanih, 1 sakriven i 615 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: darkojbn, draggan, dragoljub11987, Kenanjoz, Milometer, MilosKop, Mixelotti, opt1, Shilok