offline
- dragisa2006
- Novi MyCity građanin
- Pridružio: 17 Nov 2008
- Poruke: 12
|
E, ovako stoje stvari, skenirao sam boot time scan i pronasao ga je i obrisao ali samo na jednom mestu, uostalom evo kako stoje stvari
11/17/2008 20:09
Skenira sve lokalne diskove
Datoteka: C:\Documents and Settings\dr\My Documents\My Videos\ULarko27.rar.part\ULarko27\VA - Ultra Lounge, Cocktails With Cole Porter (2004)\18 - Ella Fitzgerald & Duke Ellington & His Orchestra - Let's Do It (Let's Fall In Love).mp3 Greška 42126 {RAR arhiva je oštecena.}
Datoteka: D:\Instalacije\ANTIVIRUSI\Norton AntiVirus 2004\SUPPORT\MSIE\IEAK6OPT.CAB\ie55urd.exe\Wise0021.bin Greška 42146 {Instalaciona arhiva je oštecena.}
Datoteka: D:\Instalacije\mikro inst\SpellunkerSetup.exe\[Embedded#02d004]\{app}\Spellunker.RWG je inficirana sa Win32:Swizzor-N [Trj], Obrisan
Datoteka: D:\System Volume Information\_restore{9E70937D-7879-4321-ADA8-2558C9E8805B}\RP86\A0011194.exe je inficirana sa Win32:Sality-gen, Obrisan
Datoteka: D:\System Volume Information\_restore{9E70937D-7879-4321-ADA8-2558C9E8805B}\RP89\A0012263.exe\[Embedded#02d004]\{app}\Spellunker.RWG je inficirana sa Win32:Swizzor-N [Trj], Obrisan
Broj skeniranih fascikla: 5952
Broj testiranih datoteka: 606272
Broj inficiranih datoteka: 3
Ostalo sam uradio po instrukcijama i rezultat je sledeci
ComboFix 08-11-16.02 - dr 2008-11-17 23:52:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.466 [GMT 1:00]
Running from: c:\documents and settings\dr\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-10-17 to 2008-11-17 )))))))))))))))))))))))))))))))
.
2008-11-17 18:45 . 2008-11-17 18:45 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-11-17 18:44 . 2008-11-17 18:44 <DIR> d-------- c:\windows\system32\LogFiles
2008-11-17 18:44 . 2008-11-17 18:44 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-11-13 14:26 . 2008-11-17 18:46 1,393 --a------ c:\windows\imsins.BAK
2008-11-13 14:23 . 2008-11-14 20:07 <DIR> d-------- c:\program files\Super Internet TV
2008-11-13 14:17 . 2008-10-03 18:41 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
2008-11-13 14:17 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2008-11-13 14:17 . 2007-03-08 06:10 991,232 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2008-11-13 14:17 . 2008-08-26 08:24 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2008-11-13 14:17 . 2008-08-26 08:24 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2008-11-13 14:17 . 2008-08-26 08:24 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2008-11-13 14:17 . 2008-08-26 08:24 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2008-11-13 14:17 . 2008-08-26 08:24 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2008-11-13 14:17 . 2008-08-25 09:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2008-11-12 12:30 . 2008-11-12 12:30 306,432 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-11-12 12:30 . 2007-12-20 10:41 29,440 --a------ c:\windows\system32\uxtuneup.dll
2008-11-12 02:38 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-10 01:20 . 2008-11-10 01:20 <DIR> d-------- c:\program files\Yahoo!
2008-11-10 01:20 . 2008-11-10 01:29 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-08 17:11 . 2008-11-17 18:09 116 --a------ c:\windows\NeroDigital.ini
2008-11-08 14:58 . 2008-11-08 14:58 <DIR> d-------- c:\program files\Common Files\Ahead
2008-11-08 14:58 . 2008-11-08 14:58 <DIR> d-------- c:\program files\Ahead
2008-11-08 14:58 . 2004-07-26 16:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2008-11-08 14:58 . 2004-07-26 16:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
2008-11-08 14:58 . 2004-07-26 16:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
2008-11-08 14:58 . 2004-07-09 08:43 364,544 --------- c:\windows\system32\TwnLib4.dll
2008-11-08 14:58 . 2004-07-26 16:16 262,144 --------- c:\windows\system32\ImagXR7.dll
2008-11-08 14:58 . 2005-09-01 11:03 127,488 --------- c:\windows\system32\drivers\imagesrv.sys
2008-11-08 14:58 . 2000-06-26 10:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-11-08 14:58 . 2005-09-01 11:03 5,888 --------- c:\windows\system32\drivers\imagedrv.sys
2008-11-05 19:25 . 2008-11-05 19:25 30,946 --a------ c:\windows\system32\drivers\Partizan.sys
2008-11-05 19:25 . 2008-11-05 19:25 28,672 --a------ c:\windows\system32\Partizan.exe
2008-11-05 19:25 . 2005-04-03 15:02 8,944 --a------ c:\windows\system32\drivers\UnHackMeDrv.sys
2008-11-05 18:40 . 2008-11-17 01:12 <DIR> d-------- c:\documents and settings\dr\Application Data\U3
2008-11-04 18:53 . 2008-11-13 15:00 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-04 16:33 . 2008-11-04 16:33 <DIR> d-------- C:\RootkitNO
2008-11-04 16:33 . 2008-11-04 16:33 123 --a------ c:\windows\rootkitno.ini
2008-11-04 11:52 . 2003-06-18 17:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-11-04 11:51 . 2008-11-04 11:51 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-04 11:51 . 2008-11-04 11:51 <DIR> d-------- c:\program files\Common Files\L&H
2008-11-04 11:50 . 2008-11-04 11:50 <DIR> d-------- c:\program files\Microsoft Works
2008-11-04 11:49 . 2008-11-04 11:51 <DIR> d-------- c:\windows\SHELLNEW
2008-11-04 11:49 . 2008-11-04 11:49 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-04 11:14 . 2008-11-04 11:14 <DIR> d-------- c:\windows\Globalization
2008-11-04 11:14 . 2008-11-04 11:14 <DIR> d-------- c:\program files\Sublight
2008-11-04 10:55 . 2008-11-17 01:15 <DIR> d-------- c:\program files\UnHackMe
2008-11-04 10:55 . 2008-11-05 19:25 (2) -rahs-ot- c:\windows\winstart.bat
2008-11-02 16:50 . 2008-11-08 20:55 <DIR> d-------- c:\documents and settings\dr\Application Data\Feedreader
2008-10-31 15:13 . 2008-11-12 12:30 <DIR> d-------- c:\program files\TuneUp Utilities 2008
2008-10-31 15:13 . 2008-10-31 15:13 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-31 15:13 . 2008-10-31 15:13 <DIR> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-10-31 06:13 . 2007-07-30 19:19 271,224 --a------ c:\windows\system32\mucltui.dll
2008-10-31 06:13 . 2007-07-30 19:19 207,736 --a------ c:\windows\system32\muweb.dll
2008-10-31 06:13 . 2007-07-30 19:19 30,072 --a------ c:\windows\system32\mucltui.dll.mui
2008-10-30 23:14 . 2008-10-30 23:14 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition
2008-10-30 23:14 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll
2008-10-30 22:44 . 2008-10-30 23:16 <DIR> d-------- c:\program files\Windows Live
2008-10-30 22:44 . 2008-10-30 22:49 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-10-30 22:44 . 2008-10-30 22:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-29 11:29 . 2008-10-29 11:29 <DIR> d-------- c:\documents and settings\dr\Application Data\TuneUp Software
2008-10-28 18:40 . 2008-10-28 18:40 <DIR> d---s---- c:\documents and settings\dr\UserData
2008-10-27 16:36 . 2008-10-27 16:36 <DIR> d-------- c:\program files\MSXML 6.0
2008-10-26 15:30 . 2008-10-26 15:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Phase One
2008-10-26 12:45 . 2008-10-26 12:45 <DIR> d-------- c:\program files\ReflexiveArcade
2008-10-26 12:45 . 2008-10-26 12:48 <DIR> d-------- c:\program files\Ballistik
2008-10-26 12:24 . 2008-10-26 12:24 <DIR> d-------- c:\program files\Phase One
2008-10-26 12:05 . 2008-10-26 12:05 <DIR> d-------- c:\program files\MSBuild
2008-10-26 12:02 . 2008-10-26 12:02 <DIR> d-------- c:\windows\system32\XPSViewer
2008-10-26 12:02 . 2008-10-26 12:02 <DIR> d-------- c:\program files\Reference Assemblies
2008-10-26 12:02 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2008-10-23 17:15 . 2008-10-23 17:15 <DIR> d-------- c:\program files\MSXML 4.0
2008-10-23 13:38 . 2008-10-23 13:38 <DIR> d-------- c:\program files\DivX
2008-10-23 13:38 . 2003-03-15 21:15 90,112 --a------ c:\windows\unvise32.exe
2008-10-22 23:58 . 2008-10-22 23:58 <DIR> d-------- c:\windows\Sun
2008-10-22 16:09 . 2008-10-22 16:09 42 --a------ c:\windows\system32\Jiii_PNUCT.pnc
2008-10-22 16:08 . 2008-10-22 16:36 <DIR> d-------- c:\program files\Perfect Uninstaller
2008-10-22 16:08 . 2008-10-22 16:08 42 --a------ c:\windows\system32\AK083E209605E394C.lie
2008-10-22 15:04 . 2008-10-22 15:04 <DIR> d-------- c:\program files\Common Files\xing shared
2008-10-21 20:54 . 2008-10-22 16:43 272 --a------ c:\documents and settings\dr\Application Data\ltbpr.dat
2008-10-21 19:01 . 2008-10-21 19:02 <DIR> d-------- c:\program files\Ydde
2008-10-21 17:45 . 2004-08-03 22:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-10-21 17:13 . 2008-10-24 14:05 104 -r-hs---- c:\windows\system32\8E03600645.sys
2008-10-21 15:58 . 2008-11-03 19:30 100 --a------ c:\windows\cdplayer.ini
2008-10-21 13:09 . 2008-10-21 13:09 <DIR> d-------- c:\program files\AcreSoft Health Stars
2008-10-21 13:09 . 2008-10-22 15:04 1,000 --a------ c:\windows\posteriza.INI
2008-10-21 12:04 . 2008-10-21 12:04 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2008-10-21 12:00 . 2008-10-24 14:05 7,520 --ahs---- c:\windows\system32\KGyGaAvL.sys
2008-10-21 11:59 . 2008-11-17 17:48 <DIR> d-------- c:\program files\Corel
2008-10-20 22:19 . 2008-10-20 22:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Adobe Systems
2008-10-20 22:18 . 2008-10-20 22:18 <DIR> d-------- c:\program files\Common Files\Adobe Systems Shared
2008-10-20 20:03 . 2008-10-20 20:03 <DIR> d-------- c:\program files\Real
2008-10-20 20:03 . 2008-10-22 15:04 <DIR> d-------- c:\program files\Common Files\Real
2008-10-20 12:58 . 2004-08-04 02:07 221,184 --a------ c:\windows\system32\wmpns.dll
2008-10-20 08:25 . 2008-10-20 08:25 <DIR> d-------- c:\program files\Java
2008-10-20 08:25 . 2008-06-10 01:32 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-19 21:58 . 2008-10-19 21:58 <DIR> d-------- c:\program files\URUSoft
2008-10-19 21:47 . 2008-10-19 21:47 <DIR> d-------- c:\program files\Webteh
2008-10-19 21:28 . 2008-10-19 21:28 <DIR> d-------- c:\program files\AMD
2008-10-19 21:28 . 2006-11-01 13:42 33,280 --a------ c:\windows\system32\drivers\AmdLLD.sys
2008-10-19 21:27 . 2008-10-21 20:54 <DIR> d-------- c:\windows\Downloaded Installations
2008-10-19 21:10 . 2008-10-19 21:10 <DIR> d-------- c:\documents and settings\dr\Application Data\CyberLink
2008-10-19 21:09 . 2008-10-19 21:09 <DIR> d-------- c:\program files\CyberLink
2008-10-19 21:09 . 2008-10-19 21:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\CyberLink
2008-10-19 21:07 . 2008-10-19 21:07 <DIR> d-------- c:\program files\K-Lite Codec Pack
2008-10-19 21:07 . 2008-07-23 17:50 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2008-10-19 21:07 . 2008-07-04 07:34 860,160 --a------ c:\windows\system32\lameACM.acm
2008-10-19 21:07 . 2008-01-10 13:15 755,027 --a------ c:\windows\system32\xvidcore.dll
2008-10-19 21:07 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2008-10-19 21:07 . 2007-09-04 17:56 164,352 --a------ c:\windows\system32\unrar.dll
2008-10-19 21:07 . 2008-01-10 13:16 159,839 --a------ c:\windows\system32\xvidvfw.dll
2008-10-19 21:07 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2008-10-19 21:07 . 2008-07-25 09:34 81,920 --a------ c:\windows\system32\dpl100.dll
2008-10-19 21:07 . 2008-06-12 19:36 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-10-19 21:07 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-10-19 21:07 . 2007-10-03 16:03 414 --a------ c:\windows\system32\lame_acm.xml
2008-10-19 21:07 . 2008-07-30 20:09 38 --a------ c:\windows\avisplitter.ini
2008-10-19 20:43 . 2008-10-19 20:43 <DIR> d-------- c:\documents and settings\dr\Application Data\Media Player Classic
2008-10-19 20:10 . 2008-08-14 11:00 2,180,352 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-19 20:10 . 2008-08-14 10:58 2,136,064 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-19 20:10 . 2008-08-14 10:22 2,057,728 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-19 20:10 . 2008-08-14 10:22 2,015,744 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-19 19:34 . 2008-06-13 14:10 272,128 --------- c:\windows\system32\drivers\bthport.sys
2008-10-19 19:34 . 2008-06-13 14:10 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-10-19 19:25 . 2008-10-19 19:25 <DIR> d-------- c:\program files\Common Files\Java
2008-10-19 18:59 . 2008-11-16 00:54 <DIR> d--h----- c:\windows\$hf_mig$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 15:23 --------- d-----w c:\program files\Mv2Player
2008-10-21 11:04 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-20 21:20 --------- d-----w c:\program files\Common Files\Adobe
2008-10-19 20:09 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-19 16:57 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-10-19 16:53 --------- d-----w c:\program files\Alwil Software
2008-10-19 16:48 --------- d-----w c:\program files\Conexant
2008-10-19 16:29 --------- d-----w c:\program files\Realtek
2008-10-19 15:55 --------- d-----w c:\program files\microsoft frontpage
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys
2008-09-04 16:42 1,106,944 ----a-w c:\windows\system32\msxml3.dll
2008-08-29 19:06 1,350,664 ----a-w c:\windows\system32\msxml6.dll
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2006-10-03 01:43 2,402,550 ----a-w c:\windows\inf\SET1E2.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"UnHackMe Monitor"="c:\program files\UnHackMe\hackmon.exe" [2007-09-17 228352]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-07 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-07 81920]
"CnxDslTaskBar"="c:\program files\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2003-10-29 462848]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2006-11-17 77824]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"nwiz"="nwiz.exe" [2007-03-07 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\dr\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"MsgCenterExe"="c:\program files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Java\\jre1.6.0_07\\launch4j-tmp\\JDownloader.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-10-19 20560]
R2 UxTuneUp;TuneUp Theme Extension;c:\windows\System32\svchost.exe -k netsvcs [2004-08-04 14336]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys [2008-10-19 60288]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys [2008-10-19 646784]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;c:\windows\system32\DRIVERS\CnxTgN.sys [2008-10-19 108675]
S0 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2008-11-05 30946]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-11-12 306432]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;"c:\program files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 98328]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48496bca-aa86-11dd-8ecc-0016e69d9ceb}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48496bcb-aa86-11dd-8ecc-0016e69d9ceb}]
\sHEll\AutopLAy\COmmand - G:\inyul.pif
\sHEll\AutoRun\command - G:\inyul.pif
\sHEll\eXPlORE\COMMand - G:\inyul.pif
\sHEll\OpEn\comMand - G:\inyul.pif
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
2008-11-14 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClick.exe [2008-01-08 13:31]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\dr\Application Data\Mozilla\Firefox\Profiles\m1i65m0j.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - [Link mogu videti samo ulogovani korisnici]
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-11-17 23:53:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-17 23:54:47
ComboFix-quarantined-files.txt 2008-11-17 22:54:45
Pre-Run: 2.216.456.192 bytes free
Post-Run: 2,264,248,320 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
260 --- E O F --- 2008-11-15 23:55:00
Dopuna: 18 Nov 2008 0:34
Malo sam bio sporiji nego sto sam rekao, izvini ako si cekao.. Poz pa sutra, prekosutra... kad nadjes vremena...
Dopuna: 18 Nov 2008 0:38
A, da, Task Manager sad radi....
Dopuna: 18 Nov 2008 18:48
A imam i neki Bog-te-pita program, valjda anti trojan, sad on nesto prijavljuje, elem pokusao sam da ga uslikam i valjda sam uspeo, sad cu da prikacim, mada jedan nistam slikao, nisam nista brisao niti popravljao da ne bi napravio veci haos.
Dopuna: 18 Nov 2008 18:50
mislim da je druga prijava bila za taj combofix pa zato nisam popravljao, racunam da to mora tako
|