msn virus

msn virus

offline
  • Pridružio: 04 Feb 2011
  • Poruke: 3

kao i vecina tako i ja sinoc pokupim virus preko msn.
samo mogu da uradim log sa DDS a kad krenem sa GMER ili rotrepar komp zakuca
DDS :

mycity.rs/must-login.png


mycity.rs/must-login.png

i uspeo sam da skeniram sa combo fix-om :
ComboFix 11-01-31.02 - DiZ 02/04/2011 14:11:57.4.2 - x86
Rockers International Team® Windows® Royal™ Home Premium 6.0.6001.1.1250.381.1033.18.2047.1209 [GMT 1:00]
Running from: c:\users\DiZ\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton Internet Security *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\System32\calc.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2011-01-04 to 2011-02-04 )))))))))))))))))))))))))))))))
.

2011-02-04 13:18 . 2011-02-04 13:18 -------- d-----w- c:\users\DiZ\AppData\Local\temp
2011-02-04 13:18 . 2011-02-04 13:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-03 08:53 . 2011-02-04 10:25 -------- d-----w- c:\users\DiZ\Tracing
2011-02-03 08:52 . 2011-02-03 08:52 -------- d-----w- c:\program files\Microsoft
2011-02-03 08:52 . 2011-02-03 08:52 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-02-03 08:51 . 2011-02-04 10:01 -------- d-----w- c:\program files\Windows Live
2011-02-03 08:44 . 2011-02-04 10:32 -------- d-----w- c:\users\DiZ\AppData\Local\Windows Live
2011-02-03 08:26 . 2011-02-03 08:26 -------- d-----w- c:\windows\system32\EventProviders
2011-02-03 06:20 . 2011-02-03 06:20 -------- d-----w- c:\program files\Common Files\Windows Live
2011-01-29 08:19 . 2011-01-29 08:19 -------- d-----w- c:\users\DiZ\AppData\Roaming\Big Fish Games
2011-01-27 12:06 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-27 12:06 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-27 12:06 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-27 12:06 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-27 12:06 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-27 12:03 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-27 12:00 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2011-01-27 12:00 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-01-27 12:00 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-27 12:00 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-01-27 12:00 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-01-27 12:00 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-01-27 12:00 . 2010-10-18 13:56 2037248 ----a-w- c:\windows\system32\win32k.sys
2011-01-27 12:00 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-27 12:00 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-27 12:00 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-01-27 11:59 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-01-27 11:59 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-01-27 11:59 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2011-01-27 11:59 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2011-01-27 11:59 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2011-01-27 11:58 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-27 11:54 . 2010-11-03 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-01-27 11:39 . 2009-04-27 12:21 17152 ----a-w- c:\windows\system32\authuitu.dll
2011-01-27 11:39 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2011-01-27 11:39 . 2011-01-27 11:39 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2011-01-24 22:10 . 2011-01-24 22:10 -------- d-----w- c:\users\DiZ\AppData\Roaming\cerasus.media
2011-01-24 22:10 . 2011-01-24 22:10 -------- d-----w- c:\windows\Mystery Stories-Island of Hope
2011-01-24 09:06 . 2011-01-27 11:57 -------- d-----w- c:\users\DiZ\AppData\Roaming\skypePM
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----w- c:\program files\Common Files\Skype
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----r- c:\program files\Skype
2011-01-23 12:53 . 2011-01-27 12:15 -------- d-----w- c:\users\DiZ\AppData\Roaming\Skype
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----w- c:\programdata\Skype
2011-01-21 22:16 . 2011-02-04 12:58 -------- d-----w- C:\TMOTM
2011-01-21 19:16 . 2011-01-21 19:16 -------- d-sh--w- c:\programdata\DSS
2011-01-21 15:42 . 2011-01-22 10:28 -------- d-----w- c:\program files\Electronic Arts
2011-01-21 15:37 . 2008-10-27 09:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2011-01-21 11:17 . 2011-01-21 22:16 -------- d-----w- c:\program files\Undercover
2011-01-21 10:41 . 2011-01-21 10:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\NVIDIA
2011-01-21 10:19 . 2011-01-21 10:19 -------- d-----w- c:\program files\bitComposer Games
2011-01-21 10:17 . 2011-01-21 10:17 -------- d-----w- C:\MONROE
2011-01-21 10:14 . 1996-11-05 15:13 299008 ----a-w- c:\windows\uninst.exe
2011-01-21 10:01 . 2011-01-21 10:06 -------- d-----w- c:\program files\Limbo
2011-01-20 14:25 . 2006-03-17 14:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2011-01-20 14:25 . 2006-03-17 11:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2011-01-20 14:25 . 2006-03-17 11:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2011-01-20 14:25 . 2006-03-17 11:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2011-01-20 14:25 . 2006-03-17 11:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\program files\Nero
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\programdata\Nero
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\program files\Common Files\Nero
2011-01-20 13:51 . 2004-08-19 23:09 619008 ----a-w- c:\windows\system32\dx7vb.dll
2011-01-20 13:51 . 2002-12-11 23:14 602624 ----a-w- c:\windows\system32\dx7vbC.dll
2011-01-20 13:51 . 2002-08-30 12:00 350208 ----a-w- c:\windows\system32\d3drm.dll
2011-01-20 13:51 . 2002-01-17 03:22 102400 ----a-w- c:\windows\system32\cpvButton.ocx
2011-01-20 13:51 . 2001-06-26 18:35 131072 ----a-w- c:\windows\system32\ARButton.ocx
2011-01-20 13:51 . 2000-05-22 14:58 140488 ----a-w- c:\windows\system32\Comdlg32.ocx
2011-01-20 13:51 . 1999-05-07 04:00 211971 ----a-w- c:\windows\system32\Tabctl32.ocx
2011-01-20 13:51 . 1999-05-07 03:00 207363 ----a-w- c:\windows\system32\Richtx32.ocx
2011-01-20 13:51 . 2011-01-20 13:53 691481 ----a-w- c:\windows\unins000.exe
2011-01-20 13:51 . 2001-04-07 15:43 65536 ----a-w- c:\windows\system32\FoxCBmp3.dl
2011-01-20 13:51 . 2000-04-21 02:52 844048 ----a-w- c:\windows\system32\Msdxm6.ocx
2011-01-20 13:51 . 1999-03-29 05:34 110595 ----a-w- c:\windows\system32\Msscript1.ocx
2011-01-20 10:46 . 2011-01-20 10:46 -------- d-----w- c:\program files\City Interactive
2011-01-20 10:33 . 2011-01-23 13:18 -------- d-----w- c:\program files\Nikopol
2011-01-18 18:52 . 2011-02-04 10:20 -------- d-----w- c:\users\DiZ\AppData\Local\SKIDROW
2011-01-18 14:26 . 2011-01-18 14:26 -------- d-----w- c:\program files\Common Files\NSV
2011-01-18 14:20 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-01-18 14:19 . 2011-01-18 14:19 -------- d-----w- c:\program files\Winamp Detect
2011-01-18 14:18 . 2011-01-18 14:18 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2011-01-18 14:18 . 2011-02-04 10:45 -------- d-----w- c:\users\DiZ\AppData\Roaming\Winamp
2011-01-18 14:18 . 2011-01-18 14:24 -------- d-----w- c:\program files\Winamp
2011-01-17 16:03 . 2011-01-17 16:04 -------- d-----w- c:\program files\directx
2011-01-17 15:22 . 2011-01-17 15:22 -------- d-----w- c:\program files\Bohemia Interactive
2011-01-17 15:11 . 2011-01-24 14:27 -------- d-----w- c:\program files\The Adventure Company
2011-01-17 15:08 . 2011-01-17 15:08 218176 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-17 15:08 . 2011-01-17 15:08 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-17 15:07 . 2011-01-17 15:10 -------- d-----w- c:\users\DiZ\AppData\Roaming\DAEMON Tools Lite
2011-01-17 15:07 . 2011-01-17 15:07 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-01-17 11:58 . 2011-01-17 11:58 -------- d-----w- c:\users\DiZ\AppData\Roaming\Vogat Interactive
2011-01-17 10:59 . 2011-01-17 10:59 -------- d-----w- c:\users\DiZ\AppData\Roaming\HdO Adventure
2011-01-17 10:35 . 2011-01-17 10:59 -------- d-----w- c:\users\DiZ\AppData\Roaming\A Gypsy's Tale - The Tower of Secrets
2011-01-13 21:58 . 2011-01-13 21:58 -------- d-----w- c:\users\DiZ\AppData\Roaming\Ghost Ship Studios
2011-01-13 11:32 . 2011-01-13 11:32 -------- d-----w- c:\users\DiZ\AppData\Roaming\Freeze Tag
2011-01-12 12:33 . 2011-01-12 12:33 -------- d-----w- c:\users\DiZ\AppData\Roaming\Gogii
2011-01-12 12:05 . 2011-01-12 12:05 -------- d-----w- c:\users\DiZ\AppData\Roaming\HSA
2011-01-12 11:41 . 2011-01-12 11:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\Casual Mechanics
2011-01-08 20:35 . 2011-01-08 20:35 -------- d-----w- c:\users\DiZ\AppData\Roaming\NevoSoft Games
2011-01-07 18:52 . 2011-01-07 18:53 -------- d-----w- c:\users\DiZ\AppData\Roaming\MastersOfMystery2
2011-01-07 10:25 . 2011-01-07 20:05 -------- d-----w- c:\programdata\MumboJumbo
2011-01-05 17:41 . 2011-01-05 17:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\AlderGames
2011-01-05 15:38 . 2011-01-05 15:38 -------- d-----w- c:\programdata\JoyBits
2011-01-05 15:37 . 2011-01-29 08:17 -------- d-----w- c:\program files\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 21:42 . 2010-12-10 12:41 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-02-03 21:41 . 2010-12-10 13:40 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-02-03 21:41 . 2010-12-10 12:40 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-03 15:16 . 2010-12-10 12:40 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-01-27 11:39 . 2010-12-10 15:31 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2011-01-19 15:25 . 2010-12-10 10:28 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-10 16:14 . 2010-12-10 15:25 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-10 13:21 . 2010-12-10 12:39 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-12-10 12:41 . 2010-12-10 12:41 22328 ----a-w- c:\users\DiZ\AppData\Roaming\PnkBstrK.sys
2010-12-10 12:03 . 2010-12-10 12:05 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-10 11:50 . 2010-12-10 10:36 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-12-10 10:41 . 2010-12-10 10:33 15600 ----a-w- c:\windows\gdrv.sys
2010-11-24 08:00 . 2010-12-13 09:15 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.

------- Sigcheck -------


[-] 2008-01-26 . 2406E3A5FAE743DCE81168A8CDB8573F . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
[-] 2008-01-26 . 2406E3A5FAE743DCE81168A8CDB8573F . 247296 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll
[7] 2006-11-02 . B264DFA21677728613267FE63802B332 . 245248 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.16386_none_caf99b2e2002860e\shsvcs.dll

c:\windows\System32\browser.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-03-11 86016]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-09-03 9726568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3764442160-3111135000-3950808551-1000]
"EnableNotificationsRef"=dword:00000001

R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe [2007-12-05 98984]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-17 218176]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20110126.001\IDSvix86.sys [2010-11-04 287792]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-12-05 594600]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2010-03-10 46256]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-11-17 102448]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-09-07 123496]


--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2011-02-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]

2011-01-31 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - DiZ.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 14:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DiZ\AppData\Roaming\Mozilla\Firefox\Profiles\v8lvo9bu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2011-02-04 14:18
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(1340)
c:\advanced wheel mouse\wh_hook.dll
.
Completion time: 2011-02-04 14:20:37
ComboFix-quarantined-files.txt 2011-02-04 13:20
ComboFix2.txt 2011-02-04 11:37
ComboFix3.txt 2011-02-04 11:01

Pre-Run: 49,423,085,568 bytes free
Post-Run: 49,390,899,200 bytes free

- - End Of File - - E98EF1A336D0E4EFAE77045CD569B7AB

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav Wink

Prvo:
Tvoj Operativini Sistem nije "untouched" verzija koju je izdao Microsoft.

Drugo:
Pokretao si ComboFix. Nemoj to vise da radis!
Pokretanje ComboFix-a bez nadzora helpera moze prozurokovati ozbiljno ostecenje na sistemu.
Pogotovo na ovakvom sistemu.
Sledeci put ako budes imao problema sa pokretanjem alata koji se navode u uputstvu, obrazlozi to u temi.

I zadnje:
Citat:kao i vecina tako i ja sinoc pokupim virus preko msn.

Kako znas da si pokupio virus preko MSN-a. Koji su simptomi? Mozes li molim te da budes malo preciznije i da pojasnis problem?

offline
  • Pridružio: 04 Feb 2011
  • Poruke: 3

pozdrav

magna86 ::Pozdrav Wink

Prvo:
Tvoj Operativini Sistem nije "untouched" verzija koju je izdao Microsoft.

prijatelju otkud ja znam da li "untouched" ili ne,dao sam bio ortaku komp i on mi je ubacio op
magna86 ::Drugo:
Pokretao si ComboFix. Nemoj to vise da radis!
Pokretanje ComboFix-a bez nadzora helpera moze prozurokovati ozbiljno ostecenje na sistemu.
Pogotovo na ovakvom sistemu.
Sledeci put ako budes imao problema sa pokretanjem alata koji se navode u uputstvu, obrazlozi to u temi.

ma to sam citao druge postove gde su drugi imali problema sa msn-om i virusima preko njega i vidim svi skeniraju sa combom i izbace izvestaj Mr. Green , znas ono kud svi tu i mujo Very Happy

magna86 ::I zadnje:
Citat:kao i vecina tako i ja sinoc pokupim virus preko msn.

Kako znas da si pokupio virus preko MSN-a. Koji su simptomi? Mozes li molim te da budes malo preciznije i da pojasnis problem?

pojavio mi se jutros neki fajl u vecini foldera i samo odjednom nestane cinimi se da pre nego sto je nestao imao je oznaku dal lux. ili lex. sad ne znam tacno, taj fajl nisam ranije imao nigde, sad se pojavljuje svuda.

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Kopiraj mi sadrzaj ovo loga.

C:\Qoobox\ComboFix3.txt

offline
  • Pridružio: 04 Feb 2011
  • Poruke: 3

nema combofix3 ima combofix2


ComboFix 11-01-31.02 - DiZ 02/04/2011 14:11:57.4.2 - x86
Rockers International Team® Windows® Royal™ Home Premium 6.0.6001.1.1250.381.1033.18.2047.1209 [GMT 1:00]
Running from: c:\users\DiZ\Desktop\ComboFix.exe
AV: Norton Internet Security *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton Internet Security *Enabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton Internet Security *Disabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\System32\calc.exe . . . is infected!!

.
((((((((((((((((((((((((( Files Created from 2011-01-04 to 2011-02-04 )))))))))))))))))))))))))))))))
.

2011-02-04 13:18 . 2011-02-04 13:18 -------- d-----w- c:\users\DiZ\AppData\Local\temp
2011-02-04 13:18 . 2011-02-04 13:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-02-03 08:53 . 2011-02-04 10:25 -------- d-----w- c:\users\DiZ\Tracing
2011-02-03 08:52 . 2011-02-03 08:52 -------- d-----w- c:\program files\Microsoft
2011-02-03 08:52 . 2011-02-03 08:52 -------- d-----w- c:\program files\Windows Live SkyDrive
2011-02-03 08:51 . 2011-02-04 10:01 -------- d-----w- c:\program files\Windows Live
2011-02-03 08:44 . 2011-02-04 10:32 -------- d-----w- c:\users\DiZ\AppData\Local\Windows Live
2011-02-03 08:26 . 2011-02-03 08:26 -------- d-----w- c:\windows\system32\EventProviders
2011-02-03 06:20 . 2011-02-03 06:20 -------- d-----w- c:\program files\Common Files\Windows Live
2011-01-29 08:19 . 2011-01-29 08:19 -------- d-----w- c:\users\DiZ\AppData\Roaming\Big Fish Games
2011-01-27 12:06 . 2009-11-08 09:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2011-01-27 12:06 . 2009-11-08 09:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2011-01-27 12:06 . 2009-11-08 09:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2011-01-27 12:06 . 2009-11-08 09:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2011-01-27 12:06 . 2009-11-08 09:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2011-01-27 12:03 . 2010-10-28 12:56 2048 ----a-w- c:\windows\system32\tzres.dll
2011-01-27 12:00 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2011-01-27 12:00 . 2010-11-06 11:10 357376 ----a-w- c:\windows\system32\taskschd.dll
2011-01-27 12:00 . 2010-11-06 11:09 603648 ----a-w- c:\windows\system32\schedsvc.dll
2011-01-27 12:00 . 2010-11-06 11:10 345088 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-01-27 12:00 . 2010-11-06 11:10 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-01-27 12:00 . 2010-11-05 00:53 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-01-27 12:00 . 2010-10-18 13:56 2037248 ----a-w- c:\windows\system32\win32k.sys
2011-01-27 12:00 . 2010-12-14 15:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-01-27 12:00 . 2010-10-18 14:01 81920 ----a-w- c:\windows\system32\consent.exe
2011-01-27 12:00 . 2009-08-24 12:16 378368 ----a-w- c:\windows\system32\winhttp.dll
2011-01-27 11:59 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-01-27 11:59 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2011-01-27 11:59 . 2010-10-12 13:52 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2011-01-27 11:59 . 2010-10-12 15:48 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2011-01-27 11:59 . 2010-10-12 13:52 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2011-01-27 11:58 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
2011-01-27 11:54 . 2010-11-03 10:51 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-01-27 11:39 . 2009-04-27 12:21 17152 ----a-w- c:\windows\system32\authuitu.dll
2011-01-27 11:39 . 2009-04-27 12:21 28928 ----a-w- c:\windows\system32\uxtuneup.dll
2011-01-27 11:39 . 2011-01-27 11:39 361216 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2011-01-24 22:10 . 2011-01-24 22:10 -------- d-----w- c:\users\DiZ\AppData\Roaming\cerasus.media
2011-01-24 22:10 . 2011-01-24 22:10 -------- d-----w- c:\windows\Mystery Stories-Island of Hope
2011-01-24 09:06 . 2011-01-27 11:57 -------- d-----w- c:\users\DiZ\AppData\Roaming\skypePM
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----w- c:\program files\Common Files\Skype
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----r- c:\program files\Skype
2011-01-23 12:53 . 2011-01-27 12:15 -------- d-----w- c:\users\DiZ\AppData\Roaming\Skype
2011-01-23 12:53 . 2011-01-23 12:53 -------- d-----w- c:\programdata\Skype
2011-01-21 22:16 . 2011-02-04 12:58 -------- d-----w- C:\TMOTM
2011-01-21 19:16 . 2011-01-21 19:16 -------- d-sh--w- c:\programdata\DSS
2011-01-21 15:42 . 2011-01-22 10:28 -------- d-----w- c:\program files\Electronic Arts
2011-01-21 15:37 . 2008-10-27 09:04 23376 ----a-w- c:\windows\system32\X3DAudio1_5.dll
2011-01-21 11:17 . 2011-01-21 22:16 -------- d-----w- c:\program files\Undercover
2011-01-21 10:41 . 2011-01-21 10:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\NVIDIA
2011-01-21 10:19 . 2011-01-21 10:19 -------- d-----w- c:\program files\bitComposer Games
2011-01-21 10:17 . 2011-01-21 10:17 -------- d-----w- C:\MONROE
2011-01-21 10:14 . 1996-11-05 15:13 299008 ----a-w- c:\windows\uninst.exe
2011-01-21 10:01 . 2011-01-21 10:06 -------- d-----w- c:\program files\Limbo
2011-01-20 14:25 . 2006-03-17 14:49 368640 ----a-w- c:\windows\system32\TwnLib4.dll
2011-01-20 14:25 . 2006-03-17 11:45 802816 ----a-w- c:\windows\system32\imagXRA7.dll
2011-01-20 14:25 . 2006-03-17 11:45 497296 ----a-w- c:\windows\system32\imagXpr7.dll
2011-01-20 14:25 . 2006-03-17 11:45 258048 ----a-w- c:\windows\system32\imagXR7.dll
2011-01-20 14:25 . 2006-03-17 11:45 1757184 ----a-w- c:\windows\system32\imagX7.dll
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\program files\Nero
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\programdata\Nero
2011-01-20 14:25 . 2011-01-20 14:25 -------- d-----w- c:\program files\Common Files\Nero
2011-01-20 13:51 . 2004-08-19 23:09 619008 ----a-w- c:\windows\system32\dx7vb.dll
2011-01-20 13:51 . 2002-12-11 23:14 602624 ----a-w- c:\windows\system32\dx7vbC.dll
2011-01-20 13:51 . 2002-08-30 12:00 350208 ----a-w- c:\windows\system32\d3drm.dll
2011-01-20 13:51 . 2002-01-17 03:22 102400 ----a-w- c:\windows\system32\cpvButton.ocx
2011-01-20 13:51 . 2001-06-26 18:35 131072 ----a-w- c:\windows\system32\ARButton.ocx
2011-01-20 13:51 . 2000-05-22 14:58 140488 ----a-w- c:\windows\system32\Comdlg32.ocx
2011-01-20 13:51 . 1999-05-07 04:00 211971 ----a-w- c:\windows\system32\Tabctl32.ocx
2011-01-20 13:51 . 1999-05-07 03:00 207363 ----a-w- c:\windows\system32\Richtx32.ocx
2011-01-20 13:51 . 2011-01-20 13:53 691481 ----a-w- c:\windows\unins000.exe
2011-01-20 13:51 . 2001-04-07 15:43 65536 ----a-w- c:\windows\system32\FoxCBmp3.dl
2011-01-20 13:51 . 2000-04-21 02:52 844048 ----a-w- c:\windows\system32\Msdxm6.ocx
2011-01-20 13:51 . 1999-03-29 05:34 110595 ----a-w- c:\windows\system32\Msscript1.ocx
2011-01-20 10:46 . 2011-01-20 10:46 -------- d-----w- c:\program files\City Interactive
2011-01-20 10:33 . 2011-01-23 13:18 -------- d-----w- c:\program files\Nikopol
2011-01-18 18:52 . 2011-02-04 10:20 -------- d-----w- c:\users\DiZ\AppData\Local\SKIDROW
2011-01-18 14:26 . 2011-01-18 14:26 -------- d-----w- c:\program files\Common Files\NSV
2011-01-18 14:20 . 2009-09-04 16:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2011-01-18 14:19 . 2011-01-18 14:19 -------- d-----w- c:\program files\Winamp Detect
2011-01-18 14:18 . 2011-01-18 14:18 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2011-01-18 14:18 . 2011-02-04 10:45 -------- d-----w- c:\users\DiZ\AppData\Roaming\Winamp
2011-01-18 14:18 . 2011-01-18 14:24 -------- d-----w- c:\program files\Winamp
2011-01-17 16:03 . 2011-01-17 16:04 -------- d-----w- c:\program files\directx
2011-01-17 15:22 . 2011-01-17 15:22 -------- d-----w- c:\program files\Bohemia Interactive
2011-01-17 15:11 . 2011-01-24 14:27 -------- d-----w- c:\program files\The Adventure Company
2011-01-17 15:08 . 2011-01-17 15:08 218176 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-01-17 15:08 . 2011-01-17 15:08 -------- d-----w- c:\program files\DAEMON Tools Lite
2011-01-17 15:07 . 2011-01-17 15:10 -------- d-----w- c:\users\DiZ\AppData\Roaming\DAEMON Tools Lite
2011-01-17 15:07 . 2011-01-17 15:07 -------- d-----w- c:\programdata\DAEMON Tools Lite
2011-01-17 11:58 . 2011-01-17 11:58 -------- d-----w- c:\users\DiZ\AppData\Roaming\Vogat Interactive
2011-01-17 10:59 . 2011-01-17 10:59 -------- d-----w- c:\users\DiZ\AppData\Roaming\HdO Adventure
2011-01-17 10:35 . 2011-01-17 10:59 -------- d-----w- c:\users\DiZ\AppData\Roaming\A Gypsy's Tale - The Tower of Secrets
2011-01-13 21:58 . 2011-01-13 21:58 -------- d-----w- c:\users\DiZ\AppData\Roaming\Ghost Ship Studios
2011-01-13 11:32 . 2011-01-13 11:32 -------- d-----w- c:\users\DiZ\AppData\Roaming\Freeze Tag
2011-01-12 12:33 . 2011-01-12 12:33 -------- d-----w- c:\users\DiZ\AppData\Roaming\Gogii
2011-01-12 12:05 . 2011-01-12 12:05 -------- d-----w- c:\users\DiZ\AppData\Roaming\HSA
2011-01-12 11:41 . 2011-01-12 11:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\Casual Mechanics
2011-01-08 20:35 . 2011-01-08 20:35 -------- d-----w- c:\users\DiZ\AppData\Roaming\NevoSoft Games
2011-01-07 18:52 . 2011-01-07 18:53 -------- d-----w- c:\users\DiZ\AppData\Roaming\MastersOfMystery2
2011-01-07 10:25 . 2011-01-07 20:05 -------- d-----w- c:\programdata\MumboJumbo
2011-01-05 17:41 . 2011-01-05 17:41 -------- d-----w- c:\users\DiZ\AppData\Roaming\AlderGames
2011-01-05 15:38 . 2011-01-05 15:38 -------- d-----w- c:\programdata\JoyBits
2011-01-05 15:37 . 2011-01-29 08:17 -------- d-----w- c:\program files\Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-03 21:42 . 2010-12-10 12:41 138160 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2011-02-03 21:41 . 2010-12-10 13:40 271200 ----a-w- c:\windows\system32\PnkBstrB.xtr
2011-02-03 21:41 . 2010-12-10 12:40 271200 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-02-03 15:16 . 2010-12-10 12:40 271200 ----a-w- c:\windows\system32\PnkBstrB.ex0
2011-01-27 11:39 . 2010-12-10 15:31 604416 ----a-w- c:\windows\system32\TUProgSt.exe
2011-01-19 15:25 . 2010-12-10 10:28 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-12-10 16:14 . 2010-12-10 15:25 124464 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-12-10 13:21 . 2010-12-10 12:39 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-12-10 12:41 . 2010-12-10 12:41 22328 ----a-w- c:\users\DiZ\AppData\Roaming\PnkBstrK.sys
2010-12-10 12:03 . 2010-12-10 12:05 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-12-10 11:50 . 2010-12-10 10:36 319456 ----a-w- c:\windows\DIFxAPI.dll
2010-12-10 10:41 . 2010-12-10 10:33 15600 ----a-w- c:\windows\gdrv.sys
2010-11-24 08:00 . 2010-12-13 09:15 108032 ----a-w- c:\windows\system32\ff_vfw.dll
.

------- Sigcheck -------


[-] 2008-01-26 . 2406E3A5FAE743DCE81168A8CDB8573F . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
[-] 2008-01-26 . 2406E3A5FAE743DCE81168A8CDB8573F . 247296 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll
[7] 2006-11-02 . B264DFA21677728613267FE63802B332 . 245248 . . [6.0.6000.16386] . . c:\windows\winsxs\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6000.16386_none_caf99b2e2002860e\shsvcs.dll

c:\windows\System32\browser.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WheelMouse"="c:\advanc~1\wh_exec.exe" [2007-03-11 86016]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-09-03 9726568]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3764442160-3111135000-3950808551-1000]
"EnableNotificationsRef"=dword:00000001

R2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe [2007-12-05 98984]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-01-17 218176]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20110126.001\IDSvix86.sys [2010-11-04 287792]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2007-12-05 594600]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2010-03-10 46256]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-11-17 102448]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-09-07 123496]


--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2011-02-04 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 13:37]

2011-01-31 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - DiZ.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 14:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://securityresponse.symantec.com/avcenter/fix_homepage
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\DiZ\AppData\Roaming\Mozilla\Firefox\Profiles\v8lvo9bu.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: PC Sync 2 Synchronisation Extension: bkmrksync@nokia.com - c:\program files\Nokia\Nokia PC Suite 7\bkmrksync
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2011-02-04 14:18
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'Explorer.exe'(1340)
c:\advanced wheel mouse\wh_hook.dll
.
Completion time: 2011-02-04 14:20:37
ComboFix-quarantined-files.txt 2011-02-04 13:20
ComboFix2.txt 2011-02-04 11:37
ComboFix3.txt 2011-02-04 11:01

Pre-Run: 49,423,085,568 bytes free
Post-Run: 49,390,899,200 bytes free

- - End Of File - - E98EF1A336D0E4EFAE77045CD569B7AB

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Ovde nema aktivnog malware-a. Logovi su cisti.
Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

Ko je trenutno na forumu
 

Ukupno su 888 korisnika na forumu :: 35 registrovanih, 4 sakrivenih i 849 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., aleksmajstor, cuculo, dankisha, darkojbn, djboj, gasha, Georgius, janbo, Još malo pa deda, Koca Popovic, krkalon, Kubovac, laki_bb, Lazarus, MB120mm, milutin134, Miškić, moldway, MrNo, naki011, operniki, pavlo, Pohovani_00, raketaš, raptorsi, rovac, S1Mk3, S2M, Simon simonović, Srle993, styg, vathra, x9, yufighter