Poslao: 01 Dec 2008 17:48
|
offline
- Pridružio: 18 Sep 2008
- Poruke: 32
|
bobby evo log-a .
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:42, on 2008-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\FarStone\VirtualDrive\VDTask.exe
C:\Program Files\Di recnik\Di.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Documents and Settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Aki\Desktop\tr3 .exe\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [Di dictionary] "C:\Program Files\Di recnik\Di.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Prevedi sa Di recnikom - C:\Program Files\Di recnik\diie.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 7888 bytes
|
|
|
|
|
Poslao: 01 Dec 2008 18:13
|
offline
- Pridružio: 18 Sep 2008
- Poruke: 32
|
ComboFix 08-11-30.02 - Aki 2008-12-01 18:02:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.577 [GMT 1:00]
Running from: c:\documents and settings\Aki\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Aki\Application Data\FunWebProducts
c:\windows\system32\Memman.vxd
c:\windows\system32\skinboxer43.dll
.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.
2063-09-19 06:50 . 2063-09-19 06:50 5,501 --a------ c:\windows\system32\rtclmg32.dll
2008-11-29 23:38 . 2008-11-29 23:38 <DIR> d-------- c:\program files\Blaze Media Pro
2008-11-29 23:38 . 2008-11-29 23:38 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{DE097E60-7F86-4350-B083-1F09B6906C92}
2008-11-29 23:34 . 2008-11-29 23:34 493,568 --a------ c:\windows\aki.scr
2008-11-29 23:33 . 2008-11-29 23:33 <DIR> d-------- c:\program files\Video Screensaver Maker
2008-11-29 23:33 . 2008-11-29 23:34 <DIR> d-------- c:\documents and settings\Aki\Application Data\VSSaver
2008-11-29 23:32 . 2008-11-29 23:32 <DIR> d-------- C:\dvd2avi
2008-11-29 23:32 . 2008-11-29 23:32 <DIR> d-------- c:\documents and settings\Aki\Application Data\DVD2AVI Ripper Professional
2008-11-29 23:25 . 2008-11-29 23:25 <DIR> d-------- C:\videodvdmaker
2008-11-29 23:25 . 2008-11-29 23:25 <DIR> d-------- c:\documents and settings\Aki\Application Data\Video DVD Maker FREE
2008-11-28 15:19 . 2008-11-28 15:19 <DIR> d-------- c:\program files\ESET
2008-11-28 15:19 . 2008-11-28 15:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-28 11:54 . 2008-11-28 11:54 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-11-28 11:53 . 2008-11-28 11:54 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-28 11:50 . 2008-11-28 11:50 <DIR> d-------- c:\documents and settings\Aki\Application Data\DAEMON Tools
2008-11-26 16:44 . 2008-11-26 16:44 <DIR> d-------- C:\digitalvideoconverter
2008-11-26 11:52 . 2008-11-26 11:54 <DIR> d-------- c:\program files\Movie DVD Maker
2008-11-26 11:51 . 2008-11-24 06:09 <DIR> d-------- c:\program files\Movie.DVD.Maker.v2.6.1123.g3n
2008-11-23 00:12 . 2008-11-23 00:12 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-22 21:07 . 2008-11-22 21:14 <DIR> d-------- C:\My Disc.VCD
2008-11-21 10:52 . 2008-11-21 10:52 137,344 --a------ c:\windows\system32\drivers\hwpsgt.sys
2008-11-21 10:52 . 2008-11-21 10:52 9,472 --a------ c:\windows\system32\drivers\lemsgt.sys
2008-11-20 21:08 . 2008-11-28 15:29 <DIR> d-------- c:\program files\PremierOpinion
2008-11-20 19:12 . 2008-11-24 16:19 <DIR> d-------- c:\program files\Crawler
2008-11-19 22:46 . 2008-11-19 22:46 <DIR> d-------- c:\documents and settings\Aki\Application Data\Games
2008-11-19 20:14 . 2008-11-19 20:45 <DIR> d-------- c:\program files\FlashGet
2008-11-19 10:53 . 2008-11-19 10:53 <DIR> d-------- c:\program files\Raw Modders Union
2008-11-18 17:40 . 2008-11-19 20:56 <DIR> d-------- c:\program files\Crypt load
2008-11-18 12:32 . 2008-11-28 13:26 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-18 11:49 . 2008-11-18 11:49 <DIR> d-------- c:\program files\FormatFactory
2008-11-17 21:04 . 2008-11-17 21:04 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-16 16:51 . 2008-11-16 16:52 <DIR> d-------- c:\program files\Any Video Converter
2008-11-16 16:51 . 2008-11-16 16:57 <DIR> d-------- c:\documents and settings\Aki\Application Data\Any Video Converter
2008-11-13 00:45 . 2008-11-13 00:45 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-11 21:25 . 2008-11-11 21:25 <DIR> d-------- c:\program files\DVD Photo Slideshow Professional
2008-11-05 11:16 . 2008-11-05 11:16 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2008-11-03 11:35 . 2008-11-03 11:35 <DIR> d-------- c:\documents and settings\Aki\Application Data\EleFun Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 22:11 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-28 10:50 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-23 18:13 --------- d-----w c:\program files\TuneUp Utilities 2006
2008-11-22 23:12 --------- d-----w c:\program files\Java
2008-11-20 20:25 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-19 19:17 --------- d-----w c:\program files\Google
2008-11-19 13:30 --------- d-----w c:\program files\Common Files\Adobe
2008-11-18 14:47 --------- d-----w c:\program files\Flash Slideshow Maker Professional
2008-11-18 11:32 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-16 10:28 --------- d-----w c:\program files\WinAVI Video Converter
2008-10-27 20:07 --------- d-----w c:\program files\Readon Technology
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 18:39 --------- d-----w c:\program files\AnvSoft Flash to Video Converter Professional
2008-10-23 18:38 --------- d-----w c:\program files\Common Files\AVSMedia
2008-10-23 18:38 --------- d-----w c:\program files\AVS4YOU
2008-10-23 18:18 --------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU
2008-10-23 18:18 --------- d-----w c:\documents and settings\Aki\Application Data\AVS4YOU
2008-10-23 17:59 --------- d-----w c:\program files\Anvsoft
2008-10-23 17:52 --------- d-----w c:\program files\Xvid
2008-10-22 21:05 --------- d-----w c:\documents and settings\Aki\Application Data\Skype
2008-10-21 22:36 --------- d-----w c:\program files\Magic Swf2Avi 2008
2008-10-21 22:36 --------- d-----w c:\program files\Flash SWF to GIF AVI Converter
2008-10-21 22:11 --------- d-----w c:\documents and settings\All Users\Application Data\Anvsoft
2008-10-19 09:03 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-19 08:52 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-17 13:51 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-17 13:16 --------- d-----w c:\documents and settings\Aki\Application Data\Software Informer
2008-10-17 10:22 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-16 18:25 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-16 18:25 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-16 09:13 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-16 09:13 --------- d-----w c:\documents and settings\Aki\Application Data\GameHouse
2008-10-14 20:49 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2008-10-13 22:31 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-10-13 22:24 --------- d-----w c:\program files\CCleaner
2008-10-13 22:23 --------- d-----w c:\program files\Yahoo!
2008-10-09 07:31 --------- d-----w c:\program files\Di recnik
2008-10-05 15:33 --------- d-----w c:\program files\Common Files\Java
2008-10-02 21:39 --------- d-----w c:\program files\Software Informer
2008-05-07 08:38 32 ----a-r c:\documents and settings\All Users\hash.dat
2004-11-18 12:15 1,950,208 ----a-w c:\program files\PPVIEWER.MSI
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-02 1267040]
[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-17 490952]
"Google Update"="c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-30 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"VirtualDrive"="c:\program files\FarStone\VirtualDrive\VDTask.exe" [2003-09-26 98304]
"Di dictionary"="c:\program files\Di recnik\Di.exe" [2006-09-29 518144]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-30 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-23 136600]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-06-18 1183744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2005-10-03 23:18 118784 c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 15:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 02:07 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Di dictionary]
--a------ 2006-09-29 14:23 518144 c:\program files\Di recnik\Di.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 08:11 8523776 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 08:11 81920 c:\windows\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2007-02-05 16:35 25370152 c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
--a------ 2005-10-03 23:18 975941 c:\program files\Acronis\TrueImage\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 08:11 1626112 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"TUWinStylerThemeSvc"=3 (0x3)
"NVSvc"=2 (0x2)
"nSvcLog"=2 (0x2)
"nSvcIp"=2 (0x2)
"ForcewareWebInterface"=2 (0x2)
"AcrSch2Svc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"d:\\IGRICE\\War Craft\\War3.exe"=
"d:\\IGRICE\\War Craft\\Warcraft III.exe"=
"c:\\Program Files\\FarStone\\VirtualDrive\\MGR.exe"=
"c:\\Documents and Settings\\Aki\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\IGRICE\\Tap a Jam\\Counter-Strike Source\\hl2.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]
R3 FVDSCSI;FVDSCSI;c:\windows\system32\DRIVERS\fvdscsi.sys [2008-07-18 60008]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\E:\NTGLM7X.sys []
S4 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"c:\program files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 98328]
.
Contents of the 'Scheduled Tasks' folder
2008-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2006\SystemOptimizer.exe [2005-09-21 21:35]
2008-12-01 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-30 10:34]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Aki\Application Data\Mozilla\Firefox\Profiles\xt6ar964.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF -: plugin - c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\1.2.131.27\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Google\Picasa3\npPicasa3.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npigl.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-12-01 18:04:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\relog_ap.dll
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-12-01 18:06:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 17:06:41
Pre-Run: 5,556,539,392 bytes free
Post-Run: 5,730,942,976 bytes free
234 --- E O F --- 2008-11-23 09:14:16
|
|
|
|
Poslao: 01 Dec 2008 18:25
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
ComboFix kaze da je nesto popravljao. Radi li sada hotmail?
|
|
|
|
Poslao: 01 Dec 2008 18:38
|
offline
- Pridružio: 18 Sep 2008
- Poruke: 32
|
poravljeno je samo preko mozille a preko msn-a kad pokusam da otvorim inbox opet nece
|
|
|
|
Poslao: 01 Dec 2008 18:43
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Pod MSN-om podrazumevas MSN Messenger ili sta?
Ako jeste MSN Messenger, je li ti MSN Messenger otvara Internet Explorer da bi pogledao mail?
|
|
|
|
Poslao: 01 Dec 2008 18:49
|
offline
- Pridružio: 18 Sep 2008
- Poruke: 32
|
otvori messenger(na njega sam mislio )internet explorer i pokusa da se loguje na sait i onda ispise "done" kao da se logovao a ostane beo ekran . Na momenat dole uspem da procitam iznad start linije nesto hidden i neki trougao ali vrlo kratko traje i ne uspem da procitam sve sto ispise iu tom momentu . zatim ostane beo ekran kao da je ucitao stranicu .
|
|
|
|
Poslao: 01 Dec 2008 19:03
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Nemam ideju. Log je cist (ne racunajuci ono sto je ComboFix vec sredio).
Je li ti comboFix uradio restart racunara nakon ciscenja?
Ako nije, onda restartuj i probaj ponovo.
Koja ti je verzija IE-a?
Za Javu isto ne mogu da vidim koja ti je verzija.
Messenger ti je isto prilicno mator.
Probaj sa updateom tih komponenti/programa.
|
|
|
|
Poslao: 01 Dec 2008 19:09
|
offline
- Pridružio: 18 Sep 2008
- Poruke: 32
|
IE je 7, java (tm)6 update 10 .Ok vazno da radi bar preko mozille hvala na potrosenom vremenu a uradicu update. da sad deinstaliram combofix?
|
|
|
|
|