offline
- Lucator
- Novi MyCity građanin
- Pridružio: 08 Sep 2008
- Poruke: 22
|
e diarno sad sam na laptopu tj. ja ne mogu da startujem moj racunar (gde se nalazi ovaj virus) juce sam mogao, sad mi pokaze desktop i zakuje mi mis u sredini i ne moze da se pomera niti mogu da udjem u taskmanager...nigde
plz pomoc sta da radim!?
Dopuna: 29 Dec 2008 10:50
USPEO SAM NEKAKO DA UKLJUCIM KOMP IZ 10TOG PUTA...EVO LOGA:
"Luka" - 2008-12-29 10:24:33 Service Pack 3
ComboFix 07-05.27.BV - Running from: "C:\Documents and Settings\Luka\Desktop\ComboFix\"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
"C:\WINDOWS\system32\crypts.dll"
((((((((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 ))))))))))))))))))))))))))))))))))
2008-12-28 13:18 90,112 --a------ C:\WINDOWS\system32\nobvrqmd.dll
2008-12-28 13:17 291,840 --a------ C:\WINDOWS\system32\ddcDvtqR.dll
2008-12-28 13:17 123,506 --ahs---- C:\WINDOWS\system32\RqtvDcdd.ini2
2008-12-28 13:12 705 --a------ C:\oruocu.exe
2008-12-28 13:12 705 --a------ C:\alfqentw.exe
2008-12-28 13:12 58,880 --a------ C:\WINDOWS\system32\pmnoPgdA.dll
2008-12-28 13:12 45,056 --a------ C:\WINDOWS\system32\fcccbaXq.dll
2008-12-28 13:12 262,106 --a------ C:\cxhfsbpt.exe
2008-12-28 13:12 185,822 --a------ C:\eoqrvvmt.exe
2008-12-28 13:12 112,364 --a------ C:\WINDOWS\system32\drivers\bf49e6db.sys
2008-12-28 13:12 <DIR> d-------- C:\DOCUME~1\Luka\APPLIC~1\gadcom
2008-12-21 16:37 <DIR> d-------- C:\Program Files\Garena
2008-12-21 13:13 <DIR> d-------- C:\Program Files\Zeallsoft
2008-12-20 17:16 487,479 --a------ C:\WINDOWS\system32\SkinMagic.dll
2008-12-20 17:16 <DIR> d-------- C:\Program Files\Smallvideosoft
2008-12-20 17:03 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
2008-12-20 17:02 <DIR> d-------- C:\Fraps
2008-12-20 15:38 4,608 --a------ C:\WINDOWS\system32\bbchlp.dll
2008-12-20 15:38 4,096 --a------ C:\WINDOWS\system32\drivers\bbcap.sys
2008-12-20 15:38 30,720 --a------ C:\WINDOWS\system32\bbcap.dll
2008-12-20 15:38 <DIR> d-------- C:\DOCUME~1\Luka\APPLIC~1\LogSys
2008-12-20 15:38 <DIR> d-------- C:\DOCUME~1\Luka\APPLIC~1\Blueberry
2008-12-20 15:37 <DIR> d--h-c--- C:\DOCUME~1\ALLUSE~1\APPLIC~1\{925D0C31-5256-42ED-B53A-2E541689BD38}
2008-12-20 15:37 <DIR> d-------- C:\WINDOWS\system32\ShellDD
2008-12-20 15:37 <DIR> d-------- C:\Program Files\Common Files\Blueberry Software
2008-12-20 15:37 <DIR> d-------- C:\Program Files\Blueberry Software
2008-12-20 15:37 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\LogSys
2008-12-20 15:36 <DIR> d-------- C:\DOCUME~1\Luka\APPLIC~1\WeGame
2008-12-20 15:35 488,800 --a------ C:\WINDOWS\system32\Ltkrn15u.dll
2008-12-20 15:35 390,496 --a------ C:\WINDOWS\system32\Lfcmp15u.dll
2008-12-20 15:35 185,688 --a------ C:\WINDOWS\system32\Ltfil15u.dll
2008-12-20 15:35 <DIR> d-------- C:\Program Files\WeGame
2008-12-20 15:16 <DIR> d-------- C:\Program Files\Quick Screen Capture
2008-12-20 15:16 <DIR> d-------- C:\MyCaptures
2008-12-19 18:50 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-12-19 18:49 <DIR> d-------- C:\Program Files\Microsoft Synchronization Services
2008-12-19 18:49 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-12-19 18:45 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-12-19 18:45 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft Help
2008-12-19 18:44 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-12-19 18:43 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2008-12-19 18:43 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-12-19 18:43 <DIR> d-------- C:\Program Files\MSBuild
2008-12-19 18:42 575,488 --------- C:\WINDOWS\system32\xpsshhdr.dll
2008-12-19 18:42 117,760 --------- C:\WINDOWS\system32\prntvpt.dll
2008-12-19 18:42 1,676,288 --------- C:\WINDOWS\system32\xpssvcs.dll
2008-12-15 15:30 <DIR> d-------- C:\Program Files\My Drivers
2008-12-14 21:54 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Drivers Headquarters
2008-12-14 21:52 <DIR> d-------- C:\Program Files\PC Drivers HeadQuarters
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-12-29 09:29:33 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\DNA
2008-12-29 09:19:04 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\Skype
2008-12-29 09:00:17 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\skypePM
2008-12-29 08:59:25 -------- d-----w C:\Program Files\DNA
2008-12-28 12:26:19 33,280 ----a-w C:\WINDOWS\system32\rundll32.exe
2008-12-21 18:44:33 41,226 ----a-w C:\WINDOWS\War3Unin.dat
2008-12-21 16:36:55 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\BitTorrent
2008-12-21 15:37:01 -------- d--h--w C:\Program Files\InstallShield Installation Information
2008-12-20 15:19:57 139,264 ----a-w C:\WINDOWS\War3Unin.exe
2008-11-27 10:12:22 -------- d-----w C:\Program Files\World of Warcraft
2008-11-26 18:00:42 -------- d-----w C:\Program Files\Common Files\Blizzard Entertainment
2008-11-26 17:21:30 1,236,208 ----a-w C:\WINDOWS\system32\aswBoot.exe
2008-11-26 17:18:25 93,296 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2008-11-26 17:18:18 94,032 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2008-11-26 17:17:36 111,184 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
2008-11-26 17:17:25 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-11-26 17:16:38 50,864 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2008-11-26 17:16:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2008-11-26 17:15:35 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2008-11-26 17:15:10 97,480 ----a-w C:\WINDOWS\system32\AvastSS.scr
2008-11-24 09:47:40 -------- d-----w C:\Program Files\Winamp
2008-11-24 09:37:37 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\Winamp
2008-11-21 11:59:36 -------- d-----w C:\Program Files\Teamspeak2_RC2
2008-11-16 21:33:17 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\BearShare
2008-11-16 11:06:24 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\Ice Age 2
2008-11-13 17:18:46 -------- d-----w C:\Program Files\Windows Live
2008-11-13 16:54:17 -------- d-----w C:\Program Files\Common Files\Windows Live
2008-11-12 18:57:25 3 ----a-w C:\WINDOWS\system32\Boot.dll
2008-11-05 19:49:29 -------- d-----w C:\DOCUME~1\Luka\APPLIC~1\Hamachi
2008-11-05 19:44:57 25,280 ----a-w C:\WINDOWS\system32\drivers\hamachi.sys
2008-11-05 12:12:27 -------- d-----w C:\Program Files\Messenger
2008-11-05 12:08:45 -------- d-----w C:\Program Files\MSXML 4.0
2008-11-05 10:13:39 -------- d-----w C:\Program Files\WinCustomize
2008-11-05 10:13:39 -------- d-----w C:\Program Files\Common Files\Stardock
2008-10-16 13:13:40 202,776 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-10-16 13:13:40 1,809,944 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-10-16 13:12:22 323,608 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-10-16 13:12:20 561,688 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-10-16 13:09:44 92,696 ----a-w C:\WINDOWS\system32\cdm.dll
2008-10-16 13:09:44 51,224 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-10-16 13:09:44 43,544 ----a-w C:\WINDOWS\system32\wups2.dll
2008-10-16 13:08:58 34,328 ----a-w C:\WINDOWS\system32\wups.dll
2008-09-30 15:43:34 1,286,152 ----a-w C:\WINDOWS\system32\msxml4.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{5C255C8A-E604-49b4-9D64-90988571CECB}=C:\Program Files\Windows Live\Messenger\wlchtc.dll [2008-09-02 21:02]
{68e9008f-e8a2-4571-9592-8555bc6490d9}=C:\WINDOWS\system32\ddcDvtqR.dll [2008-12-28 13:17]
{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c}=C:\WINDOWS\system32\pmnoPgdA.dll [2008-12-28 13:12]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 03:25]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2008-02-22 15:24]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 18:18]
"C-Media Mixer"="Mixer.exe" []
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 09:42]
"w3dr.exe"="C:\Warcraft III\w3dr.exe" [2008-08-03 15:38]
"CorelDRAW Graphics Suite 11b"="C:\Program Files\Corel\Corel Graphics 12\Languages\EN\Programs\Registration.exe" [2003-11-25 12:39]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 22:22]
"LogonStudio"="C:\Program Files\WinCustomize\LogonStudio\logonstudio.exe" [2002-09-03 18:38]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 01:04]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:42]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 14:54]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-09-09 00:02]
"Google Update"="C:\Documents and Settings\Luka\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-05 11:48]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-12-16 12:12]
"gadcom"="C:\Documents and Settings\Luka\Application Data\gadcom\gadcom.exe" [2008-12-28 13:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"="C:\WINDOWS\system32\pmnoPgdA.dll" [2008-12-28 13:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
%SystemRoot%\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnoPgdA]
pmnoPgdA.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 C:\WINDOWS\system32\ddcDvtqR
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
napagent
Contents of the 'Scheduled Tasks' folder
2008-12-29 09:12:20 C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
2008-12-29 09:00:35 C:\WINDOWS\tasks\zyhunrde.job
********************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, gmer.net
Rootkit scan 2008-12-29 10:31:23
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
disk error: C:\WINDOWS\
please note that you need administrator rights to perform deep scan
********************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\tdssserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
Completion time: 2008-12-29 10:33:56
C:\ComboFix-quarantined-files.txt ... 2008-12-29 10:33
C:\ComboFix2.txt ... 2008-09-09 18:09
--- E O F ---
|