Znaš bobby kad si čitav dan na računaru,pa više ne znaš gde si.Ja hladno dođem sa posla u stan i pročitam poruku i skeniran kućni računar,uradim sve po tvom uputstvu,ali pogrešan računar.Doduše i kući radim na istim programima,ACAD,Sewer itd.Znači.šaljem ti log sa mog ličnog računara,mada su slični.Ako je ovaj u redu,onda mi je to i značajnije,jer privatno radim projekte (vodovod,kanalizacija,projekti izvedenog stanja i slično).
Molim te pogledaj ovaj log.
Pozdrav,
Aco Mitrović sa Pala
ComboFix 08-12-28.04 - mh 2008-12-29 21:05:18.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.457 [GMT 1:00]
Running from: c:\documents and settings\mh\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
AV: AVG 7.5.552 *On-access scanning enabled* (Updated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\autorun.inf
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.
2225-04-08 20:09 . 2225-04-08 20:09 3,120 --a------ c:\windows\kgdswhree.ini
2020-12-29 19:25 . 2020-12-29 19:25 3,120 --a------ c:\windows\kgdssys.ini
2008-12-29 17:58 . 2008-12-29 17:58 236 --a------ C:\sqmdata03.sqm
2008-12-29 17:58 . 2008-12-29 17:58 200 --a------ C:\sqmnoopt03.sqm
2008-12-29 17:54 . 2008-12-29 17:54 <DIR> d-------- c:\documents and settings\mh\Application Data\SkypeCallRecorder
2008-12-29 17:53 . 2008-12-29 21:10 <DIR> d-------- c:\program files\SkypeCallRecorder
2008-12-28 23:45 . 2008-12-28 23:45 236 --a------ C:\sqmdata02.sqm
2008-12-28 23:45 . 2008-12-28 23:45 200 --a------ C:\sqmnoopt02.sqm
2008-12-28 23:24 . 2008-12-28 23:24 <DIR> d-------- c:\program files\Common Files\Aladdin Shared
2008-12-28 23:20 . 2008-12-28 23:20 <DIR> d-------- c:\program files\Rocscience
2008-12-28 01:27 . 2008-12-28 01:27 236 --a------ C:\sqmdata01.sqm
2008-12-28 01:27 . 2008-12-28 01:27 200 --a------ C:\sqmnoopt01.sqm
2008-12-27 21:35 . 2008-12-27 21:35 <DIR> d-------- c:\program files\uTorrent
2008-12-27 21:35 . 2008-12-28 09:37 <DIR> d-------- c:\documents and settings\mh\Application Data\uTorrent
2008-12-26 21:54 . 2008-12-26 21:54 236 --a------ C:\sqmdata00.sqm
2008-12-26 21:54 . 2008-12-26 21:54 200 --a------ C:\sqmnoopt00.sqm
2008-12-26 20:01 . 2000-08-19 18:14 688,128 --a------ c:\windows\system32\BCGCB473.dll
2008-12-26 19:58 . 2008-12-26 19:58 <DIR> d-------- c:\program files\WexTech
2008-12-26 19:58 . 2008-12-26 19:58 <DIR> d-------- c:\program files\Common Files\LHSPF
2008-12-26 19:58 . 2000-05-02 10:03 225,280 --a------ c:\windows\system32\awrtl30.dll
2008-12-26 19:58 . 1998-08-04 11:22 111,616 --------- c:\windows\system32\Ltih30tb.dll
2008-12-26 19:57 . 2000-10-20 13:25 487,184 --a------ c:\windows\system32\Mrt7enu.dll
2008-12-26 19:57 . 2000-10-20 13:25 446,464 --a------ c:\windows\system32\hhactivex.dll
2008-12-26 19:57 . 2000-10-20 13:25 79,360 --a------ c:\windows\system32\acdbres.dll
2008-12-26 19:57 . 2000-10-20 13:25 31,744 --a------ c:\windows\system32\Hlp95en.dll
2008-12-26 19:54 . 2008-12-26 19:58 <DIR> d-------- c:\program files\Common Files\Wextech Shared
2008-12-26 19:52 . 2008-12-26 20:03 <DIR> d-------- c:\program files\AutoCAD 2002
2008-12-26 19:16 . 2008-12-26 19:16 109,192 --ah----- c:\windows\system32\mlfcache.dat
2008-12-26 17:20 . 2008-12-28 09:50 <DIR> dr-h----- C:\$VAULT$.AVG
2008-12-26 17:06 . 2008-12-26 17:06 <DIR> d-------- c:\program files\Ashampoo
2008-12-26 16:56 . 2008-12-28 08:49 <DIR> d-------- c:\documents and settings\mh\Application Data\AVG7
2008-12-26 16:56 . 2008-12-26 16:56 <DIR> d-------- c:\documents and settings\LocalService\Application Data\AVG7
2008-12-26 16:55 . 2008-12-26 16:55 <DIR> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2008-12-26 16:55 . 2008-12-26 17:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg7
2008-12-21 21:12 . 2008-12-21 21:12 <DIR> d-------- c:\program files\IrfanView
2008-12-13 18:43 . 2008-09-27 12:24 428 --a------ C:\ma477.bin
2008-12-12 22:47 . 2008-12-12 22:47 3,751,995 --a------ c:\windows\system32\GPhotos.scr
2008-12-10 20:56 . 2008-12-10 20:56 <DIR> d-------- c:\program files\Typhoon Software
2008-12-10 20:56 . 2008-12-29 21:08 53,312 --a------ c:\windows\system32\drivers\pssdklbf.sys
2008-12-10 20:56 . 2008-12-29 21:08 36,928 --a------ c:\windows\system32\drivers\pssdk41.sys
2008-12-08 19:30 . 2008-12-08 19:31 <DIR> d-------- c:\program files\SopCast
2008-12-07 08:17 . 2008-12-07 08:17 <DIR> d-------- c:\program files\Real
2008-12-07 08:17 . 2008-12-07 08:17 <DIR> d-------- c:\program files\Common Files\xing shared
2008-12-07 08:17 . 2008-12-07 08:17 <DIR> d-------- c:\program files\Common Files\Real
2008-12-06 09:30 . 2008-12-06 09:30 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-06 09:30 . 2008-12-06 18:51 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-29 08:12 . 2008-11-29 08:12 <DIR> d-------- c:\program files\FormatFactory
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 20:11 --------- d-----w c:\documents and settings\mh\Application Data\Skype
2008-12-29 16:54 --------- d-----w c:\documents and settings\mh\Application Data\skypePM
2008-12-28 22:42 --------- d-----w c:\program files\Common Files\Autodesk Shared
2008-12-28 22:41 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-28 22:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 21:00 148,312 ----a-w c:\documents and settings\mh\Application Data\GDIPFONTCACHEV1.DAT
2008-12-28 17:42 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-27 11:03 --------- d-----w c:\documents and settings\mh\Application Data\ZoomBrowser EX
2008-12-27 11:02 --------- d-----w c:\documents and settings\All Users\Application Data\ZoomBrowser
2008-12-26 19:01 --------- d-----w c:\program files\SL-King
2008-12-26 18:41 --------- d-----w c:\program files\Radimpex
2008-12-26 16:30 --------- d-----w c:\program files\Norton SystemWorks
2008-12-26 15:46 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-11 19:57 921,632 ----a-w C:\PA207.DAT
2008-12-07 07:17 348,160 ----a-w c:\windows\system32\msvcr71.dll
2008-12-01 15:53 --------- d-----w c:\program files\Google
2008-11-29 07:38 --------- d-----w c:\program files\Autodesk
2008-11-29 07:21 --------- d-----w c:\documents and settings\mh\Application Data\LimeWire
2008-11-27 19:21 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-27 16:13 --------- d-----w c:\program files\Look 110
2008-11-27 16:13 --------- d-----w c:\program files\Common Files\Look110
2008-11-26 16:18 --------- d-----w c:\program files\Windows Live
2008-11-26 16:18 --------- d-----w c:\program files\Microsoft
2008-11-26 15:55 --------- d-----w c:\program files\Common Files\Windows Live
2008-11-26 00:39 --------- d-----w c:\program files\AVG
2008-11-25 23:58 --------- d-----w c:\documents and settings\mh\Application Data\Ipref
2008-11-11 19:24 --------- d-----w c:\program files\Ipref
2008-10-21 20:20 561,152 ----a-w c:\windows\AJScreensaver.scr
2008-11-25 21:04 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-06-29 08:16 32 --sha-w c:\windows\{1AA9496E-D86D-4F41-BBA3-871F3D31DC01}.dat
2007-06-29 08:17 32 --sha-w c:\windows\{32291D01-820F-4C83-ADBC-3FA13AFAD10F}.dat
2007-06-29 08:16 32 --sha-w c:\windows\{EE474DA8-41EB-498F-984D-E33BB296DE19}.dat
2007-06-29 08:16 32 --sha-w c:\windows\system32\{053EE95C-8EBA-4EAF-88FB-E0DDC15126F0}.dat
2007-06-29 08:16 32 --sha-w c:\windows\system32\{536BFF3C-CC4E-4293-B05B-680DC0A075C1}.dat
2007-06-29 08:17 32 --sha-w c:\windows\system32\{A4FB32A7-1145-45A2-95AC-4E0D550FCAE6}.dat
2008-08-14 08:53 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008081420080815\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"EPSON Stylus DX4400 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-02-10 1937408]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2007-11-06 791792]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-09-09 3513344]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-11-13 2105176]
"Gadwin PrintScreen"="c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2008-12-09 495616]
"Skype Call Recorder"="c:\program files\SkypeCallRecorder\SkypeCallRecorder.exe" [2008-12-08 1180160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-11-25 29744]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-12-07 185872]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-12-27 590848]
"AntiSpyWare2Guard"="c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWare2Guard.exe" [2007-08-14 2334040]
"SoundMan"="SOUNDMAN.EXE" [2004-12-22 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-12-27 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE7-10"="advpack.dll" [2007-07-22 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PC Lighthouse.lnk - c:\program files\Typhoon Software\PC Lighthouse\PC Lighthouse.exe [2008-12-10 1015808]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoCAD Startup Accelerator.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
backup=c:\windows\pss\AutoCAD Startup Accelerator.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gadwin PrintScreen 2.6]
--a------ 2008-12-09 12:08 495616 c:\program files\Gadwin Systems\PrintScreen\PrintScreen.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-14 21:14 77824 c:\program files\Java\jre1.6.0\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2004-12-20 19:41 33792 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"srservice"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AASW2_Service;Ashampoo AntiSpyWare 2 Service;c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\AntiSpyWareService.exe [2008-12-26 728920]
R3 PAC207;Look 110;c:\windows\system32\DRIVERS\PFC027.SYS [2008-11-27 507264]
R3 PsSdk41;PsSdk41;\??\c:\windows\system32\Drivers\pssdk41.sys [2008-12-10 36928]
R3 PsSdkLBF;PsSdkLBF;\??\c:\windows\system32\Drivers\pssdklbf.sys [2008-12-10 53312]
S2 63F3D464;63F3D464;c:\windows\system32\6260E4E2.EXE -k []
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-10-14 29744]
S3 GPU-Z;GPU-Z;\??\c:\docume~1\mh\LOCALS~1\Temp\GPU-Z.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{031e2ede-5011-11dd-bdef-000c76986854}]
\Shell\Auto\command - F:\auto.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\explore\Command - F:\3wcxx91.cmd
\Shell\open\Command - F:\3wcxx91.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06dc2448-4902-11dc-9f1d-000c76986854}]
\Shell\AutoRun\command - F:\yt8a.exe
\Shell\Explore\Command - F:\yt8a.exe
\Shell\Open\Command - F:\yt8a.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d0f7a56-2ab7-11dd-bd98-000c76986854}]
\Shell\Auto\command - F:\auto.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\explore\Command - F:\3wcxx91.cmd
\Shell\open\Command - F:\3wcxx91.cmd
.
Contents of the 'Scheduled Tasks' folder
2008-12-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 14:21]
2008-12-26 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Norton SystemWorks\OBC.exe [2002-08-29 20:30]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Picasa Media Detector - c:\program files\Picasa2\PicasaMediaDetector.exe
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\mh\Application Data\Mozilla\Firefox\Profiles\602ldo58.default\
FF - prefs.js: browser.startup.homepage - hxxp://www3.serbiancafe.com/lat/evropa/|http://www.politika.rs/|http://radiostanica.com/stanice.php?loc=Srb|http://mail.google.com/mail/?zx=vkmz474yxqq1&shva=1#inbox|http://www.yahoo.com/|http://bl124w.blu124.mail.live.com/mail/InboxLight.aspx?n=1926881603|http://webmail.teol.net/showmail.php?Folder=Inbox&unique=192841229191593&FolderLoad=1
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1399.3742\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-12-29 21:09:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(744)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'lsass.exe'(800)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
- - - - - - - > 'csrss.exe'(720)
c:\program files\Ashampoo\Ashampoo AntiSpyWare 2\Guard.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\progra~1\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\program files\Canon\CAL\CALMAIN.exe
.
**************************************************************************
.
Completion time: 2008-12-29 21:13:56 - machine was rebooted [mh]
ComboFix-quarantined-files.txt 2008-12-29 20:13:52
Pre-Run: 8,759,713,792 bytes free
Post-Run: 8,635,015,168 bytes free
255
|