offline
- Delete

- Ugledni građanin
- Pridružio: 24 Feb 2006
- Poruke: 435
|
Tokom rada se aktivirao Norton i izbacivao je ovo:
A kad smo taj problemcic "resili" usledio je ovaj log:
ComboFix 07-11-01.1** - zerocool 2007-11-06 1:16:12.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.265 [GMT 1:00]
Running from: C:\Documents and Settings\zerocool\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\7_exception.nls
C:\WINDOWS\system32\ati2paag.dll
C:\WINDOWS\system32\ati2psag.sys
C:\WINDOWS\system32\center.exe
C:\WINDOWS\system32\hrpdcf.bin
C:\WINDOWS\system32\kl80.bin
C:\WINDOWS\Temp\2130192234.exe
C:\WINDOWS\Temp\31751823.exe
C:\WINDOWS\Temp\323215653.exe
C:\WINDOWS\Temp\416893350.exe
C:\WINDOWS\Temp\817982033.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_ATI2PSAG
-------\LEGACY_DRIVER
-------\LEGACY_FCI
-------\LEGACY_PROTECT
-------\LEGACY_RUNTIME
-------\LEGACY_SYSLIBRARY
-------\ati2psag
-------\Driver
-------\FCI
-------\SysLibrary
((((((((((((((((((((((((( Files Created from 2007-10-06 to 2007-11-06 )))))))))))))))))))))))))))))))
.
2007-11-06 01:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-03 09:37 <DIR> d--h----- C:\WINDOWS\PIF
2007-11-03 09:30 <DIR> d-------- C:\Program Files\Xilisoft
2007-11-01 13:36 437,528 --a------ C:\WINDOWS\system32\401COMUPD.EXE
2007-11-01 13:35 144,384 --a------ C:\WINDOWS\system32\DCCMSP32.DLL
2007-11-01 13:35 104,960 --a------ C:\WINDOWS\system32\DCCEXT32.DLL
2007-11-01 13:35 37,888 --a------ C:\WINDOWS\system32\DCCWFP32.DLL
2007-11-01 13:34 <DIR> d-------- C:\Program Files\Common Files\Novell Shared
2007-11-01 13:34 5,350,912 --a------ C:\WINDOWS\system32\Crpe32.dll
2007-11-01 13:34 229,888 --a------ C:\WINDOWS\system32\Crpaig32.dll
2007-11-01 13:34 159,744 --a------ C:\WINDOWS\system32\MFCANS32.DLL
2007-11-01 13:34 132,608 --a------ C:\WINDOWS\system32\WFXMNTHQ.DLL
2007-11-01 13:34 131,072 --a------ C:\WINDOWS\system32\WFXMNT40.DLL
2007-11-01 13:34 129,536 --a------ C:\WINDOWS\system32\WFXSVC.EXE
2007-11-01 13:34 43,520 -ra------ C:\WINDOWS\system32\WFXSNT40.EXE
2007-11-01 13:34 17,920 --a------ C:\WINDOWS\system32\IMPLODE.DLL
2007-11-01 13:34 51 --a------ C:\WINDOWS\WFXDEL.BAT
2007-11-01 13:21 34,354 --a------ C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2007-11-01 13:20 31,744 --a------ C:\WINDOWS\system32\S32STAT.DLL
2007-11-01 13:19 1,046,288 --a------ C:\WINDOWS\system32\msjet35.dll
2007-11-01 13:19 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-11-01 13:19 252,176 --a------ C:\WINDOWS\system32\msrd2x35.dll
2007-11-01 13:19 182,784 --a------ C:\WINDOWS\system32\ddao35.dll
2007-11-01 13:19 123,664 --a------ C:\WINDOWS\system32\Msjint35.dll
2007-11-01 13:19 94,208 --a------ C:\WINDOWS\system32\qdcsinet.dll
2007-11-01 13:19 86,016 --a------ C:\WINDOWS\system32\apitrap.dll
2007-11-01 13:19 24,848 --a------ C:\WINDOWS\system32\msjter35.dll
2007-11-01 13:19 13,792 --a------ C:\WINDOWS\system32\drivers\qdfsdrv.sys
2007-11-01 13:17 <DIR> d-------- C:\Program Files\Symantec
2007-11-01 13:17 <DIR> d-------- C:\Program Files\Norton SystemWorks
2007-11-01 13:17 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-01 13:17 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\Symantec
2007-11-01 13:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-01 13:17 57,696 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-01 13:17 36,864 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-01 13:17 4,032 --a------ C:\WINDOWS\system32\SYMEVNT1.DLL
2007-11-01 12:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Spyware Terminator
2007-11-01 12:16 53,248 --a--c--- C:\WINDOWS\system32\dllcache\wamreg51.dll
2007-11-01 12:16 41,600 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.dll
2007-11-01 12:16 31,232 --a--c--- C:\WINDOWS\system32\dllcache\weitekp9.sys
2007-11-01 11:33 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-11-01 11:33 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-11-01 11:33 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-11-01 11:33 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-10-31 18:21 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-10-31 14:51 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-10-31 14:51 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\PC Tools
2007-10-31 14:51 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-31 14:51 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-31 14:51 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-31 14:51 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-10-31 14:51 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-10-31 14:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-31 12:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Lavasoft
2007-10-31 12:04 63,600 --a------ C:\WINDOWS\system32\seccent.exe
2007-10-31 12:04 26,736 --a------ C:\WINDOWS\system32\errorcheg.exe
2007-10-31 12:02 17,936 --a------ C:\WINDOWS\system32\frmwrk.exe
2007-10-30 22:56 7 --a------ C:\WINDOWS\system32\ngxt.bin
2007-10-30 22:53 4,608 --a------ C:\WINDOWS\system32\drivers\ntoss.sys
2007-10-30 22:53 2,464 --a------ C:\WINDOWS\system32\drivers\ntosnh.sys
2007-10-28 23:18 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\Media Player Classic
2007-10-28 21:12 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2007-10-28 20:41 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2007-10-28 18:20 <DIR> d-------- C:\Program Files\MatroskaProp
2007-10-28 18:19 <DIR> d-------- C:\Program Files\Matroska Pack
2007-10-26 15:48 <DIR> d-------- C:\Program Files\MobiK
2007-10-26 13:34 129,784 --a------ C:\WINDOWS\system32\pxafs.dll
2007-10-23 15:33 <DIR> d-------- C:\Documents and Settings\zerocool\Shared
2007-10-23 15:33 <DIR> d-------- C:\Documents and Settings\zerocool\Incomplete
2007-10-23 15:33 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\LimeWire
2007-10-22 14:40 <DIR> d-------- C:\WINDOWS\Sun
2007-10-20 12:05 <DIR> d-------- C:\Program Files\GameHouse
2007-10-18 17:39 332 --a------ C:\WINDOWS\desctemp.dat
2007-10-18 17:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2007-10-18 17:35 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-10-18 17:35 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-10-18 17:35 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-10-18 17:34 <DIR> d-------- C:\Program Files\IVT Corporation
2007-10-17 23:42 <DIR> d-------- C:\Program Files\Winamp
2007-10-16 22:42 <DIR> d-------- C:\Program Files\dellete
2007-10-16 22:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2007-10-16 11:28 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\uTorrent
2007-10-15 22:14 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-15 22:03 <DIR> d-------- C:\Program Files\Yahoo!
2007-10-15 21:57 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-10-15 21:57 <DIR> d-------- C:\Program Files\MSN Messenger
2007-10-15 21:57 <DIR> d-------- C:\Documents and Settings\zerocool\Contacts
2007-10-15 21:54 <DIR> d-------- C:\Program Files\Java
2007-10-15 21:38 <DIR> d-------- C:\Program Files\Common Files\Java
2007-10-15 21:37 <DIR> d-------- C:\Program Files\LimeWire
2007-10-15 21:05 <DIR> d-------- C:\Program Files\Opera
2007-10-15 21:03 <DIR> d-------- C:\Program Files\uTorrent
2007-10-15 21:01 <DIR> d-------- C:\Program Files\Common Files\Adobe
2007-10-15 20:45 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-15 20:40 <DIR> d-------- C:\Program Files\Lavasoft
2007-10-15 20:40 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-10-15 20:40 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\Lavasoft
2007-10-15 20:12 <DIR> d-------- C:\Documents and Settings\zerocool\Application Data\Ahead
2007-10-15 20:10 <DIR> d-------- C:\Program Files\Nero
2007-10-15 20:10 <DIR> d-------- C:\Program Files\Common Files\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-18 16:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-15 18:49 --------- d-----w C:\Program Files\ATI Technologies
2007-10-15 18:47 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-15 18:42 --------- d-----w C:\Program Files\Crystal Player
2007-10-15 18:37 --------- d-----w C:\Program Files\XviD
2007-10-15 18:37 --------- d-----w C:\Program Files\The Playa
2007-10-15 18:37 --------- d-----w C:\Program Files\DivXCodec
2007-10-15 18:37 --------- d-----w C:\Program Files\DivX
2007-10-15 18:20 --------- d-----w C:\Program Files\SiS7012
2007-10-15 18:13 --------- d-----w C:\Program Files\PowerQuest
2007-10-15 17:21 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-28 17:07 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\WINDOWS\system32\divx.dll
2007-09-04 17:56 164,352 ----a-w C:\WINDOWS\system32\unrar.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"NAV Agent"="C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe" [2001-07-21 09:09]
"WFXSwtch"="C:\PROGRA~1\NORTON~1\WinFax\WFXSWTCH.exe" [2001-07-19 08:04]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-07-19 08:04 C:\WINDOWS\system32\WFXSNT40.EXE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"noskrnl"="C:\WINDOWS\noskrnl.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-08 10:06]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS
R3 QDFSDRV;QDFSDRV;\??\C:\WINDOWS\system32\drivers\qdfsdrv.sys
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys
S3 ntosnh.sys;ntosnh.sys;\??\C:\WINDOWS\system32\drivers\ntosnh.sys
S3 ntoss.sys;ntoss.sys;\??\C:\WINDOWS\system32\drivers\ntoss.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\NCDSTART.EXE
.
Contents of the 'Scheduled Tasks' folder
"2007-11-02 21:47:24 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
"2007-11-02 16:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
"2007-11-06 00:20:54 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-11-06 01:20:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\temp
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2007-11-06 1:33:56 - machine was rebooted
.
--- E O F ---
|