offline
- dragan_v
- Novi MyCity građanin
- Pridružio: 27 Feb 2009
- Poruke: 8
|
pojavi se ikonica pored sata. crveni kruzic sa x na sebi i natips yu have security problem. da dodam - korisitm adsl vec nekoliko meseci i pokusao sam da nadjem sp1. al nikako. nasao sam i sp2 i sp3 skinuo ih al nemogu da ih instaliram bez sp1
Dopuna: 27 Feb 2009 23:18
ComboFix 09-02-27.02 - Administrator 2009-02-27 23:07:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.0.1252.1.1033.18.510.82 [GMT 1:00]
Running from: e:\documents and settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\documents and settings\Administrator\Start Menu\A360
e:\documents and settings\Administrator\Start Menu\A360\A360.lnk
e:\documents and settings\Administrator\Start Menu\A360\Help.lnk
e:\documents and settings\Administrator\Start Menu\A360\Registration.lnk
e:\program files\Common Files\System\Uninstall
e:\program files\Common Files\System\Uninstall\Uninstall A360.lnk
e:\windows\n.tmp
e:\windows\system32\6HfbdRv1.exe.a_a
e:\windows\system32\init32.exe
Infected copy of e:\windows\system32\userinit.exe was found and disinfected
Restored copy from - e:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-27 to 2009-02-27 )))))))))))))))))))))))))))))))
.
2009-02-26 08:58 . 2009-02-26 08:58 168 --a------ e:\windows\wininit.ini
2009-02-26 08:37 . 2009-02-27 10:31 <DIR> d-------- e:\program files\Spybot - Search & Destroy
2009-02-26 08:37 . 2009-02-27 10:31 <DIR> d-------- e:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-26 04:19 . 2009-02-26 04:19 300,032 --a------ e:\windows\system32\winconfig.dll
2009-02-26 00:46 . 2009-02-26 00:46 118 --a------ e:\windows\system32\MRT.INI
2009-02-24 10:43 . 2009-02-24 10:43 <DIR> d-------- e:\documents and settings\Administrator\Application Data\Logs
2009-02-24 10:36 . 2009-02-24 10:37 0 --a------ E:\END
2009-02-19 21:13 . 2001-08-17 22:36 146,944 --a------ e:\windows\system32\ptpusd.dll
2009-02-19 21:13 . 2001-08-17 13:53 13,824 --a------ e:\windows\system32\drivers\usbscan.sys
2009-02-19 21:13 . 2001-08-17 13:53 13,824 --a--c--- e:\windows\system32\dllcache\usbscan.sys
2009-02-19 21:13 . 2001-08-17 22:36 5,632 --a------ e:\windows\system32\ptpusb.dll
2009-02-18 19:17 . 2009-02-19 07:14 <DIR> d-------- e:\documents and settings\Administrator\Application Data\DivX
2009-02-18 19:13 . 2008-11-06 17:37 129,784 --------- e:\windows\system32\pxafs.dll
2009-02-18 19:13 . 2008-11-06 17:37 120,056 --------- e:\windows\system32\pxcpyi64.exe
2009-02-18 19:13 . 2008-11-06 17:37 118,520 --------- e:\windows\system32\pxinsi64.exe
2009-02-18 18:51 . 2003-03-15 22:15 90,112 --a------ e:\windows\unvise32.exe
2009-02-18 18:50 . 2009-02-18 19:13 <DIR> d-------- e:\program files\DivX
2009-02-18 18:37 . 2009-02-19 09:00 2,522 --a------ e:\windows\MDVDP.Ini
2009-02-15 15:10 . 2009-02-15 15:10 <DIR> d-------- e:\program files\Readon Technology
2009-02-15 07:44 . 2002-11-14 20:42 218,624 --a------ e:\windows\system32\srrstr.dll
2009-02-15 07:44 . 2002-11-14 20:42 218,624 --a--c--- e:\windows\system32\dllcache\srrstr.dll
2009-02-15 07:43 . 2009-02-15 07:51 <DIR> d--h-c--- e:\windows\$xpsp1hfm$
2009-02-15 07:43 . 2003-08-02 05:14 25,600 --a------ e:\windows\system32\xpsp1hfm.exe
2009-02-14 05:46 . 2009-02-14 05:46 <DIR> d-------- e:\windows\system32\bits
2009-02-13 18:53 . 2004-07-01 23:08 361,984 --a--c--- e:\windows\system32\dllcache\qmgr.dll
2009-02-13 18:53 . 2004-07-01 23:08 331,776 --a------ e:\windows\system32\winhttp.dll
2009-02-13 18:53 . 2004-07-01 00:59 158,720 --------- e:\windows\system32\xpob2res.dll
2009-02-13 18:53 . 2004-07-01 23:08 17,408 --a------ e:\windows\system32\qmgrprxy.dll
2009-02-13 18:53 . 2004-07-01 23:08 17,408 --a--c--- e:\windows\system32\dllcache\qmgrprxy.dll
2009-02-13 18:53 . 2004-07-01 23:08 7,680 -----c--- e:\windows\system32\dllcache\bitsprx2.dll
2009-02-13 18:53 . 2004-07-01 23:08 7,680 --------- e:\windows\system32\bitsprx2.dll
2009-02-13 18:53 . 2004-07-01 23:08 7,168 -----c--- e:\windows\system32\dllcache\bitsprx3.dll
2009-02-13 18:53 . 2004-07-01 23:08 7,168 --------- e:\windows\system32\bitsprx3.dll
2009-02-13 18:49 . 2009-02-13 18:49 <DIR> d---s---- e:\windows\system32\Microsoft
2009-02-13 18:48 . 2008-10-16 14:12 561,688 --a------ e:\windows\system32\wuapi.dll
2009-02-13 18:48 . 2008-10-16 14:12 323,608 --a------ e:\windows\system32\wucltui.dll
2009-02-13 18:48 . 2008-10-16 14:12 213,528 --a------ e:\windows\system32\wuaucpl.cpl
2009-02-13 18:48 . 2008-10-16 14:09 43,544 --a------ e:\windows\system32\wups2.dll
2009-02-13 18:48 . 2008-10-16 14:08 34,328 --a------ e:\windows\system32\wups.dll
2009-02-13 18:48 . 2008-10-16 14:09 31,768 --a------ e:\windows\system32\wucltui.dll.mui
2009-02-13 18:48 . 2008-10-16 14:07 23,576 --a------ e:\windows\system32\wuaucpl.cpl.mui
2009-02-13 18:48 . 2008-10-16 14:07 23,576 --a------ e:\windows\system32\wuapi.dll.mui
2009-02-13 18:48 . 2008-10-16 14:07 18,456 --a------ e:\windows\system32\wuaueng.dll.mui
2009-02-13 18:47 . 2009-02-13 18:47 <DIR> d---s---- e:\documents and settings\Administrator\UserData
2009-02-13 10:14 . 2009-02-13 10:24 <DIR> d-------- e:\program files\Online TV Player 4
2009-02-13 10:07 . 2009-02-13 10:07 <DIR> d-------- e:\program files\Common Files\Download Manager
2009-02-10 10:29 . 2009-02-10 11:04 <DIR> d-------- e:\program files\TVPlayerClassic
2009-02-10 09:48 . 2009-02-10 09:48 <DIR> d-------- e:\documents and settings\All Users\Application Data\TVU Networks
2009-02-10 09:48 . 2009-02-10 09:48 <DIR> d-------- e:\documents and settings\Administrator\Application Data\TVU Networks
2009-02-03 07:05 . 2005-06-01 22:57 697,884 --------- e:\windows\~df394b.tmp
2009-01-30 21:46 . 2005-06-21 16:43 163,840 --a------ e:\windows\system32\igfxres.dll
2009-01-30 18:38 . 2009-01-30 18:38 <DIR> d-------- e:\program files\SystemRequirementsLab
2009-01-30 18:38 . 2009-01-30 18:38 <DIR> d-------- e:\documents and settings\Administrator\Application Data\SystemRequirementsLab
2009-01-29 07:47 . 2009-01-29 07:47 <DIR> d-------- e:\windows\system32\CatRoot_bak
2009-01-28 09:28 . 2009-01-28 09:28 376,832 --------- e:\windows\Setup1.exe
2009-01-28 09:28 . 2009-01-28 09:28 73,216 --a------ e:\windows\ST6UNST.EXE
2009-01-27 23:21 . 2008-09-18 16:53 352,256 --a------ e:\windows\system32\AlphaImageControl.ocx
2009-01-27 23:21 . 2008-09-12 18:30 237,568 --a------ e:\windows\system32\Abutton.ocx
2009-01-27 23:21 . 2001-06-26 17:35 131,072 --a------ e:\windows\system32\ARButton.ocx
2009-01-27 23:21 . 1998-06-24 02:00 108,336 --a------ e:\windows\system32\MSWINSCK.OCX
2009-01-27 23:21 . 2002-07-04 12:27 61,440 --a------ e:\windows\system32\TransPictureBox.ocx
2009-01-27 23:15 . 2009-01-27 23:15 <DIR> d-------- e:\documents and settings\Administrator\Application Data\RevoluTV
2009-01-27 22:58 . 2009-01-27 22:58 <DIR> d-------- e:\documents and settings\Administrator\LocalLow
2009-01-27 22:52 . 2009-01-27 22:52 10 --a------ e:\windows\system32\810429tv4-test.jun
2009-01-27 22:44 . 2009-01-27 22:44 <DIR> d-------- e:\documents and settings\Administrator\Application Data\MMToolz
2009-01-27 22:28 . 2009-01-27 22:28 <DIR> d-------- e:\documents and settings\Administrator\Application Data\FDRLab
2009-01-27 10:59 . 2009-01-27 10:59 <DIR> d-------- e:\documents and settings\Administrator\Application Data\Participatory Culture Foundation
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-27 12:33 --------- d-----w e:\documents and settings\All Users\Application Data\Google Updater
2009-02-25 22:56 --------- d-----w e:\documents and settings\Administrator\Application Data\MSN6
2009-02-13 17:54 --------- d-----w e:\program files\Google
2009-02-13 09:47 --------- d--h--w e:\program files\InstallShield Installation Information
2009-02-13 09:47 --------- d-----w e:\program files\Common Files\InstallShield
2009-01-21 08:29 --------- d-----w e:\program files\Globe7
2009-01-21 08:12 --------- d-----w e:\documents and settings\Administrator\Application Data\Globe7
2009-01-20 21:45 --------- d-----w e:\documents and settings\Administrator\Application Data\JLC's Software
2009-01-16 20:57 --------- d-----w e:\documents and settings\Administrator\Application Data\vlc
2009-01-16 20:54 --------- d-----w e:\program files\Chama Digital Media
2009-01-16 19:58 94 ----a-w E:\Iotmrd.sys
2009-01-16 19:51 --------- d-----w e:\documents and settings\Administrator\Application Data\ppStream
2009-01-05 22:33 3,751,995 ----a-w e:\windows\system32\GPhotos.scr
2009-01-01 20:00 --------- d-----w e:\program files\Common Files\xing shared
2009-01-01 20:00 --------- d-----w e:\program files\Common Files\Real
2009-01-01 19:59 --------- d-----w e:\program files\Real
2008-12-31 19:41 --------- d-----w e:\program files\YouTube Downloader
2008-12-24 20:08 410,984 ----a-w e:\windows\system32\deploytk.dll
2008-12-11 00:33 86,016 ----a-w e:\windows\system32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w e:\windows\system32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w e:\windows\system32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w e:\windows\system32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w e:\windows\system32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w e:\windows\system32\dpu11.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\ctfmon.exe" [2001-08-23 13312]
"MSMSGS"="e:\program files\Messenger\msmsgs.exe" [2001-08-02 1077277]
"googletalk"="e:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="e:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-01 185872]
"IgfxTray"="e:\windows\System32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="e:\windows\System32\hkcmd.exe" [2005-06-21 126976]
"avast!"="e:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\System32\CTFMON.EXE" [2001-08-23 13312]
e:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - e:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecSche]
--a------ 2003-01-13 17:00 172032 e:\tv capture card\RecSche.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
R1 aswSP;avast! Self Protection;e:\windows\system32\drivers\aswSP.sys [2009-02-27 114768]
R3 PhTVTune;TV Capture Card WDM TV Tuner;e:\windows\system32\drivers\PhTVTune.sys [2008-11-16 19616]
S2 gupdate1c98e036cb3f970;Google Update Service (gupdate1c98e036cb3f970);e:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 133104]
S3 D100IB;D100IB;e:\windows\system32\drivers\D100IB5.SYS [2008-11-29 117760]
S3 NetWlan5;Symbol Based 802.11b Wireless LAN Card Driver;e:\windows\system32\drivers\NetWlan5.sys [2008-11-29 185728]
.
Contents of the 'Scheduled Tasks' folder
2009-02-27 e:\windows\Tasks\GoogleUpdateTaskMachine.job
- e:\program files\Google\Update\GoogleUpdate.exe [2009-02-13 18:49]
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: Add to Google Photos Screensa&ver - e:\windows\System32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
FF - ProfilePath - e:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\0dkeg26i.default\
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - component: e:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: e:\program files\Google\Google Updater\2.4.1439.6872\npCIDetect13.dll
FF - plugin: e:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: e:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-02-27 23:11:40
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(528-)
e:\windows\system32\ODBC32.dll
- - - - - - - > 'lsass.exe'(584)
e:\windows\System32\dssenh.dll
.
------------------------ Other Running Processes ------------------------
.
e:\program files\Alwil Software\Avast4\aswUpdSv.exe
e:\program files\Alwil Software\Avast4\ashServ.exe
e:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
e:\windows\system32\wdfmgr.exe
e:\program files\Alwil Software\Avast4\ashWebSv.exe
e:\program files\Alwil Software\Avast4\ashMaiSv.exe
.
**************************************************************************
.
Completion time: 2009-02-27 23:14:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-27 22:14:10
Pre-Run: 2.884.182.016 bytes free
Post-Run: 2,876,723,200 bytes free
WinXP_EN_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="XP NOVI"
multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="XP Kuca"
208 --- E O F --- 2009-02-25 23:46:04
|