offline
- goust
- Elitni građanin
- Pridružio: 09 Apr 2005
- Poruke: 1799
|
Kad sam pokrenuo skeniranje Combo fix-om kod stagee-a 3 i 4 mi se ponovo javio KIS sa gore navedenim problemom detected: Trojan program Trojan.Win32.Inject.jt File: C:\DOCUME~1\Sasa\LOCALS~1\Temp\wjeeeiprH6G334C.dll kojeg nije izbrisao iako sam pre toga restartovao komp, iskljucio sistem resto. Kod stage-a 8 i 36 ComboFix je poduo skenirao. Na kraju evo rezultata skeniranja:
ComboFix 07-11-08.1 - Sasa 2007-11-17 21:21:29.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.34 [GMT 1:00]
Running from: C:\Documents and Settings\Sasa\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.
2007-11-17 17:50 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-16 21:15 <DIR> d-------- C:\Program Files\Professional Registry Doctor
2007-11-13 10:27 <DIR> d--hs---- C:\Diskeeper
2007-11-13 09:19 <DIR> d-------- C:\Program Files\Diskeeper Corporation
2007-11-13 09:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Diskeeper Corporation
2007-11-09 22:21 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\CD Bank
2007-11-09 22:20 <DIR> d-------- C:\Program Files\CD Bank
2007-11-09 17:51 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\Intermedia Design
2007-11-09 17:49 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2007-11-08 09:42 <DIR> d-------- C:\Program Files\Uniblue
2007-11-07 08:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SolarWinds
2007-11-06 09:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DeskSoft
2007-11-06 09:45 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\DeskSoft
2007-11-05 13:39 <DIR> d-------- C:\Program Files\Dr.Hardware 2007 english
2007-11-03 23:34 34,308 --a------ C:\WINDOWS\system32\Chip.dll
2007-11-03 23:15 <DIR> d-------- C:\Program Files\Error Repair Professional
2007-11-03 15:00 <DIR> d-------- C:\Program Files\Common Files\Bcgsoft
2007-11-03 09:36 <DIR> d-------- C:\Program Files\D-Link
2007-11-03 09:29 <DIR> d-------- C:\Program Files\WZCBDL Service
2007-11-03 09:29 <DIR> d-------- C:\Program Files\NIOC Service
2007-11-03 07:34 24,576 --a------ C:\WINDOWS\system32\vshook.dll
2007-11-02 16:54 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\Proxima Software
2007-11-02 10:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Genie-Soft
2007-11-02 10:30 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\Genie-Soft
2007-11-02 10:27 128,104 --a------ C:\WINDOWS\system32\drivers\WimFltr.sys
2007-11-01 11:49 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\REALVIZ
2007-10-31 13:10 96,376 --a------ C:\WINDOWS\system32\GDIPFONTCACHEV1.DAT
2007-10-31 13:04 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\Pointstone
2007-10-30 10:45 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-10-28 17:50 <DIR> d-------- C:\Documents and Settings\Sasa\Application Data\ZC Dream Photo
2007-10-27 19:19 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
2007-10-27 17:24 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-27 17:19 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-10-27 17:16 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-10-27 17:16 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-10-24 08:22 <DIR> d-------- C:\Program Files\Web Photo Album
2007-10-22 16:08 <DIR> d-------- C:\Program Files\PF3DEN
2007-10-21 09:47 <DIR> d-------- C:\Program Files\Mv2Player
2007-10-20 23:46 <DIR> d-------- C:\Program Files\Fast Photo Renamer
2007-10-20 10:09 679,936 --a------ C:\WINDOWS\system\xvidcore.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 20:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-17 20:09 425,288 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 20:09 30,774,048 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-17 20:09 124,916 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-17 20:09 1,363,744 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-17 10:38 --------- d-----w C:\Program Files\Pointstone
2007-11-16 19:56 --------- d-----w C:\Program Files\FlashGet
2007-11-16 19:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-12 08:15 --------- d-----w C:\Program Files\Lexmark X1100 Series
2007-11-08 08:43 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Uniblue
2007-11-07 07:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-05 16:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\RFA_Backups
2007-11-01 07:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-31 15:20 --------- d-----w C:\Program Files\Advanced JPEG Compressor
2007-10-25 20:50 --------- d-----w C:\Program Files\Google
2007-10-22 12:46 --------- d-----w C:\Program Files\SpywareBlaster
2007-10-17 22:21 --------- d-----w C:\Program Files\Winamp
2007-10-14 14:33 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Xilisoft Corporation
2007-10-13 07:52 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Kristanix Software
2007-10-12 18:48 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Abra Academy2
2007-10-10 19:40 213,504 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2007-10-10 17:43 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-10-10 17:43 282,624 ----a-r C:\WINDOWS\Setup1.exe
2007-10-10 07:01 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Carnival Software
2007-09-29 21:17 --------- d-----w C:\Documents and Settings\Sasa\Application Data\DivX
2007-09-29 19:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\BlazeVideo
2007-09-29 13:15 --------- d-----w C:\Program Files\Summitsoft
2007-09-29 10:12 47,360 ----a-w C:\WINDOWS\system32\drivers\Pcouffin.sys
2007-09-26 06:21 --------- d-----w C:\Documents and Settings\Sasa\Application Data\Thinstall
2007-09-24 21:53 --------- d-----w C:\Program Files\XviD
2007-09-23 12:58 21,504 ---ha-r C:\WINDOWS\system32\RegistrationLib193.dll
2007-09-22 14:41 102,400 ----a-w C:\WINDOWS\system32\VB6STKIT.DLL
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
.
((((((((((((((((((((((((((((( snapshot@2007-11-17_18.15.45.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-10-30 09:46:20 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-11-17 20:01:27 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2007-10-30 09:46:20 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-11-17 20:01:27 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2007-10-30 09:46:20 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2007-11-17 20:01:28 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-10-30 09:46:20 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-11-17 20:01:26 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-10-30 09:46:20 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-11-17 20:01:28 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2007-10-30 09:46:21 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2007-11-17 20:01:28 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-10-30 09:46:21 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2007-11-17 20:01:28 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2007-10-30 09:46:21 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2007-11-17 20:01:28 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-10-30 09:46:20 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-11-17 20:01:27 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-10-30 09:46:20 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-11-17 20:01:27 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2007-10-30 09:46:21 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2007-11-17 20:01:29 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-10-30 09:46:20 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-11-17 20:01:26 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-10-30 09:46:20 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-11-17 20:01:26 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2006-12-19 21:52:18 8,453,632 -c--a-w C:\WINDOWS\system32\dllcache\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 -c--a-w C:\WINDOWS\system32\dllcache\shell32.dll
- 2007-09-28 05:19:39 18,089,592 ----a-w C:\WINDOWS\system32\MRT.exe
+ 2007-11-02 07:12:57 18,238,072 ----a-w C:\WINDOWS\system32\MRT.exe
- 2006-12-19 21:52:18 8,453,632 ----a-w C:\WINDOWS\system32\shell32.dll
+ 2007-10-26 03:36:51 8,454,656 ----a-w C:\WINDOWS\system32\shell32.dll
- 2007-03-06 01:22:36 14,048 ------w C:\WINDOWS\system32\spmsg.dll
+ 2007-03-06 01:22:33 14,048 ------w C:\WINDOWS\system32\spmsg.dll
- 2007-08-21 10:20:02 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-10-29 10:26:53 115,712 ----a-w C:\WINDOWS\system32\xpsp3res.dll
+ 2007-11-17 20:11:44 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_7fc.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-05-19 21:36]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2003-09-24 12:32]
"D-Link Air Utility"="C:\Program Files\D-Link\Air Utility\AirCFG.exe" [2003-06-26 18:13]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:54]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoStartMenuPinnedList"=0 (0x0)
"NoStartMenuMFUprogramsList"=0 (0x0)
"NoUserNameInStartMenu"=0 (0x0)
"NoStartMenuSubFolders"=0 (0x0)
"NoCommonGroups"=0 (0x0)
"NoRecentDocsMenu"=0 (0x0)
"NoPrinterTabs"=0 (0x0)
"NoDeletePrinter"=0 (0x0)
"NoAddPrinter"=0 (0x0)
"NoPrinters"=0 (0x0)
"NoFavoritesMenu"=0 (0x0)
"NoSetFolders"=0 (0x0)
"NoShellSearchButton"=0 (0x0)
"NoToolbarCustomize"=0 (0x0)
"NoRecentDocsNetHood"=0 (0x0)
"NoChangeAnimation"=0 (0x0)
"NoChangeKeyboardNavigationIndicators"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Net.Medic.lnk]
backup=C:\WINDOWS\pss\Net.Medic.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sasa^Start Menu^Programs^Startup^BWMeter.lnk]
backup=C:\WINDOWS\pss\BWMeter.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sasa^Start Menu^Programs^Startup^Xfire.lnk]
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sasa^Start Menu^Programs^Startup^YearPlanner.lnk]
backup=C:\WINDOWS\pss\YearPlanner.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GBMPro8Agent]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSN Services]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnsyslog]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NetMeter]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rfagent]
"C:\Program Files\RFA Platinum\rfagent.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THGuard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2]
C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster2]
D:\Sortirani softveri\Optimizeri\Uniblue\Registry_Booster_v2.0.1041.3208\registrybooster.exe /S
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue SpeedUpMyPC]
C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScannerPro]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZortamMp3MediaStudio]
R2 NIOC;NIOC Service;\??\C:\WINDOWS\system32\NIOC.SYS
R2 Windows-CCHook-Service;Windows-CCHook-Service;C:\WINDOWS\system32\cchservice.exe
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys
R3 NETDLWL;D-Link Air Wireless Adapter(DL) NT Driver;C:\WINDOWS\system32\DRIVERS\NETDLWL.SYS
R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"C:\Program Files\MSN Messenger\usnsvc.exe"
S3 WimFltr;WimFltr;C:\WINDOWS\system32\DRIVERS\wimfltr.sys
Start Pending2 WZCBDLService;WZCBDL Service;"C:\Program Files\WZCBDL Service\WZCBDLS.exe"
.
Contents of the 'Scheduled Tasks' folder
"2007-11-17 20:11:21 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-11-08 08:43:52 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-11-08 08:43:49 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-11-17 14:16:01 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
"2007-05-19 20:42:11 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 21:32:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 21:35:53
.
--- E O F ---
|