|
|
|
Poslao: 02 Feb 2014 22:06
|
offline
- NIx Car

- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Savetovao bih ti da ispratis moj post, kako bih ja mogao hladne glave da kazem da je tvoj racunar cist od malwarea. Ali kako hoces
|
|
|
|
|
|
|
|
Poslao: 04 Feb 2014 20:36
|
offline
- Fireskull

- Građanin
- Pridružio: 16 Maj 2013
- Poruke: 111
- Gde živiš: Kragujevac
|
Napisano: 04 Feb 2014 14:27
Evo to je ovo nisam znao gde je faj pa sam prekopirao
ComboFix 14-02-03.01 - Mihajlo 02/04/2014 14:14:57.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.114 [GMT 1:00]
Running from: c:\documents and settings\Mihajlo\My Documents\ComboFix.exe
Command switches used :: c:\documents and settings\Mihajlo\Desktop\CFScript.txt
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Mihajlo\Application Data\newnext.me
c:\documents and settings\Mihajlo\Application Data\newnext.me\cache\spark.bin
c:\documents and settings\Mihajlo\Application Data\newnext.me\nengine.cookie
c:\documents and settings\Mihajlo\Application Data\newnext.me\nengine.dll
C:\Win
c:\win\lsass.exe
c:\win\names.txt
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\MPK\1\D0000
c:\documents and settings\All Users\Application Data\MPK\1\S0000
c:\documents and settings\All Users\Application Data\MPK\2\D0000
c:\documents and settings\All Users\Application Data\MPK\2\S0000
c:\documents and settings\All Users\Application Data\MPK\CPDM\cpfm.bin
c:\documents and settings\All Users\Application Data\MPK\M0000
c:\documents and settings\All Users\Application Data\MPK\REFOG Keylogger\Order now!.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Keylogger\REFOG Keylogger on the Web.lnk
c:\documents and settings\All Users\Application Data\MPK\REFOG Keylogger\REFOG Keylogger.lnk
c:\documents and settings\All Users\Application Data\MPK\S0000
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\addon.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\amazon_ie.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\blocklist.json
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.cfg
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabStart.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabStart64.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabUninstaller.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabWrap.dll
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DefaultTabWrap64.dll
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DT.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DTReg.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\DTUpdate.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\ebay_ie.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\facebook_ie.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\search_here_ie.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\searchhere.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\twitter_ie.ico
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\uninstalldt.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\update.exe
c:\documents and settings\Mihajlo\Application Data\DefaultTab\DefaultTab\wikipedia_ie.ico
c:\program files\DefaultTab\DefaultTab.crx
c:\program files\DefaultTab\DefaultTabHost.exe
c:\program files\DefaultTab\DefaultTabHost.json
c:\program files\DefaultTab\DefaultTabSearch.exe
c:\program files\DefaultTab\uid
c:\win\names.txt
c:\windows\system32\VIRepair\vi.sif
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_DEFAULTTABSEARCH
-------\Service_DefaultTabSearch
-------\Legacy_DefaultTabUpdate
-------\Legacy_DefaultTabUpdate
-------\Service_DefaultTabUpdate
-------\Service_DefaultTabUpdate
.
.
((((((((((((((((((((((((( Files Created from 2014-01-04 to 2014-02-04 )))))))))))))))))))))))))))))))
.
.
2014-02-02 16:37 . 2014-02-02 16:40 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2014-02-02 16:37 . 2014-02-02 16:37 -------- d-----w- c:\documents and settings\Mihajlo\Application Data\Malwarebytes
2014-02-02 16:37 . 2014-02-02 16:37 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2014-02-02 13:29 . 2014-02-02 13:29 -------- d-----w- c:\documents and settings\Mihajlo\Local Settings\Application Data\TechSmith
2014-02-02 13:29 . 2014-02-02 13:29 -------- d-----w- c:\documents and settings\Mihajlo\Local Settings\Application Data\Help
2014-02-02 13:28 . 2002-05-08 02:02 110592 ----a-w- c:\windows\system32\tsccvid.dll
2014-02-02 13:28 . 2014-02-02 13:28 -------- d-----w- c:\program files\TechSmith
2014-01-17 02:18 . 2014-01-17 02:17 1194185 ----a-w- c:\windows\unins000.exe
2014-01-17 01:58 . 2004-10-22 01:18 749568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iKernel.dll
2014-01-17 01:58 . 2004-10-22 01:17 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\ctor.dll
2014-01-17 01:58 . 2004-10-22 01:17 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iscript.dll
2014-01-17 01:58 . 2004-10-22 01:16 180224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iuser.dll
2014-01-17 01:58 . 2004-10-22 01:16 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\DotNetInstaller.exe
2014-01-17 01:58 . 2014-01-17 01:58 323716 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\setup.dll
2014-01-17 01:58 . 2014-01-17 01:58 192644 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\10\50\Intel32\iGdi.dll
2014-01-16 23:18 . 2008-05-21 08:48 9694440 ----a-w- c:\windows\Bildschirmschoner.scr
2014-01-15 22:47 . 2014-01-15 22:47 -------- d-----w- c:\windows\San Andreas Mod Installer
2014-01-15 22:34 . 2014-01-17 01:59 -------- d-----w- c:\program files\Rockstar Games
2014-01-14 14:43 . 2014-01-14 14:43 -------- d-----w- c:\program files\CCleaner
2014-01-11 12:12 . 2008-04-14 01:41 21504 -c--a-w- c:\windows\system32\dllcache\hidserv.dll
2014-01-11 12:12 . 2008-04-14 01:41 21504 ----a-w- c:\windows\system32\hidserv.dll
2014-01-11 12:12 . 2001-08-17 09:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2014-01-11 12:12 . 2001-08-17 09:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2014-01-11 12:12 . 2008-04-13 20:15 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2014-01-11 12:12 . 2008-04-13 20:15 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-01-18 14:54 . 2013-12-30 03:57 60416 ----a-w- c:\windows\ALCFDRTM.VER
2014-01-02 15:20 . 2014-01-02 15:20 243128 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2013-12-30 03:57 . 2013-12-30 03:57 60416 ----a-w- c:\windows\ALCFDRTM.EXE
2013-12-21 17:22 . 2013-12-21 17:22 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2013-12-18 17:13 . 2013-12-18 14:47 2311840 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VisualStudio\10.0\1033\ResourceCache.dll
2013-12-18 14:47 . 2013-12-18 14:47 18368 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VSA\9.0\1033\ResourceCache.dll
2013-12-18 00:20 . 2013-12-18 00:20 112832 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VCExpress\10.0\1033\ResourceCache.dll
2013-12-13 09:30 . 2013-12-13 08:31 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2013-12-13 09:30 . 2013-12-13 08:31 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2013-12-13 08:34 . 2013-12-13 08:31 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2013-12-13 08:31 . 2013-12-13 08:31 22328 ----a-w- c:\documents and settings\Mihajlo\Application Data\PnkBstrK.sys
2013-12-12 05:09 . 2008-04-14 12:00 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-12-12 05:09 . 2008-04-14 12:00 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-11-27 20:21 . 2012-06-13 15:35 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2013-11-13 02:59 . 2012-02-29 14:08 150528 ----a-w- c:\windows\system32\imagehlp.dll
2013-11-07 05:38 . 2012-06-13 15:35 591360 ----a-w- c:\windows\system32\rpcrt4.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-06-13 . E17798E1E6FF1CA9C67B8576570E05EE . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent"="c:\documents and settings\Mihajlo\Application Data\BitTorrent\BitTorrent.exe" [2014-02-03 900696]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2013-10-28 3675352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-01-08 18705664]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-12-14 577536]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2013-09-24 98304]
"run32"="c:\win\lsass.exe" [BU]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2013-11-21 16:57 959904 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Facebook Update]
2014-01-01 18:43 138096 ----atw- c:\documents and settings\Mihajlo\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mobilegeni daemon]
c:\program files\Mobogenie\DaemonProcess.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\run32]
c:\win\lsass.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Software Updates Free]
c:\program files\Software Updates Free\Software Checker.exe [BU]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Mihajlo\\Application Data\\BitTorrent\\BitTorrent.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Documents and Settings\\Mihajlo\\Local Settings\\Application Data\\Facebook\\Video\\Skype\\FacebookVideoCalling.exe"=
"c:\\Program Files\\PANDORA.TV\\PanService\\KMPProcess.exe"=
.
R0 mv61xxmm;mv61xxmm;c:\windows\system32\drivers\mv61xxmm.sys [6/13/2012 4:45 PM 13616]
R0 mv64xxmm;mv64xxmm;c:\windows\system32\drivers\mv64xxmm.sys [6/13/2012 4:45 PM 5632]
R0 mvxxmm;mvxxmm;c:\windows\system32\drivers\mvxxmm.sys [6/13/2012 4:45 PM 13616]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [1/22/2013 4:05 AM 16640]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [1/2/2014 4:20 PM 243128]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [12/20/2013 6:49 PM 103040]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2/2/2014 5:37 PM 40776]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [3/30/2009 3:09 AM 239336]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-01-31 08:06 1211672 ----a-w- c:\program files\Google\Chrome\Application\32.0.1700.102\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-02-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-13 05:09]
.
2014-02-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299502267-152049171-842925246-1003Core.job
- c:\documents and settings\Mihajlo\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2014-01-01 18:43]
.
2014-02-04 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-299502267-152049171-842925246-1003UA.job
- c:\documents and settings\Mihajlo\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe [2014-01-01 18:43]
.
2014-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-28 06:17]
.
2014-02-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-28 06:17]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
TCP: DhcpNameServer = 192.168.1.1 0.0.0.0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2014-02-04 14:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_9_900_170_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2014-02-04 14:25:31
ComboFix-quarantined-files.txt 2014-02-04 13:25
.
Pre-Run: 4,513,959,936 bytes free
Post-Run: 4,517,695,488 bytes free
.
- - End Of File - - E044B281BEC9459B732B242A3AC2EA56
8F558EB6672622401DA993E1E865C861
Dopuna: 04 Feb 2014 20:36
Sta sada?
|
|
|
|
|