Trojan horse BackDoor Generic_r.EO

2

Trojan horse BackDoor Generic_r.EO

offline
  • Pridružio: 04 Avg 2008
  • Poruke: 37

Imam problem. Tokom citanja Vaseg odgovora, pojavila mi se poruka koju nisam uspela da procitam u potpunosti, a glasila je (pokusacu da, sto je moguce tacnije, opisem sta se desilo):svchost aplication error, prijavivsi neki problem u "citanju" memorije..., mislim da nisam pogresila u opisu, nakon cega sam kliknula OK. Potom sam pokusala da iskljucim svu zastitu, ali racunar nije reagovao niti na jedan klik misem. Restatovala sam racunar, nanovo pokusavsi da iskljucim zastitu, ali Comodo nije reagovao. Sledi ponovni restart, Comodo je ukljucen, pokusala sam da prevucem skript u ComboFix, ali su tada sukcesivno pocele da "iskacu" poruke Comoda da dozvolim ili nedozvolim pojedine akcije. Dozvoljavala sam sve sto je prijavljeno kao ComboFix, a zabranjivala NirCmd.exe. No, nista se nije desilo. Usledio je ponovni restart, i ovaj post.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ma, i ja imam taj comodo, dobar je, ali smara sa tim upozorenjima. Ako mozes, prvo iskljuci njega, pa sve ostale.

I onda pokusaj skriptu.

offline
  • Pridružio: 04 Avg 2008
  • Poruke: 37

Uspela sam nekako. Hvala na savetima. Evo loga:

ComboFix 09-02-12.03 - Media 2009-02-15 13:55:23.10 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.73 [GMT 1:00]
Running from: c:\documents and settings\Media\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Media\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
FW: COMODO Firewall *enabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
c:\windows\system32\drivers\NirCmd.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\drivers\NirCmd.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NIRSOFT_SERVICE_CONTROLER
-------\Service_NirSoft Service Controler


((((((((((((((((((((((((( Files Created from 2009-01-15 to 2009-02-15 )))))))))))))))))))))))))))))))
.

2009-02-14 23:40 . 2009-02-14 23:40 <DIR> d-------- c:\program files\Prevx
2009-02-14 23:40 . 2009-02-14 23:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-02-14 23:40 . 2009-02-14 23:40 21,512 --a------ c:\windows\system32\drivers\pxscan.sys
2009-02-14 23:40 . 2009-02-14 23:40 64 --a------ c:\windows\wininit.ini
2009-02-03 23:01 . 2009-02-10 23:59 54,156 --ah----- c:\windows\QTFont.qfn
2009-02-03 23:01 . 2009-02-03 23:01 1,409 --a------ c:\windows\QTFont.for
2009-02-01 22:58 . 2009-02-01 22:59 <DIR> d-------- c:\program files\MP3 CD Converter
2009-01-29 22:55 . 2009-01-29 22:55 <DIR> d-------- c:\documents and settings\Media\Application Data\SpinTop Games
2009-01-29 22:54 . 2009-01-29 22:54 <DIR> d-------- c:\windows\Mystery P I The New York Fortune
2009-01-27 20:34 . 2009-01-27 20:34 <DIR> d-------- c:\windows\Luxor Quest for the Afterlife
2009-01-27 20:34 . 2009-01-27 20:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\MumboJumbo
2009-01-25 21:46 . 2006-06-01 10:11 42,648 -ra------ c:\windows\system32\usbport.sys
2009-01-25 21:46 . 2006-06-01 10:11 21,155 -ra------ c:\windows\system32\ser2up.vxd
2009-01-25 21:33 . 2009-01-25 21:33 <DIR> d-------- c:\program files\Common Files\PCSuite
2009-01-25 21:32 . 2009-01-25 21:32 <DIR> d-------- c:\program files\Common Files\Nokia
2009-01-25 21:32 . 2006-07-17 02:53 30,368 -ra------ c:\windows\system32\drivers\usb2vcom.sys
2009-01-25 21:32 . 2008-08-26 09:26 18,816 --a------ c:\windows\system32\drivers\pccsmcfd.sys
2009-01-25 21:28 . 2009-01-25 21:28 <DIR> d-------- c:\program files\PC Connectivity Solution
2009-01-25 21:26 . 2009-01-25 21:32 <DIR> d-------- c:\program files\Nokia
2009-01-25 17:19 . 2009-01-25 17:19 <DIR> d-------- c:\windows\Chocolate Shop Frenzy

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-15 00:15 359,040 ------w c:\windows\system32\drivers\tcpip.sys
2009-02-14 23:08 --------- d-----w c:\documents and settings\Media\Application Data\uTorrent
2009-02-14 12:53 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-02-12 00:36 --------- d-----w c:\program files\AIMP2
2009-02-10 21:49 --------- d-----w c:\documents and settings\Media\Application Data\Skype
2009-02-10 07:10 --------- d-----w c:\program files\Mozilla Thunderbird
2009-01-29 07:04 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-29 07:04 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-29 07:04 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-01-26 00:38 --------- d-----w c:\documents and settings\Media\Application Data\Nokia
2009-01-25 21:11 --------- d-----w c:\documents and settings\Media\Application Data\PC Suite
2009-01-25 21:11 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2009-01-25 20:26 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2009-01-12 22:19 --------- d-----w c:\documents and settings\All Users\Application Data\DivoGames
2009-01-12 18:50 --------- d-----w c:\documents and settings\Media\Application Data\Fabulous Finds
2009-01-04 21:06 2,829 ----a-w c:\windows\War3Unin.pif
2009-01-04 21:06 139,264 ----a-w c:\windows\War3Unin.exe
2009-01-03 21:12 --------- d-----w c:\documents and settings\All Users\Application Data\PlayPond
2009-01-01 12:34 --------- d-----w c:\documents and settings\Media\Application Data\World-LooM
2008-12-21 22:47 --------- d-----w c:\documents and settings\Media\Application Data\Samsung
2008-12-21 22:41 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-21 22:41 --------- d-----w c:\program files\Samsung
2008-12-20 16:49 101,776 ----a-w c:\windows\system32\drivers\cmdguard.sys
2008-12-15 19:55 --------- d-----w c:\program files\Free MSN Emoticons Pack 1
2008-11-21 01:26 112 ----a-w C:\tw0001.dat
2007-01-23 11:46 312 ----a-w c:\documents and settings\Media\Application Data\bbbconfig.dat
2007-02-25 15:48 3,350 --sha-w c:\windows\system32\KGyGaAvL.sys
.

------- Sigcheck -------

2004-08-03 22:14 359040 9f4b36614a0fc234525ba224957de55c c:\windows\system32\dllcache\tcpip.sys
2009-02-15 01:15 359040 3bb4b08619c111c7be8bda07aa0de6a2 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-02-15_ 1.31.16.85 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 18:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2005-10-20 19:02:28 163,328 ----a-w c:\windows\erdnt\subs\ERDNT.EXE
+ 2009-02-15 12:59:21 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_2a4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-10-04 163840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-29 1601304]
"Acrobat Assistant 8.0"="d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-22 620152]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" [2008-12-02 1797880]
"COMODO SafeSurf"="c:\program files\COMODO\SafeSurf\cssurf.exe" [2008-08-07 278264]
"MSConfig"="c:\windows\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-03 158208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe [2008-11-25 295606]
Adobe Acrobat Synchronizer.lnk - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
NCProTray.lnk - c:\program files\SEC\Natural Color Pro\NCProTray.exe [2008-10-20 49220]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-29 08:04 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.VP31"= vp31vfw.dll
"msacm.divxa32"= msaud32_divx.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Synchronizer.lnk]
backup=c:\windows\pss\Adobe Acrobat Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Watch.lnk]
backup=c:\windows\pss\Watch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinNC - Launch WinNC - multiplelicense (external programming station).lnk]
backup=c:\windows\pss\WinNC - Launch WinNC - multiplelicense (external programming station).lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^3DO Registration.lnk]
backup=c:\windows\pss\3DO Registration.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^H3 The Shadow of Death(TM).lnk]
backup=c:\windows\pss\H3 The Shadow of Death(TM).lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Media^Start Menu^Programs^Startup^MostFun.lnk]
backup=c:\windows\pss\MostFun.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-05-16 08:27 153136 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-09-29 21:58 49152 c:\program files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 14:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2006-03-18 03:24 184320 c:\program files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 03:00 132496 c:\program files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
-ra------ 2003-09-23 10:06 88363 c:\windows\AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
-ra------ 2005-05-03 11:43 69632 c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
-ra------ 2006-05-18 07:27 16207872 c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LIVESRV"=2 (0x2)
"VSSERV"=2 (0x2)
"avast! Web Scanner"=3 (0x3)
"avast! Mail Scanner"=3 (0x3)
"avast! Antivirus"=2 (0x2)
"aswUpdSv"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\AoEII\\age2_x1\\age2_x1.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Documents and Settings\\Media\\My Documents\\Duke3D.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\totalcmd\\TOTALCMD.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"d:\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10317:TCP"= 10317:TCP:BitComet 10317 TCP
"10317:UDP"= 10317:UDP:BitComet 10317 UDP
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-02-14 21512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-11 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-07-11 107272]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2008-08-07 101776]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2008-08-07 31504]
R1 SSHDRV65;SSHDRV65;c:\windows\system32\drivers\SSHDRV65.sys [2007-03-18 120320]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-07-11 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-11 298264]
R2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [2009-02-14 4107832]
S3 usb2vcom;USB to Serial Bridge Controller;c:\windows\system32\drivers\usb2vcom.sys [2009-01-25 30368]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comodo.com/search/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\dokumenti\Adobe CS3\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Media\Application Data\Mozilla\Firefox\Profiles\edbk3j11.default\
FF - prefs.js: browser.startup.homepage -
FF - component: c:\documents and settings\Media\Application Data\Mozilla\Firefox\Profiles\edbk3j11.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-02-15 14:00:03
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1123561945-2025429265-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1DA74357-36D9-7A50-261E-C9DC78F35153}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"jaiklmgegkkhfbkipdpe"=hex:6a,61,68,68,67,6e,61,6e,6a,69,6a,6d,64,67,61,6b,6f,
66,68,61,00,00
"iakkjndomnpbnnfhip"=hex:6a,61,68,68,67,6e,61,6e,6a,69,6a,6d,64,67,61,6b,6f,66,
68,61,00,1a

[HKEY_USERS\S-1-5-21-1123561945-2025429265-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ac,24,63,52,7e,0d,8f,49,9f,62,93,36,b8,39,68,76,ab,b2,c7,54,21,e6,ee,
f5,0b,87,a7,57,31,af,4b,95,02,0f,6e,0d,9c,40,a0,af,1d,c3,4b,f6,02,8c,10,41,\
"??"=hex:66,16,d0,f7,71,61,e5,12,51,6c,06,2e,c0,18,58,6b
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\COMODO\Firewall\cmdagent.exe
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\CyberLink\Shared files\RichVideo.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2009-02-15 14:06:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-15 13:06:20
ComboFix2.txt 2009-02-15 01:28:26
ComboFix3.txt 2009-02-15 00:34:34

Pre-Run: 3,640,188,928 bytes free
Post-Run: 3,627,864,064 bytes free

281

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ima li sad nekih problema sa detekcijom, ili sa necim?

offline
  • Pridružio: 04 Avg 2008
  • Poruke: 37

Za sad mi deluje da je sve u redu. Zahvaljujem Vam se puno na trudu i utrosenom vremenu. Ukoliko nesto "podje po zlu", bicu slobodna da Vam se ponovo obratim. Javite mi samo, ako mozete, da li treba da uklonim ComboFix.

P. S. Ukljucila sam nanovo AVG, Comodo i Tea Timer.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

OK.

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


Ako negde zapne, tu smo, to i sama znas.

offline
  • Pridružio: 04 Avg 2008
  • Poruke: 37

Zao mi je sto tastatura moze da prenese samo veliko hvala!

Puno srece svima!

P. S. Znam gde ste ako zatreba, a kako sam samo jedna prosecna sredovecna profesorka knjizevnosti, dobro je i da mi racunar uopste radi!

Ko je trenutno na forumu
 

Ukupno su 870 korisnika na forumu :: 4 registrovanih, 0 sakrivenih i 866 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Neutral-M, Panter, pein, VJ