offline
- Pridružio: 02 Feb 2009
- Poruke: 32
|
evo loga samo da kazem da kada je zavrsio sa skeniranjem zahtevao je restart sto je sam i uradio i kada je krenuo sa restartom pisalo je da Nircmd.exe nije mogao da se pokrene ili nesta slicno onda je krenuo restart. Pri ponovnom dizanju nije htio da da log pa sam morao sve ponovo.
ComboFix 09-03-27.02 - Administrator 2009-03-28 22:40:32.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.3582.3013 [GMT 1:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090327-0] *On-access scanning disabled* (Updated)
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-28 )))))))))))))))))))))))))))))))
.
2009-03-26 23:23 . 2009-03-28 19:28 <DIR> d-------- c:\program files\Trend Micro
2009-03-19 20:50 . 2009-03-19 20:50 <DIR> d-------- c:\documents and settings\Djole\Application Data\Ahead
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-28 02:40 --------- d-----w c:\program files\Winamp
2009-03-26 21:52 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-08 23:44 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-24 22:47 --------- d-----w c:\program files\Microsoft Web Designer Tools
2009-02-24 22:47 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-24 22:44 --------- d-----w c:\program files\Microsoft Visual Studio 9.0
2009-02-24 22:39 --------- d-----w c:\program files\Microsoft.NET
2009-02-24 22:39 --------- d-----w c:\program files\Microsoft SQL Server
2009-02-15 22:22 --------- d-----w c:\program files\Reference Assemblies
2009-02-15 22:22 --------- d-----w c:\program files\MSBuild
2009-02-14 01:26 --------- d-----w c:\program files\MSXML 6.0
2009-02-13 12:53 --------- d-----w c:\program files\EasyPHP1-8
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 19:43 --------- d-----w c:\documents and settings\Vera\Application Data\Malwarebytes
2009-01-06 21:28 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-01-06 21:25 669,184 ----a-w c:\windows\system32\pbsvc.exe
2009-01-06 21:25 66,872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-01-06 21:25 22,328 ----a-w c:\documents and settings\Administrator\Application Data\PnkBstrK.sys
2009-01-06 21:25 103,736 ----a-w c:\windows\system32\PnkBstrB.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-06-23 847872]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"TWCU"="c:\program files\TP-LINK\TWCU\TWCU.exe" [2006-03-29 364544]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-11 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 15:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-03 21:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-03 21:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2009-01-08 20:24 1410296 e:\steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2005-11-15 20:31 33792 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Igre\\Valve\\hltv.exe"=
"d:\\Igre\\Valve\\hl.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"d:\\Igre\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\Igre\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Igre\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\wamp\\bin\\apache\\apache2.2.8\\bin\\httpd.exe"=
"d:\\Igre\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"d:\\Igre\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"d:\\Igre\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"d:\\Igre\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-25 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-25 20560]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80122fa4-1b8b-11dd-8725-001bfc3f3fe0}]
\Shell\AutoRun\command - G:\LaunchU3.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {20289E75-291D-4615-8A43-12F434C92DE7} = 79.143.173.161 79.143.172.3
TCP: {630EAD48-B813-49BE-84CA-438219256428} = 212.200.13.13
TCP: {E064EEA7-82EF-4689-801B-AB95BF2B0AD0} = 212.200.13.13
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-28 22:41:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1801674531-2077806209-839522115-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a2,6b,2a,37,79,3c,e4,81,c7,71,0b,25,8d,4e,fc,c5,59,2c,0a,9b,ba,a5,76,
b9,cb,bb,77,d3,b2,b7,a7,0e,b4,34,34,8e,94,86,6b,3a,51,c4,a3,41,57,37,58,69,\
"??"=hex:2e,c7,1e,64,a1,f2,51,ec,e8,bc,52,0f,50,53,63,93
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-03-28 22:42:21
ComboFix-quarantined-files.txt 2009-03-28 21:42:20
ComboFix2.txt 2009-03-28 21:38:11
ComboFix3.txt 2009-03-26 22:53:49
Pre-Run: 12.238.229.504 bytes free
Post-Run: 12,224,110,592 bytes free
131
|