Poslao: 01 Avg 2011 15:13
|
offline
- Kostolomka
- Novi MyCity građanin
- Pridružio: 24 Jul 2011
- Poruke: 23
|
ComboFix 11-07-31.04 - Jelena 08/01/2011 14:54:18.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3580.2832 [GMT 2:00]
Running from: c:\users\Jelena\Desktop\ComboFix.exe
Command switches used :: c:\users\Jelena\Desktop\CFScript.txt
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\system32\c_11862.nl_"
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB17200$
c:\windows\$NtUninstallKB17200$\926456777
c:\windows\av_ico
c:\windows\av_ico\ico_avast_desktop.ico
c:\windows\av_ico\ico_avast_start.ico
c:\windows\system32\c_11862.nl_
c:\windows\system32\c_11862.nls
c:\windows\unrar.exe
c:\windows\update.tray-7-0-lnk
c:\windows\update.tray-7-0
.
Infected copy of c:\windows\system32\drivers\cdrom.sys was found and disinfected
Restored copy from - The cat found it
.
((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 12:59 . 2011-08-01 13:01 -------- d-----w- c:\users\Jelena\AppData\Local\temp
2011-08-01 12:59 . 2011-08-01 12:59 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 12:52 . 2009-07-13 23:11 108544 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-07-27 15:00 . 2011-07-27 15:00 -------- d--h--w- c:\windows\PIF
2011-07-24 16:49 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-24 16:49 . 2011-07-24 16:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-24 16:49 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-24 16:22 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 16:22 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 16:22 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 16:22 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 16:22 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 16:22 . 2011-07-04 11:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 16:22 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 16:22 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 14:44 . 2011-07-24 14:44 -------- d-----w- c:\programdata\AVSoftware
2011-07-24 14:44 . 2011-07-24 16:09 -------- d-----w- c:\program files\UnThreat AntiVirus
2011-07-24 14:43 . 2011-07-24 14:43 -------- d-----w- c:\users\Jelena\AppData\Local\PackageAware
2011-07-24 14:11 . 2011-07-24 16:06 -------- d-----w- c:\programdata\Alwil Software
2011-07-24 14:11 . 2011-07-24 14:11 -------- d-----w- c:\program files\Alwil Software
2011-07-24 13:34 . 2011-07-24 13:34 -------- d-----w- c:\programdata\AVAST Software
2011-07-24 13:34 . 2011-07-24 13:34 -------- d-----w- c:\program files\AVAST Software
2011-07-12 15:46 . 2011-07-12 15:46 -------- d-----w- c:\program files\Microsoft Silverlight
2011-07-10 11:57 . 2011-07-10 11:57 -------- d-----w- c:\program files\Recnik20
2011-07-05 09:17 . 2011-07-06 14:13 -------- d-----w- c:\users\Jelena\AppData\Local\Microsoft Games
2011-07-02 15:19 . 2011-07-02 15:19 -------- d-----w- c:\program files\FinalWire
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-31 16:26 . 2011-05-31 16:26 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-05-31 16:09 . 2011-05-31 16:09 111960 ----a-w- c:\windows\dxsdkuninst.exe
2011-05-24 17:14 . 2011-05-31 16:34 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 17:12 . 2011-05-31 16:34 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{45A24FB3-28D2-48F1-8A7E-D777F899C08B}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4704207-C86B-4811-951E-6F322F9CEDE7}]
2011-07-12 16:16 270336 ----a-w- c:\users\Jelena\AppData\LocalLow\QuickTime\IE\QuickTime.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 17093512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2003-04-18 8192]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 QuickTimeUpdater;QuickTime Updater;c:\users\Jelena\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe [2011-07-12 20480]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-22 167936]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546552769-2391818124-2777313086-1000Core.job
- c:\users\Jelena\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 18:44]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546552769-2391818124-2777313086-1000UA.job
- c:\users\Jelena\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 18:44]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Jelena\AppData\Roaming\Mozilla\Firefox\Profiles\mcsimgx2.default\
FF - prefs.js: browser.startup.homepage - google.rs
FF - prefs.js: network.proxy.type - 0
.
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\atieclxx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2011-08-01 15:03:56 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-01 13:03
ComboFix2.txt 2011-07-31 10:00
.
Pre-Run: 6,193,135,616 bytes free
Post-Run: 6,055,157,760 bytes free
.
- - End Of File - - CD1575914860009771484433CD178E04
Jel možete da mi kažete kakav je to virus u pitanju, i da li može da izazove nešto na memoriji?
|
|
|
|
|
Poslao: 01 Avg 2011 22:12
|
offline
- Kostolomka
- Novi MyCity građanin
- Pridružio: 24 Jul 2011
- Poruke: 23
|
ComboFix 11-08-01.05 - Jelena 08/01/2011 22:04:53.3.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3580.2641 [GMT 2:00]
Running from: c:\users\Jelena\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 20:10 . 2011-08-01 20:10 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 12:59 . 2011-08-01 20:10 -------- d-----w- c:\users\Jelena\AppData\Local\temp
2011-08-01 12:52 . 2009-07-13 23:11 108544 ----a-w- c:\windows\system32\drivers\cdrom.sys
2011-07-27 15:00 . 2011-07-27 15:00 -------- d--h--w- c:\windows\PIF
2011-07-24 16:49 . 2011-07-06 17:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-24 16:49 . 2011-07-24 16:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-24 16:49 . 2011-07-06 17:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-24 16:22 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-24 16:22 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-24 16:22 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-24 16:22 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-24 16:22 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-24 16:22 . 2011-07-04 11:32 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-07-24 16:22 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-07-24 16:22 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-07-24 14:44 . 2011-07-24 14:44 -------- d-----w- c:\programdata\AVSoftware
2011-07-24 14:44 . 2011-07-24 16:09 -------- d-----w- c:\program files\UnThreat AntiVirus
2011-07-24 14:43 . 2011-07-24 14:43 -------- d-----w- c:\users\Jelena\AppData\Local\PackageAware
2011-07-24 14:11 . 2011-07-24 16:06 -------- d-----w- c:\programdata\Alwil Software
2011-07-24 14:11 . 2011-07-24 14:11 -------- d-----w- c:\program files\Alwil Software
2011-07-24 13:34 . 2011-07-24 13:34 -------- d-----w- c:\programdata\AVAST Software
2011-07-24 13:34 . 2011-07-24 13:34 -------- d-----w- c:\program files\AVAST Software
2011-07-12 15:46 . 2011-07-12 15:46 -------- d-----w- c:\program files\Microsoft Silverlight
2011-07-10 11:57 . 2011-07-10 11:57 -------- d-----w- c:\program files\Recnik20
2011-07-05 09:17 . 2011-07-06 14:13 -------- d-----w- c:\users\Jelena\AppData\Local\Microsoft Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-31 16:26 . 2011-05-31 16:26 431672 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-05-31 16:09 . 2011-05-31 16:09 111960 ----a-w- c:\windows\dxsdkuninst.exe
2011-05-24 17:14 . 2011-05-31 16:34 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-24 17:12 . 2011-05-31 16:34 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{45A24FB3-28D2-48F1-8A7E-D777F899C08B}\mpengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4704207-C86B-4811-951E-6F322F9CEDE7}]
2011-07-12 16:16 270336 ----a-w- c:\users\Jelena\AppData\LocalLow\QuickTime\IE\QuickTime.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-06-15 17093512]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-08-04 98304]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
"DisableThumbnailCache"=dword:00000001
.
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
R2 KMService;KMService;c:\windows\system32\srvany.exe [2003-04-18 8192]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-07-06 366640]
R2 QuickTimeUpdater;QuickTime Updater;c:\users\Jelena\AppData\LocalLow\QuickTime\IE\QuickTimeUpdater.exe [2011-07-12 20480]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-04 176128]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-07-06 22712]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-05-22 167936]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546552769-2391818124-2777313086-1000Core.job
- c:\users\Jelena\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 18:44]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-546552769-2391818124-2777313086-1000UA.job
- c:\users\Jelena\AppData\Local\Google\Update\GoogleUpdate.exe [2011-06-02 18:44]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Jelena\AppData\Roaming\Mozilla\Firefox\Profiles\mcsimgx2.default\
FF - prefs.js: browser.startup.homepage - google.rs
FF - prefs.js: network.proxy.type - 0
.
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(3580)
c:\windows\system32\FXSRESM.DLL
.
Completion time: 2011-08-01 22:12:06
ComboFix-quarantined-files.txt 2011-08-01 20:12
ComboFix2.txt 2011-08-01 13:03
ComboFix3.txt 2011-07-31 10:00
.
Pre-Run: 6,159,265,792 bytes free
Post-Run: 6,449,229,824 bytes free
.
- - End Of File - - C1AC01B78330E4952BAE69416EDEA59B
|
|
|
|
Poslao: 02 Avg 2011 00:35
|
offline
- Fil
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Legendarni građanin
- Pridružio: 11 Jun 2009
- Poruke: 16586
|
Kakvo je sada stanje sa računarom? Možeš li otvoriti Facebook?
|
|
|
|
|
|
Poslao: 02 Avg 2011 23:08
|
offline
- Kostolomka
- Novi MyCity građanin
- Pridružio: 24 Jul 2011
- Poruke: 23
|
Još uvek mi ne radi Malware i Avast, ne mogu ni da ih otvorim. Šta da radim?
|
|
|
|
|
|
|