offline
- Pridružio: 15 Maj 2009
- Poruke: 963
|
Postoji mogucnost da su mi nestale neke stvari sa fleske. Imam jednu datoteku FILE000.CHK koja verovatno ima tezinu koja mi fali (9mb). Ne verujem da ako fale da su mi ih izbrisali ovi programi (AVG, AVAST, MCShield,...). Sta bi FILE000.CHK trebalo da znaci, i ako fale, mogu li te stvari da mi se vrate.
MCShield sam juce instalirao i isto tako obrisao, ali je ostalo sledece:
https://www.mycity.rs/must-login.png
ComboFix
ComboFix 11-10-29.06 - Nikola 30.10.2011 6:25.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.381.1033.18.1918.1336 [GMT 1:00]
Running from: c:\users\kole017\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Avira FireWall *Enabled* {11638345-E4FC-4BEE-BB73-EC754659C5F6}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\kole017\Application Data\0ad
c:\users\kole017\Application Data\0ad\config\user.cfg
c:\users\kole017\WINDOWS
c:\users\tata\WINDOWS
c:\windows\help\tours\htmltour\unlock_playing.htm
c:\windows\XSxS
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-09-28 to 2011-10-30 )))))))))))))))))))))))))))))))
.
.
2063-09-19 05:50 . 2063-09-19 05:50 5501 ----a-w- c:\windows\system32\rtclmg32.dll
2011-10-28 20:16 . 2011-10-28 20:16 -------- d-----w- c:\users\tata\Application Data\NVIDIA
2011-10-28 07:17 . 2011-09-06 20:36 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-10-28 07:17 . 2011-09-06 20:37 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-10-28 07:17 . 2011-09-06 20:36 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-10-28 07:17 . 2011-09-06 20:38 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-28 07:17 . 2011-09-06 20:36 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-10-28 07:17 . 2011-09-06 20:36 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-10-28 07:17 . 2011-09-06 20:36 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-10-28 07:17 . 2011-09-06 20:33 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-10-28 07:17 . 2011-09-06 20:45 41184 ----a-w- c:\windows\avastSS.scr
2011-10-28 07:17 . 2011-09-06 20:45 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-10-28 07:17 . 2011-10-28 07:17 -------- d-----w- c:\users\All Users\Application Data\AVAST Software
2011-10-28 07:17 . 2011-10-28 07:17 -------- d-----w- c:\program files\AVAST Software
2011-10-28 06:05 . 2011-10-28 07:04 83793 ----a-w- c:\windows\system32\drivers\sfi.dat
2011-10-28 06:03 . 2011-10-28 06:03 -------- d-----w- c:\users\All Users\Application Data\Comodo Downloader
2011-10-28 05:53 . 2011-10-29 08:24 -------- d-----w- c:\users\kole017\Application Data\MCShield
2011-10-27 19:18 . 2011-10-27 19:23 -------- d-----w- c:\users\tata\Application Data\MCShield
2011-10-27 14:02 . 2011-10-27 14:02 -------- d-----w- c:\users\car017\Application Data\Apple Computer
2011-10-27 07:40 . 2011-10-27 07:40 -------- d-----w- c:\users\All Users\Application Data\Apple Computer
2011-10-27 07:39 . 2011-10-27 07:39 -------- d-----w- c:\users\kole017\Local Settings\Application Data\Apple
2011-10-27 07:39 . 2011-10-27 07:39 -------- d-----w- c:\users\All Users\Application Data\Apple
2011-10-27 07:39 . 2011-10-27 07:39 -------- d-----w- c:\program files\Apple Software Update
2011-10-27 07:31 . 2011-10-27 07:31 -------- d-----w- c:\program files\Common Files\Java
2011-10-27 07:31 . 2011-10-27 07:30 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-10-26 08:29 . 2011-10-26 08:29 -------- d-----w- c:\users\kole017\Application Data\pdfforge
2011-10-26 08:29 . 2011-10-26 08:29 -------- d-----w- c:\program files\PDFCreator
2011-10-25 08:39 . 2011-10-25 08:41 -------- d-----w- c:\users\Desktop
2011-10-24 19:38 . 2011-10-24 19:38 -------- d-----w- c:\users\kole017\Application Data\NVIDIA
2011-10-24 19:05 . 2011-10-24 19:06 -------- d-----w- C:\CodeBlocks
2011-10-24 12:29 . 2011-10-24 12:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 12:29 . 2011-10-24 12:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-23 11:11 . 2011-10-23 11:13 -------- d-----w- c:\users\kole017\Application Data\SharpReader
2011-10-23 06:51 . 2011-10-23 06:52 -------- d-----w- c:\users\kole017\Application Data\Workrave
2011-10-22 07:39 . 2011-10-22 07:39 -------- d-----w- c:\users\car017\Application Data\NVIDIA
2011-10-13 16:36 . 2011-10-28 05:45 -------- d-----w- c:\users\All Users\Application Data\AVG2012
2011-10-05 15:56 . 2011-10-05 15:56 11776 ----a-w- c:\program files\Mozilla Firefox\plugins\nprjplug.dll
2011-10-05 15:56 . 2011-10-05 15:56 150696 ----a-w- c:\program files\Mozilla Firefox\plugins\nppl3260.dll
2011-10-05 15:56 . 2011-10-05 15:56 107008 ----a-w- c:\program files\Mozilla Firefox\plugins\nprpjplug.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-27 07:30 . 2010-09-04 13:33 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-16 08:31 . 2011-05-15 18:01 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-05 15:56 . 2009-10-29 04:48 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-10-05 15:56 . 2006-09-25 15:39 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-09-01 12:32 . 2011-09-01 12:32 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2011-09-01 12:32 . 2011-09-01 12:32 165376 ----a-w- c:\windows\system32\drivers\atksgt.sys
2011-08-31 15:00 . 2009-12-17 10:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-18 11:28 . 2010-03-01 15:45 436792 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-08-16 13:04 . 2011-03-19 18:01 200704 ----a-w- c:\windows\iesshell.dll
2011-08-03 11:49 . 2011-09-20 13:35 600680 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-08-03 11:49 . 2011-09-20 13:35 914024 ----a-w- c:\windows\system32\nvdispco32.dll
2011-08-03 11:49 . 2011-09-20 13:35 875112 ----a-w- c:\windows\system32\nvgenco32.dll
2011-08-03 11:49 . 2011-09-20 13:35 61440 ----a-w- c:\windows\system32\OpenCL.dll
2011-08-03 11:49 . 2011-09-20 13:35 5427200 ----a-w- c:\windows\system32\nvcuda.dll
2011-08-03 11:49 . 2011-09-20 13:35 2387560 ----a-w- c:\windows\system32\nvcuvid.dll
2011-08-03 11:49 . 2011-09-20 13:35 2090088 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-08-03 11:49 . 2011-09-20 13:35 17186816 ----a-w- c:\windows\system32\nvcompiler.dll
2011-08-03 11:49 . 2009-12-08 13:55 145000 ----a-w- c:\windows\system32\nvcolor.exe
2011-08-03 11:49 . 2009-12-08 13:49 146024 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-03 11:49 . 2009-12-08 13:49 12542592 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-08-03 11:49 . 2009-12-08 13:49 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-08-03 11:49 . 2009-12-08 13:49 16191488 ----a-w- c:\windows\system32\nvoglnt.dll
2011-08-03 11:49 . 2009-12-08 13:48 111208 ----a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:49 . 2009-12-08 13:48 2404864 ----a-w- c:\windows\system32\nvapi.dll
2011-08-03 11:49 . 2009-12-08 13:48 13892200 ----a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:49 . 2009-12-08 13:48 4210816 ----a-w- c:\windows\system32\nv4_disp.dll
2011-09-29 06:53 . 2011-03-25 12:40 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2004-08-04 . BB4D3A8E6F7EB1D370BC4AD27AB23368 . 360576 . . [5.1.2600.2892] . . c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-09-06 20:45 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-08-03 13892200]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-10-05 273528]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 53760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSimpleStartMenu"= 1 (0x1)
"StartMenuFavorites"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Users^All Users^Start Menu^Programs^Startup^Device Detector 3.lnk]
backup=c:\windows\pss\Device Detector 3.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 12:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2011-06-15 13:02 15141768 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-06-09 11:06 254696 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2010-07-08 17:41 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"VirtualDrive"="c:\program files\FarStone\VirtualDrivePro\VDTask.exe" /AutoRestore
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\FarStone\\VirtualDrivePro\\MGR.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"e:\\CS 1.6 v42 FULL\\hl.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1.3.2010 16:45 436792]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [28.10.2011 8:17 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [28.10.2011 8:17 320856]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28.10.2011 8:17 20568]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [20.9.2011 14:35 2255464]
R3 FVDSCSI;FVDSCSI;c:\windows\system32\drivers\fvdscsi.sys [29.3.2010 13:43 60008]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\drivers\vcsvad.sys [9.4.2011 10:58 17792]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [8.12.2009 17:01 279680]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2011 16:18 136176]
S3 FXDrv32;FXDrv32;\??\f:\fxdrv32.sys --> f:\FXDrv32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [8.5.2011 16:18 136176]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [6.4.2009 13:19 23064]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-10-30 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-01-29 07:07]
.
2011-10-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-08 15:18]
.
2011-10-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-08 15:18]
.
2011-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1645522239-2147080141-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1645522239-2147080141-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1645522239-2147080141-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1645522239-2147080141-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1645522239-2147080141-839522115-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1645522239-2147080141-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1645522239-2147080141-839522115-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1645522239-2147080141-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1645522239-2147080141-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
2011-10-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1645522239-2147080141-839522115-1009.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-09-27 11:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.rs/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\kole017\Application Data\Mozilla\Firefox\Profiles\tt8evuvw.default\
FF - prefs.js: browser.startup.homepage - www.google.rs
FF - prefs.js: keyword.URL - hxxp://www.google.rs/#sclient=psy&hl=sr&site=&source=hp&q=
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-MCShield - c:\program files\MCShield\MCShieldRTM.exe
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-30 06:35
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\OMSCAN]
"ImagePath"="\Sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1645522239-2147080141-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:4c,f6,63,d9,8b,ef,f6,e6,56,c3,5e,0c,8c,de,25,49,b4,23,69,5c,7f,
f1,7c,5b,6a,9d,e3,5b,97,31,54,ca,2b,8e,d1,53,cc,b3,7c,66,78,81,fb,be,77,e9,\
"rkeysecu"=hex:47,1f,b8,fb,bb,d4,ad,21,79,49,7f,5a,03,4d,d0,8e
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(452)
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-10-30 06:39:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-30 05:39
.
Pre-Run: 48.888.864.768 bytes free
Post-Run: 49.938.780.160 bytes free
.
- - End Of File - - 5713173CDA65EF892687E9886095F1FB
|