Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Problem sa wormom

[es] :: Zaštita :: Problem sa wormom

[ Pregleda: 4739 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

igor_cg

Član broj: 140731
Poruke: 63
*.crnagora.net.



Profil

icon Problem sa wormom29.01.2010. u 12:21 - pre 173 meseci
Može li mi neko pomoći oko ovog worma koji sam pokupio putem fleške.Probao sam da obrišem sa Nod32 :(
"E:\SLATKO\torta.exe - a variant of Win32/Peerfrag.FU worm"
Hvala!
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Problem sa wormom29.01.2010. u 12:26 - pre 173 meseci
http://download.bleepingcomputer.com/sUBs/dds.scr

Pokreni ovaj program pa mi iskopiraj DDS.txt log
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Problem sa wormom30.01.2010. u 08:04 - pre 173 meseci
Citat:
iskopiraj DDS.txt log
 
Odgovor na temu

igor_cg

Član broj: 140731
Poruke: 63
*.crnagora.net.



Profil

icon Re: Problem sa wormom30.01.2010. u 12:32 - pre 173 meseci

DDS (Ver_09-12-01.01) - NTFSx86
Run by pc at 13:31:45.92 on Sat 01/30/2010
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.957.411 [GMT 1:00]

AV: avast! antivirus 4.8.1368 [VPS 100130-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\pc\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TouchPadHotKey] "c:\program files\fsc\touchpad hotkey utility\TouchPad_HotKey.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {7BA7E7FE-A80E-4C29-AEBE-6C37C4C3202C} = 195.66.160.1,195.66.160.2
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\pc\applic~1\mozilla\firefox\profiles\dgja7oqw.default\
FF - prefs.js: browser.startup.homepage - hxxps://webmax.t-com.me/?_task=mail&_action=today
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\pc\local settings\application data\yahoo!\browserplus\2.4.21\plugins\npybrowserplus_2.4.21.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-1-27 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-27 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-27 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-27 138680]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-27 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-27 352920]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2008-9-15 20504]
S3 KLIF;KLIF;\??\c:\windows\system32\drivers\klif.sys --> c:\windows\system32\drivers\klif.sys [?]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-9-24 1181328]
S4 SCPDFV4ReadSpool;SolidConverterPDFv4ReadSpool;c:\windows\installer\MSI4C4.tmp [2009-12-28 189688]

=============== Created Last 30 ================

2010-01-28 12:43:15 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 12:43:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 12:43:13 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-28 12:05:23 0 d-----w- c:\windows\Time Stopper
2010-01-23 09:52:21 0 d-----w- c:\documents and settings\pc\xpsun
2010-01-13 08:37:39 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-06 09:21:39 0 d-----w- c:\docume~1\pc\applic~1\TeamViewer
2010-01-06 09:21:35 0 d-----w- c:\program files\TeamViewer
2010-01-06 09:21:07 0 d-----w- c:\documents and settings\pc\temp

==================== Find3M ====================

2010-01-05 10:00:29 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00:21 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00:20 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-04 11:58:04 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-01-18 19:57:05 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011820090119\index.dat

============= FINISH: 13:32:08.85 ===============
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Problem sa wormom30.01.2010. u 19:31 - pre 173 meseci
Dosta ti koci komjuter je li tako? Promenio si nekoliko antivirusa i imas ostatke od Kasperskog.
Skini na desktop ovaj program http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Iskljuci Avasta
Pokreni sa desktopa ComboFix
klikni yes ili ok za sve sto te pita. Kad zavrsi skeniranje okaci mi log.
 
Odgovor na temu

igor_cg

Član broj: 140731
Poruke: 63
213.133.5.*



Profil

icon Re: Problem sa wormom30.01.2010. u 21:49 - pre 173 meseci
Kristi1 hvala ti na javljanju!Da koči mi računar,ali log tek u ponedeljak mogu da postavim jer se radi o računaru iz kancelariji!
Hvala ti još jednom.

P.S. ovo je sa kućnog računara(ako imaš vremena da provjeris jeli sve ok) Thanks!


DDS (Ver_09-12-01.01) - NTFSx86
Run by PC at 22:47:19.28 on Sat 01/30/2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1321 [GMT 1:00]

AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Installer\MSI44E.tmp
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Common Files\Nokia\MPlatform\NokiaMServer.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\PC\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [NokiaMServer] c:\program files\common files\nokia\mplatform\NokiaMServer /watchfiles startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [RunNarrator] Narrator.exe
IE: &Google Search - c:\program files\google\googletoolbar.dll/cmsearch.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://c:\program files\burger shop 2\images\stg_drm.ocx
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://c:\program files\burger shop 2\images\armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
AppInit_DLLs:
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\pc\applic~1\mozilla\firefox\profiles\1nptc0nz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - divx-titlovi.com
FF - prefs.js: browser.startup.homepage - hxxp://www.vijesti.me/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\1nptc0nz.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\all users\application data\zylom\zylomgamesplayer\npzylomgamesplayer.dll
FF - plugin: c:\documents and settings\pc\application data\facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\pc\local settings\application data\yahoo!\browserplus\2.4.21\plugins\npybrowserplus_2.4.21.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

FF - user.js: network.http.max-persistent-connections-per-server - 4
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/01/02 18:04:37];c:\program files\cyberlink\powerdvd9\000.fcl [2009-3-30 87536]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]
R2 SCPDFV4ReadSpool;SolidConverterPDFv4ReadSpool;c:\windows\installer\MSI44E.tmp [2009-12-27 189688]
R3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [2008-5-14 223232]
S0 Lbd;Lbd;c:\windows\system32\drivers\lbd.sys --> c:\windows\system32\drivers\Lbd.sys [?]
S2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\starwindserviceae.exe --> c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [?]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
S3 WFIOCTL;WFIOCTL;c:\program files\winfast\wfdtv\WFIOCTL.sys [2008-5-14 9446]
S4 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2008-1-4 587096]

=============== Created Last 30 ================

2010-01-30 13:04:20 54156 ---ha-w- c:\windows\QTFont.qfn
2010-01-30 13:04:20 1409 ----a-w- c:\windows\QTFont.for
2010-01-29 14:21:57 0 d-----w- c:\docume~1\pc\applic~1\Facebook
2010-01-25 22:41:02 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-15 22:50:14 0 d-----w- c:\program files\AskBarDis
2010-01-15 15:28:31 0 d-----w- c:\docume~1\pc\applic~1\Nokia Ovi Suite
2010-01-14 22:19:53 0 d-----w- c:\program files\PC Connectivity Solution
2010-01-14 21:03:03 0 d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-01-14 20:54:50 0 d-----w- c:\windows\system32\wbem\Repository
2010-01-14 20:54:36 0 d-----w- c:\program files\Your Uninstaller 2008
2010-01-14 18:12:05 0 d-----w- c:\program files\PC Connectivity Solution(2)
2010-01-14 18:07:13 0 d-----w- c:\docume~1\alluse~1\applic~1\OviInstallerCache
2010-01-13 22:19:01 0 d-----w- c:\program files\SUPERAntiSpyware
2010-01-13 22:19:01 0 d-----w- c:\docume~1\pc\applic~1\SUPERAntiSpyware.com
2010-01-12 21:50:48 0 d-----w- c:\program files\common files\Wise Installation Wizard
2010-01-12 21:49:56 0 d-----w- c:\windows\nview
2010-01-12 21:44:43 17254 ----a-w- c:\windows\system32\nvwsapps.xml
2010-01-12 21:44:43 127254 ----a-w- c:\windows\system32\nvapps.xml
2010-01-12 21:44:38 17463 ----a-w- c:\windows\system32\nvdisp.nvu
2010-01-12 21:44:38 0 d-----w- c:\windows\nview(2)
2010-01-12 21:43:18 1018772 ----a-w- c:\windows\system32\nvucode.bin
2010-01-11 22:35:29 0 d-----w- c:\program files\SUPERAntiSpyware(2)
2010-01-11 22:35:29 0 d-----w- c:\docume~1\pc\applic~1\SUPERAntiSpyware(2).com
2010-01-04 21:27:59 0 d-----w- C:\Drivers
2010-01-04 21:24:25 1409254 ----a-w- c:\windows\setupapi.log.1.old
2010-01-04 21:09:00 0 dc----w- c:\docume~1\alluse~1\applic~1\{66E2F539-12B6-4870-A500-7689CDE75C5E}
2010-01-04 21:07:12 0 d-----w- c:\docume~1\pc\applic~1\TeamViewer
2010-01-04 21:00:38 0 d-----w- c:\documents and settings\pc\.VirtualBox
2010-01-04 20:57:11 0 d-----w- c:\program files\Sun
2010-01-04 20:49:28 41424 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2010-01-03 13:38:04 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-01-03 00:01:15 0 d-----w- c:\program files\EA GAMES
2010-01-02 16:46:58 0 d-----w- c:\docume~1\pc\applic~1\URSoft
2010-01-02 15:08:43 4767 ----a-w- c:\windows\Irremote.ini
2010-01-01 23:02:51 0 d-----w- c:\program files\NCH Software
2010-01-01 23:02:43 0 d-----w- c:\program files\NCH Swift Sound
2010-01-01 20:27:02 0 d-----w- c:\program files\AimOne_AlltoMP3
2010-01-01 20:09:07 335872 ----a-w- c:\windows\system32\m4atag.dll
2010-01-01 19:45:03 0 d-----w- c:\docume~1\pc\applic~1\AVS4YOU
2010-01-01 19:44:35 0 d-----w- c:\docume~1\alluse~1\applic~1\AVS4YOU
2010-01-01 19:28:46 0 d-----w- c:\program files\common files\AVSMedia
2010-01-01 19:28:22 0 d-----w- c:\program files\AVS4YOU

==================== Find3M ====================

2010-01-07 15:07:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 15:07:04 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 17:10:44 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-01-02 17:10:44 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-12-31 15:58:01 87608 ----a-w- c:\docume~1\pc\applic~1\inst.exe
2009-12-31 15:58:00 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-12-31 15:58:00 47360 ----a-w- c:\docume~1\pc\applic~1\pcouffin.sys
2009-12-22 05:42:49 662016 ----a-w- c:\windows\system32\wininet.dll
2009-12-22 05:42:45 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-12-03 14:59:48 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-11-20 23:11:03 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-11-20 23:11:01 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2009-11-16 11:25:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2009-11-03 09:19:43 0 ----a-w- c:\documents and settings\pc\history.dat

============= FINISH: 22:47:48.53 ===============
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Problem sa wormom31.01.2010. u 07:50 - pre 173 meseci
Ovo je cisto.
 
Odgovor na temu

igor_cg

Član broj: 140731
Poruke: 63
*.crnagora.net.



Profil

icon Re: Problem sa wormom01.02.2010. u 20:08 - pre 173 meseci
ComboFix 10-01-31.05 - pc 02/01/2010 15:02:29.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.957.558 [GMT 1:00]
Running from: c:\documents and settings\pc\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100131-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\pc\RavMonLog
c:\recycler\S-1-5-21-4452432571-1359283844-355285569-2363
c:\recycler\S-1-5-21-6447609684-6125181263-496867207-2251
c:\recycler\S-1-5-21-6765914371-8869209286-718175895-5426
c:\recycler\S-1-5-21-7854750040-9194512387-477392542-4486
c:\windows\system32\AutoRun.inf

.
((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-01-28 12:43 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-28 12:43 . 2010-01-28 12:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-28 12:43 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-28 12:05 . 2010-01-28 12:05 -------- d-----w- c:\windows\Time Stopper
2010-01-23 09:52 . 2010-01-23 09:59 -------- d-----w- c:\documents and settings\pc\xpsun
2010-01-23 09:52 . 2010-01-23 09:52 57856 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\cache\6.0\47\1247e16f-2f00600d-1.1--n\ShellLink_x64.dll
2010-01-23 09:52 . 2010-01-23 09:52 53248 ----a-w- c:\documents and settings\pc\Application Data\Sun\Java\Deployment\cache\6.0\47\1247e16f-2f00600d-1.1--n\ShellLink.dll
2010-01-15 10:44 . 2010-01-15 10:44 -------- d-----w- c:\documents and settings\pc\Local Settings\Application Data\Yahoo!
2010-01-13 08:37 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-06 09:21 . 2010-01-06 09:42 -------- d-----w- c:\documents and settings\pc\Application Data\TeamViewer
2010-01-06 09:21 . 2010-01-16 10:08 -------- d-----w- c:\program files\TeamViewer
2010-01-06 09:21 . 2010-01-06 09:21 -------- d-----w- c:\documents and settings\pc\temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 11:59 . 2009-04-09 08:50 -------- d-----w- c:\documents and settings\pc\Application Data\Skype
2010-01-23 11:00 . 2009-11-13 13:31 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-22 09:33 . 2009-12-28 20:24 -------- d-----w- c:\documents and settings\pc\Application Data\SolidDocuments
2010-01-06 09:18 . 2009-11-13 12:39 -------- d-----w- c:\program files\JDownloader
2010-01-05 10:00 . 2006-02-28 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-12-28 20:21 . 2009-12-28 20:21 -------- d-----w- c:\program files\SolidDocuments
2009-12-28 20:21 . 2009-12-28 20:21 -------- d-----w- c:\documents and settings\All Users\Application Data\SolidDocuments
2009-12-22 10:57 . 2009-12-22 10:52 -------- d-----w- c:\documents and settings\pc\Application Data\eBookPro6
2009-12-11 20:43 . 2009-12-11 20:43 -------- d-----w- c:\program files\MSXML 4.0
2009-12-04 11:58 . 2009-01-27 17:04 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-04 11:55 . 2009-12-04 11:55 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-03 18:11 . 2009-01-23 13:37 -------- d-----w- c:\documents and settings\pc\Application Data\HPAppData
2009-11-24 23:54 . 2009-07-27 11:46 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-07-27 11:46 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-07-27 11:46 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-07-27 11:46 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-07-27 11:46 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-07-27 11:46 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-07-27 11:46 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-07-27 11:46 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-07-27 11:46 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-19 10:48 . 2009-11-27 17:37 872960 ----a-w- c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 10:48 . 2009-11-27 17:37 43008 ----a-w- c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 10:48 . 2009-11-27 17:37 340480 ----a-w- c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 10:48 . 2009-11-27 17:37 346624 ----a-w- c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TouchPadHotKey"="c:\program files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-06-26 360448]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Utility Tray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk
backup=c:\windows\pss\Utility Tray.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^pc^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\pc\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-12-11 14:57 948672 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-12-22 00:57 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 16:43 69632 ------r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 22:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-03-11 20:34 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-09-08 19:09 305440 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-09-04 23:54 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-08-10 13:21 16384000 ------r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSPower]
2007-08-03 14:07 53248 ----a-r- c:\windows\system32\SiSPower.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
2006-11-22 15:31 630784 ----a-r- c:\program files\Motorola\SMSERIAL\sm56hlpr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-05-10 17:22 864256 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SCPDFV4ReadSpool"=2 (0x2)
"ose"=3 (0x3)
"MDM"=2 (0x2)
"Lavasoft Ad-Aware Service"=2 (0x2)
"JavaQuickStarterService"=2 (0x2)
"iPod Service"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\v8200\\DMMultiView\\MultiView.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"17477:TCP"= 17477:TCP:NortonAV
"13606:TCP"= 13606:TCP:NortonAV
"12759:TCP"= 12759:TCP:NortonAV
"13895:TCP"= 13895:TCP:NortonAV
"12749:TCP"= 12749:TCP:NortonAV

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/27/2009 2:46 PM 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [7/27/2009 12:46 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/27/2009 12:46 PM 20560]
R3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [9/15/2008 11:34 AM 20504]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 12:17 PM 1181328]
S4 SCPDFV4ReadSpool;SolidConverterPDFv4ReadSpool;c:\windows\Installer\MSI4C4.tmp [12/28/2009 9:21 PM 189688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2010-02-01 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 17:58]

2010-01-29 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 17:58]

2010-01-28 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 17:58]

2010-01-29 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 17:58]

2010-02-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 17:58]

2009-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {7BA7E7FE-A80E-4C29-AEBE-6C37C4C3202C} = 195.66.160.1,195.66.160.2
FF - ProfilePath - c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\
FF - prefs.js: browser.startup.homepage - hxxps://webmax.t-com.me/?_task=mail&_action=today
FF - component: c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\dgja7oqw.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\documents and settings\pc\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-amva - c:\windows\system32\amvo.exe
AddRemove-DivX Plus DirectShow Filters - c:\program files\DivX\DivXDSFiltersUninstall.exe
AddRemove-HijackThis - c:\documents and settings\pc\Desktop\1234\HijackThis.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
AddRemove-{B7050CBDB2504B34BC2A9CA0A692CC29} - c:\program files\DivX\DivXWebPlayerUninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 15:08
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SCPDFV4ReadSpool]
"ImagePath"="c:\windows\Installer\MSI4C4.tmp"
.
Completion time: 2010-02-01 15:09:46
ComboFix-quarantined-files.txt 2010-02-01 14:09

Pre-Run: 48,748,695,552 bytes free
Post-Run: 50,056,720,384 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - AF41D9E7D6730530C3A8C624F7698137
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
*.ptt.rs.

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Problem sa wormom01.02.2010. u 20:38 - pre 173 meseci
Igore, imas zarazenu flesku ili neku drugu memorisku karticu, kad god je ubacis u komp ti ga inficiras. Uzmi i formatiraj taj flash ako je on u pitanju.
 
Odgovor na temu

Aleksandar Maletic
System administrator

Moderator
Član broj: 235887
Poruke: 1138
*.mbb.telenor.rs.



+89 Profil

icon Re: Problem sa wormom02.02.2010. u 09:34 - pre 173 meseci
Formatiraj sve flash-eve i kartice,nakon toga instaliraj Panda USB Vaccine,vakcinisi kompjuter i svaki flash i karticu...nakon toga,odradi scan sa Dr.Web CureIt-om,to je free AV koji se pokrece bez instalacije,uklonice ostatke ukoliko ih ima...ipak je u pitanju worm,ne siri zarazu ali ga treba upecati... :)))
A wolf is weaker than a lion and a tiger, but doesn't play in the circus.
 
Odgovor na temu

igor_cg

Član broj: 140731
Poruke: 63
213.133.5.*



Profil

icon Re: Problem sa wormom02.02.2010. u 22:03 - pre 173 meseci
Hvala na savjetima!Javljam se kada sve odradim.

P.S. Nemam pojma šta bi moglo da bude.Ako je fleška onda bih vjerovatno sa njom trebao da zarazim i komp. kojim se nalazi kući.Log sa kućnog komp.sam takođe postavio i on je čist, kako mi je rekao kristi1.
Pozz
 
Odgovor na temu

igor_cg

Član broj: 140731
Poruke: 63
*.crnagora.net.



Profil

icon Re: Problem sa wormom03.02.2010. u 13:18 - pre 173 meseci
Hvala svima,sve je ok!
 
Odgovor na temu

[es] :: Zaštita :: Problem sa wormom

[ Pregleda: 4739 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.