Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Nod32 ne moze da skenira racunar!!

[es] :: Zaštita :: Nod32 ne moze da skenira racunar!!

[ Pregleda: 3225 | Odgovora: 14 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Nod32 ne moze da skenira racunar!!29.01.2010. u 23:27 - pre 173 meseci
Ne razumem se nesto u zastitu racunara i ovaj problem mi se javlja da ne mogu da skeniram a kad palim komp, nekad se po dva puta zaglavi i tako...da ne pricam puno evo par slika...





 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!29.01.2010. u 23:48 - pre 173 meseci
Skini program Malwarebytes' Anti-Malware
Dvoklikom pokreni instalaciju
Na samom pocetku proveri da li su stiklirane ove opcije
Update Malwarebytes' Anti-Malware
Launch Malwarebytes Anti-Malware

Zatim klikni Finish.

Izaberi opciju Perform Quick Scan i klikni Scan.
Po zavrsetku procesa klikni OK, Show Results:
u listi detektovanog malware-a proveri da li su obelezene sve stavke i klikni Remove Selected.

Po zavrsetku ciscenja zakaci MBAM log na forum.


..................


Skini DDS Program na Desktop
http://download.bleepingcomputer.com/sUBs/dds.scr

Dvoklikom pokreni dds.scr

Kad zavrsi, DDS ce otvoriti dva loga:
1. DDS.txt
2. Attach.txt
Oba izvestaja sacuvaj na Desktop.
Kopiraj mi DDS.txt
 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!30.01.2010. u 10:34 - pre 173 meseci
Znaci pre toga ne treba da izbrisem nod?
 
Odgovor na temu

Sc0rp10
Virtual

Član broj: 150826
Poruke: 327



+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!30.01.2010. u 11:22 - pre 173 meseci
Ne.
Divide et impera.

Android power!
 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!30.01.2010. u 12:29 - pre 173 meseci
Malwarebytes' Anti-Malware 1.44
Database version: 3662
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

30.1.2010 13:07:50
mbam-log-2010-01-30 (13-07-50).txt

Scan type: Quick Scan
Objects scanned: 130827
Time elapsed: 7 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\secfile (Trojan.Fakealert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Documents and Settings\Srdjo\Start Menu\Programs\Startup\siszyd32.exe (Trojan.Agent) -> Delete on reboot.
D:\Documents and Settings\Srdjo\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
D:\Documents and Settings\NetworkService\Application Data\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully.
D:\Documents and Settings\Srdjo\Application Data\fvgqad.dat (Malware.Trace) -> Quarantined and deleted successfully.

......................


A od DDS-a sam dobio nesto sto sam poslao magni86 na pp
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!30.01.2010. u 18:38 - pre 173 meseci
Citat:
A od DDS-a sam dobio nesto sto sam poslao magni86 na pp


Ma slobodno postavljaj logove ovde
Obrisi taj program (DDS) i skini novi na desktop. Ponovo ga pokreni.
kopiraj mi DDS log. I reci mi ima li poboljsanja?
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!30.01.2010. u 19:56 - pre 173 meseci
edit:
Mirori DDS Programa::
http://download.bleepingcomputer.com/sUBs/dds.com

Skini DDS program sa ovih linkova i skeniraj komp po uputstvu
 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!31.01.2010. u 12:41 - pre 173 meseci
E sad sam dobio DSS.txt i Attach.txt

Evo DDS.txt


DDS (Ver_09-12-01.01) - NTFSx86
Run by Srdjo at 13:38:07,67 on ned 31.01.2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1255 [GMT 1:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Program Files\Winamp\winampa.exe
D:\Program Files\Java\jre6\bin\jusched.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
D:\Program Files\WinFast\WFDTV\DTVSchdl.exe
D:\Program Files\WinFast\WFDTV\WFWIZ.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
D:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
D:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Skype\Phone\Skype.exe
D:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\Program Files\WinZip\WZQKPICK.EXE
D:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
svchost.exe
C:\Program Files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\PnkBstrA.exe
D:\WINDOWS\system32\PnkBstrB.exe
D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
D:\Program Files\PC Connectivity Solution\ServiceLayer.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Srdjo\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
D:\Documents and Settings\Srdjo\Desktop\dds.com

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://search.live.com/sphome.aspx
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: H - No File
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - d:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - d:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - d:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "d:\program files\common files\nero\lib\NMBgMonitor.exe"
uRun: [swg] "d:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [Skype] "d:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [uTorrent] "d:\program files\utorrent\uTorrent.exe"
uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Google Update] "d:\documents and settings\srdjo\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [SkyTel] SkyTel.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [NeroFilterCheck] d:\program files\common files\nero\lib\NeroCheck.exe
mRun: [NBKeyScan] "d:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [WinampAgent] "d:\program files\winamp\winampa.exe"
mRun: [SunJavaUpdateSched] "d:\program files\java\jre6\bin\jusched.exe"
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime
mRun: [WinFastDTV] d:\program files\winfast\wfdtv\DTVSchdl.exe
mRun: [WinFast Schedule] d:\program files\winfast\wfdtv\WFWIZ.exe
mRun: [egui] "d:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [<NO NAME>]
mRun: [StatusClient] d:\program files\hewlett-packard\toolbox2.0\apache tomcat 4.0\webapps\toolbox\statusclient\StatusClient.exe /auto
mRun: [TomcatStartup] d:\program files\hewlett-packard\toolbox2.0\hpbpsttp.exe
mRun: [PCSuiteTrayApplication] d:\program files\nokia\nokia pc suite 6\LaunchApplication.exe -startup
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [CTFMON.EXE] d:\windows\system32\CTFMON.EXE
dRun: [Nokia.PCSync] d:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: d:\docume~1\srdjo\startm~1\programs\startup\adobeg~1.lnk - d:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - d:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - d:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - d:\program files\common files\autodesk shared\acstart16.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - d:\program files\winzip\WZQKPICK.EXE
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - d:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: bancaintesabeograd.com\online
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~2\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - d:\docume~1\srdjo\applic~1\mozilla\firefox\profiles\i11jdko6.default\
FF - component: d:\documents and settings\srdjo\application data\mozilla\firefox\profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: d:\documents and settings\srdjo\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [2009-3-11 159616]
R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [2009-3-11 5248]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360]
R2 ekrn;ESET Service;d:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840]
R2 StarWindService;StarWind iSCSI Service;d:\program files\alcohol soft\alcohol 120\starwind\StarWindService.exe [2005-4-2 217600]
R3 WFIOCTL;WFIOCTL;d:\program files\winfast\wfdtv\WFIOCTL.sys [2009-6-27 9446]
S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\google\update\GoogleUpdate.exe [2009-6-28 133104]
S2 icivlqm;Config Boot;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336]
S2 mvyif;Boot Shell;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336]
S2 nvenwtbvt;Microsoft Helper;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336]
S2 wefigtj;System Server;d:\windows\system32\svchost.exe -k netsvcs [2004-8-3 14336]

=============== Created Last 30 ================

2010-01-30 11:56:09 0 d-----w- d:\docume~1\srdjo\applic~1\Malwarebytes
2010-01-30 11:56:05 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 11:56:03 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-01-30 11:56:03 0 d-----w- d:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-30 11:56:02 0 d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-01-15 19:52:18 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys
2010-01-15 19:52:18 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys
2010-01-15 19:52:13 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys
2010-01-15 19:52:13 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys
2010-01-15 19:52:11 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys
2010-01-15 19:52:11 8192 ----a-w- d:\windows\system32\drivers\Changer.sys

==================== Find3M ====================

2009-12-22 05:42:49 662016 ----a-w- d:\windows\system32\wininet.dll
2009-12-22 05:42:45 81920 ----a-w- d:\windows\system32\ieencode.dll

============= FINISH: 13:38:27,96 ===============
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!31.01.2010. u 14:08 - pre 173 meseci
* Skini Combofix program
Poseti ovu stranicu za download linki Uputstvo za koriscenje Combofix programa:
http://www.elitesecurity.org/t...e-programa-HijackThis-ComboFix

* Privremeno iskljuci svoj AntiVirus program.
Poseti ovu stranicu za uputstvo:
http://www.bleepingcomputer.com/forums/topic114351.html

* Pokreni Combofix!
Kad alat zavrsi skeniranje otvorice notepad sa izvestajem (log).
Kopiraj taj izvestaj ovde. (tipicna lokacija loga: C:\ComboFix.txt)
 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!31.01.2010. u 15:15 - pre 173 meseci
Evo ga:



ComboFix 10-01-30.05 - Srdjo 31.01.2010 16:07:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1658 [GMT 1:00]
Running from: d:\documents and settings\Srdjo\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\setup.exe
D:\Thumbs.db
d:\windows\n.tmp
d:\windows\system32\_000013_.tmp.dll
d:\windows\system32\Dvbpws.dll

.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-31 )))))))))))))))))))))))))))))))
.

2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-01-15 19:52 . 2004-08-03 21:59 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\Changer.sys
2010-01-08 10:24 . 2009-12-16 13:42 43008 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-01-08 10:24 . 2009-12-16 13:42 340480 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-01-08 10:24 . 2009-12-16 13:41 346624 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-01-08 10:24 . 2009-12-16 13:42 872960 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-01-06 10:20 . 2010-01-06 10:20 -------- d-----w- d:\documents and settings\Srdjo\Local Settings\Application Data\WinZip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-31 14:59 . 2009-11-10 17:52 -------- d-----w- d:\documents and settings\Srdjo\Application Data\uTorrent
2010-01-31 14:59 . 2009-09-20 14:49 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Skype
2010-01-30 10:23 . 2009-09-20 14:55 -------- d-----w- d:\documents and settings\Srdjo\Application Data\skypePM
2010-01-16 09:59 . 2010-01-16 09:59 16 ----a-w- d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat
2010-01-14 06:24 . 2009-12-02 11:22 79488 ----a-w- d:\documents and settings\Srdjo\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-13 22:47 . 2009-05-05 12:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-06 10:20 . 2009-03-11 20:46 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2010-01-04 16:15 . 2009-06-30 19:16 133120 ----a-w- d:\documents and settings\Srdjo\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-12-27 18:54 . 2009-12-27 18:54 -------- d-----w- d:\program files\URUSoft
2009-12-27 18:48 . 2009-12-27 18:48 -------- d-----w- d:\program files\TimeAdjuster
2009-12-27 02:03 . 2009-12-27 02:03 -------- d-----w- d:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Microsoft
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live SkyDrive
2009-12-25 23:12 . 2009-12-25 23:12 -------- d-----w- d:\program files\Common Files\Windows Live
2009-12-22 05:42 . 2004-08-03 22:56 662016 ----a-w- d:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-03 22:56 81920 ----a-w- d:\windows\system32\ieencode.dll
2009-12-21 07:53 . 2009-03-11 19:24 -------- d-----w- d:\program files\Google
2009-11-23 12:26 . 2009-10-02 10:00 664 ----a-w- d:\windows\system32\d3d9caps.dat
2009-11-21 16:36 . 2004-08-03 22:56 470528 ----a-w- d:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-15 68856]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-11-10 289584]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-04 135664]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"WinFastDTV"="d:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112]
"WinFast Schedule"="d:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816]
"egui"="d:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"StatusClient"="d:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="d:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"PCSuiteTrayApplication"="d:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

d:\documents and settings\Srdjo\Start Menu\Programs\Startup\
Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Adobe Reader Speed Launch.lnk - d:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-10 10872]
WinZip Quick Pick.lnk - d:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"=
"d:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault(tm)\\mohpa.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\proobj.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [11.3.2009 20:19 5248]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R2 ekrn;ESET Service;d:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
S0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [11.3.2009 20:19 159616]
S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\Google\Update\GoogleUpdate.exe [28.6.2009 18:30 133104]
S2 icivlqm;Config Boot;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336]
S2 mvyif;Boot Shell;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336]
S2 nvenwtbvt;Microsoft Helper;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336]
S2 wefigtj;System Server;d:\windows\system32\svchost.exe -k netsvcs [3.8.2004 23:56 14336]
S3 WFIOCTL;WFIOCTL;d:\program files\WinFast\WFDTV\WFIOCTL.sys [27.6.2009 16:34 9446]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
mvyif
nvenwtbvt
wefigtj
icivlqm
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-01-31 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]

2010-01-31 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]

2010-01-30 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003Core.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]

2010-01-31 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003UA.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: bancaintesabeograd.com\online
FF - ProfilePath - d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\
FF - component: d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-31 16:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\icivlqm]
"ServiceDll"="d:\windows\system32\kqwxs.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mvyif]
"ServiceDll"="d:\windows\system32\kqwxs.dll"
--

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wefigtj]
"ServiceDll"="d:\windows\system32\kqwxs.dll"
.
Completion time: 2010-01-31 16:12:58
ComboFix-quarantined-files.txt 2010-01-31 15:12

Pre-Run: 1.296.629.760 bytes free
Post-Run: 2.556.616.704 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

- - End Of File - - 61B8DD1DDFEFD1C33541C12DA4C2C943
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!31.01.2010. u 21:54 - pre 173 meseci
Imas opasne rootkit-ove u sistemu...to pravi problem...


Otvori Notepad i kopiraj tekst koji se nalazi ispod:

Citat:
File::
d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat
d:\windows\system32\kqwxs.dll

Driver::
icivlqm
mvyif
nvenwtbvt
wefigtj

NetSvcs::
mvyif
nvenwtbvt
wefigtj
icivlqm

Registry::
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\icivlqm]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mvyif]
[-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\wefigtj]


Klikni na File\Save as i sacuvaj tekst kao CFScript na desktop




Prati uputstvo sa slike i prevuci CFScript.txt preko ikonice ComboFix.exe
To ce startovati ComboFix, mozda ce doci do restarta sistema (to je normalno)
Kada zavrsi,pojavice se log koji ces kopirati ovde i reci mi ima li poboljsanja.




 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!01.02.2010. u 12:48 - pre 173 meseci
E ima poboljsanja, komp bolje radi i nod je skenirao sve bez problema

Evo uradio sam i ovo poslednje sto je trebalo





ComboFix 10-01-31.03 - Srdjo 01.02.2010 13:34:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1610 [GMT 1:00]
Running from: d:\documents and settings\Srdjo\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\Srdjo\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active


FILE ::
"d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat"
"d:\windows\system32\kqwxs.dll"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

D:\Thumbs.db
d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat
d:\windows\system32\Dvbpws.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_ICIVLQM
-------\Legacy_MVYIF
-------\Legacy_NVENWTBVT
-------\Legacy_WEFIGTJ
-------\Service_icivlqm
-------\Service_mvyif
-------\Service_nvenwtbvt
-------\Service_wefigtj


((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.

2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-01-15 19:52 . 2004-08-03 21:59 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\Changer.sys
2010-01-08 10:24 . 2009-12-16 13:42 43008 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-01-08 10:24 . 2009-12-16 13:42 340480 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-01-08 10:24 . 2009-12-16 13:41 346624 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-01-08 10:24 . 2009-12-16 13:42 872960 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-01-06 10:20 . 2010-01-06 10:20 -------- d-----w- d:\documents and settings\Srdjo\Local Settings\Application Data\WinZip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 12:41 . 2009-11-10 17:52 -------- d-----w- d:\documents and settings\Srdjo\Application Data\uTorrent
2010-02-01 12:41 . 2009-09-20 14:49 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Skype
2010-01-30 10:23 . 2009-09-20 14:55 -------- d-----w- d:\documents and settings\Srdjo\Application Data\skypePM
2010-01-14 06:24 . 2009-12-02 11:22 79488 ----a-w- d:\documents and settings\Srdjo\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-13 22:47 . 2009-05-05 12:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-06 10:20 . 2009-03-11 20:46 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2010-01-04 16:15 . 2009-06-30 19:16 133120 ----a-w- d:\documents and settings\Srdjo\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-12-27 18:54 . 2009-12-27 18:54 -------- d-----w- d:\program files\URUSoft
2009-12-27 18:48 . 2009-12-27 18:48 -------- d-----w- d:\program files\TimeAdjuster
2009-12-27 02:03 . 2009-12-27 02:03 -------- d-----w- d:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Microsoft
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live SkyDrive
2009-12-25 23:12 . 2009-12-25 23:12 -------- d-----w- d:\program files\Common Files\Windows Live
2009-12-22 05:42 . 2004-08-03 22:56 662016 ------w- d:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-03 22:56 81920 ----a-w- d:\windows\system32\ieencode.dll
2009-12-21 07:53 . 2009-03-11 19:24 -------- d-----w- d:\program files\Google
2009-11-23 12:26 . 2009-10-02 10:00 664 ----a-w- d:\windows\system32\d3d9caps.dat
2009-11-21 16:36 . 2004-08-03 22:56 470528 ----a-w- d:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-15 68856]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-11-10 289584]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-04 135664]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"WinFastDTV"="d:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112]
"WinFast Schedule"="d:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816]
"egui"="d:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"StatusClient"="d:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="d:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"PCSuiteTrayApplication"="d:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

d:\documents and settings\Srdjo\Start Menu\Programs\Startup\
Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Adobe Reader Speed Launch.lnk - d:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-10 10872]
WinZip Quick Pick.lnk - d:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"=
"d:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault(tm)\\mohpa.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\proobj.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=

R0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [11.3.2009 20:19 159616]
R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [11.3.2009 20:19 5248]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R2 ekrn;ESET Service;d:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
R3 WFIOCTL;WFIOCTL;d:\program files\WinFast\WFDTV\WFIOCTL.sys [27.6.2009 16:34 9446]
S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\Google\Update\GoogleUpdate.exe [28.6.2009 18:30 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-01-30 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]

2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]

2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003Core.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]

2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003UA.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: bancaintesabeograd.com\online
FF - ProfilePath - d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\
FF - component: d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-01 13:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2996)
d:\program files\ESET\ESET NOD32 Antivirus\eplgHooks.dll
d:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\RUNDLL32.EXE
d:\windows\RTHDCPL.EXE
d:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
d:\windows\system32\nvsvc32.exe
d:\windows\system32\PnkBstrA.exe
d:\windows\system32\PnkBstrB.exe
d:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
d:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
d:\windows\system32\wdfmgr.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
d:\program files\PC Connectivity Solution\ServiceLayer.exe
d:\program files\Common Files\Nero\Lib\NMIndexingService.exe
d:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-01 13:46:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-01 12:46
ComboFix2.txt 2010-01-31 15:12

Pre-Run: 2.614.505.472 bytes free
Post-Run: 2.466.963.456 bytes free

- - End Of File - - 5BD33FB67E91C1E0E85B883E3057FF39
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!01.02.2010. u 14:57 - pre 173 meseci
that's it...

Zapakuj ( zip-uj ili rar-uj ) ovaj folder
C:\Qoobox

i upload-uj ga preko ovog sajta:
http://www.speedyshare.com/

link za download mi posalji na PP

...........................................................................................
Onda...
Klikni START >> RUN
U liniju za unos teksta ukucaj "Combofix /Uninstall" i klikni OK

............................................................................................
Deinstaliraj i instaliraj najnoviju verziju Java

Skini program JavaRa
Kliknuti na Remove older versions
Kada to zavrsi i izbaci log fajl, onda kliknuti na Search for updates odabrati donju opciju pa kliknuti na Search
To ce odvesti na sajt sa koga treba skinuti i instalirati zadnju verziju Jave
 
Odgovor na temu

nekoooo

Član broj: 216196
Poruke: 10
79.101.47.*



Profil

icon Re: Nod32 ne moze da skenira racunar!!01.02.2010. u 19:28 - pre 173 meseci
Uradjeno sve po uputstvu.

magna86, mnogo ti hvala na pomoci i ne znam kako da se oduzim. hvala jos jednom!
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Nod32 ne moze da skenira racunar!!01.02.2010. u 19:42 - pre 173 meseci
Citat:
nekoooo....ne znam kako da se oduzim. hvala jos jednom!

nista..sledeci put castis pivo

PozZ
 
Odgovor na temu

[es] :: Zaštita :: Nod32 ne moze da skenira racunar!!

[ Pregleda: 3225 | Odgovora: 14 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.