@ Igoritza cannot find file specified
ccc ne mogu mu nista
i combo fix sam uradio
evo log
na njemackom je tako da nemam pojma sta mu je radio, malo nesta ali slabo
ComboFix 09-01-17.04 - Administrator 2009-01-18 15:21:12.3 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.3582.3315 [GMT 1:00]
Körs frĺn: c:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090117-0] *On-access scanning enabled* (Updated)
VARNINIG -ĹTERSTÄLLNINGSKONSOLEN (THE RECOVERY CONSOLE) ÄR INTE INSTALLERAD PĹ DEN HÄR DATORN !!
.
((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Recyclers
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\system\S-1-5-21-1482476501-1644491937-682003330-1013\USB.exe
.
(((((((((((((((((((((((( Filer Skapade frĺn 2008-12-18 till 2009-01-18 ))))))))))))))))))))))))))))))
.
2009-01-18 13:25 . 2009-01-18 13:25 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-18 13:25 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-18 13:25 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-18 13:11 . 2009-01-18 15:15 62,976 --a------ c:\documents and settings\Administrator\asdsdsd.exe
2009-01-18 12:18 . 2009-01-18 12:18 <DIR> d-------- c:\program files\Common Files\Download Manager
2009-01-18 01:54 . 2009-01-18 12:44 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-18 01:25 . 2009-01-18 14:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-01-17 15:02 . 2009-01-17 15:02 <DIR> dr-hs---- C:\RECYCLE
2009-01-14 02:14 . 2009-01-18 15:21 <DIR> dr-hs---- C:\SYSTEM
2009-01-11 21:00 . 2009-01-11 21:01 <DIR> d-------- c:\program files\Packet Tracer 4.0
2009-01-10 14:17 . 2009-01-10 14:17 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Thinstall
2009-01-06 22:28 . 2009-01-06 22:28 <DIR> dr-h----- c:\documents and settings\Administrator\Application Data\SecuROM
2009-01-06 22:28 . 2009-01-06 22:28 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-01-06 22:25 . 2009-01-06 22:25 <DIR> d-------- c:\windows\system32\LogFiles
2009-01-06 22:25 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
2009-01-06 22:25 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2009-01-06 22:25 . 2007-07-19 18:14 1,358,192 --a------ c:\windows\system32\D3DCompiler_35.dll
2009-01-06 22:25 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2009-01-06 22:25 . 2009-01-06 22:25 669,184 --a------ c:\windows\system32\pbsvc.exe
2009-01-06 22:25 . 2007-07-19 18:14 444,776 --a------ c:\windows\system32\d3dx10_35.dll
2009-01-06 22:25 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2009-01-06 22:25 . 2009-01-06 22:25 103,736 --a------ c:\windows\system32\PnkBstrB.exe
2009-01-06 22:25 . 2007-04-04 18:53 81,768 --a------ c:\windows\system32\xinput1_3.dll
2009-01-06 22:25 . 2009-01-06 22:25 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2009-01-06 22:25 . 2009-01-06 22:25 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2009-01-06 22:25 . 2009-01-06 22:25 22,328 --a------ c:\documents and settings\Administrator\Application Data\PnkBstrK.sys
2008-12-30 00:43 . 2008-12-30 00:43 <DIR> d-------- c:\program files\EasyPHP1-8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 02:48 --------- d-----w c:\program files\Winamp
2008-12-11 23:56 --------- d-----w c:\program files\Common Files\Blizzard Entertainment
2008-12-11 23:53 306,432 ----a-w c:\windows\system32\TuneUpDefragService.exe
2008-12-10 23:34 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-10 16:58 --------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
2008-11-30 14:17 --------- d-----w c:\documents and settings\Administrator\Application Data\TuneUp Software
2008-10-18 17:46 2,829 ----a-w c:\windows\War3Unin.pif
2008-10-18 17:46 139,264 ----a-w c:\windows\War3Unin.exe
.
(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* tomma poster & legitima standardposter visas inte
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-06-23 847872]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"TWCU"="c:\program files\TP-LINK\TWCU\TWCU.exe" [2006-03-29 364544]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-11 136600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 15:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
--a------ 2004-08-03 21:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
--a------ 2004-08-03 21:32 455168 c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2009-01-08 20:24 1410296 e:\steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
--a------ 2005-11-15 20:31 33792 c:\program files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Igre\\Valve\\hltv.exe"=
"d:\\Igre\\Valve\\hl.exe"=
"c:\\Program Files\\RadLight Company\\RadLight 4.0\\rlkernel.exe"=
"d:\\Igre\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"d:\\Igre\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"d:\\Igre\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-26 111184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-05-26 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6bd415a8-2046-11dd-8729-001bfc3f3fe0}]
\Shell\AutoRun\command - h:\system\S-1-5-21-1482476501-1644491937-682003330-1013\USB.exe
\Shell\open\command - h:\system\S-1-5-21-1482476501-1644491937-682003330-1013\USB.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{719671db-c20d-11dd-87ee-001bfc3f3fe0}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{80122fa4-1b8b-11dd-8725-001bfc3f3fe0}]
\Shell\AutoRun\command - G:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8026f7f1-168e-11dd-8718-bd540475c893}]
\Shell\AutoOpen\command - g:\.\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\MSOCache\90000804-6000-11D3-8CFE-0150048383C9\KB915865.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b6e2d67c-370c-11dd-8744-001bfc3f3fe0}]
\Shell\AutoRun\command - ekugb3.bat
\Shell\explore\Command - ekugb3.bat
\Shell\open\Command - ekugb3.bat
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-34CX1C987132}]
c:\recycle\D-0-060-0000000000-1111111-2222222\fix.exe
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: {630EAD48-B813-49BE-84CA-438219256428} = 212.200.13.13
TCP: {E064EEA7-82EF-4689-801B-AB95BF2B0AD0} = 212.200.13.13
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-18 15:22:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
genomsökningen avslutades lyckosamt
dolda filer: 0
**************************************************************************
.
--------------------- DLLer som "laddats" under processer som körs ---------------------
- - - - - - - > 'winlogon.exe'(236)
c:\windows\system32\Ati2evxx.dll
.
Sluttid: 2009-01-18 15:22:45
ComboFix-quarantined-files.txt 2009-01-18 14:22:44
ComboFix2.txt 2008-11-04 12:58:50
Före genomsökningen: 33.275.768.832 bytes free
Efter genomsökningen: 33,291,141,120 bytes free
153