[ Vladimir__D @ 09.11.2009. 19:17 ] @
Unapred se izvilnjavam sto postavljam pitanje u vezi ovog programa ali nisam nasao slican problem na forumu, pa sam resio da otvorim novu temu (takodje se izvinajvam zbog duzine objasnjenja - samo sam hteo da opisem sve sto sam uradio). Problem je u tome sto sam koristio program ComboFix a prethodno se nisam informisao. Nakon koriscenja nisam razumeo sta sa onim log fajlom sto mi je na kraju izbacio. (ja sam inace nasao link na rapidserbia forumu: http://dl.getdropbox.com/u/955843/ComboFix.exe - Kada je program radio prvi put ponudio mi je da preuzmem noviju verziju sa sajta BleepingComputer.com sto sam mu i dozvolio, kad je zavrsio sa radom u kom nije bilo ono da izbaci koliko je skenirao Stage 1 - 50 nije mi restartovao racunar nego sam ja to uradio - valjda nije nista nasao) Instalaciju koju sam skinuo na desktop sam premestio na drugi deo harda a malo kasnije i obrisao; Prilikom ponovnog pokretanja sistema sam primetio da se onaj crni ekran (gde je ponudjeno da se bira koji windows da pokrene) pojavljuje ponovo. Na forumu sam pronasao da ovaj program moze da se obrise komandom Combofix /u u Run-u. Uradio sam to ali nije nasao neki fajl na C... (nisam se setio odmah da zapisem ili da napravim screen). Posto sam procitao na forumu da treba koristiti najnoviju verziju Combofix-a, a ne stariju. Skinuo sam je sa BleepingComputer.com (link sam naso ovde na forumu) i ponovo pokrenuo program. Kada je skenirao ovaj put bilo je onog dela gde skenira stage 1-50, i nasao je u Local Settings\Temporary Internet Files\udRemove.exe sto je valjda i obrisao. Nakon toga sam ponovo probao da obrisem Combofix sa komandom Combofix /u u Run-u. Nakon par minuta rada izbacio mi je poruku da je uspesno obrisao Combofix. (Inace kad sam prvi i drugi put pokretao program ugasio sam sve sto je bilo pokrenuto, a prilikom restarta u drugom pokretanju programa KIS 2010 se pokrenuo pa mi je program trazio da ga iskljucim sto sam i uradio - nisam siguran da li mu je to smetalo da zavrsi do kraja sta je trebalo kako treba). Sada kad god restartujem racunar onaj crni ekran se opet prikazuje kao da je Combofix i dalje instaliran. Sta treba sad da uradim kako mi se ne bi prikazivao ubuduce, a ifaklovi koje je Combofix napravio na C i dalje su tamo (folder Combofix i .TXT fajl)? Inace racunar je skoro reinstaliran pa bih to zaobisao ako nekako moze. Dole je log file koji mi je izbacio kada sam pokrenuo Combofix drugi put, ako neko moze da mi rastumaci sta je uradjeno. Unapred zahvalan. ComboFix 09-11-08.03 - Vladimir 09.11.2009 19:03.2.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.768.544 [GMT 1:00] Running from: c:\documents and settings\Vladimir\Desktop\ComboFix.exe AV: Kaspersky Internet Security *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Vladimir\Local Settings\Temporary Internet Files\udRemove.exe c:\windows\system32\msssc.dll . ((((((((((((((((((((((((( Files Created from 2009-10-09 to 2009-11-09 ))))))))))))))))))))))))))))))) . 2009-11-09 15:01 . 2009-11-09 15:01 -------- d-s---w- c:\documents and settings\Vladimir\UserData 2009-11-09 12:36 . 2009-11-09 12:37 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Adobe 2009-11-08 22:30 . 2009-11-08 22:30 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Microsoft Help 2009-11-08 22:30 . 2009-11-08 22:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-11-08 22:15 . 2009-11-08 22:14 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-11-08 22:14 . 2009-11-08 22:14 152576 ----a-w- c:\documents and settings\Vladimir\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-11-08 22:12 . 2009-11-08 22:12 79488 ----a-w- c:\documents and settings\Vladimir\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2009-11-08 21:12 . 2008-04-14 04:42 221184 ----a-w- c:\windows\system32\wmpns.dll 2009-11-08 19:46 . 2009-11-08 22:56 -------- d-----w- c:\program files\BitLord 2009-11-08 19:40 . 2009-11-08 19:41 -------- d-----w- c:\windows\LastGood 2009-11-08 18:21 . 2009-11-08 19:15 -------- d-----w- c:\program files\The KMPlayer 2009-11-08 17:56 . 2009-11-08 22:14 -------- d-----w- c:\program files\Java 2009-11-08 17:54 . 2009-11-08 17:54 -------- d-----w- c:\program files\Common Files\Java 2009-11-08 17:53 . 2009-11-08 17:53 0 ----a-w- c:\windows\nsreg.dat 2009-11-08 17:53 . 2009-11-08 17:53 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Mozilla 2009-11-08 17:49 . 2009-11-08 17:49 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Opera 2009-11-08 17:49 . 2009-11-08 17:49 -------- d-----w- c:\program files\Opera 2009-11-08 17:46 . 2009-11-08 17:46 -------- d-----w- c:\program files\Common Files\Adobe 2009-11-08 17:33 . 2009-11-08 17:33 -------- d-----w- c:\documents and settings\Vladimir\Application Data\URSoft 2009-11-08 17:33 . 2009-11-09 17:21 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-11-08 17:33 . 2009-11-08 17:39 -------- d-----w- c:\program files\Your Uninstaller 2008 2009-11-08 17:24 . 2009-11-08 17:24 -------- d-----w- c:\documents and settings\Vladimir\Application Data\ACD Systems 2009-11-08 17:22 . 2009-11-08 17:22 -------- d-----w- c:\program files\Common Files\ACD Systems 2009-11-08 17:22 . 2009-11-08 17:22 -------- d-----w- c:\program files\ACD Systems 2009-11-08 17:22 . 2009-11-08 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems 2009-11-08 17:19 . 2009-11-08 17:19 -------- d-----w- c:\windows\Downloaded Installations 2009-11-08 17:15 . 2009-11-08 17:15 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-11-08 17:15 . 2009-11-08 23:10 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM 2009-11-08 17:14 . 2009-11-09 01:40 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype 2009-11-08 17:13 . 2009-11-08 17:13 -------- d-----w- c:\program files\Common Files\Skype 2009-11-08 17:13 . 2009-11-08 17:14 -------- d-----r- c:\program files\Skype 2009-11-08 17:13 . 2009-11-08 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2009-11-08 17:00 . 2009-11-08 17:01 846312 ----a-w- c:\documents and settings\Vladimir\Application Data\MSNInstaller\msnauins.exe 2009-11-08 16:57 . 2009-11-08 17:07 -------- d-----w- c:\documents and settings\Vladimir\Application Data\MSNInstaller 2009-11-08 16:28 . 2009-11-08 16:28 932368 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\profiles-1-6.dll 2009-11-08 16:28 . 2009-11-08 16:28 678416 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\content_interpreter-1-1.dll 2009-11-08 16:28 . 2009-11-08 16:28 604688 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\gsg-3-9.dll 2009-11-08 16:28 . 2009-11-08 16:28 522768 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\database-1-5.dll 2009-11-08 16:28 . 2009-11-08 16:28 1096208 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab\AVP9\Data\KasFlt\Plugins\filtration-4-6.dll 2009-11-08 16:21 . 2009-11-08 16:21 95259 ----a-w- c:\windows\system32\drivers\klick.dat 2009-11-08 16:21 . 2009-11-08 16:21 108059 ----a-w- c:\windows\system32\drivers\klin.dat 2009-11-08 16:20 . 2009-11-09 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab 2009-11-08 16:20 . 2009-11-08 16:20 -------- d-----w- c:\program files\Kaspersky Lab 2009-11-08 16:19 . 2009-11-08 16:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-11-08 16:15 . 2001-08-23 08:25 1706800 ----a-w- c:\windows\system32\gdiplus.dll 2009-11-08 16:13 . 2009-11-08 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo 2009-11-08 16:13 . 2002-06-02 21:53 45056 ----a-w- c:\windows\system32\WSTDEC.dll 2009-11-08 16:13 . 2002-06-02 21:53 94208 ----a-w- c:\windows\system32\VbiCallback.dll 2009-11-08 16:13 . 2001-12-10 16:42 204800 ----a-w- c:\windows\system32\IVIresizeW7.dll 2009-11-08 16:13 . 2001-12-10 16:42 192512 ----a-w- c:\windows\system32\IVIresizeM6.dll 2009-11-08 16:13 . 2001-12-10 16:42 192512 ----a-w- c:\windows\system32\IVIresizeP6.dll 2009-11-08 16:13 . 2001-12-10 16:42 188416 ----a-w- c:\windows\system32\IVIresizePX.dll 2009-11-08 16:13 . 2001-12-10 16:42 200704 ----a-w- c:\windows\system32\IVIresizeA6.dll 2009-11-08 16:13 . 2001-12-10 16:42 20480 ----a-w- c:\windows\system32\IVIresize.dll 2009-11-08 16:13 . 2009-11-08 16:13 -------- d-----w- c:\program files\Common Files\InterVideo 2009-11-08 16:13 . 2009-11-08 16:13 -------- d-----w- c:\program files\InterVideo 2009-11-08 16:03 . 2008-04-14 04:42 1306624 -c----w- c:\windows\system32\dllcache\msxml6.dll 2009-11-08 16:03 . 2008-04-14 04:42 1306624 ------w- c:\windows\system32\msxml6.dll 2009-11-08 16:03 . 2008-04-13 21:57 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll 2009-11-08 16:03 . 2008-04-13 21:57 79872 ------w- c:\windows\system32\msxml6r.dll 2009-11-08 16:03 . 2007-06-26 10:30 22060 -c----w- c:\windows\system32\dllcache\npds.zip 2009-11-08 16:03 . 2007-06-26 10:26 403 -c----w- c:\windows\system32\dllcache\npdrmv2.zip 2009-11-08 16:03 . 2008-04-14 04:40 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll 2009-11-08 16:00 . 2009-11-08 16:00 -------- d-----w- c:\windows\ServicePackFiles 2009-11-08 16:00 . 2008-04-14 04:42 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-11-09 15:16 . 2009-11-08 15:12 13664 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-11-08 22:59 . 2009-11-08 19:38 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp 2009-11-08 19:41 . 2009-11-08 19:38 -------- d-----w- c:\program files\Winamp 2009-11-08 16:14 . 2009-11-08 15:19 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-11-08 16:05 . 2009-11-08 15:04 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-11-08 15:45 . 2009-11-08 15:19 -------- d-----w- c:\program files\Common Files\InstallShield 2009-11-08 15:28 . 2009-11-08 15:28 -------- d-----w- c:\program files\ATI Technologies 2009-11-08 15:24 . 2009-11-08 15:24 -------- d-----w- c:\program files\ASUS 2009-11-08 15:19 . 2009-11-08 15:19 -------- d-----w- c:\program files\Analog Devices 2009-11-08 15:06 . 2009-11-08 15:06 -------- d-----w- c:\program files\microsoft frontpage 2009-11-08 15:02 . 2009-11-08 15:02 21640 ----a-w- c:\windows\system32\emptyregdb.dat 2009-10-20 19:34 . 2009-10-20 19:34 219664 ----a-w- c:\windows\system32\klogon.dll 2009-10-20 16:54 . 2009-10-20 16:54 59992 ----a-w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe 2009-10-14 20:18 . 2009-10-14 20:18 36880 ----a-w- c:\windows\system32\drivers\klbg.sys 2009-10-02 18:39 . 2009-10-02 18:39 19472 ----a-w- c:\windows\system32\drivers\klmouflt.sys 2009-09-14 13:42 . 2009-09-14 13:42 32272 ----a-w- c:\windows\system32\drivers\klim5.sys 2009-09-09 18:01 . 2009-09-09 18:01 27675 ----a-w- c:\windows\system32\drivers\klopp.dat 2009-09-01 14:29 . 2009-09-01 14:29 128016 ----a-w- c:\windows\system32\drivers\kl1.sys 2007-10-22 02:49 . 2007-10-22 02:49 1805306 ----a-w- c:\program files\NOV2007_d3dx9_36_x64.cab 2007-10-22 02:49 . 2007-10-22 02:49 867848 ----a-w- c:\program files\NOV2007_d3dx10_36_x64.cab 2007-10-22 02:49 . 2007-10-22 02:49 807132 ----a-w- c:\program files\NOV2007_d3dx10_36_x86.cab 2007-10-22 02:49 . 2007-10-22 02:49 49392 ----a-w- c:\program files\NOV2007_X3DAudio_x64.cab 2007-10-22 02:49 . 2007-10-22 02:49 44850 ----a-w- c:\program files\dxdllreg_x86.cab 2007-10-22 02:49 . 2007-10-22 02:49 21744 ----a-w- c:\program files\NOV2007_X3DAudio_x86.cab 2007-10-22 02:49 . 2007-10-22 02:49 200010 ----a-w- c:\program files\NOV2007_XACT_x64.cab 2007-10-22 02:49 . 2007-10-22 02:49 1712608 ----a-w- c:\program files\NOV2007_d3dx9_36_x86.cab 2007-10-22 02:49 . 2007-10-22 02:49 151512 ----a-w- c:\program files\NOV2007_XACT_x86.cab . ((((((((((((((((((((((((((((( SnapShot@2009-11-09_16.38.33 ))))))))))))))))))))))))))))))))))))))))) . + 2009-11-09 18:09 . 2009-11-09 18:09 16384 c:\windows\Temp\Perflib_Perfdata_304.dat + 2009-11-08 16:02 . 2007-04-02 23:04 366080 c:\windows\ServicePackFiles\i386\digreqex.msi + 2009-11-08 16:02 . 2007-04-02 23:04 863232 c:\windows\ServicePackFiles\i386\digopt.msi + 2009-11-08 17:56 . 2009-11-08 17:56 282624 c:\windows\Installer\594ee.msi + 2009-11-08 22:14 . 2009-11-08 22:14 537600 c:\windows\Installer\39c229.msi + 2009-11-08 17:14 . 2009-11-08 17:14 794112 c:\windows\Installer\3859f4.msi + 2009-11-08 15:45 . 2009-11-08 15:45 802816 c:\windows\Installer\28387.msi + 2009-11-08 15:11 . 2009-11-08 15:11 264704 c:\windows\Installer\1e168.msi + 2004-08-04 01:07 . 2004-08-04 01:07 1326080 c:\windows\system32\webfldrs.msi + 2009-11-08 16:01 . 2007-01-01 19:14 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi + 2009-11-08 16:00 . 2007-04-02 23:12 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi + 2009-11-08 16:21 . 2009-11-08 16:21 3419136 c:\windows\Installer\8749f.msi + 2009-11-08 17:49 . 2009-11-08 17:49 2215424 c:\windows\Installer\594eb.msi + 2009-11-08 17:47 . 2009-11-08 17:47 3940352 c:\windows\Installer\594e7.msi + 2009-11-08 17:23 . 2009-11-08 17:23 1227776 c:\windows\Installer\3859f8.msi + 2009-11-08 17:13 . 2009-11-08 17:13 1565696 c:\windows\Installer\3859ed.msi + 2009-11-08 17:07 . 2009-11-08 17:07 2109440 c:\windows\Installer\319051.msi + 2005-09-23 06:48 . 2005-09-23 06:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi + 2009-11-08 17:19 . 2009-11-08 17:21 10404724 c:\windows\Downloaded Installations\{92BE18A0-BAE2-45B5-B8A1-F09403C0F957}\ACDSee 5.0 Standard.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Smapp"="c:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-29 344064] "Home Theater SchSvr"="c:\program files\Common Files\InterVideo\SchSvr\SchSvr.exe" [2003-10-22 155648] "IHTWINCINEMAMGR"="c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe" [2003-10-23 155648] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-10-20 340456] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-08 149280] "WinampAgent"="c:\program files\Winamp\winampa.exe" [2009-04-10 37888] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [10/14/2009 9:18 PM 36880] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [9/14/2009 2:42 PM 32272] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [10/2/2009 7:39 PM 19472] R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\drivers\phtvtune.sys [11/8/2009 4:45 PM 24608] . . ------- Supplementary Scan ------- . FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\7c9ys1ei.default\ FF - component: c:\program files\Mozilla Firefox\extensions\[email protected]\components\KavLinkFilter.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-11-09 19:10 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(964) c:\windows\system32\Ati2evxx.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\Ati2evxx.exe c:\windows\system32\Ati2evxx.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Completion time: 2009-11-09 19:12 - machine was rebooted ComboFix-quarantined-files.txt 2009-11-09 18:12 ComboFix2.txt 2009-11-09 16:39 Pre-Run: 13.506.113.536 bytes free Post-Run: 13.432.745.984 bytes free - - End Of File - - 0B9FACDBA1038EE430F6B88E82414896 |