E ima poboljsanja, komp bolje radi i nod je skenirao sve bez problema
Evo uradio sam i ovo poslednje sto je trebalo
ComboFix 10-01-31.03 - Srdjo 01.02.2010 13:34:38.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1610 [GMT 1:00]
Running from: d:\documents and settings\Srdjo\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\Srdjo\Desktop\CFScript.txt
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Resident AV is active
FILE ::
"d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat"
"d:\windows\system32\kqwxs.dll"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Thumbs.db
d:\windows\system32\config\systemprofile\Application Data\fvgqad.dat
d:\windows\system32\Dvbpws.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ICIVLQM
-------\Legacy_MVYIF
-------\Legacy_NVENWTBVT
-------\Legacy_WEFIGTJ
-------\Service_icivlqm
-------\Service_mvyif
-------\Service_nvenwtbvt
-------\Service_wefigtj
((((((((((((((((((((((((( Files Created from 2010-01-01 to 2010-02-01 )))))))))))))))))))))))))))))))
.
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-30 11:56 . 2010-01-07 15:07 19160 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-01-30 11:56 . 2010-01-30 11:56 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2010-01-15 19:52 . 2004-08-03 21:59 34688 -c--a-w- d:\windows\system32\dllcache\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 21:59 34688 ----a-w- d:\windows\system32\drivers\lbrtfdc.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\i2omgmt.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 -c--a-w- d:\windows\system32\dllcache\changer.sys
2010-01-15 19:52 . 2004-08-03 22:00 8192 ----a-w- d:\windows\system32\drivers\Changer.sys
2010-01-08 10:24 . 2009-12-16 13:42 43008 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-01-08 10:24 . 2009-12-16 13:42 340480 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-01-08 10:24 . 2009-12-16 13:41 346624 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-01-08 10:24 . 2009-12-16 13:42 872960 ----a-w- d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-01-06 10:20 . 2010-01-06 10:20 -------- d-----w- d:\documents and settings\Srdjo\Local Settings\Application Data\WinZip
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-01 12:41 . 2009-11-10 17:52 -------- d-----w- d:\documents and settings\Srdjo\Application Data\uTorrent
2010-02-01 12:41 . 2009-09-20 14:49 -------- d-----w- d:\documents and settings\Srdjo\Application Data\Skype
2010-01-30 10:23 . 2009-09-20 14:55 -------- d-----w- d:\documents and settings\Srdjo\Application Data\skypePM
2010-01-14 06:24 . 2009-12-02 11:22 79488 ----a-w- d:\documents and settings\Srdjo\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-13 22:47 . 2009-05-05 12:42 -------- d-----w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-06 10:20 . 2009-03-11 20:46 -------- d-----w- d:\documents and settings\All Users\Application Data\WinZip
2010-01-04 16:15 . 2009-06-30 19:16 133120 ----a-w- d:\documents and settings\Srdjo\Application Data\GRETECH\GomPlayer\GrLauncherTempSetup.exe
2009-12-27 18:54 . 2009-12-27 18:54 -------- d-----w- d:\program files\URUSoft
2009-12-27 18:48 . 2009-12-27 18:48 -------- d-----w- d:\program files\TimeAdjuster
2009-12-27 02:03 . 2009-12-27 02:03 -------- d-----w- d:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Microsoft
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live
2009-12-26 18:51 . 2009-12-26 18:51 -------- d-----w- d:\program files\Windows Live SkyDrive
2009-12-25 23:12 . 2009-12-25 23:12 -------- d-----w- d:\program files\Common Files\Windows Live
2009-12-22 05:42 . 2004-08-03 22:56 662016 ------w- d:\windows\system32\wininet.dll
2009-12-22 05:42 . 2004-08-03 22:56 81920 ----a-w- d:\windows\system32\ieencode.dll
2009-12-21 07:53 . 2009-03-11 19:24 -------- d-----w- d:\program files\Google
2009-11-23 12:26 . 2009-10-02 10:00 664 ----a-w- d:\windows\system32\d3d9caps.dat
2009-11-21 16:36 . 2004-08-03 22:56 470528 ----a-w- d:\windows\AppPatch\aclayers.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="d:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-09-20 202024]
"swg"="d:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-15 68856]
"Skype"="d:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"uTorrent"="d:\program files\uTorrent\uTorrent.exe" [2009-11-10 289584]
"msnmsgr"="d:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-04 135664]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SkyTel"="SkyTel.EXE" [2007-06-15 1826816]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
"nwiz"="nwiz.exe" [2008-10-07 1630208]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2008-10-07 86016]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 16380416]
"NeroFilterCheck"="d:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="d:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"WinampAgent"="d:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"SunJavaUpdateSched"="d:\program files\Java\jre6\bin\jusched.exe" [2009-04-24 148888]
"GrooveMonitor"="d:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"QuickTime Task"="d:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"WinFastDTV"="d:\program files\WinFast\WFDTV\DTVSchdl.exe" [2007-11-16 90112]
"WinFast Schedule"="d:\program files\WinFast\WFDTV\WFWIZ.exe" [2007-11-15 2850816]
"egui"="d:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"StatusClient"="d:\program files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe" [2002-12-16 36864]
"TomcatStartup"="d:\program files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe" [2003-03-31 155648]
"PCSuiteTrayApplication"="d:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="d:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
d:\documents and settings\Srdjo\Start Menu\Programs\Startup\
Adobe Gamma.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - d:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Adobe Reader Speed Launch.lnk - d:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2005-3-10 10872]
WinZip Quick Pick.lnk - d:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"d:\\WINDOWS\\system32\\PnkBstrA.exe"=
"d:\\WINDOWS\\system32\\PnkBstrB.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\pro_comm_msg.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\xtop.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\nms\\nmsd.exe"=
"d:\\Program Files\\EA GAMES\\Medal of Honor Pacific Assault(tm)\\mohpa.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"d:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"d:\\Program Files\\proeWildfire 2.0\\i486_nt\\obj\\proobj.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"d:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Program Files\\Hewlett-Packard\\Toolbox2.0\\Javasoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 Vax347b;Vax347b;d:\windows\system32\drivers\Vax347b.sys [11.3.2009 20:19 159616]
R0 Vax347s;Vax347s;d:\windows\system32\drivers\Vax347s.sys [11.3.2009 20:19 5248]
R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [14.5.2009 14:47 107256]
R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [14.5.2009 14:49 94360]
R2 ekrn;ESET Service;d:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [14.5.2009 14:47 731840]
R3 WFIOCTL;WFIOCTL;d:\program files\WinFast\WFDTV\WFIOCTL.sys [27.6.2009 16:34 9446]
S2 gupdate1c9f816241ab4ce;Google Update Service (gupdate1c9f816241ab4ce);d:\program files\Google\Update\GoogleUpdate.exe [28.6.2009 18:30 133104]
.
Contents of the 'Scheduled Tasks' folder
2010-01-30 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]
2010-02-01 d:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- d:\program files\Google\Update\GoogleUpdate.exe [2009-06-28 17:30]
2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003Core.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]
2010-02-01 d:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1417001333-1770027372-725345543-1003UA.job
- d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-30 08:33]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - d:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: bancaintesabeograd.com\online
FF - ProfilePath - d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\
FF - component: d:\documents and settings\Srdjo\Application Data\Mozilla\Firefox\Profiles\i11jdko6.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: d:\documents and settings\Srdjo\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: d:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: d:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-01 13:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2996)
d:\program files\ESET\ESET NOD32 Antivirus\eplgHooks.dll
d:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\windows\system32\RUNDLL32.EXE
d:\windows\RTHDCPL.EXE
d:\program files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
c:\program files\Common Files\Autodata Limited Shared\Service\ADCDLicSvc.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
d:\windows\system32\nvsvc32.exe
d:\windows\system32\PnkBstrA.exe
d:\windows\system32\PnkBstrB.exe
d:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
d:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
d:\windows\system32\wdfmgr.exe
d:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
d:\program files\PC Connectivity Solution\ServiceLayer.exe
d:\program files\Common Files\Nero\Lib\NMIndexingService.exe
d:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-01 13:46:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-01 12:46
ComboFix2.txt 2010-01-31 15:12
Pre-Run: 2.614.505.472 bytes free
Post-Run: 2.466.963.456 bytes free
- - End Of File - - 5BD33FB67E91C1E0E85B883E3057FF39