Pomoć poćetniku

1

Pomoć poćetniku

offline
  • Pridružio: 08 Avg 2007
  • Poruke: 26

Pozdrav svima ja sam novi i koristim ovu priliku da pozdravim sve članove foruma.Odmah na početku imam jedno pitanje.Imam problem sa ne znam da li je to virus ili što drugo uglavnom namjeravao sam kao i ostali članovi otvoriti program Hijack i kopirati i postaviti ovdje i kad sam gledao u objašnjenju kako da to napravim vidio sam da ovo piše:
"ukoliko nemate instaliran SP 2 za Windows...možete li mi reći šta znaći ovo SP 2 jer nisam siguran da ja to imam.
Molim vas možete li mi odgovoriti što je to SP 2? Inaće ja sam poćetnik u ovim kompjuterskim vodama pa mi je ovo sve novo.



offline
  • Cigarette Smoking Man
  • Pridružio: 14 Feb 2005
  • Poruke: 9113
  • Gde živiš: Beograd

SP2 (Service Pack 2) je skup svih "zakrpa" (sigurnosnih patcheva, dodataka, dopuna..) koje su nastale od izlaska XP-a do dana kada je SP2 izašao. Jednom rečju, svi apdejti na jednom mestu..
Ovo je kratko objašnjenje. Možeš koristiti i pretragu na forumu o ovome, naširoko se o tome pisalo..

pozdrav



offline
  • Pridružio: 08 Avg 2007
  • Poruke: 26

Kako da ja znam imam li to ili nemam ili ako nemam mogu li ja to nekako staviti tj.skinuti i instalirati.Jer imam problem i htio sam ovdje zatražiti pomoć ali viim da piše ako nemam taj SP 2 da ne trebam pitati ovdje za pomoć ili sam ja možda nešto krivo razumio?

Dopuna: 11 Okt 2007 19:13

Logfile of HijackThis v1.99.1
Scan saved at 19:11:05, on 11.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\ClocX\ClocX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Joško\Desktop\Pomoć\TR3.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MAXadsl Internet Explorer
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0d8da04e-d7fe-4a03-bea8-1ee5d60ffe21} - (no file)
O2 - BHO: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O2 - BHO: COM+ Service - {2BDEC973-B5AC-4e5b-8AB3-5A0500880DA2} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\tmpA5.tmp.dll
O2 - BHO: (no name) - {a63059c9-169a-43d9-b373-4336a3eca35b} - C:\WINDOWS\system32\kbddd5.dll
O3 - Toolbar: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Search - ?p=ZNxmk142YYHR
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\kbddd5.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\kbddd5.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: T-Com - {2074DEC8-4815-49C2-8F0C-F589C07B8300} - C:\WINDOWS\system32\kbddd5.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.tportal.hr/
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [Link mogu videti samo ulogovani korisnici]
O17 - HKLM\System\CCS\Services\Tcpip\..\{8534E55E-586F-41D5-B43D-99D8ECD8CA7C}: NameServer = 195.29.150.205 195.29.150.204
O20 - AppInit_DLLs: c:\windows\system32\awtsspq.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: imagert - imagert.dll (file missing)
O20 - Winlogon Notify: kbddd5 - C:\WINDOWS\SYSTEM32\kbddd5.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

Evo provat ću objasnit u ćemu je problem:
Imam lap top i na njemudva tvrda diska(C i E)ili je to jedan disk ali podjeljen na dva dijela ne znam.Kad upalim komp on se odmah sam spoji na internet i ja sa njim mogu normalno surfat i mogu normalno se kretat po C disku ali kad pokušam ući u E disk odmah izbaci onaj mali prozor ono kad piše na dnu Send error report i Dont send znate to ste vidjeli puno puta i ja kliknem Dont send i vrati me na radnu površinu.Znaći ne mogu niti jednu mapu u E disku otvoriti odmah mi pokaže onu poruku i vrati na radnu površinu.Jedamput mi je bio izbacio prozor na kojem je pisalo:Runtime error i još je pisalo C:/Program files/Save/save.exe i ja sam pogledao u program files i pokušao izbrisati tu ikonu u mapi Save ali mi nije dalo a mislim da je to ikona od WhenU programa koji dobiješ s BSPlayerom i onda sam skenirao s Ad-Aware 2007 i pokazao mi je dva rezultata i to obadva taj WhenU i ja sam to oznaćio kvaćicom i izbrisao i kad sam pogledao u Program files više nije bilo mape Save ali to nije ništa pomoglo opet ne mogu ući u E disk.Ali nije mi jasno zašto sad imam problema s tim WhenU programom jer ja sam ga ima prije dva mjeseca skupa s BSPlayerom instalirao i nikada nisam imao problema s njim.
Jedi još mi pada na pamet to da sam jučer skinio s jednog domaćeg trackera progrem Internet TV i kad sam ga instalirao tražilo mi je da instaliram RealPlayer i ja sam ga instalirao i nedugo nakon toga su poćeli ovi problemi.
I još samo da kažem da mi ima već dva mjeseca na kompu mi izbacuje one reklame tipa:AntiWirus 2007 i slićno a kad skeniram to ima oznaku NewDoNet i slićno to mi je puno smetalo dok sam surfao s IE ali otkad koristim FF te reklame mi iskaću svako 5-6 dana tako da mi toliko ne smetaju

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini ComboFix sa jedne od sledecih adresa:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log koji ces nam ovde iskopirati.

offline
  • Pridružio: 08 Avg 2007
  • Poruke: 26

Nisam siguran na što ste mislili kad ste rekli da će se pojaviti log i da ga iskopiram.Da li je to ovo?ComboFix 07-10-12.1 - Joçko 2007-10-11 23:23:58.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1250.1.1033.18.148 [GMT 2:00]
Running from: C:\Documents and Settings\Joçko\My Documents\radna mapa\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Program Files\Common Files\companion wizard
C:\Program Files\Common Files\companion wizard\log.txt
C:\Program Files\Common Files\Companion Wizard\log.txt
C:\WA6P
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\awtqo.exe
C:\WINDOWS\system32\dn305b4a81.dat
C:\WINDOWS\system32\kbddd5.dll
C:\WINDOWS\system32\mt_32.dll
C:\WINDOWS\system32\plus32.ocx
C:\WINDOWS\system32\tmp5C.tmp.dll
C:\WINDOWS\system32\tmp5C.tmp.dll
C:\WINDOWS\system32\tmpA5.tmp.dll
C:\WINDOWS\system32\tmpA5.tmp.dll
C:\WINDOWS\xhelper.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE


((((((((((((((((((((((((( Files Created from 2007-09-12 to 2007-10-12 )))))))))))))))))))))))))))))))
.

2007-10-11 23:22 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-11 18:16 <DIR> d-------- C:\Program Files\Security Task Manager
2007-10-11 18:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2007-10-11 11:37 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-09 06:51 <DIR> d-------- C:\My Downloads
2007-10-09 06:46 <DIR> d-------- C:\Program Files\Super Internet TV
2007-10-07 13:42 <DIR> d-------- C:\totalcmd
2007-10-07 13:42 545 --a------ C:\WINDOWS\UC.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\RAR.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\PKZIP.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\PKUNZIP.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\NOCLOSE.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\LHA.PIF
2007-10-07 13:42 545 --a------ C:\WINDOWS\ARJ.PIF
2007-10-06 14:56 <DIR> d-------- C:\Program Files\DkZ Studio
2007-10-06 07:11 <DIR> d-------- C:\Program Files\WinUHA
2007-09-28 18:08 156,992 --a------ C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-09-28 18:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-09-28 18:07 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
2007-09-28 18:07 524,288 --a------ C:\WINDOWS\system32\DivXsm.exe
2007-09-28 18:07 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll
2007-09-27 22:16 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2007-09-23 17:57 <DIR> d-------- C:\Program Files\TVAnts
2007-09-23 13:31 <DIR> d-------- C:\Program Files\ClocX
2007-09-22 19:00 <DIR> d-------- C:\Program Files\Common Files\SWF Studio
2007-09-20 20:59 <DIR> d-------- C:\WINDOWS\system32\Nexus Radio
2007-09-20 20:59 <DIR> d-------- C:\Program Files\Nexus_Radio
2007-09-20 20:59 <DIR> d-------- C:\Program Files\Nexus Radio
2007-09-20 20:59 <DIR> d-------- C:\My Recorded Files
2007-09-20 19:56 <DIR> d-------- C:\Program Files\Raven
2007-09-14 20:17 <DIR> d-------- C:\Program Files\D-Tools
2007-09-14 20:17 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2007-09-14 20:17 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2007-09-14 20:16 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2007-09-13 16:53 <DIR> d-------- C:\Program Files\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-11 16:10 5,767,168 ----a-w C:\Documents and Settings\Joško\ntuser.dat
2007-10-11 02:39 --------- d-----w C:\Program Files\Common Files\Real
2007-10-10 01:10 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-09 19:19 --------- d-----w C:\Program Files\SopCast
2007-10-09 04:56 --------- d-----w C:\Program Files\Real
2007-10-06 22:04 --------- d-----w C:\Program Files\Java
2007-10-05 03:10 --------- d-----w C:\Program Files\DivX
2007-09-30 14:05 --------- d-----w C:\Program Files\eMule
2007-09-28 16:07 9,464 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-09-28 16:07 9,336 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-09-28 16:07 43,528 ------w C:\WINDOWS\system32\drivers\PxHelp20.sys
2007-09-28 16:07 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-09-28 16:07 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-09-28 16:07 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-09-28 16:05 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-09-28 16:05 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-09-28 16:05 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-09-28 16:05 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-09-28 16:05 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-09-28 16:05 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-09-28 16:05 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-09-28 16:05 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-09-28 16:05 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-09-28 16:05 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-09-28 16:05 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-09-28 01:24 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-09-28 01:13 --------- d-----w C:\Program Files\EA SPORTS
2007-09-28 01:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-27 21:34 --------- d-----w C:\Program Files\KONAMI
2007-09-27 12:16 --------- d-----w C:\Program Files\Common Files\Adobe
2007-09-25 20:04 --------- d-----w C:\Program Files\Total Video Converter
2007-09-23 16:01 --------- d-----w C:\Program Files\TVUPlayer
2007-09-09 07:56 --------- d-----w C:\Program Files\Common Files\Java
2007-09-07 02:57 --------- d-----w C:\Program Files\Setup
2007-09-06 20:54 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-06 20:45 --------- d-----w C:\Program Files\Activision
2007-09-04 19:51 --------- d-----w C:\Program Files\ratDVD
2007-08-30 04:27 --------- d-----w C:\Program Files\Webteh
2007-08-27 01:46 --------- d-----w C:\Program Files\Folder Icon Changer
2007-08-23 01:10 9,344 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2007-08-23 01:10 8,320 ----a-w C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-22 01:40 --------- d-----w C:\Program Files\Rainlendar2
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-20 03:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2007-08-17 23:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-08-17 23:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2007-08-16 17:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-08-15 19:15 --------- d-----w C:\Program Files\SlimTV
2007-08-08 02:52 164 ----a-w C:\install.dat
2007-08-04 19:23 8,464 ----a-w C:\WINDOWS\system32\sporder.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-28 14:59 17,120 ----a-w C:\WINDOWS\system32\awtsspq.dll
2007-07-19 22:57 267,112 ----a-w C:\WINDOWS\system32\xactengine2_9.dll
2007-07-19 22:54 18,280 ----a-w C:\WINDOWS\system32\x3daudio1_2.dll
2007-07-19 22:48 77,160 ----a-w C:\DSETUP.dll
2007-07-19 22:48 503,144 ----a-w C:\DXSETUP.exe
2007-07-19 22:48 1,673,576 ----a-w C:\dsetup32.dll
2007-07-19 16:14 444,776 ----a-w C:\WINDOWS\system32\d3dx10_35.dll
2007-07-19 16:14 3,727,720 ----a-w C:\WINDOWS\system32\d3dx9_35.dll
2007-07-19 16:14 1,358,192 ----a-w C:\WINDOWS\system32\D3DCompiler_35.dll
2007-03-17 04:02 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0d8da04e-d7fe-4a03-bea8-1ee5d60ffe21}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]
2007-09-29 15:28 1453080 --a------ C:\Program Files\Nexus_Radio\tbNex1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2462d2d8-b36e-44ab-84bf-c5a9383d2429}"= C:\Program Files\Nexus_Radio\tbNex1.dll [2007-09-29 15:28 1453080]

[HKEY_CLASSES_ROOT\CLSID\{2462d2d8-b36e-44ab-84bf-c5a9383d2429}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2462D2D8-B36E-44AB-84BF-C5A9383D2429}"= C:\Program Files\Nexus_Radio\tbNex1.dll [2007-09-29 15:28 1453080]

[HKEY_CLASSES_ROOT\CLSID\{2462D2D8-B36E-44AB-84BF-C5A9383D2429}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 15:06]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 16:00 C:\WINDOWS\AGRSMMSG.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 21:24]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2007-09-14 09:45]
"RegistryMechanic"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"ClocX"="C:\Program Files\ClocX\ClocX.exe" [2005-01-26 11:04]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 01:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-09-13 12:12]
"Rainlendar2"="C:\Program Files\Rainlendar2\Rainlendar2.exe" [2007-04-15 08:31]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\imagert]
imagert.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\awtsspq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
backup=C:\WINDOWS\pss\Bluetooth.lnkCommon Startup

R1 cdrbsvsd;cdrbsvsd;C:\WINDOWS\system32\drivers\cdrbsvsd.sys
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
R3 RMSPPPOE;WAN Miniport (PPP over Ethernet Protocol);C:\WINDOWS\system32\DRIVERS\RMSPPPOE.SYS
S3 k510bus;Sony Ericsson K510 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\k510bus.sys
S3 k510mdfl;Sony Ericsson K510 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k510mdfl.sys
S3 k510mdm;Sony Ericsson K510 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\k510mdm.sys
S3 k510obex;Sony Ericsson K510 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\k510obex.sys
S3 USB_RNDIS_51;T-Com MAXadsl modem (USB, NDIS);C:\WINDOWS\system32\DRIVERS\usb8023.sys
S3 Vl813;USB Filter;C:\WINDOWS\system32\DRIVERS\Vl813.sys

.
Contents of the 'Scheduled Tasks' folder
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-09 07:00:00 C:\WINDOWS\Tasks\At10.job"
"2007-10-09 08:00:00 C:\WINDOWS\Tasks\At11.job"
"2007-10-09 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 13:00:00 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 15:00:00 C:\WINDOWS\Tasks\At18.job"
"2007-10-11 16:00:00 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 18:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 02:00:03 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 03:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 04:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-10 05:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 06:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 07:00:00 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-09 08:00:00 C:\WINDOWS\Tasks\At35.job"
"2007-10-09 09:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 10:00:00 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 11:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 12:00:00 C:\WINDOWS\Tasks\At39.job"
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 13:00:00 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 14:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 15:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 16:00:00 C:\WINDOWS\Tasks\At43.job"
"2007-10-11 17:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 18:00:01 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 19:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 20:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 21:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\Va01x10I.exe
"2007-10-11 02:00:03 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 03:00:01 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-11 04:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-10 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\7043s54v.exe
"2007-10-09 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\7043s54v.exe
.
**************************************************************************

catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-10-12 23:31:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-12 23:33:07 - machine was rebooted
.
--- E O F ---

Dopuna: 13 Okt 2007 18:32

Molim vas može li mi tko da odgovori na ovo pitanje:
Rećeno mi je da skinem ComboFix i da ga startujem i na kraju da kopiram log i ovdje da postavim i ja sam postavio ovo kao što se vidi u postu iznad samo nisam siguran da li sam dobro napravio.Može li mi reći tko da li sam ja dobro napravio ili sam možda nešto drugo trebao kopirati i postaviti.Razlog ovog mog pitanja je zbog tog što mi nitko nije odgovorio na ovaj moj prijašnji post pa se bojim da sam krivo napravio i da odgovor nikad neću doćekat.Znaći samo tražim da mi netko kaže jesam li dobro napravio u ovom mom postu iznad.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Dobro si uradio log.
Izvini na cekanju, bio sam prilicno zauzet, a tvoj log je prepun infekcija.
Pokusacu u toku veceri da ti napisem uputstvo za ciscenje.

Dopuna: 13 Okt 2007 21:30

Spakuj u jedan ZIP sledece fajlove:

C:\WINDOWS\system32\7043s54v.exe
C:\WINDOWS\system32\Va01x10I.exe
c:\windows\system32\awtsspq.dll

Uploaduj mi taj ZIP preko sledece forme:
[Link mogu videti samo ulogovani korisnici]

Daj mi i svez HijackThis log, da vidim sta je ostalo nakon ComboFix-a.

offline
  • Pridružio: 08 Avg 2007
  • Poruke: 26

Ma prijatelju nemaš se ti meni šta izvinjavati ti meni pomažeš i moje je da čekam i ako treba i deset dana i da šutim i budem zahvalan na pomoći.Samo nisam bio siguran jesam li dobro napravio ili ne da sam znao da sam dobro napravio ne bih uopće dosađivao nego bih čekao odgovor jer pretpostavio bih da nemaš vremena za odgovor i da ćeš mi ogovoriti kad budeš imao vremena.
Samo prijo ja sam početnik i nisam siguran što sad trebam da napravim jel mi možeš to malo detaljnije objasnit.Koliko ja shvaćam trebam otići u C:/WINDOWS i kad nađem ove fajlove onda svakog trebam kopirati i staviti u ZIP samo što ne znam šta je ZIP i kako da ih uploadujem preko sljedeće forme?
I na kraju što ti znaći ova zadnja rećenica:"Daj mi i svez Hijack log itd.....
Izvini znam da sam dosadan ali poćetnik sam i ne kužim se puno u rad kompa ali valjda ću i ja naućiti s vremenom.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

OK, necu da komplikujem, tako da cemo taj ZIP izostaviti.
Otvori sledeci link:
[Link mogu videti samo ulogovani korisnici]
To je nasa forma za upload sumnjivih fajlova.
Klikni dugme Browse na formi i nadji prvi fajl od onih koje sam ti zatrazio.
Selektujes taj fajl i kliknes OK. Vratice te ponovo na formu, gde sada treba da kliknes dugme Upload.
Uradi tako za svaki od onih fajlova koje sam ti zatrazio.
Time ce ti fajlovi stici meni, i ja mogu da ih pregledam.

Ono za "sve HijackThis" log - pokreni ponovo HijackThis i ponovo napravi log, onako kako si uradio na pocetku teme. Iskopiraj taj log u poruku, isto kao sto si vec jednom uradio.
Potreban je novi log da bi smo videli trenutno stanje.

offline
  • Pridružio: 08 Avg 2007
  • Poruke: 26

Imam problem nisam uspio naći sva ona tri fajla našao sam samo jednog i upload-ova sam ga i to onog zadnjeg:awtsspq.dll a ona dva prva sam tražio i nisam mogao naći a i napisao bih dolje u ime fajla i izbacilo bi mi poruku ta ta dva fajla ne postoje

Logfile of HijackThis v1.99.1
Scan saved at 14:20:38, on 15.10.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\ClocX\ClocX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Joško\My Documents\exe\utorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Joško\Desktop\Pomoć\TR3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0d8da04e-d7fe-4a03-bea8-1ee5d60ffe21} - (no file)
O2 - BHO: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {9f811bfd-8342-45e6-a6ec-f8073ae17b7a} - C:\WINDOWS\system32\dpvemx.dll
O3 - Toolbar: Nexus Radio Toolbar - {2462d2d8-b36e-44ab-84bf-c5a9383d2429} - C:\Program Files\Nexus_Radio\tbNex1.dll
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Search - ?p=ZNxmk142YYHR
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: T-Com - {2074DEC8-4815-49C2-8F0C-F589C07B8300} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.tportal.hr/
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [Link mogu videti samo ulogovani korisnici]
O17 - HKLM\System\CCS\Services\Tcpip\..\{8534E55E-586F-41D5-B43D-99D8ECD8CA7C}: NameServer = 195.29.150.205 195.29.150.204
O20 - AppInit_DLLs: c:\windows\system32\awtsspq.dll
O20 - Winlogon Notify: dpvemx - C:\WINDOWS\SYSTEM32\dpvemx.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: imagert - imagert.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini program Avenger sa sledeceg linka:
[Link mogu videti samo ulogovani korisnici]

Na prvom ekranu selektuj Input script manually pa klikni na ikonicu lupe.
U prozoru koji ce se pojavi unesi sledeci tekst:
drivers to unload:
cdrbsvsd

Files to Delete:
C:\WINDOWS\SYSTEM32\dpvemx.dll
c:\windows\system32\awtsspq.dll
C:\WINDOWS\system32\drivers\cdrbsvsd.sys
C:\WINDOWS\system32\7043s54v.exe
C:\WINDOWS\system32\Va01x10I.exe


Klikni na dugme Done.
Vratice te na prvi ekran gde je sada potrebno kliknuti na ikonicu semafora.
Ukoliko ti program sam ne zatrazi restart, onda ti sam restartuj racunar.
Nakon restartovanja bi folder trebao da bude obrisan, i backup napravljen u folderu c:\avenger.

Kada Avenger zavrsi, postavi ovde log koji ce izaci na ekranu.

Ko je trenutno na forumu
 

Ukupno su 751 korisnika na forumu :: 8 registrovanih, 3 sakrivenih i 740 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: blue, brane2208, BZ, crnogorac, havoc995, mikhailo, saputnik plavetnila, Vića