Pozdrav!
Nedavno mi se posle otvaranja jednog torrent sajta desilo da su svi moji kontakti (yahoo mail) dobili mejl bez naslova, samo sa nekim linkom koji se zavrsa sa .jpg, .png ili sl. Stavise, koliko sam uspela da pohvatam konce, nije poslat jedan mejl, vec nekoliko (od toga svaki na po jedno 5 adresa), a sam link je varirao. Naravno, mejl nisam poslala ja. Niti igde u "Sent" ima traga o tome. NOD je pokazao da je komp cist i... pre par dana - ista prica. Poneko je tu i tamo i kliknuo na link (ja nisam), a jedan prijatelj mi je rekao da je putem ne znam kog programa dobio prijavu da moj kom hoce da "preuzme" njegov (ili podatke, sta vec). Zato vas molim za pomoc (i nikako ne shvatam da mi npr. nije zarazen pop mail, a web jeste!). Probleme na svom kompjuteru nisam primetila, ali vec i ovo autonomno slanje je dovoljno neprijatno. Primer linka [potrebna CENZURA]:
mimi-knoop.com/wp-content/themes/organic_po.....ugar39.png
Procesljala sam malo yahoo help (answers / diskusije), ali nisam preduzela nista, pre nego sto probam ovde da nadjem resenje. (Otprilike, tamo se savetuje ciscenje cashe, cookies, history, temp... promena lozinke, log off... i objasnjenje je da je nalog hakovan). Hmm...
Inace, komp je pravi fosil, 32-bitni, Widows XP sp3, kablovski net
Mozda preopsirno
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Vesna at 22:03:45 on 2012-05-01
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.871 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
============== Running Processes ===============
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WimsPrg\WorldClock\wclock30.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
svchost.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Microsoft\BingBar\BBSvc.EXE
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, optimized for Bing and MSN
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WorldClock] "c:\program files\wimsprg\worldclock\wclock30.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Jet Detection] "c:\program files\creative\sblive\program\ADGJDet.exe"
mRun: [WorldClock]
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
StartupFolder: c:\docume~1\vesna\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\vesna\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\gwum.lnk - c:\program files\gigabyte\gigabyte windows utility manager\gwum.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\viarai~1.lnk - c:\program files\via\raid\raid_tool.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\icq7.7\ICQ.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1332202881890
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{BAC6BD9C-A9FE-4C43-A664-5932FC4FFDD2} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\vesna\application data\mozilla\firefox\profiles\y4sw8fse.default\
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2012-3-19 75904]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-12-21 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-12-21 94872]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2012-5-1 32768]
R2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-1-12 810144]
R2 ETDrv;ETDrv;c:\windows\system32\drivers\ETDrv.sys [2012-3-19 170128]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2012-3-20 54760]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2012-5-1 482992]
R3 MarkFun_NT;MarkFun_NT;c:\program files\gigabyte\gigabyte windows utility manager\MARKFUN.W32 [2012-3-19 8236]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2012-3-19 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2012-3-19 21184]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 253088]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 129976]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2012-05-01 16:12:13 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2012-05-01 16:12:12 -------- d-----w- c:\documents and settings\vesna\application data\Spyware Terminator
2012-05-01 16:12:12 -------- d-----w- c:\documents and settings\all users\application data\Spyware Terminator
2012-05-01 16:11:07 -------- d-----w- c:\program files\Spyware Terminator
2012-04-29 02:30:45 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2012-04-29 02:30:44 -------- d-----w- c:\program files\MagicDisc
2012-04-29 02:25:22 -------- d-----w- c:\program files\MagicISO
2012-04-27 21:16:36 -------- d-----w- c:\program files\ESET
2012-04-27 21:07:42 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-04-27 21:07:42 -------- d-----w- c:\windows\system32\wbem\Repository
2012-04-27 21:05:36 -------- d-----w- C:\Media
2012-04-27 21:05:34 -------- d-----w- C:\1100
2012-04-27 21:05:31 -------- d-----w- C:\LaserJet517
2012-04-27 21:05:31 -------- d-----w- C:\FR90PE_VOL
2012-04-27 10:23:57 -------- d-----w- c:\windows\pss
2012-04-27 01:57:17 -------- d-----w- c:\program files\ICQ7.7
2012-04-26 22:02:48 -------- d-----w- c:\program files\WimsPrg
2012-04-25 10:24:54 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 10:24:53 157352 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-04-25 10:24:53 129976 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-04-24 19:06:17 -------- d-----w- c:\windows\SxsCaPendDel
2012-04-18 10:55:42 -------- d-----w- c:\documents and settings\vesna\application data\Dropbox
2012-04-10 19:59:50 -------- d-----w- c:\program files\Windows Media Connect 2
2012-04-10 19:02:18 90112 ------w- c:\windows\Updreg.EXE
2012-04-10 19:02:15 53552 ------w- c:\windows\CTCCW.DLL
2012-04-10 19:02:15 24976 ------w- c:\windows\CTRES.DLL
2012-04-10 19:02:14 84992 ------w- c:\windows\system32\SFCVRT32.DLL
2012-04-10 19:02:14 82432 ------w- c:\windows\system32\CTWFLT32.DLL
2012-04-10 19:02:14 149504 ------w- c:\windows\system32\MFCANS32.DLL
2012-04-10 19:02:14 108032 ------w- c:\windows\system32\MFCUIA32.DLL
2012-04-10 19:02:13 26768 ------w- c:\windows\system32\CTL3D.DLL
2012-04-10 19:02:09 -------- d-----w- c:\windows\system32\Defaults
2012-04-10 19:02:08 338 ----a-w- c:\windows\ctrunonce.reg
2012-04-10 19:01:04 20480 ----a-w- c:\windows\INRES.DLL
2012-04-10 19:01:04 -------- d-----w- c:\windows\system32\Data
2012-04-10 18:58:18 55808 ------w- c:\windows\system32\CTMp3.crl
2012-04-10 18:58:03 73728 ----a-w- c:\windows\system32\CTDrmRes.dll
2012-04-10 18:58:03 28672 ----a-w- c:\windows\system32\CTIntRes.dll
2012-04-10 18:58:03 24576 ----a-w- c:\windows\system32\CTMERes.DLL
2012-04-10 18:58:03 139264 ----a-w- c:\windows\system32\Video.skn
2012-04-10 18:57:57 54784 ------w- c:\windows\system32\Inetwh32.dll
2012-04-10 18:57:57 364544 ----a-w- c:\windows\system32\ctmp3.acm
2012-04-10 18:57:57 331776 ------w- c:\windows\system32\CTMedEng.dll
2012-04-10 18:57:57 163840 ------w- c:\windows\system32\CTDRMUI.dll
2012-04-10 18:57:50 62976 ----a-w- c:\windows\system32\CTDetres.dll
2012-04-10 18:57:50 44032 ----a-w- c:\windows\system32\CTSVCCDA.EXE
2012-04-10 18:57:50 25088 ----a-w- c:\windows\system32\CTSVCCTL.EXE
2012-04-10 18:57:19 12288 ----a-w- c:\windows\system32\AHQCpURes.dll
2012-04-10 18:57:18 32768 ----a-w- c:\windows\system32\AudioHQU.cpl
2012-04-10 18:55:47 15840 ------w- c:\windows\system32\drivers\PFMODNT.SYS
2012-04-10 18:55:47 -------- d-----w- c:\program files\Creative
2012-04-09 20:30:09 -------- d-----w- c:\program files\Realtek AC97
2012-04-09 20:27:57 -------- d-----w- c:\program files\Realtek Sound Manager
2012-04-09 20:27:56 -------- d-----w- c:\program files\AvRack
2012-04-09 20:18:16 -------- d-----w- c:\program files\Realtek AC97(2)
2012-04-07 11:33:03 -------- d-----w- c:\program files\common files\ABBYY
2012-04-07 11:31:02 -------- d-----w- c:\program files\ABBYY FineReader 9.0
2012-04-07 11:31:02 -------- d-----w- c:\documents and settings\all users\application data\ABBYY
2012-04-07 10:15:08 -------- d-----w- c:\documents and settings\vesna\application data\KWorld Multimedia
2012-04-07 10:14:43 -------- d-----w- c:\program files\KWorld Multimedia
2012-04-07 09:59:17 -------- d-----w- C:\Temp
2012-04-06 13:17:15 -------- d-----w- c:\documents and settings\vesna\local settings\application data\Spotify
2012-04-06 13:14:25 -------- d-----w- c:\documents and settings\vesna\application data\Spotify
2012-04-04 05:53:56 182160 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-04-03 21:04:39 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
==================== Find3M ====================
.
2012-04-28 07:35:50 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-20 15:53:41 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2012-03-10 01:32:32 4431872 ----a-w- c:\windows\system32\GPhotos.scr
2012-03-01 11:01:32 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ------w- c:\windows\system32\html.iec
2012-02-07 09:02:40 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:22:18 1860096 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 22:04:32.00 ===============
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Vesna at 22:03:45 on 2012-05-01
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.871 [GMT 2:00]
.
AV: ESET NOD32 Antivirus 4.2 *Enabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
============== Running Processes ===============
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WimsPrg\WorldClock\wclock30.exe
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
svchost.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Microsoft\BingBar\BBSvc.EXE
C:\Program Files\Microsoft\BingBar\SeaPort.EXE
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Spyware Terminator\st_rsser.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer, optimized for Bing and MSN
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\BingExt.dll"
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WorldClock] "c:\program files\wimsprg\worldclock\wclock30.exe"
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [CTHelper] CTHELPER.EXE
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [Jet Detection] "c:\program files\creative\sblive\program\ADGJDet.exe"
mRun: [WorldClock]
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [SpywareTerminatorShield] c:\program files\spyware terminator\SpywareTerminatorShield.exe
mRun: [SpywareTerminatorUpdater] c:\program files\spyware terminator\SpywareTerminatorUpdate.exe
StartupFolder: c:\docume~1\vesna\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\docume~1\vesna\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\gwum.lnk - c:\program files\gigabyte\gigabyte windows utility manager\gwum.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\viarai~1.lnk - c:\program files\via\raid\raid_tool.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: {77F665FD-3F60-4B0A-AE14-EC124B7A7FCE} - c:\program files\icq7.7\ICQ.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1332202881890
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{BAC6BD9C-A9FE-4C43-A664-5932FC4FFDD2} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\vesna\application data\mozilla\firefox\profiles\y4sw8fse.default\
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2012-3-19 75904]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-12-21 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-12-21 94872]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2012-5-1 32768]
R2 BBSvc;Bing Bar Update Service;c:\program files\microsoft\bingbar\BBSvc.EXE [2011-10-21 196176]
R2 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\SeaPort.EXE [2011-10-13 249648]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-1-12 810144]
R2 ETDrv;ETDrv;c:\windows\system32\drivers\ETDrv.sys [2012-3-19 170128]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2012-3-20 54760]
R2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2012-5-1 482992]
R3 MarkFun_NT;MarkFun_NT;c:\program files\gigabyte\gigabyte windows utility manager\MARKFUN.W32 [2012-3-19 8236]
R3 WMIBIOS;%WMIBIOS.ServiceName%;c:\windows\system32\drivers\wmibios.sys [2012-3-19 18272]
R3 WMIINFO;WMIINFO Driver;c:\windows\system32\drivers\wmiinfo.sys [2012-3-19 21184]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-2-29 158856]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 253088]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-4-28 704872]
S3 huadio;huadio;\??\c:\huadio.tmp --> c:\huadio.tmp [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-4-25 129976]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2012-05-01 16:12:13 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
2012-05-01 16:12:12 -------- d-----w- c:\documents and settings\vesna\application data\Spyware Terminator
2012-05-01 16:12:12 -------- d-----w- c:\documents and settings\all users\application data\Spyware Terminator
2012-05-01 16:11:07 -------- d-----w- c:\program files\Spyware Terminator
2012-04-29 02:30:45 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2012-04-29 02:30:44 -------- d-----w- c:\program files\MagicDisc
2012-04-29 02:25:22 -------- d-----w- c:\program files\MagicISO
2012-04-27 21:16:36 -------- d-----w- c:\program files\ESET
2012-04-27 21:07:42 -------- d-----w- c:\windows\system32\wbem\repository\FS
2012-04-27 21:07:42 -------- d-----w- c:\windows\system32\wbem\Repository
2012-04-27 21:05:36 -------- d-----w- C:\Media
2012-04-27 21:05:34 -------- d-----w- C:\1100
2012-04-27 21:05:31 -------- d-----w- C:\LaserJet517
2012-04-27 21:05:31 -------- d-----w- C:\FR90PE_VOL
2012-04-27 10:23:57 -------- d-----w- c:\windows\pss
2012-04-27 01:57:17 -------- d-----w- c:\program files\ICQ7.7
2012-04-26 22:02:48 -------- d-----w- c:\program files\WimsPrg
2012-04-25 10:24:54 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-25 10:24:53 157352 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-04-25 10:24:53 129976 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-04-24 19:06:17 -------- d-----w- c:\windows\SxsCaPendDel
2012-04-18 10:55:42 -------- d-----w- c:\documents and settings\vesna\application data\Dropbox
2012-04-10 19:59:50 -------- d-----w- c:\program files\Windows Media Connect 2
2012-04-10 19:02:18 90112 ------w- c:\windows\Updreg.EXE
2012-04-10 19:02:15 53552 ------w- c:\windows\CTCCW.DLL
2012-04-10 19:02:15 24976 ------w- c:\windows\CTRES.DLL
2012-04-10 19:02:14 84992 ------w- c:\windows\system32\SFCVRT32.DLL
2012-04-10 19:02:14 82432 ------w- c:\windows\system32\CTWFLT32.DLL
2012-04-10 19:02:14 149504 ------w- c:\windows\system32\MFCANS32.DLL
2012-04-10 19:02:14 108032 ------w- c:\windows\system32\MFCUIA32.DLL
2012-04-10 19:02:13 26768 ------w- c:\windows\system32\CTL3D.DLL
2012-04-10 19:02:09 -------- d-----w- c:\windows\system32\Defaults
2012-04-10 19:02:08 338 ----a-w- c:\windows\ctrunonce.reg
2012-04-10 19:01:04 20480 ----a-w- c:\windows\INRES.DLL
2012-04-10 19:01:04 -------- d-----w- c:\windows\system32\Data
2012-04-10 18:58:18 55808 ------w- c:\windows\system32\CTMp3.crl
2012-04-10 18:58:03 73728 ----a-w- c:\windows\system32\CTDrmRes.dll
2012-04-10 18:58:03 28672 ----a-w- c:\windows\system32\CTIntRes.dll
2012-04-10 18:58:03 24576 ----a-w- c:\windows\system32\CTMERes.DLL
2012-04-10 18:58:03 139264 ----a-w- c:\windows\system32\Video.skn
2012-04-10 18:57:57 54784 ------w- c:\windows\system32\Inetwh32.dll
2012-04-10 18:57:57 364544 ----a-w- c:\windows\system32\ctmp3.acm
2012-04-10 18:57:57 331776 ------w- c:\windows\system32\CTMedEng.dll
2012-04-10 18:57:57 163840 ------w- c:\windows\system32\CTDRMUI.dll
2012-04-10 18:57:50 62976 ----a-w- c:\windows\system32\CTDetres.dll
2012-04-10 18:57:50 44032 ----a-w- c:\windows\system32\CTSVCCDA.EXE
2012-04-10 18:57:50 25088 ----a-w- c:\windows\system32\CTSVCCTL.EXE
2012-04-10 18:57:19 12288 ----a-w- c:\windows\system32\AHQCpURes.dll
2012-04-10 18:57:18 32768 ----a-w- c:\windows\system32\AudioHQU.cpl
2012-04-10 18:55:47 15840 ------w- c:\windows\system32\drivers\PFMODNT.SYS
2012-04-10 18:55:47 -------- d-----w- c:\program files\Creative
2012-04-09 20:30:09 -------- d-----w- c:\program files\Realtek AC97
2012-04-09 20:27:57 -------- d-----w- c:\program files\Realtek Sound Manager
2012-04-09 20:27:56 -------- d-----w- c:\program files\AvRack
2012-04-09 20:18:16 -------- d-----w- c:\program files\Realtek AC97(2)
2012-04-07 11:33:03 -------- d-----w- c:\program files\common files\ABBYY
2012-04-07 11:31:02 -------- d-----w- c:\program files\ABBYY FineReader 9.0
2012-04-07 11:31:02 -------- d-----w- c:\documents and settings\all users\application data\ABBYY
2012-04-07 10:15:08 -------- d-----w- c:\documents and settings\vesna\application data\KWorld Multimedia
2012-04-07 10:14:43 -------- d-----w- c:\program files\KWorld Multimedia
2012-04-07 09:59:17 -------- d-----w- C:\Temp
2012-04-06 13:17:15 -------- d-----w- c:\documents and settings\vesna\local settings\application data\Spotify
2012-04-06 13:14:25 -------- d-----w- c:\documents and settings\vesna\application data\Spotify
2012-04-04 05:53:56 182160 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll
2012-04-03 21:04:39 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
.
==================== Find3M ====================
.
2012-04-28 07:35:50 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-20 15:53:41 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2012-03-10 01:32:32 4431872 ----a-w- c:\windows\system32\GPhotos.scr
2012-03-01 11:01:32 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10:16 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10:16 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ------w- c:\windows\system32\html.iec
2012-02-07 09:02:40 1070352 ----a-w- c:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:22:18 1860096 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 22:04:32.00 ===============
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
|