totalno usporen internet!!!

totalno usporen internet!!!

offline
  • Pridružio: 08 Apr 2008
  • Poruke: 4

Napisano: 22 Feb 2010 15:02

problem se javio pre par dana do tada je sve bilo ok sto se brzine i downloada tice,inace imam brzinu 1024/128 kod sezama i connexant adsl modem na usb sumnjam na neke maliciozne programe evo izvestaja
DDS (Ver_09-12-01.01) - NTFSx86
Run by Millos at 14:13:32,56 on pon 22.02.2010
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.209 [GMT 1:00]

AV: ESET NOD32 Antivirus 4.2 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\Mixer.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Conexant\Adsl\dslstat.exe
C:\Program Files\Conexant\Adsl\dslagent.exe
C:\Program Files\USB Disk Security\USBGuard.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\IObit\Advanced SystemCare 3\Awc.exe
C:\Documents and Settings\Millos\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Millos\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Window Washer] c:\program files\webroot\washer\wwDisp.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Advanced SystemCare 3] "c:\program files\iobit\advanced systemcare 3\AWC.exe" /startup
uRun: [Google Update] "c:\documents and settings\millos\local settings\application data\google\update\GoogleUpdate.exe" /c
uRunOnce: [Index Washer] c:\program files\webroot\washer\WashIdx.exe "Millos"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [C-Media Mixer] Mixer.exe /startup
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [DSLSTATEXE] c:\program files\conexant\adsl\dslstat.exe icon
mRun: [DSLAGENTEXE] c:\program files\conexant\adsl\dslagent.exe
mRun: [USB Antivirus] c:\program files\usb disk security\USBGuard.exe
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\millos\applic~1\mozilla\firefox\profiles\7g2dh3nz.default\
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\millos\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-12-16 114984]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2009-12-16 95872]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/02/21 12:29:47];c:\program files\cyberlink\powerdvd9\000.fcl [2009-2-28 87536]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-12-16 806000]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2010-2-21 598856]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-2-22 38224]

=============== Created Last 30 ================

2010-02-22 12:58:14 0 d-----w- c:\docume~1\millos\applic~1\Malwarebytes
2010-02-22 12:58:10 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-22 12:58:08 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-22 12:58:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-22 12:58:06 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-22 12:00:18 0 d-----w- c:\program files\Trend Micro
2010-02-22 11:50:53 0 d-----w- c:\docume~1\millos\applic~1\IObit
2010-02-22 11:50:51 0 d-----w- c:\program files\IObit
2010-02-22 11:30:52 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-22 11:30:52 215920 ----a-w- c:\windows\system32\muweb.dll
2010-02-22 11:30:52 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
2010-02-21 22:55:56 0 d-----w- c:\program files\MSXML 4.0
2010-02-21 22:29:08 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-02-21 22:26:50 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-02-21 22:26:50 272128 ------w- c:\windows\system32\drivers\bthport.sys
2010-02-21 21:38:00 455424 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-02-21 21:21:51 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-02-21 21:21:50 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-02-21 21:21:49 2066048 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-02-21 21:10:16 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-02-21 21:10:16 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-02-21 21:05:27 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2010-02-21 21:05:27 0 d-----w- c:\windows\system32\PreInstall
2010-02-21 21:05:26 0 d--h--w- c:\windows\$hf_mig$
2010-02-21 20:56:02 0 d-----w- c:\program files\mEliteSoftware
2010-02-21 20:55:08 0 d-----w- c:\windows\system32\URTTEMP
2010-02-21 20:46:37 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-02-21 20:46:30 0 d-----w- c:\program files\DAEMON Tools Lite
2010-02-21 20:46:16 0 d-----w- c:\docume~1\millos\applic~1\DAEMON Tools Lite
2010-02-21 20:46:14 0 d-----w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2010-02-21 13:15:43 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-02-21 12:30:48 376 ----a-w- c:\windows\ODBC.INI
2010-02-21 12:30:43 17920 ----a-w- c:\windows\system32\mdimon.dll
2010-02-21 12:29:48 0 d-----w- c:\program files\Microsoft ActiveSync
2010-02-21 12:28:59 0 d-----w- c:\windows\SHELLNEW
2010-02-21 12:28:37 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-02-21 12:26:15 0 d-----w- c:\docume~1\millos\applic~1\Webroot
2010-02-21 12:26:14 0 d-----w- c:\program files\Webroot
2010-02-21 12:26:14 0 d-----w- c:\program files\common files\Webroot Shared
2010-02-21 12:26:14 0 d-----w- c:\docume~1\alluse~1\applic~1\Webroot
2010-02-21 12:26:08 194888 ----a-w- c:\windows\Unwash6.exe
2010-02-21 12:14:38 0 d-----w- c:\docume~1\millos\applic~1\URSoft
2010-02-21 12:14:28 0 d-----w- c:\program files\Your Uninstaller 2008
2010-02-21 12:12:57 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-02-21 12:12:57 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-02-21 12:12:46 91136 -c--a-w- c:\windows\system32\dllcache\kswdmcap.ax
2010-02-21 12:12:46 91136 ----a-w- c:\windows\system32\kswdmcap.ax
2010-02-21 12:12:46 61952 -c--a-w- c:\windows\system32\dllcache\kstvtune.ax
2010-02-21 12:12:46 61952 ----a-w- c:\windows\system32\kstvtune.ax
2010-02-21 12:12:46 28672 -c--a-w- c:\windows\system32\dllcache\vidcap.ax
2010-02-21 12:12:46 28672 ----a-w- c:\windows\system32\vidcap.ax
2010-02-21 12:12:45 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-02-21 12:12:45 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-02-21 12:12:45 43008 -c--a-w- c:\windows\system32\dllcache\ksxbar.ax
2010-02-21 12:12:45 43008 ----a-w- c:\windows\system32\ksxbar.ax
2010-02-21 12:09:34 0 d-----w- c:\program files\common files\FotoWire
2010-02-21 12:09:34 0 d-----w- c:\docume~1\millos\applic~1\FotoWire
2010-02-21 12:08:24 53248 ----a-r- c:\windows\system32\InstMed.exe
2010-02-21 12:08:11 5993 ----a-w- c:\windows\system32\lvcoinst.ini
2010-02-21 12:08:11 110592 ----a-w- c:\windows\system32\lvcoinst.dll
2010-02-21 12:08:10 372736 ----a-w- c:\windows\system32\LVUI2RC.dll
2010-02-21 12:08:10 204800 ----a-w- c:\windows\system32\LVUI2.dll
2010-02-21 12:08:10 19968 ----a-w- c:\windows\system32\drivers\LVUSBSta.sys
2010-02-21 12:08:09 469696 ----a-w- c:\windows\system32\drivers\lvcm.sys
2010-02-21 12:08:09 208896 ----a-w- c:\windows\system32\lvcodec2.dll
2010-02-21 12:07:45 0 d-----w- c:\program files\common files\Logitech
2010-02-21 12:07:40 264 ----a-w- c:\windows\_delis32.ini
2010-02-21 11:48:23 0 d-----w- c:\program files\CCleaner
2010-02-21 11:35:39 0 d-----r- c:\program files\Skype
2010-02-21 11:34:44 0 d-----w- c:\docume~1\alluse~1\applic~1\DFX
2010-02-21 11:34:40 0 d-----w- c:\program files\common files\DFX
2010-02-21 11:34:39 0 d-----w- c:\program files\DFX
2010-02-21 11:34:28 0 d-----w- c:\program files\Microsoft
2010-02-21 11:32:50 0 d-----w- c:\docume~1\alluse~1\applic~1\ACD Systems
2010-02-21 11:32:46 0 d-----w- c:\program files\common files\ACD Systems
2010-02-21 11:32:46 0 d-----w- c:\program files\ACD Systems
2010-02-21 11:30:50 0 d-----w- c:\program files\The KMPlayer
2010-02-21 11:29:25 0 d-----w- c:\program files\common files\CyberLink
2010-02-21 11:28:30 0 d-----w- c:\program files\common files\ODBC
2010-02-21 11:28:25 0 d-----w- c:\program files\common files\SpeechEngines
2010-02-21 11:28:06 0 d-----w- c:\program files\Winamp Detect
2010-02-21 11:27:48 0 d-----r- c:\documents and settings\all users\Documents
2010-02-21 11:26:17 0 d-----w- c:\program files\GRETECH
2010-02-21 11:24:43 0 d-----w- c:\docume~1\millos\applic~1\TeamViewer
2010-02-21 11:24:34 0 d-----w- c:\program files\TeamViewer
2010-02-21 11:22:57 0 d-----w- c:\program files\common files\Windows Live
2010-02-21 11:19:24 0 d-----w- c:\docume~1\alluse~1\applic~1\Zbshareware Lab
2010-02-21 11:19:21 0 d-----w- c:\program files\USB Disk Security
2010-02-21 11:13:09 0 d-----w- c:\program files\Nero
2010-02-21 11:13:09 0 d-----w- c:\docume~1\alluse~1\applic~1\Nero
2010-02-21 11:08:10 0 d-----w- c:\program files\Conexant
2010-02-21 11:05:52 0 d-----w- c:\program files\ESET
2010-02-21 10:58:26 0 d-----w- c:\program files\PCI Audio Applications
2010-02-21 10:57:57 0 d-----w- c:\program files\C-Media
2010-02-21 10:53:54 0 d-----w- c:\docume~1\alluse~1\applic~1\NVIDIA Corporation
2010-02-21 10:53:49 0 d-----w- c:\program files\NVIDIA Corporation
2010-02-21 10:38:41 0 d-sh--w- c:\documents and settings\all users\DRM
2010-02-21 10:38:22 0 d--h--w- c:\program files\WindowsUpdate
2010-02-21 10:37:21 0 d-----w- c:\program files\common files\MSSoap
2010-02-21 10:35:09 0 d-----w- c:\program files\Online Services
2010-02-21 10:35:03 0 d-----w- c:\program files\Messenger
2010-02-21 10:34:59 0 d-----w- c:\program files\MSN Gaming Zone
2010-02-21 10:34:12 0 d-----w- c:\program files\Windows NT

==================== Find3M ====================

2010-02-21 11:27:49 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-02-21 11:27:48 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-02-21 11:27:47 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-02-21 10:58:36 4608 ----a-w- c:\windows\system32\w95inf32.dll
2010-02-21 10:58:36 2272 ----a-w- c:\windows\system32\w95inf16.dll
2010-02-21 10:35:30 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-12 04:03:33 6359168 ----a-w- c:\windows\system32\nv4_disp.dll
2010-01-12 04:03:33 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-01-12 04:03:33 4104192 ----a-w- c:\windows\system32\nvcuda.dll
2010-01-12 04:03:33 4077672 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-01-12 04:03:33 2283526 ----a-w- c:\windows\system32\nvdata.bin
2010-01-12 04:03:33 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2010-01-12 04:03:33 182888 ----a-w- c:\windows\system32\nvcodins.dll
2010-01-12 04:03:33 182888 ----a-w- c:\windows\system32\nvcod.dll
2010-01-12 04:03:33 14458880 ----a-w- c:\windows\system32\nvoglnt.dll
2010-01-12 04:03:33 11632640 ----a-w- c:\windows\system32\nvcompiler.dll
2010-01-12 04:03:33 1081344 ----a-w- c:\windows\system32\nvapi.dll
2010-01-12 04:03:33 10276768 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2010-01-11 21:17:44 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-01-11 21:17:44 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-01-11 21:17:44 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-01-11 21:17:44 13666408 ----a-w- c:\windows\system32\nvcpl.dll
2010-01-11 21:17:44 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-01-11 21:17:40 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08:23 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-11-27 16:07:35 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07:34 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07:34 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-27 16:07:34 11264 ----a-w- c:\windows\system32\msrle32.dll
2001-11-23 04:08:20 712704 ----a-w- c:\windows\inf\other\AUDIO3D.DLL

============= FINISH: 14:14:07,43 ===============
ps ako mozete pomozite!!!

Dopuna: 22 Feb 2010 15:10

mycity.rs/must-login.png
evo izvestaja sa RootRepeal

Dopuna: 22 Feb 2010 15:11

ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2010/02/22 15:05
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: PCI_PNP8040
Image Path: \Driver\PCI_PNP8040
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xF3EB1000 Size: 49152 File Visible: No Signed: -
Status: -

Name: sptd
Image Path: \Driver\sptd
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: spyr.sys
Image Path: spyr.sys
Address: 0xF771B000 Size: 995328 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Documents and Settings\Millos\Application Data\Mozilla\Firefox\Profiles\7g2dh3nz.default\sessionstore.js
Status: Could not get file information (Error 0xc0000008-)

SSDT
-------------------
#: 019 Function Name: NtAssignProcessToJobObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130610

#: 041 Function Name: NtCreateKey
Status: Hooked by "spyr.sys" at address 0xf771c0e0

#: 057 Function Name: NtDebugActiveProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130c10

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130730

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "spyr.sys" at address 0xf7734da4

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "spyr.sys" at address 0xf7735132

#: 119 Function Name: NtOpenKey
Status: Hooked by "spyr.sys" at address 0xf771c0c0

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf41304b0

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130570

#: 137 Function Name: NtProtectVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf41306d0

#: 160 Function Name: NtQueryKey
Status: Hooked by "spyr.sys" at address 0xf773520a

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "spyr.sys" at address 0xf773508a

#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130690

#: 229 Function Name: NtSetInformationThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130650

#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf41307d0

#: 247 Function Name: NtSetValueKey
Status: Hooked by "spyr.sys" at address 0xf773529c

#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130510

#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130590

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf41304d0

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf41305d0

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\ehdrv.sys" at address 0xf4130750

Stealth Objects
-------------------
Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP]
Process: System Address: 0x867d81f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_CREATE]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_CLOSE]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_POWER]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: sys, IRP_MJ_PNP]
Process: System Address: 0x863fb1f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP]
Process: System Address: 0x864061f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_READ]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_POWER]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: dmio, IRP_MJ_PNP]
Process: System Address: 0x867681f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CREATE]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_CLOSE]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_POWER]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: usbuhci, IRP_MJ_PNP]
Process: System Address: 0x864881f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP]
Process: System Address: 0x867da1f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP]
Process: System Address: 0x865021f8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CREATE]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_CLOSE]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_POWER]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: usbehci, IRP_MJ_PNP]
Process: System Address: 0x8645f2b8 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP]
Process: System Address: 0x863a8500 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_CREATE]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_CLOSE]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_READ]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_QUERY_INFORMATION]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_SET_INFORMATION]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_QUERY_VOLUME_INFORMATION]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_DIRECTORY_CONTROL]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_FILE_SYSTEM_CONTROL]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_DEVICE_CONTROL]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_SHUTDOWN]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_LOCK_CONTROL]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_CLEANUP]
Process: System Address: 0x862b74b0 Size: 121

Object: Hidden Code [Driver: 0000, IRP_MJ_PNP]
Process: System Address: 0x862b74b0 Size: 121

==EOF==

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Pozdrav i Dobrodosao na forum Smile

Logovi su prilicno cisti, tako da sumnjam da je malware u pitanju.
Probaj kontaktirati Provajdera ili potrazi pomoc u Windows podforumu.

offline
  • Pridružio: 08 Apr 2008
  • Poruke: 4

diarno ::Pozdrav i Dobrodosao na forum Smile

Logovi su prilicno cisti, tako da sumnjam da je malware u pitanju.
Probaj kontaktirati Provajdera ili potrazi pomoc u Windows podforumu.
pozdrav i hvala na odgovoru pa uglavnom ja sam skenirao kako i pise u uputstvu ali ako kazete da je cisto onda jeste.pogledacu u windows potforumu.

Ko je trenutno na forumu
 

Ukupno su 937 korisnika na forumu :: 50 registrovanih, 7 sakrivenih i 880 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, A.R.Chafee.Jr., airsuba, ajo baba, aleksandarbl, amaterSRB, Atomski čoban, bobomicek, bokisha253, Brana01, cavatina, darkojbn, Denaya, Dimitrise93, havoc995, HrcAk47, ikan, ivica976, Još malo pa deda, kybonacci, lord sir giga, Lubica, Lutvo_Redzepagic, MB120mm, Metanoja, mgolub, Milometer, Miskohd, nebidrag, Panter, panzerwaffe, pein, RJ, robertino, Romibrat, rovac, S2M, Sančo, sevenino, slonic_tonic, sokars, Srky Boy, suton, theNedjeljko, trajkoni018, vathra, VP6919, wolf431, |_MeD_|, šumar bk2