DVD video

1

DVD video

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Od kako sam instalirao ms update preko autopatchera ne mogu da pokrenem ni jedan dvd video :S
evo log-a

Logfile of HijackThis v1.99.1
Scan saved at 8:40:27 AM, on 12/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lock My PC 4\LmpcServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Nettalk6\Nettalk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Opera 9\Opera.exe
C:\Documents and Settings\Dejan\Desktop\New Folder\TR3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/intl/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0DCE0F0-10E9-4651-AF14-5D9026F052B0}: NameServer = 77.105.0.19 77.105.0.18
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: fsp_lmwl - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lock My PC Service (LmpcService) - Unknown owner - C:\Program Files\Lock My PC 4\LmpcServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...

Pomenuti problem nema veze sa malware-om, no u postavljenom logu se vide tragovi infekcije.


Upload-uj mi: C:\WINDOWS\system32\__c0021F10.dat

preko sledeće forme: http://www.mycity.rs/ambulanta-upload.php


-------------------------------------------------------------------------------------


Skini ComboFix sa jedne od sledecih adresa:
http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log koji ces nam ovde iskopirati.

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

nemam taj fajl...

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Isprati ostatak uputstva kako bi bili sigurni u to.

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

sad sam pretrazio ceo hard, nema __c0021F10.dat

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

U redu.

Hoće li biti nešto od ComboFix loga?

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

ComboFix 07-12-19.2 - Dejan 2007-12-19 8:22:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.73 [GMT 1:00]
Running from: C:\Documents and Settings\Dejan\Desktop\New Folder (2)\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\sfsync02.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_SFSYNC02
-------\sfsync02


((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.

2007-12-18 10:12 . 2007-12-18 10:20 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2007-12-18 09:50 . 2007-12-18 09:50 <DIR> d-------- C:\Your.Uninstaller_.2008.PRO
2007-12-18 09:47 . 2007-12-18 09:48 3,783,357 --a------ C:\Your.Uninstaller_.2008.PRO.rar
2007-12-16 18:07 . 2007-12-16 18:07 <DIR> d-------- C:\Program Files\General
2007-12-16 15:25 . 2007-12-16 15:25 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-12-16 09:12 . 2007-12-16 09:12 <DIR> d-------- C:\Program Files\Hotfix Manager
2007-12-16 08:46 . 2007-12-16 08:46 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-16 08:46 . 2007-12-16 08:46 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-16 08:15 . 2007-12-16 08:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-16 08:13 . 2007-12-16 08:13 <DIR> d-------- C:\Program Files\Malicious Software Removal Tool
2007-12-16 08:13 . 2007-03-07 18:45 6,054,400 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-16 08:13 . 2007-04-03 05:36 2,453,952 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-16 08:13 . 2007-01-31 07:47 991,232 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-16 08:13 . 2007-03-07 18:45 458,752 --a--c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-16 08:13 . 2007-04-03 15:46 383,488 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-16 08:13 . 2007-03-07 18:45 266,752 --a--c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-16 08:13 . 2007-03-07 18:45 51,712 --a--c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-16 08:13 . 2007-02-27 09:20 13,824 --a--c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-16 08:05 . 2007-12-16 08:05 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-16 07:45 . 2007-12-16 07:45 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-12-16 07:44 . 2007-12-16 07:44 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-12-16 07:44 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-12-16 07:39 . 2007-12-16 07:39 <DIR> d--h-c--- C:\WINDOWS\$SQLUninstallMSXML2SP6-KB887606-x86-ENU$
2007-12-16 07:39 . 2007-12-16 09:20 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-16 07:38 . 2007-12-16 07:38 <DIR> d-------- C:\Program Files\PowerMenu
2007-12-16 07:24 . 2007-03-12 16:16 10,752 --a------ C:\WINDOWS\system32\aamd532.dll
2007-12-16 07:18 . 2007-12-16 07:24 <DIR> d-------- C:\Program Files\AutoPatcher
2007-12-15 22:28 . 2007-12-16 01:07 319,507,151 --a------ C:\AutoPatcher_WinXP_May07_x86_ENU_Core.exe
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Program Files\OrphansRemover
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\OrphansRemover
2007-12-15 14:17 . 2003-09-12 04:26 646,784 --a------ C:\WINDOWS\system32\drivers\CnxEtU.sys
2007-12-15 14:17 . 2003-10-29 08:07 163,840 --a------ C:\WINDOWS\system32\CnxHwIo.dll
2007-12-15 14:17 . 2002-08-06 08:59 118,784 --a------ C:\WINDOWS\system32\CnxMfdCo.dll
2007-12-15 14:17 . 2001-10-03 08:08 118,784 --a------ C:\WINDOWS\system32\CnxClsCo.dll
2007-12-15 14:17 . 2003-10-29 08:02 108,675 --a------ C:\WINDOWS\system32\drivers\CnxTgN.sys
2007-12-15 14:17 . 2003-09-12 04:26 60,288 --a------ C:\WINDOWS\system32\drivers\CnxEtP.sys
2007-12-15 13:46 . 2003-10-29 14:11 233,472 --a------ C:\WINDOWS\system32\CnxUnist.exe
2007-12-13 18:55 . 2005-04-30 23:41 200,704 --a------ C:\WINDOWS\system32\IfsDrives.dll
2007-12-13 18:55 . 2006-10-23 18:20 132,736 --a------ C:\WINDOWS\system32\drivers\ext2fs.sys
2007-12-13 18:55 . 2005-02-04 15:35 57,344 --a------ C:\WINDOWS\system32\IfsDrives.cpl
2007-12-13 18:55 . 2004-09-25 00:28 4,608 --a------ C:\WINDOWS\system32\drivers\IfsDrives.sys
2007-12-12 21:40 . 2007-12-12 21:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-12-12 21:37 . 2007-02-22 10:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-12-12 21:37 . 2007-02-22 10:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-12-12 21:37 . 2007-02-22 10:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-12-12 21:37 . 2007-02-22 10:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-12-11 17:58 . 2007-12-11 17:58 <DIR> d-------- C:\Program Files\Hirc
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\SystemRequirementsLab
2007-12-06 19:17 . 2007-12-13 20:13 90,980 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-06 19:17 . 2007-12-13 20:13 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-06 19:16 . 2007-12-19 08:33 19,995,168 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-06 19:16 . 2007-12-19 08:32 268,844 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-06 19:16 . 2007-12-19 08:33 205,600 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-06 19:16 . 2007-12-19 08:32 20,324 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-05 10:03 . 2007-12-11 12:34 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\gtk-2.0
2007-12-05 09:56 . 2007-12-05 09:56 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\Inkscape
2007-12-05 09:51 . 2007-12-05 09:55 <DIR> d-------- C:\Program Files\Inkscape
2007-11-25 19:26 . 2007-11-25 19:26 697 --a------ C:\WINDOWS\EReg515.dat
2007-11-25 18:00 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2007-11-25 18:00 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2007-11-25 18:00 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-11-25 18:00 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2007-11-25 18:00 . 2007-11-25 18:00 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-11-25 18:00 . 2007-11-25 18:00 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-11-25 17:56 . 2007-11-26 20:25 1,477 --a------ C:\WINDOWS\disney.ini
2007-11-21 09:34 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-19 06:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-18 19:06 --------- d-----w C:\Program Files\MSN Messenger
2007-12-18 19:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-18 10:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-18 09:36 --------- d-----w C:\Program Files\Paint.NET
2007-12-16 14:25 --------- d-----w C:\Program Files\Stardock
2007-12-16 06:55 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-16 06:50 --------- d-----w C:\Program Files\MSBuild
2007-12-15 17:15 --------- d-----w C:\Program Files\mIRC
2007-12-15 15:36 --------- d-----w C:\Documents and Settings\Dejan\Application Data\uTorrent
2007-12-15 14:24 --------- d-----w C:\Program Files\Blaze Media Pro
2007-12-15 13:04 --------- d-----w C:\Program Files\eMule
2007-12-15 12:54 --------- d-----w C:\Program Files\Gigatron
2007-12-15 12:51 --------- d-----w C:\Program Files\ConTEXT
2007-12-15 12:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-15 12:15 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{9EEC710E-58B9-4B76-93C5-36D01182487C}
2007-12-15 12:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 20:44 --------- d-----w C:\Program Files\Nokia
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\Nokia
2007-12-12 20:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-06 18:16 --------- d-----w C:\Program Files\Kaspersky Lab
2007-11-30 12:21 --------- d-----w C:\Documents and Settings\Dejan\Application Data\Nokia
2007-11-22 19:14 --------- d-----w C:\Program Files\Trillian
2007-11-20 09:10 --------- d-----w C:\Documents and Settings\Dejan\Application Data\LimeWire
2007-11-14 20:56 --------- d-----w C:\Program Files\Common Files\SWF Studio
2007-11-13 05:37 11,264 --sha-w C:\Program Files\Thumbs.db
2007-11-13 05:37 --------- d-----w C:\Program Files\XviD
2007-11-13 05:37 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-11-13 05:37 --------- d-----w C:\Program Files\mpegable
2007-11-12 18:35 --------- d-----w C:\Program Files\Nettalk6
2007-11-08 14:21 720,896 ----a-w C:\WINDOWS\iun6002.exe
2007-10-30 12:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Stardock
2007-10-23 10:31 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-10-23 10:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-23 10:25 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-21 06:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-20 14:47 --------- d-----w C:\Program Files\Opera 9
2007-06-25 14:58 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45819 PM).mht
2007-06-25 14:57 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45656 PM).mht
2007-05-08 21:05 80 --sha-r C:\WINDOWS\system32\AAF32A9973.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2003-10-29 08:11]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35]

C:\Documents and Settings\Dejan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-12-16 15:25:54]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-12-16 07:38:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-09-23 10:10 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Uniblue RegistryBooster 2"=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"

R1 Ext2fs;Ext2fs;C:\WINDOWS\system32\DRIVERS\ext2fs.sys [2006-10-23 18:20]
R1 IfsDrives;IfsDrives;C:\WINDOWS\system32\DRIVERS\IfsDrives.sys [2004-09-25 00:28]
R2 LmpcService;Lock My PC Service;C:\Program Files\Lock My PC 4\LmpcServ.exe [2007-03-18 11:51]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2003-09-12 04:26]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2003-09-12 04:26]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2003-10-29 08:02]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

.
Contents of the 'Scheduled Tasks' folder
"2006-07-03 16:18:24 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-19 08:34:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
Completion time: 2007-12-19 8:37:35 - machine was rebooted

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Uploaduj mi sledeći file:
C:\WINDOWS\system32\actskn45.ocx


Upload link: http://www.mycity.rs/ambulanta-upload.php

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Vas fajl je uspesno uploadovan. Smile

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pokreni HijackThis, skeniraj i čekiraj sledeće linije:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.bearshare.com/intl/
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

Klikni Fix Checked.


-------------------------------------------------------------------------------------


Pronađi i obriši file: C:\WINDOWS\system32\actskn45.ocx

-------------------------------------------------------------------------------------


Klikni Start - Run i ukucaj:

regedit


Kada se Regedit pokrene, pronađi (u levom prozoru) i klikni na sledeći ključ:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

U desnom prozoru će biti prikazane vrednosti koje se nalaze unutar toga ključa.
Dvoklik na vrednost AppInit_DLLs će otvoriti prozor u kome ćeš moći modifikovati sadržaj te stavke.

Pod Value data će se nalaziti sledeće:

C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

Potrebno je da obrišeš ono obeleženo crvenom bojom i da klikneš OK.

Znači, nakon promene, ta stavka treba da izgleda ovako:

wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll





Kada si odradio ovo gore, restartuj PC i postavi novi HT log.

Ko je trenutno na forumu
 

Ukupno su 737 korisnika na forumu :: 2 registrovanih, 0 sakrivenih i 735 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bigfoot, Milos82