Imam isti problem, i upao sam u tudju temu

Imam isti problem, i upao sam u tudju temu

offline
  • Pridružio: 11 Okt 2008
  • Poruke: 11

exej...imam isti problem...smrc

ComboFix 08-10-09.06 - branko 2008-10-10 15:53:30.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1250.1.1033.18.1020 [GMT 2:00]
Running from: C:\Users\branko\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\x64
C:\Windows\system32\x64\csnp2uvc.dll
C:\Windows\system32\x64\rsnpvc64.dll
C:\Windows\system32\x64\sncduvc.sys
C:\Windows\system32\x64\snp2uvc.sys
C:\Windows\system32\x64\vsnpvc64.dll

.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.

2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\Users\branko\AppData\Roaming\Malwarebytes
2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\Users\All Users\Malwarebytes
2008-10-10 12:37 . 2008-10-10 12:37 <DIR> d-------- C:\ProgramData\Malwarebytes
2008-09-19 19:53 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-09-19 19:53 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll
2008-09-10 10:57 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-10 10:57 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
2008-09-10 10:57 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
2008-09-10 10:57 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-10 10:57 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-10 10:57 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-10 10:57 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-10 13:57 --------- d-----w C:\Users\branko\AppData\Roaming\Skype
2008-10-10 13:26 48,438 ----a-w C:\Users\branko\AppData\Roaming\nvModes.dat
2008-10-02 09:37 --------- d-----w C:\Program Files\Google
2008-09-25 20:39 --------- d-----w C:\Program Files\SpeedFan
2008-09-17 21:32 --------- d-----w C:\Users\branko\AppData\Roaming\mIRC
2008-09-11 20:13 --------- d-----w C:\Users\branko\AppData\Roaming\LimeWire
2008-09-10 09:10 --------- d-----w C:\ProgramData\Microsoft Help
2008-09-10 09:07 --------- d-----w C:\Program Files\Microsoft Works
2008-09-07 09:30 --------- d-----w C:\Program Files\Winamp
2008-09-03 01:55 --------- d-----w C:\Users\branko\AppData\Roaming\Winamp
2008-09-01 17:51 --------- d-----w C:\Program Files\Java
2008-09-01 17:44 --------- d-----w C:\Program Files\Common Files\Java
2008-09-01 17:40 --------- d-----w C:\Program Files\LimeWire
2008-08-24 14:53 --------- d-----w C:\Program Files\Great Secrets Da Vinci
2008-08-23 15:39 --------- d-----w C:\Program Files\Common Files\xing shared
2008-08-23 15:39 --------- d-----w C:\Program Files\Common Files\Real
2008-08-19 13:09 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 09:33 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 21:07 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-31 14:35 174 --sha-w C:\Program Files\desktop.ini
2008-02-19 18:17 0 ----a-w C:\Users\branko\AppData\Roaming\wklnhst.dat
2007-11-26 17:38 32 ----a-w C:\Users\All Users\ezsid.dat
2007-11-26 17:38 32 ----a-w C:\ProgramData\ezsid.dat
2008-05-06 22:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-05-06 22:38 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-26 457216]
"eAudio"="C:\Acer\Empowering Technology\eAudio\eAudio.exe" [2007-06-11 1286144]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-03-08 40048]
"LManager"="C:\PROGRA~1\LAUNCH~1\LManager.exe" [2007-08-15 772616]
"MSPService"="C:\Program Files\Acer Arcade Deluxe\SportsCap\Kernel\MagicSports\MSPMirage.exe" [2007-02-14 102400]
"TVEService"="C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe" [2007-06-02 151552]
"PlayMovie"="C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-24 206952]
"PLFSetL"="C:\Windows\PLFSetL.exe" [2007-07-05 94208]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-06-06 159744]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-05-23 151552]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-11-23 949376]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-25 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-25 8433664]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-25 81920]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-08-23 185896]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-07-25 535336]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-12-26 118784]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2606352464-3568935387-3783892624-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{93095D21-614D-4009-B519-EFD2A48F45DF}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{32945355-CDBE-48E8-AA99-E3234C3E3E07}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D5107B99-FAD3-484B-B1FD-0F99B02215B0}"= C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Acer Arcade Deluxe.exe:Acer Arcade Deluxe
"{F2979B51-C7D7-4432-AC71-A5771C73BB2D}"= C:\Program Files\Acer Arcade Deluxe\VideoMagician\VideoMagician.exe:VideoMagician
"{9C8B4F34-9FE3-4EEC-9D40-CAEA3189C548}"= C:\Program Files\Acer Arcade Deluxe\HomeMedia\HomeMedia.exe:HomeMedia
"{A287267E-E282-4EE2-89E6-DBF838D4E07D}"= C:\Program Files\Acer Arcade Deluxe\DV Wizard\DV Wizard.exe:DV Wizard
"{A25E77DD-5854-4064-B13B-3EFC20045A1C}"= C:\Program Files\Acer Arcade Deluxe\DVDivine\DVDivine.exe:DVDivine
"{F6286C0B-548D-4FF8-A8C5-D0CD7098A58A}"= C:\Program Files\Acer Arcade Deluxe\SportsCap\SportsCap.exe:SportsCap
"{212BD598-B73A-46CF-A1E2-AFC451A13C1D}"= C:\Program Files\Acer Arcade Deluxe\TV Joy\TV Joy.exe:TV Joy
"{AD50A072-E21B-4281-85D9-F329811DB42C}"= C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe:TV Joy Resident Program
"{C0D524FC-D5BB-4E9E-A57A-555568F45575}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PlayMovie.exe:Play Movie
"{3D87BAAD-7219-4C6D-9CFA-938A9DB987E8}"= C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe:Play Movie Resident Program
"{4DF3DC89-57CA-46C3-94C7-579C45BD74C9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{183DC3BA-B733-454B-9D52-30B1BFA30BC4}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{28FA2CE7-CA99-4B3E-BA10-C4B1D45EB2E6}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{13A1130F-391B-4BEA-B5BE-B6CA95A911A2}C:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= UDP:C:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"UDP Query User{F107D3C5-43B1-4B38-8435-60671D9663C4}C:\\program files\\bearshare applications\\bearshare\\bearshare.exe"= TCP:C:\program files\bearshare applications\bearshare\bearshare.exe:BearShare
"{C065C261-7E16-402C-9D4A-AE471AD87F9B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{5E9F1BF5-D622-4FAB-A6C2-3245023ED7C9}C:\\program files\\dap\\dap.exe"= UDP:C:\program files\dap\dap.exe:Download Accelerator Plus
"UDP Query User{27AB6FDC-BDB1-4EBD-9DD3-03C041036D5B}C:\\program files\\dap\\dap.exe"= TCP:C:\program files\dap\dap.exe:Download Accelerator Plus
"{D0427FDD-799C-4843-ADC4-251D385C93D5}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{C8F849F7-E421-4691-9A8C-D173F534DC0C}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{38A998F3-CB80-4EF4-9EED-3C4F77BB90F3}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{88E43180-94A1-40D5-A966-319AF0652A65}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A1580DB6-45AF-4896-861B-2938D51A6F28}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{559A4BD4-4D11-4E70-8C0C-002220566DD7}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{F593D2D4-A45E-456A-9CEC-8F9D7E0D13C4}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{F1ECEDEE-A20A-4BF5-A8B6-3299D2B3F8DC}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{A1660D43-5121-40D5-9E07-84D36072954D}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{FE1BB9B6-7D5B-481A-AB54-2CEEE7DA7E14}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{6C0C7E68-ACF9-4384-A4AC-5A2D6261079F}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{6FECC61F-43D1-465D-A651-8B58E26897CA}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{9360BF8D-AFEB-4019-A045-C9226373D25E}C:\\program files\\spontania video collaboration\\dialcomwcs.exe"= UDP:C:\program files\spontania video collaboration\dialcomwcs.exe:dialcomwcs
"UDP Query User{70AD7CB9-E7C1-46D8-84AD-4059A49ED48B}C:\\program files\\spontania video collaboration\\dialcomwcs.exe"= TCP:C:\program files\spontania video collaboration\dialcomwcs.exe:dialcomwcs
"TCP Query User{69FC1129-CAA1-43EA-86C1-3EEBC0D316C2}C:\\program files\\valve\\hl.exe"= UDP:C:\program files\valve\hl.exe:Half-Life Launcher
"UDP Query User{5DD4CE0A-55A2-4885-885B-4A03552CBC16}C:\\program files\\valve\\hl.exe"= TCP:C:\program files\valve\hl.exe:Half-Life Launcher
"TCP Query User{09419CC9-9990-4FF2-B744-16570D4FDCBF}C:\\program files\\skype\\phone\\skype.exe"= UDP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"UDP Query User{EF1D80BE-B27A-404D-81DA-538982B552E6}C:\\program files\\skype\\phone\\skype.exe"= TCP:C:\program files\skype\phone\skype.exe:Skype. Take a deep breath
"TCP Query User{B664E91B-881C-42B0-8D74-0217D2382887}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{ED5578D5-E9B8-414D-AC30-F34CFA127662}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{4242BF99-213B-458E-B752-C7C17205873C}C:\\program files\\valve\\hlds.exe"= UDP:C:\program files\valve\hlds.exe:HLDS Launcher
"UDP Query User{0EDDA47F-D8E2-4E53-B7F9-B61F4132D096}C:\\program files\\valve\\hlds.exe"= TCP:C:\program files\valve\hlds.exe:HLDS Launcher
"{38131963-1F90-48DE-BB43-DC34AFF320CD}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{D520795B-C7D5-43E3-A80A-6CBCA9E5899C}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{391E42B7-3093-49F5-B7B6-F2A56A785E59}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{2A769639-0C71-4E12-B36A-AD9D28139247}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FC83DF06-6B42-455C-8468-7B272DDAFC05}C:\\program files\\empire xp 5\\empire xp.exe"= UDP:C:\program files\empire xp 5\empire xp.exe:Empire XP 5.2
"UDP Query User{554811A9-5265-4A45-8FBA-9B5DD7A14114}C:\\program files\\empire xp 5\\empire xp.exe"= TCP:C:\program files\empire xp 5\empire xp.exe:Empire XP 5.2
"{917FF743-327A-47E5-B0B3-C5BC0F36EA8C}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{8ED00B15-3DA3-46FC-AA48-4835E3F0C694}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{A9D7EBD7-3CE7-4009-B2A4-0B2349422547}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{05B0F2F7-DA4E-4D6C-8E27-91DD355CA815}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{C7FE2817-A816-45AF-AC35-DEC59F43B25A}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{0A1AEDFA-A98A-4A69-A87F-D580B91B2919}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{1F8CB8E2-1EA7-464A-9044-3F2B33AF26D4}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{BA54C92C-20A2-46C3-AF9F-D75A0F04EDB1}C:\\program files\\icall\\icall.exe"= UDP:C:\program files\icall\icall.exe:iCall Internet Phone
"UDP Query User{048F8C80-1885-4992-A59A-9AF3BF985715}C:\\program files\\icall\\icall.exe"= TCP:C:\program files\icall\icall.exe:iCall Internet Phone
"{94FF60D5-0391-4F84-9956-0D7232FE4D91}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{99010A96-6FA4-4F86-8CE8-724202A6A60D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{3AC95D85-8E95-42F4-BEA9-6DA9F5485F90}C:\\programdata\\chat republic games\\chatrepublicplayer.exe"= UDP:C:\programdata\chat republic games\chatrepublicplayer.exe:Executable Install, Update, Uninstall
"UDP Query User{405A114B-100D-47DC-97C2-0CC5EDB048D5}C:\\programdata\\chat republic games\\chatrepublicplayer.exe"= TCP:C:\programdata\chat republic games\chatrepublicplayer.exe:Executable Install, Update, Uninstall
"TCP Query User{B2C7E9C2-F795-4488-B475-C9D3B5B3038E}C:\\program files\\winamp\\winamp.exe"= UDP:C:\program files\winamp\winamp.exe:Winamp
"UDP Query User{2FE0AECF-8D39-496C-A638-79B535552DC5}C:\\program files\\winamp\\winamp.exe"= TCP:C:\program files\winamp\winamp.exe:Winamp
"TCP Query User{C4A14C80-51ED-402B-A612-49A0ABC3C4B1}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{74549E06-E39E-414F-B54B-00E2C9996E33}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
"C:\\Program Files\\iCall\\iCall.exe"= C:\Program Files\iCall\iCall.exe:*:Enabled:iCall

R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-03 01:51 13560]
R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 45848]
R2 LogWatch;Event Log Watch;C:\Windows\LogWatNT.exe [2000-06-08 50176]
R2 TVECapSvc;TVEnhance Background Capture Service (TBCS);C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVECapSvc.exe [2007-06-02 286820]
R2 TVESched;TVEnhance Task Scheduler (TTS));C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVESched.exe [2007-06-02 110682]
R3 A310;AVerMedia A310 DVB-T;C:\Windows\system32\DRIVERS\AVerA310USB.sys [2007-08-19 26496]
R3 BDASwCap;AVerMedia A310 BDA DVBT Capture Device;C:\Windows\system32\drivers\AVerA310Cap.sys [2007-08-19 42496]
R3 enecir;ENE CIR Receiver;C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
S2 gupdate1c905f7c70fb470;Google Update Service (gupdate1c905f7c70fb470);C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-30 133104]
S3 btwaudio;Bluetooth Audio Device Service;C:\Windows\system32\drivers\btwaudio.sys [2007-05-17 79664]
S3 btwavdt;Bluetooth AVDT;C:\Windows\system32\drivers\btwavdt.sys [2007-05-17 81200]
S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-05-17 16432]
S3 usnjsvc;Usluga Messenger Sharing Folders USN Journal Reader;C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2007-02-22 2808664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{485acae7-3606-11dd-9d3d-001b3857b22d}]
\shell\AutoRun\command - H:\LaunchU3.exe -a

*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-09-14 C:\Windows\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart\ErrorSmart.exe []

2008-09-14 C:\Windows\Tasks\ErrorSmart Scheduled Scan.job
- C:\Program Files\ErrorSmart []

2008-10-10 C:\Windows\Tasks\GoogleUpdateTaskMachine.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2008-08-30 11:52]

2008-10-10 C:\Windows\Tasks\RegCure Program Check.job
- C:\Program Files\RegCure\RegCure.exe [2008-03-10 19:57]

2008-07-24 C:\Windows\Tasks\RegCure.job
- C:\Program Files\RegCure\RegCure.exe [2008-03-10 19:57]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Acer Tour Reminder - (no file)


.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Users\branko\AppData\Roaming\Mozilla\Firefox\Profiles\pyfreqeq.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.daemon-search.com/startpage
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-10-10 15:57:47
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-10 16:00:11
ComboFix-quarantined-files.txt 2008-10-10 13:59:50

Pre-Run: 20.665.204.736 bytes free
Post-Run: 20,598,775,808 bytes free

253 --- E O F --- 2008-10-07 21:02:34

i to vec duzi vremenski period...
sta mi preporucujete da odradim...

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Upravo si prekrsio par pravila ovog foruma, i sada pretpostavljam da ocekujes jos i da ti neko od nas ovde pomogne:

1. Upao si u tudju temu
2. Pratio si uputstva koja se nisu odnosila na tvoj kompjuter
3. Pustio si ComboFix bez da ti iko to kaze, i nama ovde sada unistio pocetne vektore infekcije tako da mi ne znamo od cega da krenemo
4. Sto mislis da se sledeca tema zove kako se vec zove, i sto je obelezena crvenim slovima, pa jos pise Vazno ispred naslova teme:
http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

offline
  • Pridružio: 11 Okt 2008
  • Poruke: 11

izvini...
...ovako imam problem pri dizanju windowsa kad se ulogujem na profil izlazi mi pocetak intalacije blootutha par puta izadje (tachnije dva) i onda se vidi da je not rispondig i sam iskljuci i posle je sve ok...
...to mi se dogodilo kad je jedan lik probao da instalira blootuth na kompu a vec imam integrisani...
...da li moze pomoc...

Dopuna: 12 Okt 2008 17:14

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:11:46, on 12.10.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Users\branko\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Windows\System32\rundll32.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\branko\Desktop\New Folder\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hr.intl.acer.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Update Helper - {77D7E795-33C5-4323-974D-A2A49AB75517} - C:\Program Files\Google\Update\1.2.131.11\GoopdateBho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live pomagač za prijavljivanje - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [MSPService] C:\Program Files\Acer Arcade Deluxe\SportsCap\Kernel\MagicSports\MSPMirage.exe
O4 - HKLM\..\Run: [TVEService] "C:\Program Files\Acer Arcade Deluxe\TV Joy\TVEService.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [PLFSetL] C:\Windows\PLFSetL.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Objavi ovo u blogu - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Objavi ovo u blogu u okviru usluge Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com/microsoftupdate/v6.....8514362062
O16 - DPF: {8EF3CEAF-7227-46FC-A58E-9686C74EF4A7} (ChatRepublicPlayer ActiveX) - formula-data1.chat-republic.com/~crg/activex/ChatRepublicPlayer.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - a532.g.akamai.net/f/532/6712/5m/virtools.do.....taller.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Update Service (gupdate1c905f7c70fb470) (gupdate1c905f7c70fb470) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\Windows\LogWatNT.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: TVEnhance Background Capture Service (TBCS) (TVECapSvc) - Unknown owner - C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVECapSvc.exe
O23 - Service: TVEnhance Task Scheduler (TTS)) (TVESched) - Unknown owner - C:\Program Files\Acer Arcade Deluxe\TV Joy\Kernel\TV\TVESched.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10863 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Izvini, samo da te obavestim da nisam zaboravio na temu, ali ce mi trebati vremena posto smo slabo imali prilike da radimo logove sa Viste tako da svaku liniju posebno moram da proverim (skoro nista od ovoga iz logova ne znam napamet).

offline
  • Pridružio: 11 Okt 2008
  • Poruke: 11

oki...ma samo opusteno...nista mi nije hitno pomirio sam se tim...
...ali bih voleo da ga nema...pozzz

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Zdravo branko87,

dr_Bora je pregledao tvoj log u mom odsustvu, i kaze da je log cist.

Probaj da potrazis pomoc u Windows forumu, posto u Ambulanti resavamo samo slucajeve infekcija malwareom.

offline
  • Pridružio: 11 Okt 2008
  • Poruke: 11

oki....hvala...

Ko je trenutno na forumu
 

Ukupno su 631 korisnika na forumu :: 44 registrovanih, 7 sakrivenih i 580 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., ALBION101, Aleksandar Tomić, amaterSRB, balkan1, Boris90, Buzdovan, cenejac111, Cirkon, cole77, DonRumataEstorski, dragoljub11987, Drug pukovnik, Duh sa sekirom, havoc995, HrcAk47, Insan, Kibice, Konda, konstruktor, Krusarac, lovac12, MB120mm, Milan A. Nikolic, mnn2, mustangkg, pein, piton, royst33, sakota79, sizif, slonic_tonic, Smd, stug, theNedjeljko, vathra, virked, VJ, vlvl, vrag81, W123, wizzardone, yufighter, |_MeD_|