Molim Vas za proveru Loga

Molim Vas za proveru Loga

offline
  • Pridružio: 10 Okt 2007
  • Poruke: 72
  • Gde živiš: Kingstown

svchost.exe zauzme 100% cpu i non-stop nesto vuce sa neta


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:55:07 AM, on 12/26/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Windows7\Analog Clock\AnalogClock.exe
C:\Program Files\Windows7\TopDesk\topdesk.exe
C:\Program Files\Windows7\UberIcon\UberIcon Manager.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\DOCUME~1\salence\LOCALS~1\Temp\RtkBtMnt.exe
c:\program files\winamp toolbar\WinampTbServer.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\totalcmd\TOTALCMD.EXE
c:\Documents and Settings\salence\My Documents\antivirus\rkekoke.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favorites
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [KRun] C:\Program Files\Windows7\RunMe\RunMe.exe
O4 - HKLM\..\Run: [Viena Explorer] "C:\Program Files\Windows7\Vienna Explorer\Vienna Explorer.exe"
O4 - HKLM\..\Run: [Visual Task Tips] "C:\Program Files\Windows7\VisualTaskTips\VisualTaskTips.exe"
O4 - HKLM\..\Run: [Pie Dock] "C:\Program Files\Windows7\Windows 7 Pie Dock\Windows 7 Pie Dock.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [AnalogClock] C:\Program Files\Windows7\Analog Clock\AnalogClock.exe
O4 - HKCU\..\Run: [TopDesk] C:\Program Files\Windows7\TopDesk\topdesk.exe
O4 - HKCU\..\Run: [TransBar] C:\Program Files\Windows7\TransBar\TransBar.exe /s
O4 - HKCU\..\Run: [UberIcon] "C:\Program Files\Windows7\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

--
End of file - 9734 bytes

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Pozdrav....

Uradi sledece :

Arrow Klikni desnim tasterom na Avira ikonicu ( ) u donjem, desnom uglu ekrana i deštikliraj AntiVir Guard Enable.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.

Arrow Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 10 Okt 2007
  • Poruke: 72
  • Gde živiš: Kingstown

ComboFix 08-12-24.01 - salence 2008-12-26 5:32:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1790.1272 [GMT 7:00]
Running from: c:\documents and settings\salence\My Documents\antivirus\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\tmp.reg

.
((((((((((((((((((((((((( Files Created from 2008-11-25 to 2008-12-25 )))))))))))))))))))))))))))))))
.

2008-12-26 05:23 . 2008-12-26 05:23 <DIR> d-------- c:\windows\LastGood
2008-12-26 05:10 . 2008-12-26 05:10 <DIR> d-------- c:\documents and settings\Administrator
2008-12-26 04:45 . 2008-06-13 18:05 272,128 --------- c:\windows\system32\drivers\bthport.sys
2008-12-26 04:45 . 2008-06-13 18:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-26 04:29 . 2008-12-26 04:29 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-26 04:29 . 2008-12-26 04:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-26 04:07 . 2008-12-26 04:07 <DIR> d-------- c:\program files\Lavasoft
2008-12-26 04:07 . 2008-12-26 04:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-26 04:03 . 2008-12-26 04:03 <DIR> d-------- c:\program files\Malware Removal Tool
2008-12-26 03:36 . 2008-12-13 13:40 3,593,216 -----c--- c:\windows\system32\dllcache\mshtml.dll
2008-12-26 03:21 . 2008-08-14 17:11 2,189,184 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-26 03:21 . 2008-08-14 17:09 2,145,280 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-26 03:21 . 2008-08-14 16:33 2,066,048 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-26 03:21 . 2008-08-14 16:33 2,023,936 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-26 03:17 . 2008-10-24 18:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-25 22:43 . 2008-12-25 22:43 <DIR> d-------- c:\documents and settings\salence\Application Data\ACD Systems
2008-12-25 22:42 . 2008-12-25 22:42 <DIR> d-------- c:\program files\Common Files\ACD Systems
2008-12-25 22:42 . 2008-12-25 22:42 <DIR> d-------- c:\program files\ACD Systems
2008-12-25 22:42 . 2008-12-25 22:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2008-12-25 22:40 . 2008-09-05 00:15 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-25 19:37 . 2005-02-25 10:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2008-12-25 19:37 . 2008-12-26 05:07 1,393 --a------ c:\windows\imsins.BAK
2008-12-25 14:19 . 2008-12-25 14:19 <DIR> d-------- c:\documents and settings\salence\Application Data\IObit
2008-12-25 14:09 . 2008-12-25 14:19 <DIR> d-------- c:\program files\IObit
2008-12-25 14:03 . 2008-12-25 14:04 <DIR> d-------- c:\program files\totalcmd
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\UC.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\RAR.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\PKZIP.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\PKUNZIP.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\NOCLOSE.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\LHA.PIF
2008-12-25 14:03 . 2008-08-08 07:04 545 --a------ c:\windows\ARJ.PIF
2008-12-25 14:01 . 2008-12-25 14:01 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-12-24 21:50 . 2008-12-24 21:51 <DIR> d-------- c:\documents and settings\internet\Application Data\Winamp
2008-12-23 17:49 . 2008-12-25 00:35 <DIR> d-------- c:\documents and settings\internet
2008-12-23 16:43 . 2008-12-23 16:43 <DIR> d-------- c:\windows\system32\QuickTime
2008-12-23 16:43 . 2008-12-23 16:43 <DIR> d-------- c:\documents and settings\salence\Application Data\Quark
2008-12-23 16:42 . 2008-12-23 16:42 <DIR> d-------- c:\program files\Quark
2008-12-23 16:42 . 2008-12-23 16:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\Quark
2008-12-23 16:41 . 2008-12-23 16:41 <DIR> d-------- c:\program files\InstallShield Installation Information
2008-12-23 16:40 . 2008-12-23 16:41 <DIR> d-------- c:\program files\QuickTime
2008-12-23 16:40 . 2008-12-23 16:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-23 14:03 . 2008-12-23 14:03 <DIR> d-------- c:\documents and settings\salence\Application Data\Abvent
2008-12-23 14:03 . 2008-12-23 14:03 <DIR> d-------- c:\documents and settings\All Users\Application Data\Abvent
2008-12-23 14:02 . 2008-12-23 15:59 <DIR> d-------- c:\documents and settings\salence\Application Data\Abvent_Artlantis2
2008-12-23 14:00 . 2008-12-23 14:03 <DIR> d-------- c:\program files\Artlantis Studio 2
2008-12-23 13:55 . 2008-12-23 13:57 <DIR> d-------- c:\program files\photoshopcs4fportable
2008-12-23 03:35 . 2008-12-23 03:35 <DIR> d-------- c:\program files\Winamp Toolbar
2008-12-23 03:35 . 2008-12-23 03:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Winamp Toolbar
2008-12-23 03:34 . 2008-12-23 03:34 <DIR> d-------- c:\program files\Winamp Remote
2008-12-23 03:34 . 2008-12-23 03:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\OrbNetworks
2008-12-23 03:28 . 2008-12-23 03:40 <DIR> d-------- c:\program files\Winamp
2008-12-23 03:28 . 2008-12-23 03:55 <DIR> d-------- c:\documents and settings\salence\Application Data\Winamp
2008-12-22 04:39 . 2008-12-22 16:19 <DIR> d-------- c:\documents and settings\salence\Application Data\AdobeUM
2008-12-22 04:38 . 2008-12-25 13:59 <DIR> d-------- c:\program files\Common Files\Adobe
2008-12-22 03:49 . 2008-12-22 03:49 <DIR> d-------- c:\program files\NOS
2008-12-22 03:49 . 2008-12-22 03:49 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-12-22 03:27 . 2008-12-24 01:47 <DIR> d-------- C:\Temp
2008-12-22 03:26 . 2007-04-12 15:16 <DIR> d-------- c:\program files\CorelDraw X3 with SP2 Thinstalled
2008-12-22 02:14 . 2008-12-22 02:33 <DIR> d-------- c:\program files\Corel
2008-12-22 02:09 . 2008-12-22 02:09 <DIR> d-------- c:\documents and settings\jacika
2008-12-22 02:09 . 2008-04-14 05:42 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-22 01:16 . 2008-12-22 01:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-22 01:09 . 2008-12-22 01:09 <DIR> d-------- c:\documents and settings\salence\Application Data\Corel
2008-12-22 01:02 . 2008-12-22 01:02 <DIR> d-------- c:\program files\Yahoo!
2008-12-22 01:02 . 2008-12-22 01:02 <DIR> d-------- c:\program files\CCleaner
2008-12-22 00:45 . 2008-12-22 00:45 56 -r-hs---- c:\windows\system32\AB2FE7E68B.sys
2008-12-22 00:43 . 2005-03-14 14:01 208,896 --------- c:\windows\system32\SSRemove.exe
2008-12-22 00:43 . 2005-03-03 13:32 151,552 --a------ c:\windows\system32\SSCoInst.exe
2008-12-22 00:43 . 2005-03-03 19:09 57,344 --a------ c:\windows\system32\SSCoInst.dll
2008-12-22 00:43 . 2005-04-08 11:29 20,622 --a------ c:\windows\system32\SUGS2LMK.DLL
2008-12-22 00:43 . 2005-03-14 14:01 8,478 --------- c:\windows\system32\SP119.ICO
2008-12-22 00:43 . 2005-03-03 20:23 604 --a------ c:\windows\system32\SUGS2LMK.SMT
2008-12-22 00:42 . 2008-12-22 00:42 <DIR> d-------- c:\windows\Samsung
2008-12-22 00:42 . 2008-12-22 00:42 <DIR> d-------- c:\program files\CONEXANT
2008-12-22 00:42 . 2005-03-14 14:01 41,984 --------- c:\windows\system32\drivers\DGIVECP.SYS
2008-12-22 00:37 . 2008-12-22 04:18 <DIR> d-------- c:\program files\SUPERAntiSpyware
2008-12-22 00:37 . 2008-12-22 00:37 <DIR> d-------- c:\documents and settings\salence\Application Data\SUPERAntiSpyware.com
2008-12-22 00:37 . 2008-12-22 00:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2008-12-22 00:36 . 2008-12-26 04:06 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-12-22 00:33 . 2008-12-22 00:33 <DIR> d-------- c:\program files\Avira
2008-12-21 23:37 . 2008-12-21 23:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2008-12-21 23:37 . 2008-12-22 02:31 3,350 --ahs---- c:\windows\system32\KGyGaAvL.sys
2008-12-21 23:27 . 2008-12-23 16:40 <DIR> d-------- c:\program files\Common Files\InstallShield
2008-12-21 23:16 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-12-21 23:15 . 2008-12-21 23:15 <DIR> d-------- c:\program files\Microsoft Works
2008-12-21 23:14 . 2008-12-21 23:14 <DIR> d-------- c:\program files\MSBuild
2008-12-21 23:10 . 2008-12-21 23:14 <DIR> d-------- c:\windows\SHELLNEW
2008-12-21 23:09 . 2008-12-21 23:09 <DIR> dr-h----- C:\MSOCache
2008-12-21 23:09 . 2008-12-22 04:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-21 23:05 . 2003-03-29 21:45 89,184 --------- c:\windows\system32\drivers\imagedrv.sys
2008-12-21 23:05 . 2003-05-26 20:12 57,344 --------- c:\windows\system32\ImageDrive.cpl
2008-12-21 23:04 . 2008-12-21 23:04 <DIR> d-------- c:\program files\Common Files\Ahead
2008-12-21 23:04 . 2008-12-21 23:04 <DIR> d-------- c:\program files\Ahead
2008-12-21 23:04 . 2001-07-06 20:41 569,344 -ra------ c:\windows\system32\imagr5.dll
2008-12-21 23:04 . 2001-07-06 18:44 544,768 -ra------ c:\windows\system32\imagx5.dll
2008-12-21 23:04 . 2001-07-07 00:24 283,920 -ra------ c:\windows\system32\ImagXpr5.dll
2008-12-21 23:04 . 2001-07-09 17:50 155,648 -ra------ c:\windows\system32\NeroCheck.exe
2008-12-21 23:04 . 2001-06-26 14:15 38,912 -ra------ c:\windows\system32\picn20.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-21 15:50 --------- d-----w c:\documents and settings\salence\Application Data\Graphisoft
2008-12-21 15:48 --------- d-----w c:\documents and settings\All Users\Application Data\QuickTime
2008-12-21 15:42 --------- d-----w c:\program files\WIBUKEY
2008-12-21 15:42 --------- d-----w c:\program files\WIBU-SYSTEMS
2008-12-21 15:29 --------- d-----w c:\program files\Graphisoft
2008-12-21 15:28 --------- d-----w c:\program files\Java
2008-12-21 15:28 --------- d-----w c:\program files\Common Files\Java
2008-12-21 15:01 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-12-21 14:55 --------- d-----w c:\documents and settings\salence\Application Data\OtakuSoftware
2008-12-21 14:53 --------- d-----w c:\program files\Windows7
2008-12-21 14:53 --------- d-----w c:\program files\RocketDock
2008-12-21 08:42 --------- d-----w c:\program files\microsoft frontpage
2008-12-21 08:37 --------- d-----w c:\program files\Windows Media Connect 2
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 07:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 07:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 07:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 07:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 07:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 07:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 07:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 07:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-08-24 17:12 13,622 ----a-w c:\documents and settings\salence\STARTUP.reg
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-17 1266992]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"AnalogClock"="c:\program files\Windows7\Analog Clock\AnalogClock.exe" [2005-11-05 480256]
"TopDesk"="c:\program files\Windows7\TopDesk\topdesk.exe" [2007-06-20 1912832]
"TransBar"="c:\program files\Windows7\TransBar\TransBar.exe" [2005-06-01 65536]
"UberIcon"="c:\program files\Windows7\UberIcon\UberIcon Manager.exe" [2006-05-21 180224]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-28 25088]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-04-01 507904]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2008-12-21 2250256]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KRun"="c:\program files\Windows7\RunMe\RunMe.exe" [2007-04-06 518656]
"Viena Explorer"="c:\program files\Windows7\Vienna Explorer\Vienna Explorer.exe" [2006-11-18 581632]
"Visual Task Tips"="c:\program files\Windows7\VisualTaskTips\VisualTaskTips.exe" [2007-09-06 36352]
"Pie Dock"="c:\program files\Windows7\Windows 7 Pie Dock\Windows 7 Pie Dock.exe" [2007-09-02 586240]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_04\bin\jusched.exe" [2004-02-22 32881]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-12-23 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RTHDCPL"="RTHDCPL.EXE" [2006-08-16 c:\windows\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-08-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"nltide_3"="advpack.dll" [2008-10-17 c:\windows\system32\advpack.dll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=

R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024]
R3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-22 33752]

*Newly Created Service* - PROCEXP90
.
.
------- Supplementary Scan -------
.
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-12-26 05:33:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(532)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscui.dll

- - - - - - - > 'lsass.exe'(588-)
c:\windows\system32\SETUPAPI.dll
.
Completion time: 2008-12-26 5:33:55
ComboFix-quarantined-files.txt 2008-12-25 22:33:40

Pre-Run: 10,904,436,736 bytes free
Post-Run: 10,900,500,480 bytes free

231 --- E O F --- 2008-12-25 22:07:37

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Ovo izgleda OK... Tj, nema malware-a.
Mozes otvoriti temu u windows potforumu..Tamo ce se naci neko ko ce ti pomoci oko ovog problema.

offline
  • Pridružio: 10 Okt 2007
  • Poruke: 72
  • Gde živiš: Kingstown

Puno hvala!

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Uradi jos ovo kako bi deinstalirali Combofix :

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore

Ko je trenutno na forumu
 

Ukupno su 1129 korisnika na forumu :: 49 registrovanih, 3 sakrivenih i 1077 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., aleksmajstor, amaterSRB, AMCXXL, Andrija357, Bobrock1, Boris BM, Boris90, ccoogg123, cenejac111, Centauro, comi_pfc, dankisha, Denaya, djboj, dmdr, doktor1964, DragoslavS, Džordžino, FileFinder, Još malo pa deda, kobaja77, Kubovac, ladro, maiden6657, mercedesamg, Metanoja, mikki jons, milanovic, Millennium, miodrag, Miškić, moldway, nuke92, panzerwaffe, pavlo, powSrb, procesor, repac, saputnik plavetnila, ss10, stagezin, Stanlio, Tvrtko I, Vlada78, vladulns, x9, yagosh, 1107