Nemoze da se ukloni

2

Nemoze da se ukloni

offline
  • Miroslav Tanaskovic
  • Gradjevinski tehnicar
  • Pridružio: 02 Jan 2009
  • Poruke: 810
  • Gde živiš: Cacak

Nema, problem je resen. Hvala na pomoci.



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8654
  • Gde živiš: Novi Beograd

OK.

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.



offline
  • Miroslav Tanaskovic
  • Gradjevinski tehnicar
  • Pridružio: 02 Jan 2009
  • Poruke: 810
  • Gde živiš: Cacak

Kad sam pokrenuo deinstalaciju on je ponovio skeniranje iponovo izbacio izvestaj:ComboFix 10-09-14.01 - Juca 09/15/2010 7:50.26.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1250.381.1033.18.2046.1111 [GMT 2:00]
Running from: c:\documents and settings\Juca\Desktop\ComboFix.exe
Command switches used :: /Uninstal
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.

((((((((((((((((((((((((( Files Created from 2010-08-15 to 2010-09-15 )))))))))))))))))))))))))))))))
.

2010-09-08 10:59 . 2010-09-08 10:59 53248 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\Microsoft Office Enterprise 2007\30000000d900002h\DW20.EXE
2010-09-08 10:59 . 2010-09-08 10:59 53248 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\Microsoft Office Enterprise 2007\300000007100002h\ODSERV.EXE
2010-09-04 12:05 . 2010-09-04 12:05 7680 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\Blood Ties\40000047800002i\BloodTies.exe
2010-09-02 13:25 . 2010-09-02 13:25 -------- d-----w- c:\documents and settings\Juca\Application Data\Frogwares
2010-08-31 09:23 . 2010-08-31 09:23 -------- d-----w- c:\program files\Wally
2010-08-27 13:27 . 2010-08-27 13:27 -------- d-----w- c:\program files\Common Files\Java
2010-08-24 15:33 . 2010-08-24 15:33 -------- d-----w- c:\program files\QuickTime
2010-08-22 07:42 . 2010-08-22 07:42 -------- d-----w- c:\documents and settings\Juca\Application Data\BfgBar
2010-08-22 07:42 . 2010-08-22 07:42 -------- d-----w- c:\program files\BfgBar
2010-08-22 06:11 . 2010-08-22 06:11 -------- d-----w- c:\program files\bfgclient
2010-08-21 13:40 . 2010-08-22 06:10 3965944 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\Unpack\bfgsetup_s1_l1.exe
2010-08-21 13:40 . 2010-08-22 06:11 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2010-08-17 01:38 . 2010-08-17 01:38 143392 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\stub\the-heritage_s1_l1_gF5699T1L1_d1003180817.exe
2010-08-17 01:38 . 2010-08-17 01:38 143392 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\stub\the-heritage_s1_l1_gF5699T1L1_d1003180817(2).exe
2010-08-17 01:38 . 2010-08-17 01:38 3908896 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\Upgrade\clientinstaller\bfgsetup_s1_l1.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-15 05:57 . 2010-02-28 16:39 16608 ----a-w- c:\windows\gdrv.sys
2010-09-15 05:45 . 2009-02-18 18:08 -------- d-----w- c:\documents and settings\Juca\Application Data\uTorrent
2010-09-15 05:34 . 2009-12-28 07:33 0 ----a-w- c:\documents and settings\Juca\Local Settings\Application Data\prvlcl.dat
2010-09-14 21:16 . 2010-01-19 06:52 311 ----a-w- c:\windows\system32\InetLock.dat
2010-09-14 21:16 . 2008-12-17 07:03 17659 ----a-w- c:\windows\system32\drivers\inetlock.sys
2010-09-13 21:11 . 2009-02-19 11:12 -------- d-----w- c:\documents and settings\Juca\Application Data\Thinstall
2010-09-12 15:02 . 2009-06-07 14:46 -------- d-----w- c:\documents and settings\Juca\Application Data\Canon
2010-09-12 14:58 . 2009-03-06 14:01 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2010-09-12 14:56 . 2009-03-06 13:56 -------- d-----w- c:\program files\Canon
2010-09-12 05:56 . 2009-02-19 11:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-11 16:53 . 2009-10-13 10:28 -------- d-----w- c:\program files\FolderHighlight
2010-09-10 15:24 . 2010-08-11 14:02 188152 ----a-w- c:\documents and settings\Juca\Application Data\Mozilla\Firefox\Profiles\mfgjnbjj.default\FlashGot.exe
2010-09-07 05:29 . 2010-08-08 06:42 -------- d-----w- c:\program files\SensorsViewPro31
2010-09-04 09:19 . 2010-04-28 08:34 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-03 11:57 . 2009-12-07 07:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-09-02 17:00 . 2009-02-19 12:05 -------- d-----w- c:\documents and settings\Juca\Application Data\Skype
2010-09-02 10:21 . 2009-02-19 12:07 -------- d-----w- c:\documents and settings\Juca\Application Data\skypePM
2010-08-29 09:12 . 2010-05-02 13:00 -------- d-----w- c:\program files\SuperMP3Download
2010-08-28 05:38 . 2010-05-02 13:00 -------- d-----w- c:\program files\Hot_MP3
2010-08-27 13:35 . 2010-04-01 05:32 7 ----a-w- c:\windows\treeskp.sys
2010-08-27 13:35 . 2009-02-20 14:53 7 ----a-w- c:\windows\sbacknt.bin
2010-08-27 13:27 . 2009-02-19 09:12 -------- d-----w- c:\program files\Java
2010-08-24 15:33 . 2009-12-11 09:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-08-15 15:44 . 2010-03-18 18:51 -------- d-----w- c:\documents and settings\Juca\Application Data\Big Fish Games
2010-08-13 08:51 . 2010-08-13 08:51 503808 ----a-w- c:\documents and settings\Juca\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-788b706a-n\msvcp71.dll
2010-08-13 08:51 . 2010-08-13 08:51 499712 ----a-w- c:\documents and settings\Juca\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-788b706a-n\jmc.dll
2010-08-13 08:51 . 2010-08-13 08:51 348160 ----a-w- c:\documents and settings\Juca\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-788b706a-n\msvcr71.dll
2010-08-13 08:51 . 2010-08-13 08:51 61440 ----a-w- c:\documents and settings\Juca\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-38296207-n\decora-sse.dll
2010-08-13 08:51 . 2010-08-13 08:51 12800 ----a-w- c:\documents and settings\Juca\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-38296207-n\decora-d3d.dll
2010-08-10 16:05 . 2010-08-08 11:03 -------- d-----w- c:\documents and settings\Juca\Application Data\Toolbar4
2010-08-10 12:40 . 2009-02-18 16:07 56432 ----a-w- c:\documents and settings\Juca\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-09 15:31 . 2010-06-25 22:30 -------- d-----w- c:\program files\EvilLyrics
2010-08-08 21:39 . 2010-08-08 17:02 -------- d-----w- c:\program files\iColorFolder
2010-08-08 15:12 . 2010-04-06 15:45 -------- d-----w- c:\documents and settings\Juca\Application Data\gigasizetb
2010-08-08 11:03 . 2010-08-08 11:03 -------- d-----w- c:\program files\HyCam2
2010-08-08 05:14 . 2010-08-04 16:52 -------- d-----w- c:\program files\Simple Port Forwarding
2010-08-08 05:13 . 2010-02-18 14:06 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-08-06 14:34 . 2009-05-11 04:54 -------- d-----w- c:\program files\Unlocker
2010-08-06 14:26 . 2010-08-06 14:26 -------- d-----w- c:\documents and settings\Juca\Application Data\GRETECH
2010-08-06 14:24 . 2009-02-21 12:38 -------- d-----w- c:\program files\GRETECH
2010-08-06 13:50 . 2010-08-06 13:49 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-08-05 10:34 . 2010-08-05 10:34 -------- d-----w- c:\program files\Time Stopper
2010-08-05 10:04 . 2009-02-18 19:32 -------- d-----w- c:\program files\Common Files\Adobe
2010-08-04 13:27 . 2010-08-04 13:26 5125664 ----a-w- c:\documents and settings\Juca\Application Data\Uniblue\RegistryBooster\_temp\ub.exe
2010-08-02 04:56 . 2009-02-19 12:26 -------- d-----w- c:\program files\SpywareBlaster
2010-07-30 14:53 . 2010-07-30 14:53 -------- d-----w- c:\documents and settings\Juca\Application Data\Canon Drivers Update Utility
2010-07-29 05:49 . 2010-01-25 10:57 -------- d-----w- c:\program files\MKVtoolnix
2010-07-29 05:49 . 2010-01-09 06:38 -------- d-----w- c:\program files\Memorija v1.4
2010-07-29 05:49 . 2009-08-19 10:11 -------- d-----w- c:\program files\mobile PhoneTools
2010-07-29 05:49 . 2009-09-14 08:53 -------- d-----w- c:\program files\kikin
2010-07-29 05:49 . 2009-08-19 10:12 -------- d-----w- c:\program files\LiveUpdate
2010-07-29 05:49 . 2010-06-06 05:02 -------- d-----w- c:\program files\HandBrake
2010-07-29 05:49 . 2009-10-26 13:50 -------- d-----w- c:\program files\360desktop
2010-07-29 05:49 . 2009-02-18 20:15 -------- d-----w- c:\program files\BSPlayer
2010-07-28 15:01 . 2010-07-28 15:01 7680 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\Smart Data Recovery v4.3\4000008000002i\Splash Screen.exe
2010-07-26 12:19 . 2010-07-20 13:22 -------- d-----w- c:\documents and settings\Juca\Application Data\dvdcss
2010-07-23 05:28 . 2010-03-06 13:57 -------- d-----w- c:\documents and settings\Juca\Application Data\Uniblue
2010-07-23 05:28 . 2010-07-23 05:28 -------- d-----w- c:\program files\Uniblue
2010-07-20 10:37 . 2010-07-20 10:37 -------- d-----w- c:\documents and settings\Juca\Application Data\Marine Aquarium 3
2010-07-17 17:21 . 2010-07-17 17:21 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-07-17 17:21 . 2010-07-17 17:21 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-07-17 17:21 . 2010-07-17 17:21 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-07-17 17:21 . 2010-03-18 07:55 45056 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-07-17 17:21 . 2010-07-17 17:21 40960 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-07-17 17:21 . 2010-07-17 17:21 14848 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-07-17 17:21 . 2010-03-18 07:55 49152 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-07-17 17:21 . 2010-03-18 07:55 308808 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-07-17 17:21 . 2010-07-17 17:21 341600 ----a-w- c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-07-17 17:20 . 2009-02-19 09:04 -------- d-----w- c:\program files\Real
2010-07-17 17:20 . 2009-02-18 18:28 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-07-17 17:20 . 2009-02-18 18:28 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-07-17 17:19 . 2009-03-16 13:32 -------- d-----w- c:\program files\Google
2010-07-17 03:00 . 2010-05-11 10:10 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-14 08:00 . 2010-08-06 13:49 108032 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-29 09:45 . 2010-06-29 09:45 39936 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\ImageConverter Plus 7.1\40000018000002i\icp.exe
2010-06-28 13:28 . 2010-06-28 13:28 7168 ----a-w- c:\documents and settings\Juca\Application Data\Thinstall\Natura Sound Therapy\10000001500003i\NAT.exe
2010-06-22 06:42 . 2010-02-18 14:06 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-22 06:42 . 2010-06-22 06:42 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-22 06:41 . 2010-03-14 11:55 25168 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-06-22 06:41 . 2010-02-18 14:06 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-23 10:28 . 2010-06-23 10:28 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot_2010-09-14_08.18.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-15 05:25 . 2010-09-15 05:25 16384 c:\windows\temp\Perflib_Perfdata_a88.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot1.dll" [2010-06-07 2515552]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-24 19:25 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]
2010-06-07 04:29 2515552 ----a-w- c:\program files\Hot_MP3\tbHot1.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 08:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E601996F-E400-41CA-804B-CD6373A7EEE2}]
2010-02-10 01:34 750256 ----a-w- c:\program files\kikin\ie_kikin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{9384bd4c-dd14-4be9-80f7-f6277511e4f5}"= "c:\program files\Hot_MP3\tbHot1.dll" [2010-06-07 2515552]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-24 333192]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
"{9384BD4C-DD14-4BE9-80F7-F6277511E4F5}"= "c:\program files\Hot_MP3\tbHot1.dll" [2010-06-07 2515552]

[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CLASSES_ROOT\clsid\{9384bd4c-dd14-4be9-80f7-f6277511e4f5}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TBPanel"="c:\program files\XpertVision\TBPanel.exe" [2008-07-03 2161160]
"VisualTaskTips"="c:\program files\VisualTaskTips\VisualTaskTips.exe" [2008-06-22 65536]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [BU]
"µTorrent"="c:\documents and settings\Juca\Desktop\utorrent.exe" [2010-02-01 177152]
"Wally"="c:\program files\Wally\Wally.exe" [2010-01-02 10278581]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2008-05-16 1630208]
"PCTVRemote"="c:\program files\Pinnacle\PCTV Stereo\Remote\Remoterm.exe" [2002-10-11 61699]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 16857600]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-22 2065760]
"GEST"="c:\program files\GIGABYTE\GEST\run.exe" [2009-03-12 236040]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-07-17 202256]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-23 30192]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\Juca\Start Menu\Programs\Startup\
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2008-3-19 4742184]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-2-19 450560]
Software Director Scheduler.lnk - c:\program files\Common Files\Cloanto\Software Director\softdir.exe [2010-2-13 288328]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-06-22 06:42 12536 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2004-08-04 01:07 628224 ----a-w- c:\windows\system32\catsrvut.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Juca^Start Menu^Programs^Startup^FrostWire On Startup.lnk]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Klipfolio"="c:\program files\KlipFolio\Klipfolio.exe" /BOOT

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"d:\\Skidanje sa RapidShare\\CryptLoad 1.0.6\\CryptLoad.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\JDownloader.exe"=
"c:\\WINDOWS\\system32\\java.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Juca\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Juca\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\360desktop\\360desktop.exe"=
"c:\\Program Files\\360desktop\\360manager.exe"=
"d:\\Portabl programi\\uTorrent_1.8.5.17091_Final_Portable\\App\\utorrent\\utorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"d:\\Nova mapa\\utorrent.exe"=
"c:\\Documents and Settings\\Juca\\Desktop\\utorrent.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54945:TCP"= 54945:TCP:tcp54945
"54945:UDP"= 54945:UDP:udp54945
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [3/14/2010 1:55 PM 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2/18/2010 4:06 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/18/2010 4:06 PM 216400]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/18/2010 4:06 PM 243024]
R2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [2/25/2009 11:31 AM 234888]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [6/22/2010 8:42 AM 308136]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [6/22/2010 8:41 AM 2331032]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [6/22/2010 8:41 AM 5897808]
R2 HdThemeEnabler;Hyperdesk Theme Enabler;c:\program files\The Skins Factory\Hyperdesk\Common\HdThemeEnabler.exe [7/21/2008 12:50 PM 106496]
R2 INETLOCK;INETLOCK;c:\windows\system32\drivers\inetlock.sys [12/17/2008 9:03 AM 17659]
R2 INETLOCKSVC;Internet Lock Service;c:\program files\Internet Lock\ILSvc.exe [12/17/2008 10:14 AM 139264]
R2 sensorsview;sensorsview;c:\windows\system32\drivers\sensorsview.sys [8/17/2007 6:00 PM 4224]
R3 3xHybrid;Pinnacle PCTV Stereo service;c:\windows\system32\drivers\3xhybrid.sys [2/18/2009 9:28 PM 698368]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/14/2010 1:53 PM 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [3/14/2010 1:53 PM 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [3/14/2010 1:53 PM 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [3/14/2010 1:53 PM 26192]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\gsvr.exe [2/18/2009 7:43 PM 55816]
R3 NTProcDrv;Process creation detector for NT.;\??\c:\windows\TEMP\drv1.tmp --> c:\windows\TEMP\drv1.tmp [?]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [2/18/2009 9:28 PM 6400]
S0 Lbd;Lbd; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/17/2010 7:19 PM 136176]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/14/2010 1:53 PM 30104]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;d:\portabl programi\Everest\kerneld.wnt [8/2/2010 7:34 PM 7168]
S3 F-Secure Standalone Minifilter;F-Secure Standalone Minifilter; [x]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/23/2010 12:27 PM 30192]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/29/2009 10:12 AM 721904]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-08-20 11:24 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder

2010-09-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2010-09-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-17 17:18]

2010-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-17 17:18]

2010-09-15 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1659004503-2077806209-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-09-15 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1659004503-2077806209-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-06-03 01:02]

2010-09-15 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-04 07:50]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]{764716AD-6EF3-4A7C-A91B-F047E3057AAC}
mStart Page = [Link mogu videti samo ulogovani korisnici]{764716AD-6EF3-4A7C-A91B-F047E3057AAC}
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: &Download all 4shared files
IE: &Download using 4shared Desktop
IE: &Webshots Photo Search - c:\program files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Vorlesen mit MWS Reader 4
IE: {{0F7195C2-6713-4d93-A1BC-DA5FA33F0A65} - {E601996F-E400-41CA-804B-CD6373A7EEE2} - c:\program files\kikin\ie_kikin.dll
TCP: {C5A62D61-DD73-4038-8C7F-E808128A0E20} = 192.168.1.1,192.168.1.2
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - ProfilePath - c:\documents and settings\Juca\Application Data\Mozilla\Firefox\Profiles\mfgjnbjj.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\Juca\Application Data\Mozilla\Firefox\Profiles\mfgjnbjj.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\components\dtTransparency.dll
FF - component: c:\documents and settings\Juca\Application Data\Mozilla\Firefox\Profiles\mfgjnbjj.default\extensions\firefox@kidzui.com\platform\WINNT_x86-msvc\components\WinKiosk.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\Juca\Application Data\Mozilla\plugins\np-mswmp.dll
FF - plugin: c:\documents and settings\Juca\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Juca\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\Juca\Local Settings\Application Data\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Virtools\3D Life Player\npvirtools.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2010-09-15 07:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\d:\portabl programi\Everest\kerneld.wnt"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NTProcDrv]
"ImagePath"="\??\c:\windows\TEMP\drv1.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\WININET.dll
c:\program files\VisualTaskTips\VttHooks.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-09-15 07:59:46
ComboFix-quarantined-files.txt 2010-09-15 05:59
ComboFix2.txt 2010-09-14 10:15
ComboFix3.txt 2010-09-14 08:21
ComboFix4.txt 2010-08-06 08:43
ComboFix5.txt 2010-09-15 05:47

Pre-Run: 89,135,489,024 bytes free
Post-Run: 89,132,687,360 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=3 Sets=1,2,3,4
- - End Of File - - AA7634834C06880580ED3AAA451FF86C
Jeli to u redu ili treba nesto drugo uraditi.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8654
  • Gde živiš: Novi Beograd

Nisi dobro kucao, kucao si /Uninstal, a treba /Uninstall

offline
  • Miroslav Tanaskovic
  • Gradjevinski tehnicar
  • Pridružio: 02 Jan 2009
  • Poruke: 810
  • Gde živiš: Cacak

Sada je sve u redu , nisam primetuio da je ispusteno l jos jednom hvala.

Ko je trenutno na forumu
 

Ukupno su 1838 korisnika na forumu :: 47 registrovanih, 7 sakrivenih i 1784 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4. Ozrenska, 6.5lapua, Blizzard035, bojanM84, Borski1977, brundo65, bunker, carinko, comi_pfc, Djokislav, draggan, dragoljub11987, duro1990duro, Dzigy, HrcAk47, JK, JOntra, Još malo pa deda, komenski, kybonacci, LUDI, mikhailo, nixos, opt1, Panter, pobeda, Profesor_018, Ravac, repac, S94, sajorg, sekretar, shadower78, Sharpshooter, shone34, Sinisa76, sreckop, srđan, synergia, Tastatura ratnik, theNedjeljko, Timočka Divizija, trpche, voja64, vranjanac29, Yekaterinburg, zlaya011