Otvara se stranica

1

Otvara se stranica

offline
  • Pridružio: 06 Dec 2006
  • Poruke: 21

Mojoj sestri se otvara prozor sa za-odrasle-o sadrzajem, dopisuje se sa mnom i samo joj iskoci za-odrasle-o sajt, zivi vani i ima slabo znanje o kompjuterima. objasnio sam joj kako da uradi log i molim vas da mi pomognete da joj to sredimo. Nemojte se ljutiti ako bude islo malo sporije, ja cu joj morati prvo dobro objasniti sta da radi da nesto ne zezne. ima adsl vezu

Logfile of HijackThis v1.99.1
Scan saved at 23.08.18, on 17/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Documents and Settings\Amministratore\Dati applicazioni\SysServDLL32.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
C:\Programmi\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
C:\Programmi\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Programmi\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\Programmi\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\Amministratore\Dati applicazioni\DLLrecover32.exe
C:\Programmi\MSN Messenger\livecall.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Amministratore\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmi\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmi\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [E06IXLRD_3065671] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Programmi\Webshots\Launcher.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Controllo dello stato.lnk = C:\Programmi\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: MS_update_0610_KB72306.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?4a7d394fa0a4623a5591b537c18ed90
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?4a7d394fa0a4623a5591b537c18ed90
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra button: ScaricaMP3 - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Amministratore\Dati applicazioni\ScaricaMP3[1].exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O12 - Plugin for .mov: C:\Programmi\Internet Explorer\PLUGINS\npqtplugin.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A6E2975-CB4E-4CC2-96B9-347FD1984A7C}: NameServer = 85.37.17.39 85.38.28.71
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: LoadDLLServ - Unknown owner - C:\Documents and Settings\Amministratore\Dati applicazioni\SysServDLL32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Dopuna: 18 Dec 2006 16:47

AVG AV je napisao ovo ....

CNTE-oiduuys(1).gif Trojan horse Downloader.Small.57.A

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

Izvini sto si cekao ali imamo par sumnjivih fajlova koje bi bilo dobro da nam uploadujes ako si u mogucnosti.

1. C:\Documents and Settings\Amministratore\Dati applicazioni\SysServDLL32.exe - proveri da li ovaj fajl postoji i ako postoji uploaduj i njega

2. C:\Documents and Settings\Amministratore\Dati applicazioni\ScaricaMP3[1].exe - proveri da li ovaj fajl postoji i ako postoji uploaduj i njega

posle toga reci sestri da downloaduje Ewido sa ove adrese i da preskenira racunar.

postavi novi log posle toga samo preimenuj HijackThis u npr HJ4





--------DOPUNA--------

Ispustio sam sledeci fajl: C:\Documents and Settings\Amministratore\Dati applicazioni\DLLrecover32.exe - proveri da li ovaj fajl postoji i ako postoji uploaduj i njega

offline
  • Pridružio: 06 Dec 2006
  • Poruke: 21

SysServDLL32.exe sam upload, a od drugog ima samo ScaricaMP3.ico , ne postoji exe fajl

Dopuna: 19 Dec 2006 16:50

Uh, tek sam vidio ovaj treci....moram cekati da zavrsi scan u safe modu i da mi se javi.

Dopuna: 19 Dec 2006 19:25

AVG

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 19.15.10 19/12/2006

+ Scan result:



C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\6T35AEE2\index[5].htm -> Downloader.Psyme.cg : No action taken.
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\6T35AEE2\index[6].htm -> Downloader.Psyme.cg : No action taken.
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\DAYLHGXU\index[11].htm -> Downloader.Psyme.cg : No action taken.
:mozilla.255:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.349:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.444:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.530:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.531:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.532:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.533:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.534:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.538:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.539:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.540:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.541:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.542:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.543:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.544:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.545:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.546:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.547:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.549:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@amazonbebe.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@msninvite.112.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.526:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.71i : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@adserver.71i[1].txt -> TrackingCookie.71i : No action taken.
:mozilla.229:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.230:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.231:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.509:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.512:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.480:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
:mozilla.486:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.491:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.494:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.14:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.496:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@bfast[2].txt -> TrackingCookie.Bfast : No action taken.
:mozilla.400:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@ads20.bpath[2].txt -> TrackingCookie.Bpath : No action taken.
:mozilla.514:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@com[1].txt -> TrackingCookie.Com : No action taken.
:mozilla.79:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.302:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@e-2dj6wjlyelcpmdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.259:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@estat[1].txt -> TrackingCookie.Estat : No action taken.
:mozilla.175:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Etracker : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@www.etracker[1].txt -> TrackingCookie.Etracker : No action taken.
:mozilla.515:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.516:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.517:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.518:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.519:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@as1.falkag[1].txt -> TrackingCookie.Falkag : No action taken.
:mozilla.411:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.412:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@media.fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.443:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.466:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.467:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.468:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.470:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.471:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.247:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.248:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.249:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.270:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.271:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.361:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.362:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.363:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.364:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.365:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.366:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@ehg-pharmacia.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@ehg-salomon.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.472:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@counter.hitslink[1].txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.253:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Ivwbox : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@ivwbox[2].txt -> TrackingCookie.Ivwbox : No action taken.
:mozilla.296:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.487:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.490:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@sales.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.67:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.113:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.116:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.117:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.118:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@overture[1].txt -> TrackingCookie.Overture : No action taken.
:mozilla.119:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.120:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.121:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.107:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.108:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.109:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.92:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.93:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.94:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.95:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.96:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.336:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.337:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.338:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.339:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.340:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.442:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@counter13.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@counter15.sextracker[1].txt -> TrackingCookie.Sextracker : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@sextracker[2].txt -> TrackingCookie.Sextracker : No action taken.
:mozilla.523:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.525:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.137:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.145:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.192:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.195:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@trafic[1].txt -> TrackingCookie.Trafic : No action taken.
:mozilla.88:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.445:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.450:C:\Documents and Settings\Amministratore\Dati applicazioni\Mozilla\Firefox\Profiles\njfdzs2u.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Amministratore\Cookies\amministratore@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\PCFAAYNR\MoviePlayer[1].exe -> Trojan.Agent : No action taken.
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\QXX2WOHG\download_video[1].exe -> Trojan.Agent : No action taken.


::Report end

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

trenutno nisam u mogucnosti da pregledam ovo ali do sutra cu ti napisati sta dalje.

offline
  • Pridružio: 06 Dec 2006
  • Poruke: 21

HJT

Logfile of HijackThis v1.99.1
Scan saved at 19.58.47, on 19/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Documents and Settings\Amministratore\Dati applicazioni\SysServDLL32.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
C:\Programmi\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Programmi\HP\HP Software Update\HPWuSchd2.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Programmi\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Programmi\Skype\Phone\Skype.exe
C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Programmi\HP\Digital Imaging\bin\hpqgalry.exe
C:\Programmi\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Amministratore\Dati applicazioni\DLLrecover32.exe
C:\Programmi\MSN Messenger\livecall.exe
C:\Documents and Settings\Amministratore\Documenti\My Skype Received Files\H3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Encarta Web Companion Oggetto helper - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programmi\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Encarta Web Companion - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Programmi\File comuni\Microsoft Shared\Encarta Web Companion\ENCWCBAR.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programmi\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programmi\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Programmi\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Programmi\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Programmi\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [CnxTrApp] rundll32.exe "C:\Programmi\Aethra\ADSL EB1070 USB\CnxTrApp.dll",AppEntry -REG "Aethra\ADSL EB1070 USB"
O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HP Software Update] "C:\Programmi\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Programmi\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Programmi\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [E06IXLRD_3065671] "C:\Programmi\Microsoft Encarta\Microsoft Encarta Enciclopedia DVD - 2006\EDICT.EXE" -m
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Webshots.lnk = C:\Programmi\Webshots\Launcher.exe
O4 - Global Startup: Avvio rapido di HP Image Zone.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Controllo dello stato.lnk = C:\Programmi\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmi\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Programmi\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Apri in nuova scheda in primo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/230?4a7d394fa0a4623a5591b537c18ed90
O8 - Extra context menu item: Apri in nuova scheda in secondo piano - res://C:\Programmi\Windows Live Toolbar\Components\it-it\msntabres.dll.mui/229?4a7d394fa0a4623a5591b537c18ed90
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm (file missing)
O9 - Extra button: ScaricaMP3 - {EF6D6AE3-2625-40D6-A5AB-920DFD2DAF8C} - C:\Documents and Settings\Amministratore\Dati applicazioni\ScaricaMP3[1].exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O12 - Plugin for .mov: C:\Programmi\Internet Explorer\PLUGINS\npqtplugin.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{9A6E2975-CB4E-4CC2-96B9-347FD1984A7C}: NameServer = 85.37.17.39 85.38.28.71
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Programmi\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: LoadDLLServ - Unknown owner - C:\Documents and Settings\Amministratore\Dati applicazioni\SysServDLL32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programmi\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Dopuna: 19 Dec 2006 19:51

Uradio sam upload treceg fajla,
nije problem, kada bude vremena
Hvala

offline
  • Pridružio: 06 Apr 2005
  • Poruke: 1023

mkdir c:\upload
move "C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\6T35AEE2\index[5].htm" c:\upload
move "C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\6T35AEE2\index[6].htm" c:\upload
move "C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\DAYLHGXU\index[11].htm" c:\upload
move "C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\PCFAAYNR\MoviePlayer[1].exe" c:\upload
move "C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\QXX2WOHG\download_video[1].exe" c:\upload



iskopiraj ovaj kod iznad u Notepad i fajl snimi kao upload.bat. Taj fajl posalji svojoj sestri. Ona neka ga pokrene. Pokretanje fajla ce napraviti folder c:\upload, i u njega ce premesti sve one zarazene fajlove koji nas interesuju iz Ewido loga.

Taj folder spakuj u zip i uploaduj ga. Kad ti potvrdim da smo dobili fajlove folder upload mozes izbrisati i time smo se resilih tih fajlova.

sledeca 2 fajla ces morati sam da nadjes.
prvi bi trebalo da se nalazi u C:\Documents and Settings\Amministratore\Dati applicazioni\ odavde nam treba ScaricaMP3.ico posto mislimo da je to exe fajl sa laznom extenzijom.

drugi fajl bi trebalo da se nalazi u C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ na italianskom bi to mozda moglo biti C:\Documents and Settings\All \ menu di inizio \ programmi \ partenza \ ili nesto slicno posto italianski stvarno neznam, koristio sam recnik. Odavde nam treba MS_update_0610_KB72306.exe

offline
  • Pridružio: 06 Dec 2006
  • Poruke: 21

Poslao sam fajlove,
trazimo fajl MS_update_0610_KB72306.exe i nikako da ga pronadjemo.

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

@Penzioner
u onome sto si poslao nema onih fajlova koje je gornji skript trebao da pokupi. U Ewido logu se takodje ne vidi da ih je on uklonio.
Jeste li cistili naknadno jos jednom Ewidom, pa ih pobrisali pre nego sto ste startovali onaj batch skript gore?

offline
  • Pridružio: 06 Dec 2006
  • Poruke: 21

Ewido log je prije radjen, sada to nismom radili, napravljen je c:\upload bez problema i ubacila je u njega sysserv i scarica i dllrecover, uradila rar i poslala meni i ja sam ga upload, vise nista nismo radili, cekali smo javljanje.
Provjerili smo sada i nasla je sysservdll32.ini i sysservdll32.log,
exe fajla nema. Kliknula je na c:\uload i nasla ove exe fajlove.
sada ce ponoviti slanje fajlova

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

A onih HTML i EXE fajlova iz cachea Internet Explorera nema u folderu Upload?

Ko je trenutno na forumu
 

Ukupno su 1098 korisnika na forumu :: 45 registrovanih, 11 sakrivenih i 1042 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., amaterSRB, Apok, babaroga, Bokiboks, bokisha253, botta, darkangel, dekan.m, drimer, FOX, Georgius, Insan, Karla, Klecaviks, Kubovac, kubura91, kunktator, ljuba, marsovac 2, Mercury, Mi lao shu, milenko crazy north, minmatar34957, mrav pesadinac, ObelixSRB, Oscar, panonski mornar, Parker, pein, prle122, procesor, raptorsi, RJ, shone34, Sirius, slonic_tonic, Smajser, Srki94, stalja, Sumadija34, Tvrtko I, vathra, Zoca, 79693