Problem oko PC i Graficke ...

1

Problem oko PC i Graficke ...

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 20 Apr 2012 18:03

Od kad sam skinuo neki (zabranjeno) program nzn tacno uvezi cega sam skinuo bzv nesto
(ja kreten sve me zanima )

tad je krenulo sve nizbrdo ,,,

Obrisao sve BackUP failove ubacio mi tonu virusa ( ali mislim da sam sve viruse obrisao ali da su ostale posledice jos od toga )

i od tad pocinje pc da mi mnogo laguje , primecujem veliku razliku ali nzn kokretno sta je u pitanju ,,,,
Ako bi bio neko ljubazan da mi da neki savet sta da proverim ....

Graficka mi nekako losije radi ... ( jer igram WOW i LOL i po tome primecujem da je 80% slabije nego pre )

i pc nekako mnogo spor ...

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.3244 BrowserJavaVersion: 1.6.0_31
Run by Marko at 17:59:20 on 2012-04-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.363 [GMT 2:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\program files\common files\spigot\search settings\searchsettings.exe
svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.speedbit.com/?aff=svd_0
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
uURLSearchHooks: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
BHO: SWEETIE: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - SWEETIE Class
BHO: Winamp Toolbar BHO: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\5.4\youtubedownloaderToolbarIE.dll
TB: IObit Toolbar: {0bda0769-fd72-49f4-9266-e1fb004f4d8f} - c:\program files\iobit toolbar\ie\5.4\iobitToolbarIE.dll
TB: {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Google Update] "c:\documents and settings\marko\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [<NO NAME>]
mRun: [SearchSettings] c:\program files\common files\spigot\search settings\searchsettings.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{6B9952E5-896F-4F20-9427-C0111EBFFD15} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: TPSvc - TPSvc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\marko\application data\mozilla\firefox\profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\marko\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-30 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-30 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2012-2-29 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-3-29 490840]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-4-12 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-30 20696]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-30 44768]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2012-2-29 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2008-5-19 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\symantec\norton ghost 2003\ghpciscan.sys --> c:\program files\symantec\norton ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-11-28 2253120]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\genericmount.sys --> c:\windows\system32\drivers\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-20 15:34:58 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36:57 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01:45 -------- d-----w- c:\documents and settings\marko\local settings\application data\ApplicationHistory
2012-04-13 23:14:53 -------- d-----w- c:\program files\IObit Toolbar
2012-04-13 23:11:20 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2012-04-10 08:12:29 -------- d-----w- C:\Download
2012-04-07 08:24:05 -------- d-----w- c:\documents and settings\marko\local settings\application data\Adobe
2012-04-04 14:37:26 -------- d-----w- c:\documents and settings\marko\application data\uTorrent
2012-04-04 08:25:36 -------- d-----w- c:\windows\NV39962096.TMP
2012-04-04 08:25:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2012-04-04 08:12:18 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09:47 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09:10 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:36:36 602432 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2012-04-03 21:21:11 -------- d-----w- c:\windows\nview
2012-04-02 20:26:48 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01:47 -------- d-----w- c:\program files\common files\SpeedBit
2012-04-02 09:01:45 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01:45 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01:36 -------- d-----w- c:\documents and settings\marko\application data\Toolbar4
2012-04-02 09:01:33 -------- d-----w- c:\documents and settings\all users\application data\SpeedBit
2012-04-02 09:01:32 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32:24 -------- d-----w- c:\documents and settings\all users\application data\YTD YouTube Downloader & Converter
2012-03-31 17:17:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06:42 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:05:43 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-03-28 16:53:23 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53:23 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12:36 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:09:27 -------- d-----w- c:\windows\setup.pss
2012-03-27 12:01:58 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28:38 -------- d-----w- c:\documents and settings\all users\application data\DivX
2012-03-25 20:48:25 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2012-04-14 20:20:37 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-03 21:36:24 285788 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-04-03 21:36:24 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-04-03 21:36:18 285788 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-03-31 17:16:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59:04 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15:19 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:03:51 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
.
============= FINISH: 18:02:01.53 ===============

Dopuna: 20 Apr 2012 18:42

I ako neko moze da mi kaze sta da mi bude ukljuceno u StartUP

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6102

@MareBatice

Pozdrav i dobrodosao na forum. Wink

Nisi ispratio Korak#3 iz uputstva.

Pokreni Gmer po uputstvu ( ili RootRepeal ukoliko imas problema sa pokretanjem Gmer-a) i postavi nam dobijene izvestaje.

Takodje, koristis dva aktivna AntiVirus programa:
-Lavasoft Ad-Watch Live! Anti-Virus
-avast! Antivirus

Opredeli se za jedan AV a drugi deinstlairaj.

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 20 Apr 2012 22:13

evo sad zavrsavam .... GMER

kad sam skinuo taj program ubacio mi neke viruse kad unistaliram neki program ostajali su mi PRAZNI

failovi koje nisam mogo da obrisem i jos su mi u folderu .....

a taj anti virus mi nije u progress samo mi u folderu stoji i nemogu da ga obrisem zbog tih nekih praznih failova ....

Dopuna: 20 Apr 2012 22:19



zbog toga ne mogu da obrisem ... wtf

Dopuna: 20 Apr 2012 22:32

mycity.rs/must-login.png



mycity.rs/must-login.png



mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6102

Mare, ja tebe gore slabo sta da sam razumeo. Moraces biti jasniji i moraces pratiti moja uputstva.


Arrow Deinstaliraj Spigot.

Arrow Mozes imati samo jedan aktivan Antivirus. Drugi deinstaliraj.

Arrow Takodje ti preporucujem da deinstaliras i sve te Toolbarove koje imas jer ti ne koriste mnogo cemu a znaju da uspore sistem.


Arrow Kada sve to odradis, ponovo pokreni DDS i kopiraj/okaci mi oba loga koja dobijes:

1. DDS.txt
2. Attach.txt

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.3244 BrowserJavaVersion: 1.6.0_31
Run by Marko at 23:47:45 on 2012-04-20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.625 [GMT 2:00]
.
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webteh\BSplayer\bsplayer.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASC.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\WINDOWS\system32\msiexec.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.speedbit.com/?aff=svd_0
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SWEETIE: {1a0aadcd-3a72-4b5f-900f-e3bb5a838e2a} - SWEETIE Class
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: SweetIM For Internet Explorer: {bc4ffe41-de9f-46fa-b455-aad49b9f9938} -
TB: {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - No File
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [Google Update] "c:\documents and settings\marko\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [<NO NAME>]
mRun: [SearchSettings] c:\program files\common files\spigot\search settings\searchsettings.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /installquiet
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
TCP: Interfaces\{6B9952E5-896F-4F20-9427-C0111EBFFD15} : DhcpNameServer = 89.216.1.30 89.216.1.50
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: TPSvc - TPSvc.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\marko\application data\mozilla\firefox\profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\marko\local settings\application data\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_233.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-11-30 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-11-30 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2012-2-29 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-3-29 490840]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-4-12 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-11-30 20696]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-11-30 44768]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-4-20 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2012-2-29 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [2008-5-19 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\symantec\norton ghost 2003\ghpciscan.sys --> c:\program files\symantec\norton ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-2 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\genericmount.sys --> c:\windows\system32\drivers\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-04-20 21:42:42 -------- d-----w- c:\documents and settings\marko\application data\IObit
2012-04-20 16:51:18 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51:18 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51:18 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51:18 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51:04 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46:01 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45:44 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08:34 -------- d-----w- c:\documents and settings\all users\application data\MCShield
2012-04-20 16:08:33 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34:58 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36:57 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01:45 -------- d-----w- c:\documents and settings\marko\local settings\application data\ApplicationHistory
2012-04-10 08:12:29 -------- d-----w- C:\Download
2012-04-07 08:24:05 -------- d-----w- c:\documents and settings\marko\local settings\application data\Adobe
2012-04-04 14:37:26 -------- d-----w- c:\documents and settings\marko\application data\uTorrent
2012-04-04 08:25:00 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\09\01\intel32\DotNetInstaller.exe
2012-04-04 08:12:18 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09:47 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09:10 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:21:11 -------- d-----w- c:\windows\nview
2012-04-02 20:26:48 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01:47 -------- d-----w- c:\program files\common files\SpeedBit
2012-04-02 09:01:45 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01:45 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01:36 -------- d-----w- c:\documents and settings\marko\application data\Toolbar4
2012-04-02 09:01:33 -------- d-----w- c:\documents and settings\all users\application data\SpeedBit
2012-04-02 09:01:32 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32:24 -------- d-----w- c:\documents and settings\all users\application data\YTD YouTube Downloader & Converter
2012-03-31 17:17:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06:42 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:05:43 -------- d-----w- c:\program files\common files\Wise Installation Wizard
2012-03-28 16:53:23 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53:23 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53:08 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53:08 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12:36 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:09:27 -------- d-----w- c:\windows\setup.pss
2012-03-27 12:01:58 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28:38 -------- d-----w- c:\documents and settings\all users\application data\DivX
2012-03-25 20:48:25 -------- d-----w- c:\program files\CCleaner
.
==================== Find3M ====================
.
2012-04-20 16:59:09 294604 ----a-w- c:\windows\system32\nvdrsdb1.bin
2012-04-20 16:59:09 294604 ----a-w- c:\windows\system32\nvdrsdb0.bin
2012-04-20 16:59:09 1 ----a-w- c:\windows\system32\nvdrssel.bin
2012-04-14 20:20:37 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59:04 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15:19 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:03:51 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-02-29 23:58:00 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58:00 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58:00 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58:00 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58:00 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58:00 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58:00 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58:00 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-02-29 23:58:00 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
.
============= FINISH: 23:50:25.17 ===============




mycity.rs/must-login.png




mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6102

Odradi sledece:

Arrow Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Napisano: 21 Apr 2012 0:50

ComboFix 12-04-20.03 - Marko 04/21/2012 0:29.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.656 [GMT 2:00]
Running from: c:\documents and settings\Marko\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Marko\Application Data\Toolbar4
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\about SpeedBit Video Downloader.html
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\amazon_logo.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Ask-logo-16.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\basis.xml
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\cog.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Ebay-logo-16.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\empty.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\info.txt
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\localcopy.xml
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Mercado_Livre.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Mercado_Livre0.1.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\speedbit_icon0.2.bmp
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\speedbit_icon0.2.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\SpeedBitToolbar_icons.bmp
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\TbHelper2.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\Translate_webpage.png
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\uninstall.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\update.exe
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\version.txt
c:\documents and settings\Marko\Application Data\Toolbar4\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}\video.png
c:\documents and settings\Marko\Application Data\vso_ts_preview.xml
c:\documents and settings\Marko\Templates\Temp.exe
c:\program files\MSNCS
c:\program files\MSNCS\data\emxfile001.dat
c:\program files\MSNCS\data\msnusr.ini
c:\program files\MSNCS\data\ps_demo_report.html
c:\program files\MSNCS\data\testftpok.html
c:\program files\MSNCS\help.chm
c:\program files\MSNCS\License.txt
c:\program files\MSNCS\logs\Log5192008124518.html
c:\program files\MSNCS\logs\Log5192008125053.html
c:\program files\MSNCS\logs\Log5192008125825.html
c:\program files\MSNCS\readme.txt
c:\program files\MSNCS\unins000.dat
c:\program files\MSNCS\unins000.exe
c:\windows\$NtUninstallKB14960$
c:\windows\$NtUninstallKB14960$\2136390361\@
c:\windows\$NtUninstallKB14960$\2136390361\L\tzweokge
c:\windows\$NtUninstallKB14960$\2136390361\loader.tlb
c:\windows\$NtUninstallKB14960$\2136390361\U\@00000001
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cf
c:\windows\$NtUninstallKB14960$\2136390361\U\@80000000
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cf
c:\windows\$NtUninstallKB14960$\3395889811
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\
c:\windows\system32\closeapp.exe
c:\windows\system32\mxpvct22.dat
c:\windows\system32\mxpvct25.dat
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2012-03-20 to 2012-04-20 )))))))))))))))))))))))))))))))
.
.
2012-04-20 21:42 . 2012-04-20 21:47 -------- d-----w- c:\documents and settings\Marko\Application Data\IObit
2012-04-20 16:52 . 2012-04-20 16:52 -------- d-----w- c:\documents and settings\UpdatusUser.MARKO-B6212365F
2012-04-20 16:51 . 2012-02-29 20:30 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51 . 2012-02-29 20:30 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51 . 2012-02-29 20:30 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51 . 2012-02-29 20:30 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51 . 2012-02-29 20:30 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46 . 2012-02-29 23:58 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45 . 2012-02-29 23:58 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08 . 2012-04-20 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\MCShield
2012-04-20 16:08 . 2012-04-20 16:08 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34 . 2012-04-20 15:34 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36 . 2012-04-20 07:36 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01 . 2012-04-19 12:01 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\ApplicationHistory
2012-04-10 08:12 . 2012-04-10 08:24 -------- d-----w- C:\Download
2012-04-07 08:24 . 2012-04-11 13:33 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\Adobe
2012-04-04 14:37 . 2012-04-06 12:23 -------- d-----w- c:\documents and settings\Marko\Application Data\uTorrent
2012-04-04 08:25 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-04-04 08:12 . 2006-12-19 03:12 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09 . 2012-04-04 08:09 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:38 . 2012-04-03 21:38 -------- d-----w- c:\documents and settings\UpdatusUser\Searches
2012-04-03 21:27 . 2012-04-03 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2012-04-03 21:21 . 2012-04-03 21:57 -------- d-----w- c:\windows\nview
2012-04-02 20:26 . 2012-04-14 20:20 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01 . 2012-04-02 09:01 -------- d-----w- c:\program files\Common Files\SpeedBit
2012-04-02 09:01 . 2012-04-02 09:01 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01 . 2012-04-02 09:01 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01 . 2012-04-02 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2012-04-02 09:01 . 1998-12-05 11:18 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32 . 2012-04-01 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\YTD YouTube Downloader & Converter
2012-03-31 17:18 . 2012-03-31 17:18 -------- d-----w- c:\program files\Common Files\Java
2012-03-31 17:17 . 2012-03-31 17:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06 . 2012-03-28 17:06 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:06 . 2012-03-28 17:07 -------- d-----w- c:\program files\AGEIA Technologies
2012-03-28 17:05 . 2012-03-28 17:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-03-28 16:53 . 2001-08-17 11:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53 . 2001-08-17 11:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12 . 2012-03-27 12:12 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:01 . 2012-03-27 12:01 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28 . 2012-03-26 09:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2012-03-25 20:48 . 2012-03-25 20:48 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 20:20 . 2011-11-28 18:57 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16 . 2012-02-02 10:14 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59 . 2007-12-09 15:58 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15 . 2011-11-30 11:57 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2012-03-08 21:14 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-11-30 11:58 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2011-11-30 11:58 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2011-11-30 11:58 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2011-11-30 11:58 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2011-11-30 11:58 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2011-11-30 11:58 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2011-11-30 11:58 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2011-11-30 11:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-29 23:58 . 2011-11-28 13:50 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58 . 2011-11-28 13:50 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58 . 2011-11-28 13:50 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58 . 2011-11-28 13:50 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-02-29 23:58 . 2008-12-25 22:08 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58 . 2008-12-25 22:08 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58 . 2008-12-25 22:08 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58 . 2006-08-16 07:35 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58 . 2006-08-16 07:35 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-03-18 08:38 . 2012-02-24 02:23 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-29 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-30 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Marko^Start Menu^Programs^Startup^YouTube Uploader.lnk]
backup=c:\windows\pss\YouTube Uploader.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KiweeHook
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Magentic
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Uniblue RegistryBooster 2
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2011-11-12 08:42 1647448 ----a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-23 09:42 136176 ----atw- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCShield Monitor]
2012-03-12 20:25 583680 ----a-w- c:\program files\MCShield\MCShieldRTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56528:TCP"= 56528:TCP:Pando Media Booster
"56528:UDP"= 56528:UDP:Pando Media Booster
"57294:TCP"= 57294:TCP:Pando Media Booster
"57294:UDP"= 57294:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/9/2007 5:58 PM 697328]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11/30/2011 1:58 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/30/2011 1:58 PM 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2/29/2012 11:17 PM 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [3/29/2012 9:56 AM 490840]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [4/12/2012 10:31 AM 784792]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/30/2011 1:58 PM 20696]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [4/20/2012 6:51 PM 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2/29/2012 11:17 PM 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [5/19/2008 1:04 AM 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys --> c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/2/2012 10:26 PM 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys --> c:\windows\system32\DRIVERS\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:20]
.
2012-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-04-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007Core.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
2012-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007UA.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.speedbit.com/?aff=svd_0
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
Notify-TPSvc - TPSvc.dll
SafeBoot-Wdf01000.sys
MSConfigStartUp-SearchSettings - c:\program files\common files\spigot\search settings\searchsettings.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-04-21 00:43
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
.
**************************************************************************
.
Completion time: 2012-04-21 00:47:21 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-20 22:47
.
Pre-Run: 22,582,022,144 bytes free
Post-Run: 22,570,954,752 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[Boot Loader]
Timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /usepmtimer /NoExecute=OptOut
.
- - End Of File - - 8733AB146D7A575B905CB797837018B0




mycity.rs/must-login.png

Dopuna: 21 Apr 2012 1:12

c:\windows\$NtUninstallKB14960$
c:\windows\$NtUninstallKB14960$\2136390361\@
c:\windows\$NtUninstallKB14960$\2136390361\L\tzweokge
c:\windows\$NtUninstallKB14960$\2136390361\loader.tlb
c:\windows\$NtUninstallKB14960$\2136390361\U\@00000001
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@000000cf
c:\windows\$NtUninstallKB14960$\2136390361\U\@80000000
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000c0
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cb
c:\windows\$NtUninstallKB14960$\2136390361\U\@800000cf
c:\windows\$NtUninstallKB14960$\3395889811
---------------------------------------------------------------------------

Ovo me unistilo.... sad se secam GUZ - Glavom U Zid

Dopuna: 21 Apr 2012 10:38

magma batice jel treba jos nesto da se radi ...


mycity.rs/must-login.png


Sta sad ?

Dopuna: 21 Apr 2012 10:40

magna Very Happy Very Happy Very Happy

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6102

MareBatice :: magna Very Happy Very Happy Very Happy

Polako druze, imam ja i svoj privatni zivot Wink




Korak #1
Logovi pokazuju tragove ostataka od ESET-a i Lavasoft Ad Watch Antivirusa:

Arrow Te ostatke ces ukloniti pomocu programa AppRemover

Procitaj taj clanak i isprati uputstvo da bi uklonio te ostatke:
Izabraces ovu opciju:
Clean Up a Failed Uninstall!

Takodje ti preporucujem da deinstaliras "SweetIM For Internet Explorer 3.0b" , a ja cu ukloniti ostatke Spigot Inc-a




.




Korak#2

Otvoriti Notepad i iskopirati sledeci tekst:


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]

DDS::
uStart Page = hxxp://search.speedbit.com/?aff=svd_0

Firefox::
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=
FF - prefs.js: browser.search.selectedEngine - Speedbit Search
FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/search.aspx?aff=svd_0&q=

ClearJavaCache::

Driver::
Application Updater

Folder::
c:\program files\Application Updater



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 20 Apr 2012
  • Poruke: 6

Ma opusteno ,nisi me razumeo samo sam napisao ispravno tvoj nick jer 1 put sam pogresio ... Smile

A program AppRemover

Pod opcijom Clean UP a Failed Uninstall nista mi nije naso ...


ComboFix 12-04-20.03 - Marko 04/21/2012 12:14:40.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.616 [GMT 2:00]
Running from: c:\documents and settings\Marko\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Marko\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Lavasoft Ad-Watch Live! Anti-Virus *Enabled/Updated* {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Application Updater
c:\program files\Application Updater\ApplicationUpdater.exe
c:\program files\Application Updater\config.ini
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_APPLICATION_UPDATER
-------\Service_Application Updater
.
.
((((((((((((((((((((((((( Files Created from 2012-03-21 to 2012-04-21 )))))))))))))))))))))))))))))))
.
.
2012-04-20 21:42 . 2012-04-20 21:47 -------- d-----w- c:\documents and settings\Marko\Application Data\IObit
2012-04-20 16:52 . 2012-04-20 16:52 -------- d-----w- c:\documents and settings\UpdatusUser.MARKO-B6212365F
2012-04-20 16:51 . 2012-02-29 20:30 15494464 ----a-w- c:\windows\system32\nvcpl.dll
2012-04-20 16:51 . 2012-02-29 20:30 143680 ----a-w- c:\windows\system32\nvcolor.exe
2012-04-20 16:51 . 2012-02-29 20:30 164160 ----a-w- c:\windows\system32\nvsvc32.exe
2012-04-20 16:51 . 2012-02-29 20:30 108352 ----a-w- c:\windows\system32\nvmctray.dll
2012-04-20 16:51 . 2012-02-29 20:30 54272 ----a-w- c:\windows\system32\nvwddi.dll
2012-04-20 16:46 . 2012-02-29 23:58 2437440 ----a-w- c:\windows\system32\nvcuvenc.dll
2012-04-20 16:45 . 2012-02-29 23:58 17534976 ----a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 16:08 . 2012-04-20 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\MCShield
2012-04-20 16:08 . 2012-04-20 16:08 -------- d-----w- c:\program files\MCShield
2012-04-20 15:34 . 2012-04-20 15:34 -------- d-----w- c:\program files\Trend Micro
2012-04-20 07:36 . 2012-04-20 07:36 1409 ----a-w- c:\windows\QTFont.for
2012-04-19 12:01 . 2012-04-19 12:01 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\ApplicationHistory
2012-04-10 08:12 . 2012-04-10 08:24 -------- d-----w- C:\Download
2012-04-07 08:24 . 2012-04-11 13:33 -------- d-----w- c:\documents and settings\Marko\Local Settings\Application Data\Adobe
2012-04-04 14:37 . 2012-04-06 12:23 -------- d-----w- c:\documents and settings\Marko\Application Data\uTorrent
2012-04-04 08:25 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2012-04-04 08:12 . 2006-12-19 03:12 16062464 ------r- c:\windows\RTHDCPL.exe
2012-04-04 08:09 . 2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
2012-04-04 08:09 . 2012-04-04 08:09 315392 ----a-w- c:\windows\HideWin.exe
2012-04-03 21:38 . 2012-04-03 21:38 -------- d-----w- c:\documents and settings\UpdatusUser\Searches
2012-04-03 21:27 . 2012-04-03 21:27 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles
2012-04-03 21:21 . 2012-04-03 21:57 -------- d-----w- c:\windows\nview
2012-04-02 20:26 . 2012-04-14 20:20 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-02 09:01 . 2012-04-02 09:01 -------- d-----w- c:\program files\Common Files\SpeedBit
2012-04-02 09:01 . 2012-04-02 09:01 84480 ----a-w- c:\windows\system32\EasyHook32.dll
2012-04-02 09:01 . 2012-04-02 09:01 102912 ----a-w- c:\windows\system32\EasyHook64.dll
2012-04-02 09:01 . 2012-04-02 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2012-04-02 09:01 . 1998-12-05 11:18 172032 ----a-w- c:\windows\system32\AniGIF.ocx
2012-04-01 23:32 . 2012-04-01 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\YTD YouTube Downloader & Converter
2012-03-31 17:18 . 2012-03-31 17:18 -------- d-----w- c:\program files\Common Files\Java
2012-03-31 17:17 . 2012-03-31 17:16 73728 ----a-w- c:\windows\system32\javacpl.cpl
2012-03-28 17:06 . 2012-03-28 17:06 -------- d-----w- c:\windows\system32\AGEIA
2012-03-28 17:06 . 2012-03-28 17:07 -------- d-----w- c:\program files\AGEIA Technologies
2012-03-28 17:05 . 2012-03-28 17:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-03-28 16:53 . 2001-08-17 11:48 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2012-03-28 16:53 . 2001-08-17 11:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2012-03-28 16:53 . 2007-10-30 16:47 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2012-03-27 12:12 . 2012-03-27 12:12 -------- d-----w- C:\$WIN_NT$.~BT
2012-03-27 12:01 . 2012-03-27 12:01 -------- d-----w- c:\program files\Alcohol Soft
2012-03-26 09:28 . 2012-03-26 09:28 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2012-03-25 20:48 . 2012-03-25 20:48 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-14 20:20 . 2011-11-28 18:57 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-31 17:16 . 2012-02-02 10:14 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-03-27 11:59 . 2007-12-09 15:58 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2012-03-07 00:15 . 2011-11-30 11:57 41184 ----a-w- c:\windows\avastSS.scr
2012-03-07 00:15 . 2012-03-08 21:14 201352 ----a-w- c:\windows\system32\aswBoot.exe
2012-03-07 00:03 . 2011-11-30 11:58 612184 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-03-07 00:03 . 2011-11-30 11:58 337880 ----a-w- c:\windows\system32\drivers\aswSP.sys
2012-03-07 00:02 . 2011-11-30 11:58 35672 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2012-03-07 00:01 . 2011-11-30 11:58 53848 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2012-03-07 00:01 . 2011-11-30 11:58 95704 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2012-03-07 00:01 . 2011-11-30 11:58 89048 ----a-w- c:\windows\system32\drivers\aswmon.sys
2012-03-07 00:01 . 2011-11-30 11:58 20696 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-03-06 23:58 . 2011-11-30 11:58 24920 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2012-02-29 23:58 . 2011-11-28 13:50 65536 ----a-w- c:\windows\system32\OpenCL.dll
2012-02-29 23:58 . 2011-11-28 13:50 881984 ----a-w- c:\windows\system32\nvgenco32.dll
2012-02-29 23:58 . 2011-11-28 13:50 2522944 ----a-w- c:\windows\system32\nvcuvid.dll
2012-02-29 23:58 . 2011-11-28 13:50 1000256 ----a-w- c:\windows\system32\nvdispco32.dll
2012-02-29 23:58 . 2008-12-25 22:08 5918720 ----a-w- c:\windows\system32\nvcuda.dll
2012-02-29 23:58 . 2008-12-25 22:08 2291712 ----a-w- c:\windows\system32\nvapi.dll
2012-02-29 23:58 . 2008-12-25 22:08 18624512 ----a-w- c:\windows\system32\nvoglnt.dll
2012-02-29 23:58 . 2006-08-16 07:35 4309760 ----a-w- c:\windows\system32\nv4_disp.dll
2012-02-29 23:58 . 2006-08-16 07:35 13417632 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2012-03-18 08:38 . 2012-02-24 02:23 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-20_22.43.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-21 10:27 . 2012-04-21 10:27 16384 c:\windows\Temp\Perflib_Perfdata_7a0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-03-07 00:15 123536 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-07 4241512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2012-02-29 15494464]
"NvMediaCenter"="NvMCTray.dll" [2012-02-29 108352]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-02-29 1634112]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2007-10-30 15360]
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Marko^Start Menu^Programs^Startup^YouTube Uploader.lnk]
backup=c:\windows\pss\YouTube Uploader.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 21:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 5]
2011-11-12 08:42 1647448 ----a-w- c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 10:43 69632 ------r- c:\windows\Alcmtr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2012-03-23 09:42 136176 ----atw- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCShield Monitor]
2012-03-12 20:25 583680 ----a-w- c:\program files\MCShield\MCShieldRTM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-04-16 21:12 3872080 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-16 10:04 2879488 ------r- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RichVideo"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56528:TCP"= 56528:TCP:Pando Media Booster
"56528:UDP"= 56528:UDP:Pando Media Booster
"57294:TCP"= 57294:TCP:Pando Media Booster
"57294:UDP"= 57294:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/9/2007 5:58 PM 697328]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [11/30/2011 1:58 PM 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/30/2011 1:58 PM 337880]
R2 713xTVCard;SAA7130 TV Card;c:\windows\system32\drivers\SAA713x.sys [2/29/2012 11:17 PM 279552]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [3/29/2012 9:56 AM 490840]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/30/2011 1:58 PM 20696]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [4/20/2012 6:51 PM 2348352]
R2 WDMTVTuner;Universal WDM TV Tuner;c:\windows\system32\drivers\WDMTuner.sys [2/29/2012 11:17 PM 25984]
R3 bbcap;bbcap;c:\windows\system32\drivers\bbcap.sys [5/19/2008 1:04 AM 4096]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S1 GhPciScan;GhostPciScanner;\??\c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys --> c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 2:16 PM 130384]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/2/2012 10:26 PM 253088]
S3 fsbl-standalone;F-Secure BlackLight Beta Engine Driver; [x]
S3 GenericMount;Generic Mount Driver;c:\windows\system32\DRIVERS\GenericMount.sys --> c:\windows\system32\DRIVERS\GenericMount.sys [?]
S3 Lavasoft Kernexplorer;Lavasoft helper driver; [x]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\x:\ntglm7x.sys --> x:\NTGLM7X.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 2:16 PM 753504]
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-02 20:20]
.
2012-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 15:57]
.
2012-04-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007Core.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
2012-04-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-73586283-1532298954-682003330-1007UA.job
- c:\documents and settings\Marko\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-23 09:42]
.
.
------- Supplementary Scan -------
.
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyServer = proxy.vektor.net:8080
uInternet Settings,ProxyOverride = <local>
IE: Add to Windows &Live Favorites - favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 89.216.1.30 89.216.1.50
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Marko\Application Data\Mozilla\Firefox\Profiles\8ugh0x66.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: network.proxy.ftp - proxy.vektor.net
FF - prefs.js: network.proxy.ftp_port - 8080
FF - prefs.js: network.proxy.http - proxy.vektor.net
FF - prefs.js: network.proxy.http_port - 8080
FF - prefs.js: network.proxy.socks - proxy.vektor.net
FF - prefs.js: network.proxy.socks_port - 8080
FF - prefs.js: network.proxy.ssl - proxy.vektor.net
FF - prefs.js: network.proxy.ssl_port - 8080
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-04-21 12:28
Windows 5.1.2600 Service Pack 3, v.3244 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RunDLL32.exe
c:\program files\AVAST Software\Avast\setup\avast.setup
.
**************************************************************************
.
Completion time: 2012-04-21 12:32:42 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-21 10:32
ComboFix2.txt 2012-04-20 22:47
.
Pre-Run: 22,243,041,280 bytes free
Post-Run: 22,077,931,520 bytes free
.
- - End Of File - - F3F758B88BEC216A636A00F46552EF40

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6102

Idea Sto se tice samog malware-a, imao si na sistemu aktivan ZeroAccess i on je sad uklonjen.
Na sistemu vise nemas aktivnog malware-a.




Arrow Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.





Arrow Poseti ovu temu:
http://www.mycity.rs/Zastitni-programi/Programi-za.....tvera.html
Preuzmi ESET Uninstaller i alat pokreni iz Safe Moda po uputstvu.

To bi bilo to. Pozdrav. Wink

Ko je trenutno na forumu
 

Ukupno su 429 korisnika na forumu :: 7 registrovanih, 1 sakriven i 421 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., galijot, goxin, nenad81, Oscar2, pein, samsung