Problem sa Trojancima!!!

2

Problem sa Trojancima!!!

offline
  • Pridružio: 29 Jan 2009
  • Poruke: 54

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]



offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Iskljuci system restore dok ne zavrsimo sa ciscenjem

[Link mogu videti samo ulogovani korisnici]

Zatim instaliraj Avast Free Antivirus

[Link mogu videti samo ulogovani korisnici]

Kada zavrsis sa instalacijom pokreni njegov interfejs dvoklikom na ikonicu na desktopu. Zatim namesti sledeca podesavanja :






Restartuj racunar i kada se zavrsi skeniranje(uu toku skeniranja imaces da biras opcije ukoliko malware bude detektovan, ti izaberi move to quarantine) okaci log koji se nalazi na sledecoj lokaciji.

C:\Documents and Settings\All Users\Application Data\Alwil Software\Avast5\log\aswBoot.log



offline
  • Pridružio: 29 Jan 2009
  • Poruke: 54

Mogu da odradim to tamo tek u cet ili petak nisam kuci do tada a sada nemam vremena..Tako da ti se javljam tada..A komp i ovako niko ne koristi sem mene..

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Sad bi stanje trebalo da je mnogo bolje, al moras imati AV. Ok.. ali obavezno ovo odradi da vidim na cemu smo sad.

offline
  • Pridružio: 29 Jan 2009
  • Poruke: 54

Evo odradio sam i to nadam se da je sada ok
[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Pozdrav, opet ja.


Arrow Postavi mi svez ComboFix log.
Uputstvo si vec dobio u temi.


Arrow Nemoj ubacivati USB uredjaje (ukoliko ih imas) dok ti to ne budem napisao da uradis.

offline
  • Pridružio: 29 Jan 2009
  • Poruke: 54

[Link mogu videti samo ulogovani korisnici]


ComboFix 10-07-09.02 - Vladimir 07/17/2010 14:13:08.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.82 [GMT 2:00]
Running from: c:\documents and settings\Vladimir\My Documents\Preuzimanja\ComboFix.exe
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
- REDUCED FUNCTIONALITY MODE -
.

((((((((((((((((((((((((( Files Created from 2010-06-17 to 2010-07-17 )))))))))))))))))))))))))))))))
.

2010-07-16 15:55 . 2010-07-16 15:55 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-07-16 15:50 . 2010-07-16 15:50 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-07-16 15:50 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-16 15:50 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-07-16 15:50 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-07-16 15:50 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-07-16 15:50 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-07-16 15:50 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-07-16 15:50 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-07-16 15:49 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-07-16 15:49 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-07-16 15:49 . 2010-07-16 15:49 -------- d-----w- c:\program files\Alwil Software
2010-07-16 15:49 . 2010-07-16 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-11 10:09 . 2003-05-25 02:11 60416 ----a-w- c:\windows\system32\antiwpa.dll
2010-07-09 20:22 . 2008-04-14 03:42 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-07-09 20:22 . 2008-04-14 03:42 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-07-09 20:14 . 2008-04-13 22:09 23040 -c--a-w- c:\windows\system32\dllcache\mouclass.sys
2010-07-09 20:14 . 2008-04-13 22:09 23040 ----a-w- c:\windows\system32\drivers\mouclass.sys
2010-07-09 14:44 . 2010-07-09 14:44 -------- d-----w- c:\program files\Trend Micro
2010-07-09 00:36 . 2010-07-09 00:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-07 19:31 . 2010-07-11 00:20 -------- d-----w- c:\documents and settings\Vladimir\Tracing
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Microsoft
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Windows Live
2010-07-07 18:12 . 2010-07-07 18:12 -------- d-----w- c:\program files\Common Files\Windows Live
2010-07-06 17:22 . 2010-07-06 17:22 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Malwarebytes
2010-07-06 17:22 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-06 17:22 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-06 17:22 . 2010-07-06 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-06 17:22 . 2010-07-06 18:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-02 18:22 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-07-02 18:22 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2010-07-02 18:17 . 2010-07-02 18:17 -------- d-----w- c:\program files\Microsoft Works
2010-07-02 18:16 . 2010-07-02 18:16 -------- d-----w- c:\program files\MSBuild
2010-07-02 18:02 . 2010-07-02 18:14 -------- d-----w- c:\windows\SHELLNEW
2010-07-02 18:01 . 2010-07-02 18:01 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Microsoft Help
2010-07-02 18:00 . 2010-07-02 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-02 17:58 . 2010-07-02 17:58 -------- d-----r- C:\MSOCache
2010-07-02 16:10 . 2010-07-02 16:10 -------- d-----w- c:\program files\uTorrent
2010-07-02 16:10 . 2010-07-02 18:03 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent
2010-07-02 10:20 . 2010-07-02 10:20 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-07-02 10:20 . 2010-07-11 00:23 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM
2010-07-02 10:19 . 2010-07-11 00:47 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype
2010-07-02 10:18 . 2010-07-02 10:18 -------- d-----w- c:\program files\Common Files\Skype
2010-07-02 10:18 . 2010-07-02 10:19 -------- d-----r- c:\program files\Skype
2010-07-02 10:18 . 2010-07-02 10:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-07-02 10:01 . 2010-07-08 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\RFA_Backups
2010-07-02 09:59 . 2010-07-02 09:59 0 ----a-w- c:\windows\nsreg.dat
2010-07-02 09:59 . 2010-07-02 09:59 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Mozilla
2010-07-02 09:59 . 2010-07-02 09:59 -------- d-----w- c:\program files\RFA
2010-07-01 19:49 . 2010-07-01 19:50 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Micro Forte
2010-07-01 19:48 . 2007-07-19 22:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
2010-07-01 19:48 . 2007-07-19 16:14 444776 ----a-w- c:\windows\system32\d3dx10_35.dll
2010-07-01 19:48 . 2007-07-19 16:14 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll
2010-07-01 19:48 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2010-07-01 19:48 . 2007-07-19 22:54 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll
2010-07-01 19:48 . 2007-06-20 18:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2010-07-01 19:48 . 2007-05-16 14:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2010-07-01 19:48 . 2007-05-16 14:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2010-07-01 19:48 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2010-06-27 17:38 . 2008-04-13 22:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-06-27 16:57 . 2010-07-16 16:16 -------- d-----w- c:\program files\Google
2010-06-23 17:56 . 2010-06-24 17:40 10 ----a-w- c:\windows\popcinfo.dat
2010-06-23 12:39 . 2010-06-23 12:39 4096 ----a-w- c:\windows\d3dx.dat
2010-06-23 12:38 . 2010-07-02 09:45 -------- d-----w- c:\program files\GameHouse
2010-06-23 12:35 . 2010-06-24 17:42 -------- d-----w- c:\program files\Zuma Deluxe
2010-06-23 12:34 . 2010-06-23 12:34 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Opera
2010-06-23 12:34 . 2010-06-23 12:34 -------- d-----w- c:\program files\Opera
2010-06-20 17:03 . 2010-06-20 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2010-06-20 17:03 . 2010-06-20 19:59 14 ----a-w- c:\windows\popcinfot.dat
2010-06-20 17:03 . 2010-06-20 17:03 0 ----a-w- c:\windows\popcreg.dat
2010-06-19 19:59 . 2010-06-19 19:59 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Media Player Classic
2010-06-19 19:59 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-06-19 19:59 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-19 19:59 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-06-19 19:59 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-06-19 19:59 . 2009-12-11 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-19 19:59 . 2010-06-19 19:59 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-06-19 19:57 . 2010-07-02 21:50 -------- d-----w- c:\documents and settings\Vladimir\Application Data\BSplayer PRO
2010-06-19 19:57 . 2010-06-19 19:57 -------- d-----w- c:\program files\Webteh

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-09 14:23 . 2002-08-29 12:00 1033728 ----a-w- c:\windows\explorer.exe
2010-07-07 18:11 . 2010-06-18 16:57 69232 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-02 10:46 . 2010-06-18 17:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-18 21:08 . 2010-06-18 17:43 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp
2010-06-18 21:08 . 2010-06-18 17:43 -------- d-----w- c:\program files\Winamp
2010-06-18 17:03 . 2010-06-18 17:03 -------- d-----w- c:\documents and settings\Vladimir\Application Data\InterTrust
2010-06-18 17:03 . 2010-06-18 17:03 -------- d-----w- c:\program files\Intel
2010-06-18 17:03 . 2010-06-18 16:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-18 17:00 . 2010-06-18 17:00 -------- d-----w- c:\program files\ATI Technologies
2010-06-18 16:59 . 2010-06-18 16:59 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-18 16:52 . 2010-06-18 16:25 70691 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2010-06-18 16:27 . 2010-06-18 16:27 -------- d-----w- c:\program files\microsoft frontpage
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\LB1Z9JHR.DAT
2010-06-18 16:26 . 2010-06-18 16:26 558142 ----a-w- c:\windows\java\Packages\UU0H7FFB.ZIP
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\D31FZNVD.DAT
2010-06-18 16:26 . 2010-06-18 16:26 155995 ----a-w- c:\windows\java\Packages\SAD3TZNZ.ZIP
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\PZL75FTZ.DAT
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\DJ5FHFDN.DAT
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\0YFVTZ5B.DAT
2010-06-18 16:23 . 2010-06-18 16:23 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
.

((((((((((((((((((((((((((((( [Link mogu videti samo ulogovani korisnici] )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 22:02 . 2009-07-11 22:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2010-07-16 15:50 . 2010-07-16 15:50 22528 c:\windows\Installer\55efa5.msi
+ 2009-07-11 22:02 . 2009-07-11 22:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 22:05 . 2009-07-11 22:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2010-07-16 15:49 . 2010-07-16 15:49 219648 c:\windows\Installer\55efa0.msi
+ 2009-07-11 22:02 . 2009-07-11 22:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 22:02 . 2009-07-11 22:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-01-12 315392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/16/2010 5:50 PM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/16/2010 5:50 PM 17744]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/16/2010 5:50 PM 136176]
.
Contents of the 'Scheduled Tasks' folder

2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-16 15:50]

2010-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-16 15:50]
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\PCHealth\HelpCtr\System\panels\blank.htm
uStart Page = [Link mogu videti samo ulogovani korisnici]
mLocal Page = c:\windows\PCHealth\HelpCtr\System\panels\blank.htm
IE: &Google Search - c:\program files\Google\googletoolbar.dll/cmsearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward &Links - c:\program files\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\googletoolbar.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\googletoolbar.dll/cmtrans.html
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\4y1emjty.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\nppdf32.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2010-07-17 14:15
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(612)
c:\windows\system32\antiwpa.dll
.
Completion time: 2010-07-17 14:18:42
ComboFix-quarantined-files.txt 2010-07-17 12:18
ComboFix2.txt 2010-07-10 15:49
ComboFix3.txt 2010-07-10 14:17
ComboFix4.txt 2010-07-10 11:18
ComboFix5.txt 2010-07-17 12:12

Pre-Run: 3,620,925,440 bytes free
Post-Run: 3,611,267,072 bytes free

- - End Of File - - D1D14021F10D88EC7D25CBD889E6E57A

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Skini novu kopiju ComboFix-a na Desktop i odatle ga pokreni.

Tj. ispostuj detaljno uputstvo koje ti je dato:
-> [Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 29 Jan 2009
  • Poruke: 54

ComboFix 10-07-16.02 - Vladimir 07/18/2010 13:18:28.6.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.255.119 [GMT 2:00]
Running from: c:\documents and settings\Vladimir\My Documents\Preuzimanja\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.

2010-07-16 15:55 . 2010-07-16 15:55 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-07-16 15:50 . 2010-07-16 15:50 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-07-16 15:50 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-07-16 15:50 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-07-16 15:50 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-07-16 15:50 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-07-16 15:50 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-07-16 15:50 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-07-16 15:50 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-07-16 15:49 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-07-16 15:49 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-07-16 15:49 . 2010-07-16 15:49 -------- d-----w- c:\program files\Alwil Software
2010-07-16 15:49 . 2010-07-16 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-11 10:09 . 2003-05-25 02:11 60416 ----a-w- c:\windows\system32\antiwpa.dll
2010-07-09 20:22 . 2008-04-14 03:42 39424 -c--a-w- c:\windows\system32\dllcache\grpconv.exe
2010-07-09 20:22 . 2008-04-14 03:42 39424 ----a-w- c:\windows\system32\grpconv.exe
2010-07-09 20:14 . 2008-04-13 22:09 23040 -c--a-w- c:\windows\system32\dllcache\mouclass.sys
2010-07-09 20:14 . 2008-04-13 22:09 23040 ----a-w- c:\windows\system32\drivers\mouclass.sys
2010-07-09 14:44 . 2010-07-09 14:44 -------- d-----w- c:\program files\Trend Micro
2010-07-09 00:36 . 2010-07-09 00:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-07 19:31 . 2010-07-11 00:20 -------- d-----w- c:\documents and settings\Vladimir\Tracing
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Microsoft
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-07-07 19:22 . 2010-07-07 19:22 -------- d-----w- c:\program files\Windows Live
2010-07-07 18:12 . 2010-07-07 18:12 -------- d-----w- c:\program files\Common Files\Windows Live
2010-07-06 17:22 . 2010-07-06 17:22 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Malwarebytes
2010-07-06 17:22 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-06 17:22 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-06 17:22 . 2010-07-06 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-06 17:22 . 2010-07-06 18:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-02 18:22 . 2006-10-26 17:56 33104 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2010-07-02 18:22 . 2006-10-26 17:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2010-07-02 18:17 . 2010-07-02 18:17 -------- d-----w- c:\program files\Microsoft Works
2010-07-02 18:16 . 2010-07-02 18:16 -------- d-----w- c:\program files\MSBuild
2010-07-02 18:02 . 2010-07-02 18:14 -------- d-----w- c:\windows\SHELLNEW
2010-07-02 18:01 . 2010-07-02 18:01 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Microsoft Help
2010-07-02 18:00 . 2010-07-02 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-02 17:58 . 2010-07-02 17:58 -------- d-----r- C:\MSOCache
2010-07-02 16:10 . 2010-07-02 16:10 -------- d-----w- c:\program files\uTorrent
2010-07-02 16:10 . 2010-07-02 18:03 -------- d-----w- c:\documents and settings\Vladimir\Application Data\uTorrent
2010-07-02 10:20 . 2010-07-02 10:20 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-07-02 10:20 . 2010-07-18 02:26 -------- d-----w- c:\documents and settings\Vladimir\Application Data\skypePM
2010-07-02 10:19 . 2010-07-18 02:55 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Skype
2010-07-02 10:18 . 2010-07-02 10:18 -------- d-----w- c:\program files\Common Files\Skype
2010-07-02 10:18 . 2010-07-02 10:19 -------- d-----r- c:\program files\Skype
2010-07-02 10:18 . 2010-07-02 10:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-07-02 10:01 . 2010-07-08 18:09 -------- d-----w- c:\documents and settings\All Users\Application Data\RFA_Backups
2010-07-02 09:59 . 2010-07-02 09:59 0 ----a-w- c:\windows\nsreg.dat
2010-07-02 09:59 . 2010-07-02 09:59 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Mozilla
2010-07-02 09:59 . 2010-07-02 09:59 -------- d-----w- c:\program files\RFA
2010-07-01 19:49 . 2010-07-01 19:50 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Micro Forte
2010-07-01 19:48 . 2007-07-19 22:57 267112 ----a-w- c:\windows\system32\xactengine2_9.dll
2010-07-01 19:48 . 2007-07-19 16:14 444776 ----a-w- c:\windows\system32\d3dx10_35.dll
2010-07-01 19:48 . 2007-07-19 16:14 1358192 ----a-w- c:\windows\system32\D3DCompiler_35.dll
2010-07-01 19:48 . 2007-07-19 16:14 3727720 ----a-w- c:\windows\system32\d3dx9_35.dll
2010-07-01 19:48 . 2007-07-19 22:54 18280 ----a-w- c:\windows\system32\x3daudio1_2.dll
2010-07-01 19:48 . 2007-06-20 18:46 266088 ----a-w- c:\windows\system32\xactengine2_8.dll
2010-07-01 19:48 . 2007-05-16 14:45 443752 ----a-w- c:\windows\system32\d3dx10_34.dll
2010-07-01 19:48 . 2007-05-16 14:45 1124720 ----a-w- c:\windows\system32\D3DCompiler_34.dll
2010-07-01 19:48 . 2007-05-16 14:45 3497832 ----a-w- c:\windows\system32\d3dx9_34.dll
2010-06-27 17:38 . 2008-04-13 22:15 26368 -c--a-w- c:\windows\system32\dllcache\usbstor.sys
2010-06-27 16:57 . 2010-07-16 16:16 -------- d-----w- c:\program files\Google
2010-06-23 17:56 . 2010-06-24 17:40 10 ----a-w- c:\windows\popcinfo.dat
2010-06-23 12:39 . 2010-06-23 12:39 4096 ----a-w- c:\windows\d3dx.dat
2010-06-23 12:38 . 2010-07-02 09:45 -------- d-----w- c:\program files\GameHouse
2010-06-23 12:35 . 2010-06-24 17:42 -------- d-----w- c:\program files\Zuma Deluxe
2010-06-23 12:34 . 2010-06-23 12:34 -------- d-----w- c:\documents and settings\Vladimir\Local Settings\Application Data\Opera
2010-06-23 12:34 . 2010-06-23 12:34 -------- d-----w- c:\program files\Opera
2010-06-20 17:03 . 2010-06-20 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2010-06-20 17:03 . 2010-06-20 19:59 14 ----a-w- c:\windows\popcinfot.dat
2010-06-20 17:03 . 2010-06-20 17:03 0 ----a-w- c:\windows\popcreg.dat
2010-06-19 19:59 . 2010-06-19 19:59 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Media Player Classic
2010-06-19 19:59 . 2009-08-16 15:08 178176 ----a-w- c:\windows\system32\unrar.dll
2010-06-19 19:59 . 2009-05-29 21:37 205824 ----a-w- c:\windows\system32\xvidvfw.dll
2010-06-19 19:59 . 2009-05-29 21:31 881664 ----a-w- c:\windows\system32\xvidcore.dll
2010-06-19 19:59 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-06-19 19:59 . 2009-12-11 18:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-06-19 19:59 . 2010-06-19 19:59 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-06-19 19:57 . 2010-07-02 21:50 -------- d-----w- c:\documents and settings\Vladimir\Application Data\BSplayer PRO
2010-06-19 19:57 . 2010-06-19 19:57 -------- d-----w- c:\program files\Webteh

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-09 14:23 . 2002-08-29 12:00 1033728 ----a-w- c:\windows\explorer.exe
2010-07-07 18:11 . 2010-06-18 16:57 69232 ----a-w- c:\documents and settings\Vladimir\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-02 10:46 . 2010-06-18 17:03 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-18 21:08 . 2010-06-18 17:43 -------- d-----w- c:\documents and settings\Vladimir\Application Data\Winamp
2010-06-18 21:08 . 2010-06-18 17:43 -------- d-----w- c:\program files\Winamp
2010-06-18 17:03 . 2010-06-18 17:03 -------- d-----w- c:\documents and settings\Vladimir\Application Data\InterTrust
2010-06-18 17:03 . 2010-06-18 17:03 -------- d-----w- c:\program files\Intel
2010-06-18 17:03 . 2010-06-18 16:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-06-18 17:00 . 2010-06-18 17:00 -------- d-----w- c:\program files\ATI Technologies
2010-06-18 16:59 . 2010-06-18 16:59 -------- d-----w- c:\program files\Common Files\InstallShield
2010-06-18 16:52 . 2010-06-18 16:25 70691 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2010-06-18 16:27 . 2010-06-18 16:27 -------- d-----w- c:\program files\microsoft frontpage
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\LB1Z9JHR.DAT
2010-06-18 16:26 . 2010-06-18 16:26 558142 ----a-w- c:\windows\java\Packages\UU0H7FFB.ZIP
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\D31FZNVD.DAT
2010-06-18 16:26 . 2010-06-18 16:26 155995 ----a-w- c:\windows\java\Packages\SAD3TZNZ.ZIP
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\PZL75FTZ.DAT
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\DJ5FHFDN.DAT
2010-06-18 16:26 . 2010-06-18 16:26 2678 ----a-w- c:\windows\java\Packages\Data\0YFVTZ5B.DAT
2010-06-18 16:23 . 2010-06-18 16:23 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2010-06-03 02:41 . 2010-06-03 02:41 3600384 ----a-w- c:\windows\system32\GPhotos.scr
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-01-12 315392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/16/2010 5:50 PM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/16/2010 5:50 PM 17744]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/16/2010 5:50 PM 136176]
.
Contents of the 'Scheduled Tasks' folder

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-16 15:50]

2010-07-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-07-16 15:50]
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\PCHealth\HelpCtr\System\panels\blank.htm
uStart Page = [Link mogu videti samo ulogovani korisnici]
mLocal Page = c:\windows\PCHealth\HelpCtr\System\panels\blank.htm
IE: &Google Search - c:\program files\Google\googletoolbar.dll/cmsearch.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Backward &Links - c:\program files\Google\googletoolbar.dll/cmbacklinks.html
IE: Cac&hed Snapshot of Page - c:\program files\Google\googletoolbar.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Si&milar Pages - c:\program files\Google\googletoolbar.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\googletoolbar.dll/cmtrans.html
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
FF - ProfilePath - c:\documents and settings\Vladimir\Application Data\Mozilla\Firefox\Profiles\4y1emjty.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Opera\program\plugins\nppdf32.dll

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2010-07-18 13:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(612)
c:\windows\system32\antiwpa.dll
.
Completion time: 2010-07-18 13:28:05
ComboFix-quarantined-files.txt 2010-07-18 11:28
ComboFix2.txt 2010-07-17 12:18

Pre-Run: 3,589,206,016 bytes free
Post-Run: 3,581,427,712 bytes free

- - End Of File - - 420D5E2B79BB5AE7A10FD6EA933CFB88

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Postavi mi svez Hijack This log (kao sto si u prvom post-u uradio).

Ko je trenutno na forumu
 

Ukupno su 2046 korisnika na forumu :: 85 registrovanih, 9 sakrivenih i 1952 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, 8u47, Abebe Bikila, AirSremac, ajo baba, Beria, boj.an, Bojke549, Borski1977, bpop, bpvl, branko7, Bumbo, Cicumile, cifra, darkojovxp, delboy, Denaya, Dimitrise93, djuradj, Dogma21, dolinalima, Dorcolac, eagle.rs, FilipSRB, Gitzherai, halkin gol, IpMan, Jeremiah, JK, jmsk, jodzula, Jozo74, Kajzer Soze, KizJ, komenski, Koridor, Lap720, Macalone, MagicniHerpes, Makeitdrip, markolopin, Mercury, Mi lao shu, micke83, miki kv, Miki01, Miki281, mikrimaus, Milan A. Nikolic, milos.cbr, nikoladim, nixos, nuke92, oldtimer, Orc, Paklenica, predragc, Prle90, Pv123, raptorsi, ruso, sale755, Sevatar, Sharpshooter, silikon, tanakadzo, Tribal, Trpe Grozni, vaci, Vanja_03, vathra, Velički, vensla, Vica1958, vidra boy, VJ, Weah88, xAlex2, yiyi, Zastava, zeka013, |_MeD_|, šumar bk2, 79693