Provjera loga

Provjera loga

offline
  • Pridružio: 16 Maj 2010
  • Poruke: 4

Napisano: 18 Maj 2010 21:13

Pozdrav

prije 2 dana sam skenirao kompjuter sa programom "Malwarebytes' Anti-Malware" i našao mi je bio 4 infekcije koje je kasnije valjda i uklonio ali želim da budem 100 % siguran da nešta nije ipak ostalo, pa bih vas zamolio ako imate vremena da mi prekontrolišete logove od DDS programa. I imam još jedan problem a to je da kad pokrenem GMER ili RootRepeal slika na desktopu mi se zaledi i jedino što mi ostaje je da restartujem kompjuter preko kućišta. Pa ne znam koliko će vam pomoći ovaj DDS, ali ako mogu GMER ili RootRepeal zamjeniti nekim drugim programom recite i okačiću logove od tog programa.



DDS (Ver_10-03-17.01) - NTFSx86
Run by Pc at 21:02:41,02 on uto 18.05.2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2399 [GMT 2:00]

AV: Kaspersky Internet Security *On-access scanning enabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *enabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\The Skins Factory\Hyperdesk\Common\HDThemeEnabler.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Documents and Settings\Pc\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe
C:\Program Files\Anuko\World Clock\timesync.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
C:\Program Files\Hotspot Shield\bin\hsswd.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sandboxie\SbieSvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorService.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\PROGRA~1\Bandoo\Bandoo.exe
C:\PROGRA~1\SPEEDB~2\VideoAcceleratorEngine.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Pc\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot0.dll
uURLSearchHooks: AstroburnBar Toolbar: {e802027b-1f2b-40bd-b307-0bd96d036835} - c:\program files\astroburnbar\tbAstr.dll
uURLSearchHooks: freeonlinetvbar Toolbar: {5258c432-c281-42f7-8fa4-41fd1e6747b8} - c:\program files\freeonlinetvbar\tbfre1.dll
uURLSearchHooks: ToolbarURLSearchHook Class: {ca3eb689-8f09-4026-aa10-b9534c691ce0} - c:\program files\speedbit video downloader\toolbar\tbhelper.dll
uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll
uURLSearchHooks: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\tbSoft.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SBCONVERT Class: {3017fb3e-9a77-4396-88c5-0ec9548fb42f} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: WormRadar.com IESiteBlocker.NavFilter: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - AVG Safe Search
BHO: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\tbSoft.dll
BHO: freeonlinetvbar Toolbar: {5258c432-c281-42f7-8fa4-41fd1e6747b8} - c:\program files\freeonlinetvbar\tbfre1.dll
BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2010\ievkbd.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: FlashGetBHO: {b070d3e3-fec0-47d9-8e8a-99d4eeb3d3b0} - c:\documents and settings\pc\application data\flashgetbho\FlashGetBHO3.dll
BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll
BHO: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot0.dll
BHO: SHOUTcast Loader: {ccec60fc-2608-4e58-9659-3ffc159e8ea9} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
BHO: GOM Player + Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: AstroburnBar Toolbar: {e802027b-1f2b-40bd-b307-0bd96d036835} - c:\program files\astroburnbar\tbAstr.dll
BHO: BandooIEPlugin Class: {eb5cee80-030a-4ed8-8e20-454e9c68380f} - c:\program files\bandoo\plugins\ie\ieplugin.dll
BHO: Hotspot Shield Class: {f9e4a054-e9b1-4bc3-83a3-76a1ae736170} - c:\program files\hotspot shield\hssie\HssIE.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: GrabberObj Class: {ff7c3cf0-4b15-11d1-abed-709549c10000} - c:\progra~1\speedb~1\toolbar\grabber.dll
TB: Hotspot Shield Toolbar: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - c:\program files\hotspot_shield\tbHot0.dll
TB: AstroburnBar Toolbar: {e802027b-1f2b-40bd-b307-0bd96d036835} - c:\program files\astroburnbar\tbAstr.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: freeonlinetvbar Toolbar: {5258c432-c281-42f7-8fa4-41fd1e6747b8} - c:\program files\freeonlinetvbar\tbfre1.dll
TB: SpeedBit Video Downloader: {0329e7d6-6f54-462d-93f6-f5c3118badf2} - c:\program files\speedbit video downloader\toolbar\tbcore3.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\tbVuze.dll
TB: Softonic-Eng7 Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - c:\program files\softonic-eng7\tbSoft.dll
TB: SHOUTcast Radio Toolbar: {0457331d-8ca6-4f97-9c26-6a9ef2b2dba8} - c:\program files\shoutcast radio toolbar\shoutcasttb.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\pc\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRunOnce: [<NO NAME>]
StartupFolder: c:\docume~1\pc\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
IE: &SHOUTcast Search - c:\documents and settings\all users\application data\shoutcast radio toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2010\ie_banner_deny.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Download All By FlashGet3 - c:\documents and settings\pc\application data\flashgetbho\GetAllUrl.htm
IE: Download By FlashGet3 - c:\documents and settings\pc\application data\flashgetbho\GetUrl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {0D2BE054-F0DC-4AF4-BDF3-50B3489E79E6}
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2010\klwtbbho.dll
LSP: c:\progra~1\speedb~2\sblsp.dll
LSP: c:\progra~1\netdog\netd.dll
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
TCP: {BC3C2651-01B0-4A84-9A19-3883A04043DD} = 8.8.8.8,8.8.4.4
TCP: {C1545814-0505-498A-A67A-29B464393CDB} = 8.8.8.8,8.8.4.4
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: klogon - c:\windows\system32\klogon.dll
AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll ,c:\progra~1\kasper~1\kasper~1\kloehk.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
mASetup: {A8D647C8-65AC-409F-B7B2-3C0FEE1A32F2} - c:\program files\pixiepack codec pack\InstallerHelper.exe

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\pc\applic~1\mozilla\firefox\profiles\cas2szaz.default\
FF - prefs.js: browser.search.defaulturl - hxxp://flvdirect.iamwired.net/websearch.php?src=tops&search=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.ask.com/web?o=13796&l=dis&q=
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - component: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\firefox@bandoo.com\components\FFPlugin.dll
FF - component: c:\program files\mozilla firefox\extensions\linkfilter@kaspersky.ru\components\KavLinkFilter.dll
FF - component: c:\program files\speedbit video downloader\spfirefox\components\Engine.dll
FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll
FF - plugin: c:\documents and settings\pc\application data\mozilla\firefox\profiles\cas2szaz.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\pc\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npkimi.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-10-14 36880]
R0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\drivers\tdrpm251.sys [2009-10-12 902432]
R1 16507821;16507821;c:\windows\system32\drivers\16507821.sys [2010-4-18 128016]
R1 kl1;Kl1;c:\windows\system32\drivers\kl1.sys [2009-9-1 128016]
R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2010-4-15 315408]
R1 setup_9.0.0.722_18.04.2010_13-14drv;setup_9.0.0.722_18.04.2010_13-14drv;c:\windows\system32\drivers\1650782.sys [2010-4-18 315408]
R2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\common files\acronis\cdp\afcdpsrv.exe [2009-10-31 2326920]
R2 AnukoTime;Anuko Time;c:\program files\anuko\world clock\timesync.exe [2009-11-30 241664]
R2 AVP;Kaspersky Internet Security;c:\program files\kaspersky lab\kaspersky internet security 2010\avp.exe [2009-10-20 340456]
R2 Fabs;FABS - Helping agent for MAGIX media database;c:\program files\common files\magix services\database\bin\FABS.exe [2009-8-27 1253376]
R2 HdThemeEnabler;Hyperdesk Theme Enabler;c:\program files\the skins factory\hyperdesk\common\HDThemeEnabler.exe [2008-7-23 106496]
R2 HssWd;Hotspot Shield Monitoring Service;c:\program files\hotspot shield\bin\hsswd.exe [2010-1-9 285744]
R2 StarWindServiceAE;StarWind AE Service;c:\program files\alcohol soft\alcohol 120\starwind\StarWindServiceAE.exe [2007-5-28 275968]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2009-10-30 1021256]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\speedb~2\videoacceleratorservice.exe -start -scm --> c:\progra~1\speedb~2\VideoAcceleratorService.exe -start -scm [?]
R3 afcdp;afcdp;c:\windows\system32\drivers\afcdp.sys [2009-10-31 159168]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-9-14 32272]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-10-2 19472]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]
R3 NTProcDrv;Process creation detector for NT.;c:\windows\temp\drv1.tmp [2010-5-16 3584]
R3 RRNetCapMP;RRNetCapMP;c:\windows\system32\drivers\rrnetcap.sys [2010-4-29 31848]
R3 SbieDrv;SbieDrv;c:\program files\sandboxie\SbieDrv.sys [2009-12-1 119296]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2009-10-14 10064]
S0 16507822;16507822 Boot Guard Driver;c:\windows\system32\drivers\16507822.sys --> c:\windows\system32\drivers\16507822.sys [?]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\common files\magix services\database\bin\fbserver.exe [2008-8-7 3276800]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\pc\locals~1\temp\jet320.tmp --> c:\docume~1\pc\locals~1\temp\JET320.tmp [?]
S3 PsSdk41;PsSdk41;c:\windows\system32\drivers\pssdk41.sys [2009-12-11 36928]
S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.sys [2009-12-11 53312]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 RRNetCap;RRNetCap Service;c:\windows\system32\drivers\rrnetcap.sys [2010-4-29 31848]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\f:\ntglm7x.sys --> f:\NTGLM7X.sys [?]

============== File Associations ===============

JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1

=============== Created Last 30 ================

2010-05-16 18:05:09 0 d-----w- c:\docume~1\pc\applic~1\WinPatrol
2010-05-16 18:05:01 0 d-----w- c:\program files\BillP Studios
2010-05-15 01:12:50 0 d-----w- c:\program files\EASEUS
2010-05-15 00:57:06 0 d-----w- c:\windows\Migo Recover Lost Data
2010-05-10 17:35:10 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-05-09 15:27:08 0 d-----w- c:\program files\JDownloader
2010-05-08 17:53:13 0 d-----w- c:\docume~1\alluse~1\applic~1\DivX
2010-05-06 23:29:59 0 d-----w- c:\docume~1\pc\applic~1\MAGIX
2010-05-06 23:27:11 0 d-----w- c:\docume~1\alluse~1\applic~1\MAGIX
2010-05-06 23:27:09 0 d-----w- c:\program files\common files\MAGIX Services
2010-05-06 22:02:41 0 d-----w- c:\documents and settings\all users\CyberLink
2010-05-06 21:59:47 0 d-----w- c:\program files\SmartSound Software
2010-05-06 21:59:47 0 d-----w- c:\docume~1\alluse~1\applic~1\SmartSound Software Inc
2010-05-06 20:12:28 38 ----a-w- c:\windows\avisplitter.ini
2010-05-06 20:12:28 165376 ----a-w- c:\windows\system32\unrar.dll
2010-05-06 20:12:27 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-05-06 20:12:27 151552 ----a-w- c:\windows\system32\ac3acm.acm
2010-05-06 20:12:25 0 d-----w- c:\program files\K-Lite Codec Pack
2010-05-06 18:29:09 654 ----a-w- C:\ma477.bin
2010-05-06 06:42:33 0 d-----w- c:\program files\Sound Doctrine
2010-05-06 06:06:00 0 d-----w- c:\docume~1\pc\applic~1\ImTOO Software Studio
2010-05-02 02:06:18 16031972 ----a-w- c:\documents and settings\pc\Desktop-1
2010-04-30 17:12:05 0 d-----w- c:\program files\PixiePack Codec Pack
2010-04-30 17:11:00 0 d-----w- c:\program files\RapidSolution
2010-04-30 17:11:00 0 d-----w- c:\docume~1\alluse~1\applic~1\RapidSolution
2010-04-30 13:25:54 0 d-----w- c:\documents and settings\pc\vw
2010-04-30 13:25:53 0 d-----w- c:\documents and settings\pc\VisualRoute
2010-04-30 13:04:50 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-04-30 12:56:31 406 ----a-w- c:\windows\system32\ioloBootDefrag.cfg
2010-04-30 12:54:03 74703 ----a-w- c:\windows\system32\mfc45.dll
2010-04-30 12:52:09 0 d-----w- c:\docume~1\pc\applic~1\iolo
2010-04-30 12:52:09 0 d-----w- c:\docume~1\alluse~1\applic~1\iolo
2010-04-28 22:11:01 37920 ----a-w- c:\windows\system32\drivers\tbhsd.sys
2010-04-28 22:10:55 31848 ----a-w- c:\windows\system32\drivers\rrnetcap.sys
2010-04-28 00:13:15 6912054 ----a-w- c:\windows\Pc.bmp
2010-04-26 22:54:05 691 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.c3
2010-04-26 22:54:05 691 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.c1
2010-04-26 22:54:05 639 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.c4
2010-04-26 22:54:05 495104 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.exe
2010-04-26 22:54:05 38368 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.c2
2010-04-26 22:54:05 370070 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.ico
2010-04-26 22:54:05 174108 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.swf
2010-04-26 22:54:05 0 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.ini
2010-04-26 22:54:04 903680 ----a-w- c:\windows\Inrumor.com ScreenSaver V.2.scr
2010-04-26 22:54:04 0 d-----w- c:\windows\Inrumor.com ScreenSaver V.2 Uninstaller
2010-04-26 22:23:28 0 d-----w- c:\program files\Premium Clock
2010-04-26 22:04:42 353592 ----a-w- c:\windows\system32\DivXControlPanelApplet.cpl
2010-04-26 18:51:25 0 d-----w- c:\docume~1\pc\applic~1\Canneverbe Limited
2010-04-26 18:51:25 0 d-----w- c:\docume~1\alluse~1\applic~1\Canneverbe Limited
2010-04-26 18:51:14 7168 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2010-04-26 17:40:53 0 d-----w- c:\program files\Ask.com
2010-04-26 11:41:33 0 d-----w- c:\program files\FileASSASSIN
2010-04-26 11:40:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-26 11:40:05 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 11:40:05 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-26 11:15:24 341504 ----a-w- c:\windows\system32\yowindow.scr
2010-04-25 14:40:08 0 d-----w- c:\program files\eMule
2010-04-25 14:19:43 32 ----a-w- c:\windows\system32\ndupoem.rst
2010-04-23 16:45:52 0 d-----w- c:\program files\Emsa Save My Work
2010-04-23 13:15:25 0 d-----w- c:\program files\SamsonSoft
2010-04-23 13:15:11 169 ----a-w- c:\windows\ultra.INI
2010-04-23 12:47:30 0 d-----w- c:\docume~1\pc\applic~1\Microsys
2010-04-23 12:47:27 0 d-----w- c:\program files\Microsys
2010-04-23 12:38:27 0 d-----w- c:\docume~1\alluse~1\applic~1\Bimesoft
2010-04-23 01:17:59 0 d-----w- c:\documents and settings\pc\Livestation
2010-04-23 01:17:59 0 d-----w- c:\docume~1\pc\applic~1\Mchid
2010-04-23 01:17:59 0 d-----w- c:\docume~1\pc\applic~1\Livestation
2010-04-23 01:17:53 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2010-04-23 01:17:53 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2010-04-23 01:17:53 0 d-----w- c:\program files\OpenAL
2010-04-23 01:17:50 0 d-----w- c:\program files\Livestation
2010-04-23 00:42:25 0 d-----w- c:\program files\NCH Software
2010-04-23 00:42:17 0 d-----w- c:\docume~1\pc\applic~1\NCH Software
2010-04-22 21:13:59 0 d-----w- c:\program files\FramePhotoEditor
2010-04-22 18:56:33 0 d-----w- c:\program files\XPCSpy
2010-04-22 11:13:42 0 d-----w- c:\docume~1\alluse~1\applic~1\ACD Systems
2010-04-22 11:13:36 0 d-----w- c:\program files\ACD Systems
2010-04-22 10:13:03 0 d-----w- c:\program files\SHOUTcast Radio Toolbar
2010-04-22 10:13:03 0 d-----w- c:\docume~1\alluse~1\applic~1\SHOUTcast Radio Toolbar
2010-04-22 09:30:28 0 d-----w- c:\program files\MediaMonkey
2010-04-22 09:22:39 0 d-----w- c:\program files\foobar2000
2010-04-20 12:10:17 2285056 ----a-w- c:\windows\system32\TUKernel.exe

==================== Find3M ====================

2010-05-10 23:08:11 230432 ----a-w- C:\PA7302.DAT
2010-05-05 14:25:11 97549 ----a-w- c:\windows\system32\drivers\klick.dat
2010-05-05 14:25:11 113933 ----a-w- c:\windows\system32\drivers\klin.dat
2010-04-26 17:37:37 53312 ----a-w- c:\windows\system32\drivers\pssdklbf.sys
2010-04-26 17:37:35 36928 ----a-w- c:\windows\system32\drivers\pssdk41.sys
2010-04-25 16:30:07 138384 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-04-25 16:25:57 215128 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-04-20 11:18:30 3088 --sha-w- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2010-04-16 18:00:00 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-04-15 05:41:31 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-03-31 11:04:15 262320 ----a-w- c:\windows\system32\ScreensPro.scr
2010-03-31 03:32:04 29184 ----a-w- c:\windows\system32\sstunst2.exe
2010-03-31 03:32:01 499200 ----a-w- c:\windows\system32\BlueAngels2005.scr
2010-03-31 03:32:01 249344 ----a-w- c:\windows\FSScrCtl.exe
2010-03-31 03:31:47 230818 ----a-w- c:\windows\system32\uninstall Binary_M.exe
2010-03-31 03:31:47 19768139 ----a-w- c:\windows\system32\Binary_M.scr
2010-03-31 03:29:23 344710 ----a-w- c:\windows\system32\uninstall Data_Sca.exe
2010-03-31 03:29:23 18070143 ----a-w- c:\windows\system32\Data_Sca.scr
2010-03-31 03:28:44 344494 ----a-w- c:\windows\system32\uninstall Disco.exe
2010-03-31 03:28:05 344494 ----a-w- c:\windows\system32\uninstall Pandemic.exe
2010-03-31 03:28:05 32404544 ----a-w- c:\windows\system32\Pandemic.scr
2010-03-31 01:58:04 133616 ------w- c:\windows\system32\pxafs.dll
2010-03-31 01:58:04 125424 ------w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58:04 123888 ------w- c:\windows\system32\pxcpyi64.exe
2010-03-27 23:28:12 996864 ----a-w- c:\windows\system32\UsefulSaver.scr
2010-03-27 23:28:12 99328 ----a-w- c:\windows\system32\ErrorReporting.dll
2010-03-17 14:32:42 286720 ----a-w- c:\windows\iun506.exe
2010-03-16 06:51:59 6432128 ----a-w- c:\windows\system32\nv4_disp.dll
2010-03-16 06:51:59 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-03-16 06:51:59 600680 ----a-w- c:\windows\system32\nvudisp.exe
2010-03-16 06:51:59 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-03-16 06:51:59 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-03-16 06:51:59 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcodins.dll
2010-03-16 06:51:59 215656 ----a-w- c:\windows\system32\nvcod.dll
2010-03-16 06:51:59 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-03-16 06:51:59 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-03-16 06:51:59 11640832 ----a-w- c:\windows\system32\nvcompiler.dll
2010-03-16 06:51:59 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-03-16 01:37:50 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-03-16 01:37:50 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-03-16 01:37:50 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-03-16 01:37:50 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-03-16 01:37:50 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-03-16 01:37:44 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-03-12 09:26:36 600680 ----a-w- c:\windows\system32\nvuninst.exe
2010-03-09 02:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-08 17:59:18 94208 ----a-w- c:\windows\system32\dpl100.dll
2010-03-08 16:42:30 13231608 ----a-w- c:\windows\system32\Blue Horizon.scr
2010-03-02 10:45:34 12633638 ----a-w- c:\windows\system32\Prismatic.scr
2010-02-21 22:31:34 13675139 ----a-w- c:\windows\system32\Nightly.scr
2010-02-21 22:29:44 21523179 ----a-w- c:\windows\system32\World Block.scr
2010-02-21 20:56:47 138056 ----a-w- c:\docume~1\pc\applic~1\PnkBstrK.sys
2010-02-21 20:56:26 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-02-21 20:56:26 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-02-20 09:50:10 19875167 ----a-w- c:\windows\system32\HiFly.scr
2010-02-20 09:41:40 16163242 ----a-w- c:\windows\system32\PatricksParticular.scr
2010-02-20 09:25:04 13539136 ----a-w- c:\windows\system32\Glas.scr
2010-02-19 23:47:50 3604480 ----a-w- c:\windows\system32\GPhotos.scr
2010-02-19 19:27:36 720384 ----a-w- c:\windows\system32\DivX.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2010-02-19 19:27:16 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2010-02-19 19:27:16 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2010-02-19 19:27:16 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2010-02-19 19:27:16 839680 ----a-w- c:\windows\system32\divx_xx11.dll

============= FINISH: 21:03:46,23 ===============

Dopuna: 18 Maj 2010 21:16

izvinjenje zaboravih da dodam i drugi fajl od DDS-a

mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Pozdrav!
Idemo na dodatnu proveru.


Preuzmi SysProt AntiRootkit sa sledeće stranice:

SysProt downlaod

Na strani koja se otvori treba kliknuti "here" link.



Raspakuj arhivu u neki folder (uputstvo), a zatim:
dvoklikom pokreni program i pređi na Log karticu;

štikliraj svih osam stavki i klikni Create log;

nakon određenog vremena će se pojaviti upit u kome treba obeležiti
Scan root drive only i kliknuti Start;

po završetku skeniranja pojaviće se obaveštenje koje treba zatvoriti klikom na OK;

izveštaj (log) će biti sačuvan u istom folderu u kome se nalazi i sam program.


Slikoviti prikaz postupka

Priloži kreirani izveštaj uz poruku korišćenjem opcije Prikači fajl.

offline
  • Pridružio: 16 Maj 2010
  • Poruke: 4

evo log, pa kad budeš imao vremena provjeri. Hvala unaprijed i izvini nisam stvarno mogao ranije postaviti log
mycity.rs/must-login.png

offline
  • magna86  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 21 Jun 2008
  • Poruke: 6103

Nista...logovi su cisti. Ovde nema malware-a. Wink

offline
  • Pridružio: 16 Maj 2010
  • Poruke: 4

u redu druže, hvala ti

Ko je trenutno na forumu
 

Ukupno su 1090 korisnika na forumu :: 46 registrovanih, 4 sakrivenih i 1040 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, Alibaba1981, antonije64, Apok, bankulen, Brana01, cavatina, ccoogg123, CikaKURE, Denaya, dijica, Dimitrije Paunovic, DonRumataEstorski, esx66, FileFinder, Frunze, gorozup, goxin, kjkszpj, kolle.the.kid, Krvava Devetka, kunktator, kybonacci, ljuba, milenko crazy north, mnn2, moldway, mrav pesadinac, MrNo, nemkea71, nikoladim, opt1, Panonsky, pein, procesor, rajkoplje, raketaš, RJ, sasa87, stegonosa, Sumadija34, suton, Toper, Trpe Grozni, Tvrtko I, virked