Windows mi ne prepoznaje User-a

2

Windows mi ne prepoznaje User-a

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja. Samo jos ovo Doktore mi objasni.Neznam sta stim?

Dopuna: 07 Jul 2008 23:04

ComboFix 08-07-05.1 - pc 2008-07-07 22:52:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.288 [GMT 2:00]
Running from: C:\Documents and Settings\pc.VARGA\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pc.VARGA\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfweltpen.dll
C:\WINDOWS\mrvtdpqe.exe
C:\WINDOWS\system32\byXQIaYS.dll_old
C:\WINDOWS\system32\cdqjcqge.dll
C:\WINDOWS\system32\RichVideoCodec.dll
C:\WINDOWS\system32\yqflguyl.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\TEMP\Local Settings\Temporary Internet Files\
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfweltpen.dll
C:\WINDOWS\mrvtdpqe.exe
C:\WINDOWS\system32\byXQIaYS.dll_old
C:\WINDOWS\system32\cdqjcqge.dll
C:\WINDOWS\system32\RichVideoCodec.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))
.

2008-07-07 22:49 . 2004-08-04 03:07 388,608 --a------ C:\WINDOWS\system32\CF5491.exe
2008-07-07 22:39 . 2008-07-07 22:39 <DIR> d--hs---- C:\found.001
2008-07-07 17:17 . 2008-07-07 17:17 <DIR> d-------- C:\Documents and Settings\TEMP
2008-07-07 17:15 . 2008-07-07 21:47 474 ---hs---- C:\WINDOWS\system32\lyuglfqy.ini
2008-07-07 17:11 . 2008-07-07 17:18 <DIR> d-------- C:\Documents and Settings\pc.VARGA
2008-07-06 23:57 . 2008-07-07 00:00 <DIR> d-------- C:\effbot.exe
2008-07-06 01:25 . 2008-07-06 01:25 244 --ah----- C:\sqmnoopt00.sqm
2008-07-06 01:25 . 2008-07-06 01:25 232 --ah----- C:\sqmdata00.sqm
2008-07-06 00:43 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-07-06 00:28 . 2008-07-06 00:28 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-06 00:24 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-07-05 02:17 . 2008-07-05 02:20 193 --a------ C:\WINDOWS\wininit.ini
2008-07-05 00:03 . 2008-07-04 23:59 691,545 --a------ C:\WINDOWS\unins000.exe
2008-07-05 00:03 . 2008-07-05 00:03 2,537 --a------ C:\WINDOWS\unins000.dat
2008-07-04 23:53 . 2008-07-05 00:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-04 23:53 . 2008-07-05 00:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-04 23:17 . 2008-07-04 23:32 <DIR> d-------- C:\Program Files\Pawn 2
2008-07-04 15:25 . 2008-07-04 15:26 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-29 12:58 . 2004-08-04 03:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-29 01:26 . 2008-06-29 01:26 <DIR> d-------- C:\Program Files\SanDisk
2008-06-28 15:11 . 2008-06-28 15:11 <DIR> d-------- C:\Program Files\Robster Productions
2008-06-26 19:43 . 2008-06-26 19:43 <DIR> d-------- C:\Program Files\Analog Devices
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a--c--- C:\WINDOWS\system32\dllcache\aec.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-26 19:29 . 2001-09-19 14:47 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a--c--- C:\WINDOWS\system32\dllcache\a3d.dll
2008-06-26 19:29 . 2001-09-19 14:47 720,896 --a------ C:\WINDOWS\system32\Audio3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a------ C:\WINDOWS\system32\a3d.dll
2008-06-26 19:21 . 2008-06-26 19:21 <DIR> d-------- C:\Program Files\VIA
2008-06-26 19:21 . 2003-10-31 05:22 77,312 -ra------ C:\WINDOWS\system32\drivers\viasraid.sys
2008-06-26 19:19 . 2003-04-15 10:59 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-06-26 19:19 . 2008-06-26 19:38 2,881 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-06-26 18:11 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-26 18:06 . 2008-06-26 18:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-26 17:44 . 2008-06-26 17:44 <DIR> d--hs---- C:\found.000
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-26 12:11 . 2008-06-26 12:12 <DIR> d-------- C:\Program Files\ScriptCryptor
2008-06-26 00:26 . 2008-07-04 18:21 <DIR> d-------- C:\Program Files\Quick Batch File Compiler
2008-06-26 00:19 . 2008-06-26 00:19 <DIR> d-------- C:\Program Files\SAGEM
2008-06-25 23:46 . 2008-06-25 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-06-25 23:45 . 2008-06-24 20:18 211 --a------ C:\boot.ini.comodofirewall
2008-06-25 23:44 . 2008-06-25 23:44 <DIR> d-------- C:\Program Files\Comodo
2008-06-25 21:31 . 2008-07-07 22:45 53 --a------ C:\biosinfo
2008-06-25 21:29 . 2006-02-15 19:15 176,128 --a------ C:\WINDOWS\autoclk.exe
2008-06-25 21:29 . 2008-06-26 00:19 990 --a------ C:\WINDOWS\adiras.ini
2008-06-25 21:22 . 2008-06-26 15:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-25 21:20 . 2008-06-25 21:20 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-06-25 21:20 . 2003-09-20 00:45 21,248 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-06-25 21:19 . 2008-06-25 21:19 <DIR> d-------- C:\Program Files\ArcSoft
2008-06-25 21:19 . 1995-08-01 13:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\WINDOWS\PixArt
2008-06-25 21:18 . 2008-07-02 15:46 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Trust
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Common Files\PCCamera
2008-06-25 21:18 . 2008-06-26 15:09 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-25 21:16 . 2008-06-25 21:16 0 --a------ C:\WINDOWS\msicpl.ini
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-25 19:17 . 2008-06-25 19:30 <DIR> d-------- C:\WINDOWS\vf_hip
2008-06-25 19:17 . 2008-06-25 19:17 32 --a------ C:\WINDOWS\go
2008-06-25 19:13 . 2008-06-25 19:30 <DIR> d-------- C:\Program Files\Hide IP Platinum
2008-06-25 18:39 . 2003-06-19 02:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-25 18:39 . 2008-07-07 00:02 376 --a------ C:\WINDOWS\ODBC.INI
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-06-25 18:36 . 2008-06-25 18:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-25 18:35 . 2008-06-25 18:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-25 18:29 . 2008-07-06 20:44 <DIR> d-------- C:\Program Files\Windows Live
2008-06-25 18:29 . 2008-06-25 18:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-25 18:28 . 2008-06-25 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-25 18:18 . 2008-06-25 18:31 <DIR> d-------- C:\Documents and Settings\pc\Contacts
2008-06-25 18:18 . 2006-09-25 01:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-06-25 18:18 . 2007-09-05 02:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-06-25 18:18 . 2007-09-21 10:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-06-25 18:18 . 2007-10-04 01:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-06-25 18:17 . 2008-06-25 18:17 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-25 18:17 . 2007-09-29 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-25 18:17 . 2007-07-25 23:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-25 18:17 . 2007-09-29 02:05 739,840 --a------ C:\WINDOWS\system32\divx.dll
2008-06-25 18:17 . 2007-03-10 21:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-25 18:17 . 2004-01-26 02:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-06-25 18:17 . 2007-09-29 02:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-06-25 18:17 . 2007-07-30 01:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-25 18:17 . 2007-07-11 02:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-25 18:16 . 2008-06-25 18:16 <DIR> d-------- C:\Program Files\Winamp
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Ahead
2008-06-25 18:15 . 2001-07-06 23:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-06-25 18:15 . 2001-07-06 21:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-06-25 18:15 . 2001-07-07 03:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-06-25 18:15 . 2001-07-09 20:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-25 18:15 . 2004-03-04 06:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-06-25 18:15 . 2000-06-26 20:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-25 18:15 . 2001-06-26 17:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-06-25 18:15 . 2004-03-04 06:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-06-25 18:14 . 2008-07-04 22:09 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-25 18:13 . 2008-06-29 01:26 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-25 18:13 . 2008-06-25 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-25 18:13 . 2008-06-25 18:13 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-25 18:12 . 2008-06-25 18:13 <DIR> d-------- C:\Program Files\CyberLink
2008-06-25 18:12 . 2008-06-25 18:11 505,392 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-06-25 18:12 . 2008-06-25 18:11 353,840 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-06-25 18:10 . 2008-07-05 16:47 <DIR> d-------- C:\Program Files\Eset
2008-06-25 18:10 . 2008-06-25 18:10 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-06-25 18:10 . 2008-06-25 18:10 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-06-25 18:10 . 2008-06-25 18:10 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-06-25 18:09 . 2008-06-25 18:09 <DIR> d-------- C:\WINDOWS\Cache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-29 00:14 90,112 ----a-w C:\WINDOWS\DUMP30c4.tmp
2008-06-25 22:19 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-24 18:26 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((( snapshot@2008-07-07_17.16.21.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 14:59:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-07 20:44:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-25 18:10 949376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 20:50 155648]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 03:15 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 04:37 69632]
"Comodo Firewall"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-06-26 12:41 1115728]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-16 16:51 7569408]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-16 16:51 86016]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 21:06 62760]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-17 04:20 91432]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 07:59 57344 C:\WINDOWS\SOUNDMAN.EXE]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-06-26 00:19:28 1205840]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2008-06-26 19:21:54 565248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 20:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 18:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
--a------ 2007-10-22 12:52 75584 C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-05-13 21:08 1271032 E:\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-25 16:10 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-04-16 16:51 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 Inspect;Comodo Network Engine;C:\WINDOWS\system32\DRIVERS\inspect.sys [2008-06-26 12:47]
R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys [2004-08-04 01:07]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 05:22]
R1 nod32drv;nod32drv;C:\WINDOWS\system32\drivers\nod32drv.sys [2008-06-25 18:10]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 09:12]
R2 RichVideo;Cyberlink RichVideo Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo.exe [2007-10-16 05:46]
R3 aeaudio;aeaudio;C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 08:15]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 22:48]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 14:13]
R3 smwdm;smwdm;C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 16:00]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 22:47]
S2 NVSvc;NVIDIA Display Driver Service;C:\WINDOWS\system32\nvsvc32.exe [2006-04-16 16:51]
S3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-07 16:15]
S3 GMSIPCI;GMSIPCI;G:\INSTALL\GMSIPCI.SYS []
S3 WpdUsb;WpdUsb;C:\WINDOWS\system32\Drivers\wpdusb.sys []

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-07-07 22:54:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-07-07 22:56:40
ComboFix-quarantined-files.txt 2008-07-07 20:56:29
ComboFix2.txt 2008-07-07 15:17:09

Pre-Run: 15,264,952,320 bytes free
Post-Run: 15,253,266,432 bytes free

250 --- E O F --- 2008-06-26 13:49:45
Setio sam se !!!

Dopuna: 07 Jul 2008 23:54

Da li mozes da mi kazes sta da izbacim iz Start Up-a.


Dopuna: 07 Jul 2008 23:59

Ovo sve podize kad upalim Pc.Da li je nesto od toga nepotrebno?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ima dosta toga nepotrebnog. Sve zavisi sta od toga koristis. Bolje nemoj da diras, da deci nesto ne pokvaris. I sacekaj dalja uputstva. Sutra cu ti ih napisati.

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Doco , ja cekam , strpljivo..

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\WINDOWS\system32\lyuglfqy.ini

DirLook::
C:\effbot.exe


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

ComboFix 08-07-08.1 - pc 2008-07-09 14:15:41.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.216 [GMT 2:00]
Running from: C:\Documents and Settings\pc.VARGA\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pc.VARGA\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\lyuglfqy.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\lyuglfqy.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.

2008-07-09 13:49 . 2008-07-09 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-08 20:24 . 2008-07-08 20:24 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Ahead
2008-07-08 20:18 . 2008-07-08 20:18 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\DivX
2008-07-08 19:15 . 2008-07-08 19:15 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\AdobeUM
2008-07-08 01:47 . 2008-07-08 13:33 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Contacts
2008-07-08 00:40 . 2008-07-08 00:40 <DIR> d-------- C:\Program Files\bfgclient
2008-07-08 00:38 . 2008-07-09 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-07-08 00:24 . 2008-07-08 00:25 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Winamp
2008-07-07 23:30 . 2008-07-07 23:32 <DIR> d-------- C:\Program Files\WebPosition 4
2008-07-07 22:39 . 2008-07-07 22:39 <DIR> d--hs---- C:\found.001
2008-07-07 17:17 . 2008-07-07 17:17 <DIR> d-------- C:\Documents and Settings\TEMP
2008-07-07 17:15 . 2008-07-07 17:15 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Comodo
2008-07-07 17:11 . 2008-07-08 01:47 <DIR> d-------- C:\Documents and Settings\pc.VARGA
2008-07-06 23:57 . 2008-07-07 00:00 <DIR> d-------- C:\effbot.exe
2008-07-06 01:25 . 2008-07-06 01:25 244 --ah----- C:\sqmnoopt00.sqm
2008-07-06 01:25 . 2008-07-06 01:25 232 --ah----- C:\sqmdata00.sqm
2008-07-06 00:43 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-07-06 00:28 . 2008-07-06 00:28 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-06 00:24 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-07-05 02:17 . 2008-07-05 02:20 193 --a------ C:\WINDOWS\wininit.ini
2008-07-05 00:03 . 2008-07-04 23:59 691,545 --a------ C:\WINDOWS\unins000.exe
2008-07-05 00:03 . 2008-07-05 00:03 2,537 --a------ C:\WINDOWS\unins000.dat
2008-07-04 23:53 . 2008-07-05 00:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-04 23:53 . 2008-07-05 00:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-04 23:17 . 2008-07-04 23:32 <DIR> d-------- C:\Program Files\Pawn 2
2008-07-04 15:25 . 2008-07-04 15:26 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-29 12:58 . 2004-08-04 03:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-29 01:26 . 2008-06-29 01:26 <DIR> d-------- C:\Program Files\SanDisk
2008-06-28 15:11 . 2008-06-28 15:11 <DIR> d-------- C:\Program Files\Robster Productions
2008-06-26 19:43 . 2008-06-26 19:43 <DIR> d-------- C:\Program Files\Analog Devices
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a--c--- C:\WINDOWS\system32\dllcache\aec.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-26 19:29 . 2001-09-19 14:47 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a--c--- C:\WINDOWS\system32\dllcache\a3d.dll
2008-06-26 19:29 . 2001-09-19 14:47 720,896 --a------ C:\WINDOWS\system32\Audio3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a------ C:\WINDOWS\system32\a3d.dll
2008-06-26 19:21 . 2008-06-26 19:21 <DIR> d-------- C:\Program Files\VIA
2008-06-26 19:21 . 2003-10-31 05:22 77,312 -ra------ C:\WINDOWS\system32\drivers\viasraid.sys
2008-06-26 19:19 . 2003-04-15 10:59 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-06-26 19:19 . 2008-06-26 19:38 2,881 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-06-26 18:11 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-26 18:06 . 2008-06-26 18:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-26 17:44 . 2008-06-26 17:44 <DIR> d--hs---- C:\found.000
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-26 12:11 . 2008-06-26 12:12 <DIR> d-------- C:\Program Files\ScriptCryptor
2008-06-26 00:26 . 2008-07-04 18:21 <DIR> d-------- C:\Program Files\Quick Batch File Compiler
2008-06-26 00:19 . 2008-06-26 00:19 <DIR> d-------- C:\Program Files\SAGEM
2008-06-25 23:46 . 2008-06-25 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-06-25 23:45 . 2008-06-24 20:18 211 --a------ C:\boot.ini.comodofirewall
2008-06-25 23:44 . 2008-06-25 23:44 <DIR> d-------- C:\Program Files\Comodo
2008-06-25 21:31 . 2008-07-09 12:20 53 --a------ C:\biosinfo
2008-06-25 21:29 . 2006-02-15 19:15 176,128 --a------ C:\WINDOWS\autoclk.exe
2008-06-25 21:29 . 2008-06-26 00:19 990 --a------ C:\WINDOWS\adiras.ini
2008-06-25 21:22 . 2008-06-26 15:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-25 21:20 . 2008-06-25 21:20 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-06-25 21:20 . 2003-09-20 00:45 21,248 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-06-25 21:19 . 2008-06-25 21:19 <DIR> d-------- C:\Program Files\ArcSoft
2008-06-25 21:19 . 1995-08-01 13:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\WINDOWS\PixArt
2008-06-25 21:18 . 2008-07-02 15:46 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Trust
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Common Files\PCCamera
2008-06-25 21:18 . 2008-06-26 15:09 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-25 21:16 . 2008-06-25 21:16 0 --a------ C:\WINDOWS\msicpl.ini
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-25 19:17 . 2008-06-25 19:30 <DIR> d-------- C:\WINDOWS\vf_hip
2008-06-25 19:17 . 2008-06-25 19:17 32 --a------ C:\WINDOWS\go
2008-06-25 19:13 . 2008-06-25 19:30 <DIR> d-------- C:\Program Files\Hide IP Platinum
2008-06-25 18:39 . 2003-06-19 02:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-25 18:39 . 2008-07-07 00:02 376 --a------ C:\WINDOWS\ODBC.INI
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-06-25 18:36 . 2008-06-25 18:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-25 18:35 . 2008-06-25 18:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-25 18:29 . 2008-07-06 20:44 <DIR> d-------- C:\Program Files\Windows Live
2008-06-25 18:29 . 2008-06-25 18:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-25 18:28 . 2008-06-25 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-25 18:18 . 2008-06-25 18:31 <DIR> d-------- C:\Documents and Settings\pc\Contacts
2008-06-25 18:18 . 2006-09-25 01:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-06-25 18:18 . 2007-09-05 02:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-06-25 18:18 . 2007-09-21 10:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-06-25 18:18 . 2007-10-04 01:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-06-25 18:17 . 2008-06-25 18:17 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-25 18:17 . 2007-09-29 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-25 18:17 . 2007-07-25 23:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-25 18:17 . 2007-09-29 02:05 739,840 --a------ C:\WINDOWS\system32\divx.dll
2008-06-25 18:17 . 2007-03-10 21:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-25 18:17 . 2004-01-26 02:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-06-25 18:17 . 2007-09-29 02:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-06-25 18:17 . 2007-07-30 01:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-25 18:17 . 2007-07-11 02:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-25 18:16 . 2008-06-25 18:16 <DIR> d-------- C:\Program Files\Winamp
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Ahead
2008-06-25 18:15 . 2001-07-06 23:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-06-25 18:15 . 2001-07-06 21:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-06-25 18:15 . 2001-07-07 03:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-06-25 18:15 . 2001-07-09 20:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-25 18:15 . 2004-03-04 06:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-06-25 18:15 . 2000-06-26 20:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-25 18:15 . 2001-06-26 17:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-06-25 18:15 . 2004-03-04 06:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-06-25 18:14 . 2008-07-04 22:09 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-25 18:13 . 2008-06-29 01:26 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-25 18:13 . 2008-06-25 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-25 18:13 . 2008-06-25 18:13 664 --a------ C:\WINDOWS\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-07 22:40 0 ----a-w C:\Program Files\temp01
2008-06-29 00:14 90,112 ----a-w C:\WINDOWS\DUMP30c4.tmp
2008-06-25 22:19 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-24 18:26 --------- d-----w C:\Program Files\microsoft frontpage
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\effbot.exe ----



((((((((((((((((((((((((((((( snapshot@2008-07-07_17.16.21.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 14:59:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-09 10:19:44 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-02-22 21:41:12 304,544 ----a-w C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:07 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-25 18:10 949376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 20:50 155648]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 03:15 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 04:37 69632]
"Comodo Firewall"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-06-26 12:41 1115728]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-16 16:51 7569408]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-16 16:51 86016]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-17 04:20 91432]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 03:07 158208]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 07:59 57344 C:\WINDOWS\SOUNDMAN.EXE]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-06-26 00:19:28 1205840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 2007-10-11 21:06 62760 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 20:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 18:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
--a------ 2007-10-22 12:52 75584 C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-05-13 21:08 1271032 E:\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-25 16:10 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-04-16 16:51 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 05:22]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 09:12]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 22:48]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 22:47]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-07-09 14:19:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-07-09 14:21:26
ComboFix-quarantined-files.txt 2008-07-09 12:20:54
ComboFix2.txt 2008-07-07 20:56:42
ComboFix3.txt 2008-07-07 15:17:09

Pre-Run: 15,118,741,504 bytes free
Post-Run: 15,131,906,048 bytes free

238 --- E O F --- 2008-06-26 13:49:45
Evo doktore..

Dopuna: 09 Jul 2008 14:28

Ne rece mi nista za Start Up??

Dopuna: 09 Jul 2008 21:13

Doco sta za Start Up,a?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ne mogu ti tacno reci sta ti treba, a sta ne. To je pitanje za neku drugu temu, u podforumu windows.

Dopuna: 09 Jul 2008 23:02

Imas li jos tih problema sa korisnickim nalozima?

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Ne,hvala ti puno,znaci idem u podforum windows.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Hvala ti Helen 1., spasio si me muka a i para.Ovde za gazenje PC-a traze 20Eur.Hvala jos jednom.Pozzz.

Ko je trenutno na forumu
 

Ukupno su 933 korisnika na forumu :: 52 registrovanih, 6 sakrivenih i 875 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Rade, A.R.Chafee.Jr., amstel, Andrija357, Apok, babaroga, BlekMen, bojcistv, Boris90, Bubimir, cenejac111, Dimitrise93, djordjekec, Dorcolac, Duh sa sekirom, dule10savic, esx66, HrcAk47, Istman, ivan1973, Kibice, kolle.the.kid, Koridor, Kubovac, kunktator, Luka Blažević, Marko Marković, mercedesamg, Mercury, Milometer, mrvica78, Nemanja.M, Nobunaga, panonski mornar, pein, prashinar, randja26, Ripanjac, Sirius, slonic_tonic, sombrero, Steeeefan, t84dar, Tandrkalo, theNedjeljko, uruk, vathra, Vatreni Zmaj, Vlada1389, vobo, šumar bk2, žeks62