problem...eksplorasi.exe

problem...eksplorasi.exe

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:35:56, on 18.3.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Eset\nod32kui.exe
C:\Documents and Settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\r\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\Documents and Settings\r\Desktop\New Folder\TR3.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = search.live.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = search.live.com/sphome.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = yahoo.com/
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Remote Control.lnk = C:\Program Files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DF4C82B-7802-4FEB-9736-94EB6BA84D78}: NameServer = 213.244.255.2,213.244.255.3
O18 - Protocol: bw+0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP1\RpcAgentSrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 19245 bytes

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

* Otvori Nod32 Control Center (Klik na njegovu tray ikonicu ( ) u donjem desnom uglu ekrana).
* Izaberi AMON iz Threat Protection grupe opcija.
* Na desnom panelu deštikliraj opciju File system monitor (AMON) enabled.
* Gašenje ove opcije pokazaće se kroz promenu boje Control Center-a iz zelene u crvenu.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.


Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

Evo odradio sam sve po uputstvu....
ComboFix 09-03-15.01 - r 2009-03-18 20:08:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2544 [GMT 1:00]
Running from: c:\documents and settings\r\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.

2009-03-18 19:56 . 2009-03-18 19:56 25 --a------ c:\windows\cdplayer.ini
2009-03-18 19:55 . 2009-03-18 19:55 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-18 13:58 . 2009-03-18 13:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-03-18 12:47 . 2009-03-18 12:47 <DIR> d-------- c:\program files\TuneUp Utilities 2008
2009-03-18 12:47 . 2009-03-18 12:47 307,968 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-03-18 12:47 . 2008-02-27 13:15 28,416 --a------ c:\windows\system32\uxtuneup.dll
2009-03-18 12:46 . 2009-03-18 12:46 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-18 12:05 . 2009-03-18 12:05 <DIR> d-------- c:\program files\Common Files\Adobe
2009-03-18 12:04 . 2009-03-18 12:05 <DIR> d-------- c:\program files\7-Zip
2009-03-16 10:54 . 2009-03-16 10:54 <DIR> d-------- c:\documents and settings\r\Application Data\Uniblue
2009-03-16 10:54 . 2009-03-16 11:39 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{6F6DBADD-35E9-42D7-82C1-1F65F2F31141}
2009-03-16 10:37 . 2009-03-16 10:37 (2) -rahs-ot- c:\windows\winstart.bat
2009-03-16 10:36 . 2009-03-18 12:45 <DIR> d-------- c:\program files\UnHackMe
2009-03-15 23:08 . 2009-03-15 23:08 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-03-15 21:41 . 2009-03-18 11:48 <DIR> d-------- c:\documents and settings\r\Tracing
2009-03-15 21:33 . 2009-03-17 12:10 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-03-15 21:32 . 2009-03-15 21:32 <DIR> d-------- c:\program files\Microsoft Sync Framework
2009-03-15 21:32 . 2009-02-06 18:08 55,152 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys
2009-03-15 21:31 . 2009-03-15 21:31 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition
2009-03-15 21:27 . 2009-03-15 21:27 <DIR> d-------- c:\program files\Microsoft
2009-03-15 21:26 . 2009-03-15 21:26 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-15 21:07 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-15 21:07 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-15 21:07 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-15 16:29 . 2009-03-15 16:29 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-03-13 15:22 . 2009-03-13 15:21 512,096 --a------ c:\windows\system32\drivers\amon.sys
2009-03-13 15:22 . 2009-03-13 15:21 298,104 --a------ c:\windows\system32\imon.dll
2009-03-13 15:22 . 2009-03-13 15:21 15,424 --a------ c:\windows\system32\drivers\nod32drv.sys
2009-03-12 22:41 . 2009-03-14 23:31 <DIR> d-------- c:\program files\Eset
2009-03-12 22:40 . 2009-03-12 22:40 <DIR> d-------- c:\program files\Morton Benson
2009-03-12 22:38 . 2009-03-12 22:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\GRETECH
2009-03-12 22:37 . 2009-03-12 22:37 <DIR> d-------- c:\program files\GRETECH
2009-03-12 22:37 . 2009-03-12 22:37 <DIR> d-------- c:\documents and settings\r\Application Data\GRETECH
2009-03-12 22:36 . 2009-03-12 22:37 <DIR> d-------- c:\documents and settings\r\Contacts
2009-03-12 22:34 . 2009-03-15 21:32 <DIR> d-------- c:\program files\Windows Live
2009-03-12 22:34 . 2009-03-12 22:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2009-03-12 22:34 . 2009-03-12 22:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-03-12 22:26 . 2009-03-18 19:53 <DIR> d-------- c:\program files\AIMP2
2009-03-11 00:37 . 2009-03-11 00:38 <DIR> d-------- c:\program files\Counter-Strike 1.6
2009-03-09 21:38 . 2009-03-18 11:52 <DIR> d-------- c:\program files\YouTube Downloader
2009-03-09 15:21 . 2009-03-09 15:21 <DIR> d-------- c:\program files\EA GAMES
2009-03-09 14:41 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-03-09 13:50 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll
2009-03-09 12:20 . 2009-03-09 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-03-06 02:40 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2009-03-06 02:40 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2009-03-06 02:40 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2009-03-06 02:36 . 2009-03-06 02:36 <DIR> d-------- c:\program files\Flagship Studios
2009-02-28 11:27 . 2009-02-28 11:36 <DIR> d-------- c:\documents and settings\r\Application Data\Red Alert 3
2009-02-27 23:15 . 2009-02-27 23:15 <DIR> dr-h----- c:\documents and settings\r\Application Data\SecuROM
2009-02-27 23:15 . 2009-02-27 23:15 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-02-27 23:12 . 2009-02-27 23:12 <DIR> d-------- C:\ProgramData
2009-02-27 22:51 . 2009-02-27 22:51 <DIR> d-------- c:\windows\Logs
2009-02-27 22:51 . 2009-03-09 13:46 <DIR> d-------- c:\program files\Electronic Arts
2009-02-27 22:51 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
2009-02-27 22:51 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 1,358,192 --a------ c:\windows\system32\D3DCompiler_35.dll
2009-02-27 22:51 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 444,776 --a------ c:\windows\system32\d3dx10_35.dll
2009-02-27 22:48 . 2009-02-28 12:08 <DIR> d-------- c:\program files\DAEMON Tools
2009-02-27 22:48 . 2009-02-27 22:48 223,128 --a------ c:\windows\system32\drivers\dtscsi.sys
2009-02-27 22:46 . 2009-02-27 22:46 642,560 --a------ c:\windows\system32\drivers\sptd.sys
2009-02-27 22:46 . 2009-02-27 22:46 96,384 --a------ c:\windows\system32\drivers\sptd2829.sys
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\program files\MSBuild
2009-02-25 16:22 . 2008-07-06 13:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-25 16:22 . 2008-07-06 13:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-25 16:22 . 2008-07-06 11:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-25 16:22 . 2008-07-06 13:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-25 16:22 . 2008-07-06 13:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-25 16:22 . 2008-07-06 13:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-25 16:22 . 2008-07-06 13:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 18:55 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-18 18:55 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-18 18:55 --------- d-----w c:\program files\Google
2009-03-18 18:55 --------- d-----w c:\program files\Common Files\Real
2009-03-18 13:27 --------- d-----w c:\documents and settings\r\Application Data\DNA
2009-03-18 11:14 --------- d-----w c:\program files\DNA
2009-03-18 10:59 --------- d-----w c:\program files\Common Files\ACD Systems
2009-03-18 10:59 --------- d-----w c:\program files\ACD Systems
2009-03-18 10:43 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2009-03-14 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-03-12 21:34 --------- d-----w c:\program files\Real
2009-02-28 09:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 18:03 307,576 ----a-w c:\windows\WLXPGSS.SCR
2009-01-31 17:51 --------- d-----w c:\documents and settings\r\Application Data\uTorrent
2009-01-31 17:51 --------- d-----w c:\documents and settings\r\Application Data\BitTorrent
2009-01-19 17:27 348,160 ----a-w c:\windows\MSVCR71.DLL
2009-01-19 17:27 1,060,864 ----a-w c:\windows\MFC71.DLL
2009-01-15 21:29 40,960 ----a-w c:\windows\SimTestDll.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-16 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-02-13 7557120]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-02-13 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-03-13 949376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-18 198160]
"nwiz"="nwiz.exe" [2006-02-13 c:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Remote Control.lnk - c:\program files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe [2008-11-16 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"LDM"=c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"
"Google Update"="c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RTHDCPL"=RTHDCPL.EXE
"Alcmtr"=ALCMTR.EXE
"SunJavaUpdateSched"=c:\program files\Java\j2re1.4.2_01\bin\jusched.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" /hide
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe"
"PVR Agent"=c:\program files\KWorld Multimedia\PVR Plus\TVR\Scheduled.exe
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\r\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\r\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP1\\RpcAgentSrv.exe"=
"c:\\Program Files\\HeadlineViewer\\HeadlineViewer.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-03-13 15424]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-15 55152]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\drivers\Cap713x.sys [2008-11-16 672128]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP1\RpcAgentSrv.exe [2008-11-18 98488]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GUPDATE1C9A7FBBE34666
*Deregistered* - gupdate1c9a7fbbe34666

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-03-18 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]

2009-03-18 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-18 19:54]

2009-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1604221776-1801674531-1003.job
- c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-16 17:16]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.yahoo.com/
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
LSP: c:\windows\system32\imon.dll
TCP: {4DF4C82B-7802-4FEB-9736-94EB6BA84D78} = 213.244.255.2,213.244.255.3
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\r\Application Data\Mozilla\Firefox\Profiles\hbyn7kze.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\r\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\r\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJPI142_01.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPOJI610.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\npdsplay.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava11.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava12.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava13.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava14.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava32.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJPI142_01.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPOJI610.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nppl3260.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nprjplug.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPSWF32.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\npwmsdrm.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2009-03-18 20:09:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-220523388-1604221776-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:85,8c,d6,d2,7b,26,9a,e7,3d,ce,da,d0,93,d1,f4,8e,69,a8,db,bd,ab,46,88,
cb,ac,c5,e9,f3,56,3d,b6,ed,68,d3,9d,3d,ea,5a,c3,97,24,67,2f,5b,26,b5,38,ba,\
"??"=hex:c6,62,71,0d,95,d7,ac,ca,4b,29,9e,7f,d2,e7,aa,ce

[HKEY_USERS\S-1-5-21-220523388-1604221776-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:58,10,20,8e,48,41,ba,73,84,b4,66,06,d0,cb,02,8c,df,e5,2e,aa,6b,
ce,3c,92,e6,25,1e,f3,14,a6,9f,14,3c,40,7a,09,f0,89,2c,d0,ed,8e,81,c7,af,61,\
"rkeysecu"=hex:11,79,f5,16,ea,f6,a8,bf,e1,75,3d,09,2b,6a,29,25
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1012)
c:\windows\system32\imon.dll
.
Completion time: 2009-03-18 20:10:19
ComboFix-quarantined-files.txt 2009-03-18 19:10:11

Pre-Run: 11.546.869.760 bytes free
Post-Run: 11,882,528,768 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

265 --- E O F --- 2009-03-17 02:00:22

Dopuna: 19 Mar 2009 1:04

Sad je sve u najboljem redu.....hvala puno...nego sta da radim sad sa ovim combo fix-om...?pozdrav....

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Izvini zbog. nejavljanja... obaveze... reci cu ti sutra.. nadam se da nije problem ...

Dopuna: 19 Mar 2009 14:11

Ok ovde nema vise problematicnih fajlova tako da uradi sledece :

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


To je to...

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

eheeej....ma sve u redu hvala puno...nego ovo zadnje mi mnogo komplikovano da radim.....jel nista ne smeta da ostane kako jeste.....da ne diram combo fix uopste...plasim se da ne zabrljam nesto....?

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Ovaaj.. to deluje komplikovano ali je zapravo vrlo jednostavno.....

Znaci : Start>Run> Combofix.exe /u pa kliknes ok....

I to je to... Ova komanda ce sve srediti i sigurno nece biti nikakvih problema Wink

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

to je tooo.....i ovo je reseno....sta da vam kazem drugo sem svaka pohvala....najjaci ste...pozdrav....

Ko je trenutno na forumu
 

Ukupno su 478 korisnika na forumu :: 6 registrovanih, 0 sakrivenih i 472 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: alkatraz080, Fog of War, Litostroton, Mixelotti, Nobunaga, Tas011