problem...eksplorasi.exe

problem...eksplorasi.exe

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:35:56, on 18.3.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Eset\nod32kui.exe
C:\Documents and Settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\r\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
C:\Documents and Settings\r\Desktop\New Folder\TR3.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [Link mogu videti samo ulogovani korisnici]
F2 - REG:system.ini: Shell=Explorer.exe "C:\WINDOWS\eksplorasi.exe"
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_6_2_0.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Remote Control.lnk = C:\Program Files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe
O8 - Extra context menu item: &Google Search - [Link mogu videti samo ulogovani korisnici]\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - [Link mogu videti samo ulogovani korisnici]\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - [Link mogu videti samo ulogovani korisnici]\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - [Link mogu videti samo ulogovani korisnici]\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - [Link mogu videti samo ulogovani korisnici]\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{4DF4C82B-7802-4FEB-9736-94EB6BA84D78}: NameServer = 213.244.255.2,213.244.255.3
O18 - Protocol: bw+0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {716A5C18-52C0-4F08-876D-C389343130DE} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2009.SP1\RpcAgentSrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 19245 bytes



offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

* Otvori Nod32 Control Center (Klik na njegovu tray ikonicu ( ) u donjem desnom uglu ekrana).
* Izaberi AMON iz Threat Protection grupe opcija.
* Na desnom panelu deštikliraj opciju File system monitor (AMON) enabled.
* Gašenje ove opcije pokazaće se kroz promenu boje Control Center-a iz zelene u crvenu.

Napomena: Ne zaboravi da uključiš ovu opciju po završetku čišćenja.


Skini ComboFix sa jedne od sledecih adresa na Desktop:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.



offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

Evo odradio sam sve po uputstvu....
ComboFix 09-03-15.01 - r 2009-03-18 20:08:38.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2544 [GMT 1:00]
Running from: c:\documents and settings\r\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt

.
((((((((((((((((((((((((( Files Created from 2009-02-18 to 2009-03-18 )))))))))))))))))))))))))))))))
.

2009-03-18 19:56 . 2009-03-18 19:56 25 --a------ c:\windows\cdplayer.ini
2009-03-18 19:55 . 2009-03-18 19:55 <DIR> d-------- c:\program files\Common Files\xing shared
2009-03-18 13:58 . 2009-03-18 13:58 <DIR> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-03-18 12:47 . 2009-03-18 12:47 <DIR> d-------- c:\program files\TuneUp Utilities 2008
2009-03-18 12:47 . 2009-03-18 12:47 307,968 --a------ c:\windows\system32\TuneUpDefragService.exe
2009-03-18 12:47 . 2008-02-27 13:15 28,416 --a------ c:\windows\system32\uxtuneup.dll
2009-03-18 12:46 . 2009-03-18 12:46 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-18 12:05 . 2009-03-18 12:05 <DIR> d-------- c:\program files\Common Files\Adobe
2009-03-18 12:04 . 2009-03-18 12:05 <DIR> d-------- c:\program files\7-Zip
2009-03-16 10:54 . 2009-03-16 10:54 <DIR> d-------- c:\documents and settings\r\Application Data\Uniblue
2009-03-16 10:54 . 2009-03-16 11:39 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{6F6DBADD-35E9-42D7-82C1-1F65F2F31141}
2009-03-16 10:37 . 2009-03-16 10:37 (2) -rahs-ot- c:\windows\winstart.bat
2009-03-16 10:36 . 2009-03-18 12:45 <DIR> d-------- c:\program files\UnHackMe
2009-03-15 23:08 . 2009-03-15 23:08 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-03-15 21:41 . 2009-03-18 11:48 <DIR> d-------- c:\documents and settings\r\Tracing
2009-03-15 21:33 . 2009-03-17 12:10 <DIR> d-------- c:\program files\Microsoft Silverlight
2009-03-15 21:32 . 2009-03-15 21:32 <DIR> d-------- c:\program files\Microsoft Sync Framework
2009-03-15 21:32 . 2009-02-06 18:08 55,152 --a------ c:\windows\system32\drivers\fssfltr_tdi.sys
2009-03-15 21:31 . 2009-03-15 21:31 <DIR> d-------- c:\program files\Microsoft SQL Server Compact Edition
2009-03-15 21:27 . 2009-03-15 21:27 <DIR> d-------- c:\program files\Microsoft
2009-03-15 21:26 . 2009-03-15 21:26 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-03-15 21:07 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-03-15 21:07 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-03-15 21:07 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-03-15 16:29 . 2009-03-15 16:29 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-03-13 15:22 . 2009-03-13 15:21 512,096 --a------ c:\windows\system32\drivers\amon.sys
2009-03-13 15:22 . 2009-03-13 15:21 298,104 --a------ c:\windows\system32\imon.dll
2009-03-13 15:22 . 2009-03-13 15:21 15,424 --a------ c:\windows\system32\drivers\nod32drv.sys
2009-03-12 22:41 . 2009-03-14 23:31 <DIR> d-------- c:\program files\Eset
2009-03-12 22:40 . 2009-03-12 22:40 <DIR> d-------- c:\program files\Morton Benson
2009-03-12 22:38 . 2009-03-12 22:38 <DIR> d-------- c:\documents and settings\All Users\Application Data\GRETECH
2009-03-12 22:37 . 2009-03-12 22:37 <DIR> d-------- c:\program files\GRETECH
2009-03-12 22:37 . 2009-03-12 22:37 <DIR> d-------- c:\documents and settings\r\Application Data\GRETECH
2009-03-12 22:36 . 2009-03-12 22:37 <DIR> d-------- c:\documents and settings\r\Contacts
2009-03-12 22:34 . 2009-03-15 21:32 <DIR> d-------- c:\program files\Windows Live
2009-03-12 22:34 . 2009-03-12 22:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2009-03-12 22:34 . 2009-03-12 22:34 <DIR> d-------- c:\documents and settings\All Users\Application Data\WindowsLiveInstaller
2009-03-12 22:26 . 2009-03-18 19:53 <DIR> d-------- c:\program files\AIMP2
2009-03-11 00:37 . 2009-03-11 00:38 <DIR> d-------- c:\program files\Counter-Strike 1.6
2009-03-09 21:38 . 2009-03-18 11:52 <DIR> d-------- c:\program files\YouTube Downloader
2009-03-09 15:21 . 2009-03-09 15:21 <DIR> d-------- c:\program files\EA GAMES
2009-03-09 14:41 . 2005-05-26 15:34 2,297,552 --a------ c:\windows\system32\d3dx9_26.dll
2009-03-09 13:50 . 2006-11-29 13:06 3,426,072 --a------ c:\windows\system32\d3dx9_32.dll
2009-03-09 12:20 . 2009-03-09 12:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-03-06 02:40 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
2009-03-06 02:40 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
2009-03-06 02:40 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
2009-03-06 02:36 . 2009-03-06 02:36 <DIR> d-------- c:\program files\Flagship Studios
2009-02-28 11:27 . 2009-02-28 11:36 <DIR> d-------- c:\documents and settings\r\Application Data\Red Alert 3
2009-02-27 23:15 . 2009-02-27 23:15 <DIR> dr-h----- c:\documents and settings\r\Application Data\SecuROM
2009-02-27 23:15 . 2009-02-27 23:15 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-02-27 23:12 . 2009-02-27 23:12 <DIR> d-------- C:\ProgramData
2009-02-27 22:51 . 2009-02-27 22:51 <DIR> d-------- c:\windows\Logs
2009-02-27 22:51 . 2009-03-09 13:46 <DIR> d-------- c:\program files\Electronic Arts
2009-02-27 22:51 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
2009-02-27 22:51 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 1,358,192 --a------ c:\windows\system32\D3DCompiler_35.dll
2009-02-27 22:51 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2009-02-27 22:51 . 2007-07-19 18:14 444,776 --a------ c:\windows\system32\d3dx10_35.dll
2009-02-27 22:48 . 2009-02-28 12:08 <DIR> d-------- c:\program files\DAEMON Tools
2009-02-27 22:48 . 2009-02-27 22:48 223,128 --a------ c:\windows\system32\drivers\dtscsi.sys
2009-02-27 22:46 . 2009-02-27 22:46 642,560 --a------ c:\windows\system32\drivers\sptd.sys
2009-02-27 22:46 . 2009-02-27 22:46 96,384 --a------ c:\windows\system32\drivers\sptd2829.sys
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\windows\system32\XPSViewer
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\program files\Reference Assemblies
2009-02-25 16:22 . 2009-02-25 16:22 <DIR> d-------- c:\program files\MSBuild
2009-02-25 16:22 . 2008-07-06 13:06 1,676,288 --------- c:\windows\system32\xpssvcs.dll
2009-02-25 16:22 . 2008-07-06 13:06 1,676,288 -----c--- c:\windows\system32\dllcache\xpssvcs.dll
2009-02-25 16:22 . 2008-07-06 11:50 597,504 -----c--- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-02-25 16:22 . 2008-07-06 13:06 575,488 --------- c:\windows\system32\xpsshhdr.dll
2009-02-25 16:22 . 2008-07-06 13:06 575,488 -----c--- c:\windows\system32\dllcache\xpsshhdr.dll
2009-02-25 16:22 . 2008-07-06 13:06 117,760 --------- c:\windows\system32\prntvpt.dll
2009-02-25 16:22 . 2008-07-06 13:06 89,088 -----c--- c:\windows\system32\dllcache\filterpipelineprintproc.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-18 18:55 499,712 ----a-w c:\windows\system32\msvcp71.dll
2009-03-18 18:55 348,160 ----a-w c:\windows\system32\msvcr71.dll
2009-03-18 18:55 --------- d-----w c:\program files\Google
2009-03-18 18:55 --------- d-----w c:\program files\Common Files\Real
2009-03-18 13:27 --------- d-----w c:\documents and settings\r\Application Data\DNA
2009-03-18 11:14 --------- d-----w c:\program files\DNA
2009-03-18 10:59 --------- d-----w c:\program files\Common Files\ACD Systems
2009-03-18 10:59 --------- d-----w c:\program files\ACD Systems
2009-03-18 10:43 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2009-03-14 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\ACD Systems
2009-03-12 21:34 --------- d-----w c:\program files\Real
2009-02-28 09:49 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-09 11:13 1,846,784 ----a-w c:\windows\system32\win32k.sys
2009-02-06 18:03 307,576 ----a-w c:\windows\WLXPGSS.SCR
2009-01-31 17:51 --------- d-----w c:\documents and settings\r\Application Data\uTorrent
2009-01-31 17:51 --------- d-----w c:\documents and settings\r\Application Data\BitTorrent
2009-01-19 17:27 348,160 ----a-w c:\windows\MSVCR71.DLL
2009-01-19 17:27 1,060,864 ----a-w c:\windows\MFC71.DLL
2009-01-15 21:29 40,960 ----a-w c:\windows\SimTestDll.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-16 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-02-13 7557120]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-02-13 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-03-13 949376]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-18 198160]
"nwiz"="nwiz.exe" [2006-02-13 c:\windows\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Remote Control.lnk - c:\program files\KWorld Multimedia\PVR-TV 7131 Utilities\P3XRCtl.exe [2008-11-16 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"Skype"="c:\program files\Skype\Phone\Skype.exe" /nosplash /minimized
"LDM"=c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"
"Google Update"="c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RTHDCPL"=RTHDCPL.EXE
"Alcmtr"=ALCMTR.EXE
"SunJavaUpdateSched"=c:\program files\Java\j2re1.4.2_01\bin\jusched.exe
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" /hide
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe"
"PVR Agent"=c:\program files\KWorld Multimedia\PVR Plus\TVR\Scheduled.exe
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\r\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\r\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP1\\RpcAgentSrv.exe"=
"c:\\Program Files\\HeadlineViewer\\HeadlineViewer.exe"=
"c:\\Program Files\\Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2009.SP1\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-03-13 15424]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-03-15 55152]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 Cap713x;Philips Cap713x Video Capture;c:\windows\system32\drivers\Cap713x.sys [2008-11-16 672128]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2009.SP1\RpcAgentSrv.exe [2008-11-18 98488]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GUPDATE1C9A7FBBE34666
*Deregistered* - gupdate1c9a7fbbe34666

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-03-18 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-02-29 14:24]

2009-03-18 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-18 19:54]

2009-03-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-1604221776-1801674531-1003.job
- c:\documents and settings\r\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-16 17:16]
.
.
------- Supplementary Scan -------
.
mStart Page = [Link mogu videti samo ulogovani korisnici]
uInternet Connection Wizard,ShellNext = [Link mogu videti samo ulogovani korisnici]
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
LSP: c:\windows\system32\imon.dll
TCP: {4DF4C82B-7802-4FEB-9736-94EB6BA84D78} = 213.244.255.2,213.244.255.3
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\r\Application Data\Mozilla\Firefox\Profiles\hbyn7kze.default\
FF - prefs.js: browser.search.defaulturl - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\documents and settings\r\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\r\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPJPI142_01.dll
FF - plugin: c:\program files\Java\j2re1.4.2_01\bin\NPOJI610.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\npdsplay.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava11.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava12.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava13.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava14.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJava32.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPJPI142_01.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPOJI610.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nppl3260.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nprjplug.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\nprpjplug.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\NPSWF32.dll
FF - plugin: c:\program files\Opera75\Program\Plugins\npwmsdrm.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-03-18 20:09:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-220523388-1604221776-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:85,8c,d6,d2,7b,26,9a,e7,3d,ce,da,d0,93,d1,f4,8e,69,a8,db,bd,ab,46,88,
cb,ac,c5,e9,f3,56,3d,b6,ed,68,d3,9d,3d,ea,5a,c3,97,24,67,2f,5b,26,b5,38,ba,\
"??"=hex:c6,62,71,0d,95,d7,ac,ca,4b,29,9e,7f,d2,e7,aa,ce

[HKEY_USERS\S-1-5-21-220523388-1604221776-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:58,10,20,8e,48,41,ba,73,84,b4,66,06,d0,cb,02,8c,df,e5,2e,aa,6b,
ce,3c,92,e6,25,1e,f3,14,a6,9f,14,3c,40,7a,09,f0,89,2c,d0,ed,8e,81,c7,af,61,\
"rkeysecu"=hex:11,79,f5,16,ea,f6,a8,bf,e1,75,3d,09,2b,6a,29,25
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(1012)
c:\windows\system32\imon.dll
.
Completion time: 2009-03-18 20:10:19
ComboFix-quarantined-files.txt 2009-03-18 19:10:11

Pre-Run: 11.546.869.760 bytes free
Post-Run: 11,882,528,768 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer

265 --- E O F --- 2009-03-17 02:00:22

Dopuna: 19 Mar 2009 1:04

Sad je sve u najboljem redu.....hvala puno...nego sta da radim sad sa ovim combo fix-om...?pozdrav....

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Izvini zbog. nejavljanja... obaveze... reci cu ti sutra.. nadam se da nije problem ...

Dopuna: 19 Mar 2009 14:11

Ok ovde nema vise problematicnih fajlova tako da uradi sledece :

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


To je to...

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

eheeej....ma sve u redu hvala puno...nego ovo zadnje mi mnogo komplikovano da radim.....jel nista ne smeta da ostane kako jeste.....da ne diram combo fix uopste...plasim se da ne zabrljam nesto....?

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Ovaaj.. to deluje komplikovano ali je zapravo vrlo jednostavno.....

Znaci : Start>Run> Combofix.exe /u pa kliknes ok....

I to je to... Ova komanda ce sve srediti i sigurno nece biti nikakvih problema Wink

offline
  • Pridružio: 18 Mar 2009
  • Poruke: 41
  • Gde živiš: NIŠ

to je tooo.....i ovo je reseno....sta da vam kazem drugo sem svaka pohvala....najjaci ste...pozdrav....

Ko je trenutno na forumu
 

Ukupno su 1012 korisnika na forumu :: 160 registrovanih, 10 sakrivenih i 842 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -Max-, Akiro, aleksandar11332, aleksandarbl, aleksmajstor, AndrejPetar, Antoni S, Aristotle2002, babaroga, baltazarxx, bax0904, Bbbggg1979, belov, bigbear, black venom, Bobrock1, Bojan198527, bojanstros9, boranin45, bounty hunters, Bozjidar87, BrusLi, BUDDAR70, Bvp, CHARLIE JA., Christianviking, cifra, Clouseau, comi, crnogorac, cyprus, Daba75, Darth Malak, Dekanovic, deki1001, deks, djboj, dnevnasoba, Dolinc, Dorcolac, Dovla 1980, dragan_mig31, drimer, Duk011, dukajov, Dzambas, Electron, ElGenius, ElvisP, Fliper, fokac, Fructo, Futurama, gale48, Georgius, Glavni Oružni, gobrad, GrobarPovratak, Grochow, hugoxz, Insan, Jablan, Jester, Jezekijel, jon istvan, Još malo pa deda, Kapetan Hadok, kibihrchak, kolateralnasteta, kondenzator, kutija11, ladro, laurusri, LeGrandCharles, Leonov, livada123, ljuba.b, loon123, lord sir giga, LostInSpaceandTime, m94j, magyar, Marko Marković, Marko1238, markolopin, Marky, Mig 29, Miki 84, Miki281, Milan A. Nikolic, Miler88, milikonst, Milovan Dinic, miodrag, mitja2512, mmelezovic, mrzimregistraciju, Natuzzi, nazgul75, Nebojsa81, neko iz mase, nelezele, nenad81, Nikola.M, NklJov123, nnovakis, Orlova, Paki, Papadubi, Pavel Medved, Pavle01, pceklic, Pero Petković, Perudin_92, Phalanx, picknick, Pilipenda, PMsnow, Poof, Prometeus, Qvazimodo, RajkoB, Remain, Remarqe, Resnica, Rok A Bit, Sale0501, samo_citam, SANDRO1973, Singidunumac, Sone1983, sparkie, spot4chulle, StalniPromatrač, stevo svinja, tamno.nebo, Tas011, Tastatura ratnik, TBoy, tehnika, The_new_Statesman, trinitrotoluen, troki1971, ujke, Vanderx, Vatreni Zmaj, vazduh, vdeki, Velibor Radoja, vladetije, vojnik švejk, wize, x011, yorov, Zgembo78, zil10, zivojin32, zlatkoa987, Zorge, Žoržo