problem s postom

1

problem s postom

offline
  • Pridružio: 18 Sep 2008
  • Poruke: 32

bobby evo log-a .

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:42, on 2008-12-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\FarStone\VirtualDrive\VDTask.exe
C:\Program Files\Di recnik\Di.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Documents and Settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Aki\Desktop\tr3 .exe\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [VirtualDrive] "C:\Program Files\FarStone\VirtualDrive\VDTask.exe" /AutoRestore
O4 - HKLM\..\Run: [Di dictionary] "C:\Program Files\Di recnik\Di.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMax] "C:\Program Files\Analog Devices\SoundMAX\SMax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BlueSoleil.lnk = ?
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Prevedi sa Di recnikom - C:\Program Files\Di recnik\diie.htm
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 7888 bytes

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

offline
  • Pridružio: 18 Sep 2008
  • Poruke: 32

ComboFix 08-11-30.02 - Aki 2008-12-01 18:02:14.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.577 [GMT 1:00]
Running from: c:\documents and settings\Aki\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Aki\Application Data\FunWebProducts
c:\windows\system32\Memman.vxd
c:\windows\system32\skinboxer43.dll

.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.

2063-09-19 06:50 . 2063-09-19 06:50 5,501 --a------ c:\windows\system32\rtclmg32.dll
2008-11-29 23:38 . 2008-11-29 23:38 <DIR> d-------- c:\program files\Blaze Media Pro
2008-11-29 23:38 . 2008-11-29 23:38 <DIR> d--h-c--- c:\documents and settings\All Users\Application Data\{DE097E60-7F86-4350-B083-1F09B6906C92}
2008-11-29 23:34 . 2008-11-29 23:34 493,568 --a------ c:\windows\aki.scr
2008-11-29 23:33 . 2008-11-29 23:33 <DIR> d-------- c:\program files\Video Screensaver Maker
2008-11-29 23:33 . 2008-11-29 23:34 <DIR> d-------- c:\documents and settings\Aki\Application Data\VSSaver
2008-11-29 23:32 . 2008-11-29 23:32 <DIR> d-------- C:\dvd2avi
2008-11-29 23:32 . 2008-11-29 23:32 <DIR> d-------- c:\documents and settings\Aki\Application Data\DVD2AVI Ripper Professional
2008-11-29 23:25 . 2008-11-29 23:25 <DIR> d-------- C:\videodvdmaker
2008-11-29 23:25 . 2008-11-29 23:25 <DIR> d-------- c:\documents and settings\Aki\Application Data\Video DVD Maker FREE
2008-11-28 15:19 . 2008-11-28 15:19 <DIR> d-------- c:\program files\ESET
2008-11-28 15:19 . 2008-11-28 15:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-11-28 11:54 . 2008-11-28 11:54 <DIR> d-------- c:\program files\DAEMON Tools Toolbar
2008-11-28 11:53 . 2008-11-28 11:54 <DIR> d-------- c:\program files\DAEMON Tools Lite
2008-11-28 11:50 . 2008-11-28 11:50 <DIR> d-------- c:\documents and settings\Aki\Application Data\DAEMON Tools
2008-11-26 16:44 . 2008-11-26 16:44 <DIR> d-------- C:\digitalvideoconverter
2008-11-26 11:52 . 2008-11-26 11:54 <DIR> d-------- c:\program files\Movie DVD Maker
2008-11-26 11:51 . 2008-11-24 06:09 <DIR> d-------- c:\program files\Movie.DVD.Maker.v2.6.1123.g3n
2008-11-23 00:12 . 2008-11-23 00:12 410,976 --a------ c:\windows\system32\deploytk.dll
2008-11-22 21:07 . 2008-11-22 21:14 <DIR> d-------- C:\My Disc.VCD
2008-11-21 10:52 . 2008-11-21 10:52 137,344 --a------ c:\windows\system32\drivers\hwpsgt.sys
2008-11-21 10:52 . 2008-11-21 10:52 9,472 --a------ c:\windows\system32\drivers\lemsgt.sys
2008-11-20 21:08 . 2008-11-28 15:29 <DIR> d-------- c:\program files\PremierOpinion
2008-11-20 19:12 . 2008-11-24 16:19 <DIR> d-------- c:\program files\Crawler
2008-11-19 22:46 . 2008-11-19 22:46 <DIR> d-------- c:\documents and settings\Aki\Application Data\Games
2008-11-19 20:14 . 2008-11-19 20:45 <DIR> d-------- c:\program files\FlashGet
2008-11-19 10:53 . 2008-11-19 10:53 <DIR> d-------- c:\program files\Raw Modders Union
2008-11-18 17:40 . 2008-11-19 20:56 <DIR> d-------- c:\program files\Crypt load
2008-11-18 12:32 . 2008-11-28 13:26 <DIR> d-------- c:\program files\Kaspersky Lab
2008-11-18 11:49 . 2008-11-18 11:49 <DIR> d-------- c:\program files\FormatFactory
2008-11-17 21:04 . 2008-11-17 21:04 2,306,113 --a------ c:\windows\system32\GPhotos.scr
2008-11-16 16:51 . 2008-11-16 16:52 <DIR> d-------- c:\program files\Any Video Converter
2008-11-16 16:51 . 2008-11-16 16:57 <DIR> d-------- c:\documents and settings\Aki\Application Data\Any Video Converter
2008-11-13 00:45 . 2008-11-13 00:45 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-11 21:25 . 2008-11-11 21:25 <DIR> d-------- c:\program files\DVD Photo Slideshow Professional
2008-11-05 11:16 . 2008-11-05 11:16 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2008-11-03 11:35 . 2008-11-03 11:35 <DIR> d-------- c:\documents and settings\Aki\Application Data\EleFun Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-29 22:11 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-28 10:50 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-11-23 18:13 --------- d-----w c:\program files\TuneUp Utilities 2006
2008-11-22 23:12 --------- d-----w c:\program files\Java
2008-11-20 20:25 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-19 19:17 --------- d-----w c:\program files\Google
2008-11-19 13:30 --------- d-----w c:\program files\Common Files\Adobe
2008-11-18 14:47 --------- d-----w c:\program files\Flash Slideshow Maker Professional
2008-11-18 11:32 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-11-16 10:28 --------- d-----w c:\program files\WinAVI Video Converter
2008-10-27 20:07 --------- d-----w c:\program files\Readon Technology
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 18:39 --------- d-----w c:\program files\AnvSoft Flash to Video Converter Professional
2008-10-23 18:38 --------- d-----w c:\program files\Common Files\AVSMedia
2008-10-23 18:38 --------- d-----w c:\program files\AVS4YOU
2008-10-23 18:18 --------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU
2008-10-23 18:18 --------- d-----w c:\documents and settings\Aki\Application Data\AVS4YOU
2008-10-23 17:59 --------- d-----w c:\program files\Anvsoft
2008-10-23 17:52 --------- d-----w c:\program files\Xvid
2008-10-22 21:05 --------- d-----w c:\documents and settings\Aki\Application Data\Skype
2008-10-21 22:36 --------- d-----w c:\program files\Magic Swf2Avi 2008
2008-10-21 22:36 --------- d-----w c:\program files\Flash SWF to GIF AVI Converter
2008-10-21 22:11 --------- d-----w c:\documents and settings\All Users\Application Data\Anvsoft
2008-10-19 09:03 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-10-19 08:52 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-17 13:51 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-17 13:16 --------- d-----w c:\documents and settings\Aki\Application Data\Software Informer
2008-10-17 10:22 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2008-10-16 18:25 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2008-10-16 18:25 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2008-10-16 09:13 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-16 09:13 --------- d-----w c:\documents and settings\Aki\Application Data\GameHouse
2008-10-14 20:49 --------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2008-10-13 22:31 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-10-13 22:24 --------- d-----w c:\program files\CCleaner
2008-10-13 22:23 --------- d-----w c:\program files\Yahoo!
2008-10-09 07:31 --------- d-----w c:\program files\Di recnik
2008-10-05 15:33 --------- d-----w c:\program files\Common Files\Java
2008-10-02 21:39 --------- d-----w c:\program files\Software Informer
2008-05-07 08:38 32 ----a-r c:\documents and settings\All Users\hash.dat
2004-11-18 12:15 1,950,208 ----a-w c:\program files\PPVIEWER.MSI
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{57BCA5FA-5DBB-45a2-B558-1755C3F6253B}"= "c:\program files\Winamp Toolbar\winamptb.dll" [2008-07-02 1267040]

[HKEY_CLASSES_ROOT\clsid\{57bca5fa-5dbb-45a2-b558-1755c3f6253b}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch.1]
[HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
[HKEY_CLASSES_ROOT\WINAMPTB.AOLTBSearch]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-17 490952]
"Google Update"="c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-30 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"VirtualDrive"="c:\program files\FarStone\VirtualDrive\VDTask.exe" [2003-09-26 98304]
"Di dictionary"="c:\program files\Di recnik\Di.exe" [2006-09-29 518144]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-30 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-23 136600]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-06-10 1447168]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 c:\windows\system32\bthprops.cpl]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BlueSoleil.lnk - c:\program files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2008-06-18 1183744]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2005-10-03 23:18 118784 c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2005-10-28 15:25 94208 c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2004-08-04 02:07 15360 c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Di dictionary]
--a------ 2006-09-29 14:23 518144 c:\program files\Di recnik\Di.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-12-05 08:11 8523776 c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-12-05 08:11 81920 c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
--a------ 2007-02-05 16:35 25370152 c:\program files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
--a------ 2005-10-03 23:18 975941 c:\program files\Acronis\TrueImage\TrueImageMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2007-12-05 08:11 1626112 c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"TUWinStylerThemeSvc"=3 (0x3)
"NVSvc"=2 (0x2)
"nSvcLog"=2 (0x2)
"nSvcIp"=2 (0x2)
"ForcewareWebInterface"=2 (0x2)
"AcrSch2Svc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"d:\\IGRICE\\War Craft\\War3.exe"=
"d:\\IGRICE\\War Craft\\Warcraft III.exe"=
"c:\\Program Files\\FarStone\\VirtualDrive\\MGR.exe"=
"c:\\Documents and Settings\\Aki\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"d:\\IGRICE\\Tap a Jam\\Counter-Strike Source\\hl2.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

R1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys [2008-06-10 34312]
R3 FVDSCSI;FVDSCSI;c:\windows\system32\DRIVERS\fvdscsi.sys [2008-07-18 60008]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\E:\NTGLM7X.sys []
S4 usnjsvc;Messenger Sharing Folders USN Journal Reader service;"c:\program files\Windows Live\Messenger\usnsvc.exe" [2007-10-18 98328]
.
Contents of the 'Scheduled Tasks' folder

2008-11-28 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2006\SystemOptimizer.exe [2005-09-21 21:35]

2008-12-01 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-30 10:34]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-DAEMON Tools - c:\program files\DAEMON Tools\daemon.exe


.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Aki\Application Data\Mozilla\Firefox\Profiles\xt6ar964.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF -: plugin - c:\documents and settings\Aki\Local Settings\Application Data\Google\Update\1.2.131.27\npGoogleOneClick6.dll
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Google\Picasa3\npPicasa3.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npigl.dll
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-12-01 18:04:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(900)
c:\windows\system32\relog_ap.dll
c:\windows\system32\imon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\rundll32.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wdfmgr.exe
.
**************************************************************************
.
Completion time: 2008-12-01 18:06:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 17:06:41

Pre-Run: 5,556,539,392 bytes free
Post-Run: 5,730,942,976 bytes free

234 --- E O F --- 2008-11-23 09:14:16

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

ComboFix kaze da je nesto popravljao. Radi li sada hotmail?

offline
  • Pridružio: 18 Sep 2008
  • Poruke: 32

poravljeno je samo preko mozille a preko msn-a kad pokusam da otvorim inbox opet nece

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Pod MSN-om podrazumevas MSN Messenger ili sta?
Ako jeste MSN Messenger, je li ti MSN Messenger otvara Internet Explorer da bi pogledao mail?

offline
  • Pridružio: 18 Sep 2008
  • Poruke: 32

otvori messenger(na njega sam mislio )internet explorer i pokusa da se loguje na sait i onda ispise "done" kao da se logovao a ostane beo ekran . Na momenat dole uspem da procitam iznad start linije nesto hidden i neki trougao ali vrlo kratko traje i ne uspem da procitam sve sto ispise iu tom momentu . zatim ostane beo ekran kao da je ucitao stranicu .

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Nemam ideju. Log je cist (ne racunajuci ono sto je ComboFix vec sredio).

Je li ti comboFix uradio restart racunara nakon ciscenja?
Ako nije, onda restartuj i probaj ponovo.

Koja ti je verzija IE-a?
Za Javu isto ne mogu da vidim koja ti je verzija.
Messenger ti je isto prilicno mator.

Probaj sa updateom tih komponenti/programa.

offline
  • Pridružio: 18 Sep 2008
  • Poruke: 32

IE je 7, java (tm)6 update 10 .Ok vazno da radi bar preko mozille hvala na potrosenom vremenu a uradicu update. da sad deinstaliram combofix?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Yup.

Skini ComboFix sa jedne od sledecih adresa na Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log (C:\ComboFix.txt) koji ces nam ovde iskopirati.

Ko je trenutno na forumu
 

Ukupno su 876 korisnika na forumu :: 37 registrovanih, 6 sakrivenih i 833 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: _Sale, A.R.Chafee.Jr., AC-DC, amonsrb, Atomski čoban, babaroga, Battlehammer, BlekMen, bojcistv, BSD, cavatina, darios, Georgius, h8propaganda, HrcAk47, Ivica1102, ksyyaj, ljuba, Lubica, Lucije Kvint, Mi lao shu, milenko crazy north, nemkea71, NoOneEver Dreams, ozzy, pein, pera12345, Rogan33, shone34, Steeeefan, stegonosa, Sumadija34, tubular, vaso1, yrraf, YU-UKI, šumar bk2