treba mi pomoc u vezi hjt loga.... :)

2

treba mi pomoc u vezi hjt loga.... :)

offline
  • Pridružio: 12 Jan 2009
  • Poruke: 8

ComboFix 09-01-11.04 - User 2009-01-12 19:58:58.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.76 [GMT 1:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\User\Desktop\CFScript.txt
AV: ESET NOD32 antivirus system 2.70 *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\docume~1\user\applic~1\4sectmix\bindballwindow.exe
c:\windows\system32\wmplayer.exe
c:\windows\tasks\A816A49992595B11.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\docume~1\ALLUSE~1\APPLIC~1\Frag great bend logo
c:\docume~1\User\APPLIC~1\4SectMix
c:\docume~1\User\APPLIC~1\4SectMix\0
c:\docume~1\User\APPLIC~1\4SectMix\bind ball window.exe
c:\docume~1\User\APPLIC~1\4SectMix\erqkrtcm.exe
c:\docume~1\User\APPLIC~1\4SectMix\ixwoqcag.exe
c:\docume~1\User\APPLIC~1\4SectMix\lgygynzc.exe
c:\windows\system32\wmplayer.exe
c:\windows\tasks\A816A49992595B11.job

.
((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-12 17:45 . 2009-01-12 17:46 <DIR> d-------- C:\Lop SD
2009-01-11 23:38 . 2009-01-12 13:16 <DIR> d-------- C:\HJT
2009-01-11 01:24 . 2009-01-11 01:28 332 --a------ c:\windows\desctemp.dat
2009-01-10 16:02 . 2009-01-10 16:02 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-01-10 09:59 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-01-10 09:59 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-01-10 09:59 . 2008-02-06 03:21 23,832 -ra------ c:\windows\system32\drivers\lvuvcflt.sys
2009-01-10 09:59 . 2009-01-12 13:05 0 --a------ c:\windows\system32\drivers\logiflt.iad
2009-01-10 09:58 . 2009-01-10 09:58 <DIR> d-------- c:\documents and settings\User\Application Data\Leadertech
2009-01-10 09:58 . 2009-01-10 09:58 127,034 -r------- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-01-10 09:54 . 2009-01-10 09:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logishrd
2009-01-10 09:53 . 2009-01-10 09:58 <DIR> d-------- c:\program files\Logitech
2009-01-10 09:53 . 2009-01-10 10:00 <DIR> d-------- c:\program files\Common Files\LogiShrd
2009-01-10 09:53 . 2009-01-10 09:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\Logitech
2009-01-07 01:11 . 2009-01-07 23:59 <DIR> d-------- c:\program files\PC Health Plan
2009-01-07 00:56 . 2009-01-07 00:56 <DIR> d-------- c:\program files\CleanMyPC
2009-01-06 21:30 . 2009-01-06 21:30 <DIR> d-------- c:\windows\EasyDecrypter v1.12
2009-01-06 21:30 . 2009-01-06 21:30 <DIR> d-------- c:\program files\EasyDecrypter v1.12
2009-01-06 21:30 . 2008-12-17 20:27 217 --a------ c:\windows\clean.vbs
2009-01-06 21:30 . 2008-12-17 20:34 149 --a------ c:\windows\clean1.bat
2009-01-06 21:30 . 2008-12-17 20:28 28 --a------ c:\windows\clean2.bat
2009-01-05 23:10 . 2009-01-05 23:10 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-05 23:02 . 2009-01-06 11:42 <DIR> d-------- c:\program files\NOS
2009-01-05 23:02 . 2009-01-06 11:42 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-01-05 22:55 . 2009-01-05 22:56 <DIR> d-------- c:\windows\system32\Adobe
2009-01-01 20:04 . 2009-01-01 20:06 <DIR> d-------- c:\program files\Xilisoft
2008-12-29 14:05 . 2002-11-21 15:07 765,952 --a------ c:\windows\system\crlds3d.dll
2008-12-29 14:05 . 2003-11-13 15:05 481,596 --a------ c:\windows\system32\drivers\ALCXWDM.SYS
2008-12-29 14:05 . 2003-11-13 19:25 391,680 --a------ c:\windows\system32\drivers\ALCXSENS.SYS
2008-12-29 14:05 . 2003-11-21 16:58 208,896 --------- c:\windows\alcupd.exe
2008-12-29 14:05 . 2002-02-05 13:54 141,016 --a------ c:\windows\system32\ALSNDMGR.WAV
2008-12-29 14:05 . 2003-11-21 16:56 139,264 --------- c:\windows\alcrmv.exe
2008-12-29 14:05 . 2003-08-19 19:36 65,536 --a------ c:\windows\system32\Audio3D.dll
2008-12-29 14:05 . 2003-08-19 19:36 65,536 --a------ c:\windows\system32\a3d.dll
2008-12-29 06:00 . 1999-10-29 02:08 34,551 --a------ c:\windows\system32\drivers\VIAUDIO.SYS
2008-12-29 05:53 . 2008-12-29 05:53 7,680 --ahs---- c:\windows\Thumbs.db
2008-12-29 05:53 . 2008-12-29 05:53 5,632 --ahs---- C:\Thumbs.db
2008-12-29 01:52 . 2008-12-29 01:52 <DIR> d-------- c:\windows\system32\Lang
2008-12-29 01:49 . 2008-07-15 13:58 524,288 --a------ c:\windows\RtlExUpd.dll
2008-12-29 01:49 . 2008-12-29 01:49 319,488 --a------ c:\windows\HideWin.exe
2008-12-28 23:45 . 2008-12-28 23:45 <DIR> d-------- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2008-12-28 23:17 . 2008-12-28 23:19 21 --a------ c:\windows\CMISETUP.INI
2008-12-28 12:13 . 2008-12-28 12:13 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Softland
2008-12-28 12:10 . 2008-12-28 12:10 <DIR> d-------- c:\program files\Softland
2008-12-28 12:10 . 2008-12-02 12:11 20,632 --a------ c:\windows\system32\dopdfmn6.dll
2008-12-28 12:10 . 2008-12-02 12:11 18,072 --a------ c:\windows\system32\dopdfmi6.dll
2008-12-28 12:10 . 2008-10-13 15:23 7,533 --a------ c:\windows\system32\dopdf6.ctm
2008-12-28 12:09 . 2008-12-28 12:09 1,674,392 --a------ c:\program files\dopdf.exe
2008-12-18 02:29 . 2004-02-24 03:42 1,386,496 --a------ c:\windows\system32\msvbvm60.dll
2008-12-18 02:29 . 2002-12-20 23:02 1,077,336 --a------ c:\windows\system32\MSCOMCTL.OCX
2008-12-18 02:29 . 2006-11-02 15:34 547,840 --a------ c:\windows\system32\wiaaut.dll
2008-12-18 02:29 . 2007-06-04 23:10 132,880 --a------ c:\windows\system32\MSINET.OCX
2008-12-18 02:29 . 2005-06-06 20:31 108,336 --a------ c:\windows\system32\Mswinsck.ocx
2008-12-18 02:29 . 2008-01-31 12:15 102,400 --a------ c:\windows\system32\DinkITXPUIMenus.ocx
2008-12-18 02:29 . 2003-04-05 19:19 65,536 --a------ c:\windows\system32\EnhSliderOcx.ocx
2008-12-18 02:29 . 2008-02-04 04:55 64,000 --a------ c:\windows\system32\wiaaut.oca
2008-12-13 23:52 . 2008-12-13 23:52 <DIR> d-------- c:\program files\Apple Software Update
2008-12-13 23:50 . 2008-12-28 00:07 <DIR> d-------- c:\program files\Common Files\Apple
2008-12-13 23:43 . 2008-12-13 23:43 68,756,776 --a------ c:\program files\iTunesSetup.exe
2008-12-13 00:36 . 2009-01-08 00:50 <DIR> d-------- C:\Downloads

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-12 19:03 --------- d-----w c:\documents and settings\User\Application Data\SlimBrowser
2009-01-12 12:06 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-12 12:05 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2009-01-12 10:37 --------- d-----w c:\documents and settings\User\Application Data\SolidDocuments
2009-01-11 18:51 --------- d-----w c:\program files\Winamp Remote
2009-01-11 16:18 --------- d-----w c:\windows\system32\config\systemprofile\Application Data\SolidDocuments
2009-01-11 14:10 --------- d-----w c:\documents and settings\User\Application Data\Skype
2009-01-11 09:40 --------- d-----w c:\documents and settings\User\Application Data\skypePM
2009-01-10 18:48 --------- d-----w c:\documents and settings\All Users\Application Data\OrbNetworks
2009-01-10 08:58 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-05 22:10 --------- d-----w c:\program files\Common Files\Adobe
2009-01-05 22:02 --------- d-----w c:\program files\SlimBrowser
2008-12-29 18:07 --------- d-----w c:\documents and settings\User\Application Data\Eltima Software
2008-12-28 22:52 --------- d-----w c:\program files\Common Files\Download Manager
2008-12-27 20:39 --------- d-----w c:\program files\Musicnotes
2008-12-27 20:35 --------- d-----w c:\program files\CyberLink
2008-12-27 20:28 --------- d-----w c:\program files\Yahoo!
2008-12-27 20:28 --------- d-----w c:\documents and settings\User\Application Data\Yahoo!
2008-12-27 20:28 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-13 22:57 --------- d-----w c:\program files\Bonjour
2008-12-13 22:56 --------- d-----w c:\program files\QuickTime
2008-12-12 23:50 --------- d-----w c:\documents and settings\User\Application Data\Nokia
2008-11-29 11:47 --------- d-----w c:\program files\LimeWire
2008-11-12 18:19 --------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-12 17:53 --------- d-----w c:\program files\Common Files\Macrovision Shared
2008-10-23 12:51 284,160 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-03-29 22:02 81,920 ----a-w c:\documents and settings\User\Application Data\ezpinst.exe
2008-03-29 22:02 47,360 ----a-w c:\documents and settings\User\Application Data\pcouffin.sys
2007-12-26 00:32 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
1990-11-07 22:17 178,290 ----a-w c:\program files\PREF.EXE
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"Orb"="c:\program files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 495616]
"Registry Cleaner Scheduler"="c:\program files\CleanMyPC\Registry Cleaner\RCHelper.exe" [2009-01-07 471650]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2007-07-11 949376]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 227328]
"DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-04-01 36352]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-11-06 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 564496]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 2196240]
"SoundMan"="SOUNDMAN.EXE" [2003-11-13 c:\windows\SOUNDMAN.EXE]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 217193]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-08 113664]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-01-10 66864]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck smrgdf c:\documents and settings\User\Application Data\iolo\\0lsdelete

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Documents and Settings\\User\\Shared\\Skype.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype-2.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\SlimBrowser\\sbrowser.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24358:TCP"= 24358:TCP:BitComet 24358 TCP
"24358:UDP"= 24358:UDP:BitComet 24358 UDP

R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2007-07-11 15424]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service;c:\program files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 UPnPService;UPnPService;c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe --> c:\program files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [?]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchMigratedDefaultURL = [Link mogu videti samo ulogovani korisnici]{searchTerms}&ei=utf-8&fr=b1ie7
mSearch Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
Handler: ic32pp - {BBCA9F81-8F4F-11D2-90FF-0080C83D3571} - c:\windows\wc98pp.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-01-12 20:02:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(840)
c:\windows\system32\imon.dll
.
Completion time: 2009-01-12 20:07:05
ComboFix-quarantined-files.txt 2009-01-12 19:06:53
ComboFix2.txt 2009-01-12 14:01:43

Pre-Run: 1.455.431.680 bytes free
Post-Run: 1,458,483,200 bytes free

229 --- E O F --- 2009-01-10 15:02:27



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8653
  • Gde živiš: Novi Beograd

Kakvo je sad stanje na kompu?



offline
  • Pridružio: 12 Jan 2009
  • Poruke: 8

evo restartovala sam ga, i vise se ne pojavljuje onaj prozor! Very Happy hvala puno! Smile

odsad cu ovde da dolazim cim naidjem na neke probleme Wink

pozz!

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8653
  • Gde živiš: Novi Beograd

Uradi jos ovo:

Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore


Ako bude problema, javi se.

offline
  • Pridružio: 12 Jan 2009
  • Poruke: 8

evo, opet ja... primetila sam da mi se sve cesce pojavljuje prozorcic (sad konkretno kad sam otvarala BitComet) sa ovim detaljima:

Application popup: UPNP.exe - Application Error : The exception unknown software exception (0xc0000409) occurred in the application at location 0x0044bd8d.

evo uradila sam i hjt scan ako kojim slucajem zatreba, a evo loga:

Logfile of HijackThis v1.99.1
Scan saved at 21:25:30, on 13.1.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Winamp Remote\bin\Orb.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\SlimBrowser\sbrowser.exe
C:\HJT\P84.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - D:\Program files (web design)\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Solid Converter PDF - {259F616C-A300-44F5-B04A-ED001A26C85C} - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\ExploreExtPDF.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - D:\Program files (web design)\/Adobe Contribute CS3/contributeieplugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCHelper.exe" /startup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &D&ownload &with BitComet - [Link mogu videti samo ulogovani korisnici]\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - [Link mogu videti samo ulogovani korisnici]\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - [Link mogu videti samo ulogovani korisnici]\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - [Link mogu videti samo ulogovani korisnici]\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - [Link mogu videti samo ulogovani korisnici]
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: SolidPDFConverterReadSpool (ScReadSpool) - VoyagerSoft, LLC - C:\Program Files\SolidDocuments\SolidConverterPDF\SCPDF\SolidPdfService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: UPnPService - Unknown owner - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe (file missing)

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8653
  • Gde živiš: Novi Beograd

Log je cist.

Puko je BitComet.

Ko je trenutno na forumu
 

Ukupno su 767 korisnika na forumu :: 55 registrovanih, 8 sakrivenih i 704 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Ailton, aleph_one, ALEXV, Andrija357, ArchaBasha, Bane san, blue, bobomicek, Bojcca, bokicacar, Bubimir, Cirkon, debeli, dinamik, Dorcolac, dule10savic, Giskard, Great White, hellenic, Hitri, IQ116, Ir, ivicasimo, Jaxupa, Jozo74, KizJ, krokodokodil, laurusri, mexo, mikoyan21, misaru, MK10, Mrav Obrad, nixos, Njubara, oldusername, Orc, Parker, peraklio, Pilence, PrincipL, Remarqe, royst33, ruma, S-lash, Sale0501, singa, Skakac7, skok, they live, Tricko4190, Vanderx, Vlada78, volimpivuvolimrakiju, WerWolf14