Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
Trenutno vreme je: 15. Jul 2025, 10:26:28
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 1 gost pregledaju ovu temu.

 Napomena: Za sva pitanja u vezi kupovine novog hardware-a ili procene vrednosti i preporuke koristite - ovu temu

Spyware,sta je,kako radi,kako se zastititi? :: Kako rade mreze :: Burek Anti-virus software review :: Index tema koje ne treba propustiti

Idi dole
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: log  (Pročitano 1372 puta)
28. Apr 2009, 23:03:44
Svakodnevni prolaznik


Ne diraj me, krele! ;)

Zodijak
Pol Muškarac
Poruke 221
OS
Windows XP
Browser
Mozilla Firefox 3.0.9
Smem li da postavim log da vidite da li je sve u redu, jer su mi se pokretale neke nepoznate "stvari" prilikom podizanja sistema  i tako...
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Moderator
Svedok stvaranja istorije


necu da ti kazem, chelavi...

Zodijak Libra
Pol Muškarac
Poruke 22017
Zastava La45.2590  Lo19.8330
OS
Windows XP
Browser
Mozilla Firefox 3.0.10
mob
Apple iPhone 12, S21
budi detaljniji...kakve stvari?
skini malwarebytes antimalware odradi update i idi na quick scan, pa kada zavrsi daj log koji ti izbaci i tada daj svez hjt log...
IP sačuvana
social share
- A robot may not injure a human being or, through inaction, allow a human being to come to harm
- A robot must obey the orders given to it by human beings, except where such orders would conflict with the First Law
- A robot must protect its own existence as long as such protection does not conflict with the First or Second Laws
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Svakodnevni prolaznik


Ne diraj me, krele! ;)

Zodijak
Pol Muškarac
Poruke 221
OS
Windows XP
Browser
Mozilla Firefox 3.0.9
Anti-Malware :


Malwarebytes' Anti-Malware 1.36
Database version: 2055
Windows 5.1.2600 Service Pack 3

4/28/2009 10:27:22 PM
mbam-log-2009-04-28 (22-27-22).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 127464
Time elapsed: 19 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Dxdiag.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)








Hijackthis:




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:35:41 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

--
End of file - 5820 bytes








ComboFix:




ComboFix 09-04-27.05 - Beka and Jeka 04/28/2009 22:53.1 - NTFSx86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1535.964 [GMT 2:00]
Running from: c:\documents and settings\Beka and Jeka\Desktop\ComboFix.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
 * Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\pthreadGC2.dll

.
(((((((((((((((((((((((((   Files Created from 2009-05-28 to 2009-4-28  )))))))))))))))))))))))))))))))
.

2009-04-28 20:03 . 2009-04-28 20:03   --------   d-----w   c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-28 18:54 . 2009-04-28 18:54   --------   d-----w   c:\program files\Spybot - Search & Destroy
2009-04-28 18:54 . 2009-04-28 18:55   --------   d-----w   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-28 18:43 . 2009-04-28 18:43   --------   d-----w   c:\documents and settings\Beka and Jeka\Application Data\Malwarebytes
2009-04-28 18:43 . 2009-04-06 13:32   15504   ----a-w   c:\windows\system32\drivers\mbam.sys
2009-04-28 18:43 . 2009-04-06 13:32   38496   ----a-w   c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-28 18:43 . 2009-04-28 18:43   --------   d-----w   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-28 18:43 . 2009-04-28 18:45   --------   d-----w   c:\program files\Malwarebytes' Anti-Malware
2009-04-28 18:42 . 2009-04-28 18:42   --------   d-----w   c:\program files\NO1 DVD Ripper
2009-04-28 18:10 . 2007-05-16 14:45   443752   ----a-w   c:\windows\system32\d3dx10_34.dll
2009-04-28 18:09 . 2009-04-28 18:09   --------   d-----w   c:\documents and settings\Beka and Jeka\Local Settings\Application Data\Google
2009-04-28 14:50 . 2009-04-28 20:56   --------   d-----w   c:\documents and settings\Beka and Jeka\Tracing
2009-04-28 14:50 . 2009-04-28 14:50   --------   d-----w   c:\program files\Microsoft
2009-04-28 14:49 . 2009-04-28 14:49   --------   d-----w   c:\program files\Windows Live SkyDrive
2009-04-28 14:48 . 2006-10-26 17:56   32592   ----a-w   c:\windows\system32\msonpmon.dll
2009-04-28 14:47 . 2009-04-28 14:47   --------   d-----w   c:\program files\Microsoft Works
2009-04-28 14:47 . 2009-04-28 14:47   --------   d-----w   c:\program files\MSBuild
2009-04-28 14:46 . 2009-04-28 18:09   --------   d-----w   c:\program files\Google
2009-04-28 14:44 . 2009-04-28 14:47   --------   d-----w   c:\windows\SHELLNEW
2009-04-28 14:43 . 2009-04-28 14:43   --------   d-----w   c:\documents and settings\Beka and Jeka\Local Settings\Application Data\Microsoft Help
2009-04-28 14:43 . 2009-04-28 14:49   --------   d-----w   c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-28 14:43 . 2009-04-28 14:43   --------   d--h--r   C:\MSOCache
2009-04-28 14:40 . 2009-04-28 14:40   --------   d-----w   c:\program files\uTorrent
2009-04-28 14:40 . 2009-04-28 20:56   --------   d-----w   c:\documents and settings\Beka and Jeka\Application Data\uTorrent
2009-04-28 14:39 . 2009-04-28 14:39   --------   d-----w   c:\program files\Trend Micro
2009-04-28 14:38 . 2009-04-28 14:38   --------   d-----w   c:\program files\Common Files\Windows Live
2009-04-28 14:37 . 2009-04-28 14:37   410984   ----a-w   c:\windows\system32\deploytk.dll
2009-04-28 14:37 . 2009-04-28 14:37   --------   d-----w   c:\program files\Java
2009-04-28 14:35 . 2009-04-28 14:35   --------   d-sh--w   c:\documents and settings\Beka and Jeka\PrivacIE
2009-04-28 14:35 . 2009-04-28 14:35   --------   d-sh--w   c:\documents and settings\Beka and Jeka\IETldCache
2009-04-28 14:32 . 2009-04-28 14:32   --------   d-----w   c:\program files\YouTube Downloader
2009-04-28 14:31 . 2009-04-28 14:32   --------   dc-h--w   c:\windows\ie8
2009-04-28 08:52 . 2009-04-28 08:52   --------   d-----w   c:\documents and settings\LocalService\Application Data\Ahead
2009-04-28 00:30 . 2008-04-14 03:42   9728   ------w   c:\windows\system32\rwnh.dll
2009-04-28 00:30 . 2008-04-14 03:42   10752   ------w   c:\windows\system32\smtpapi.dll
2009-04-28 00:27 . 2009-04-28 00:27   --------   d-----w   c:\documents and settings\Beka and Jeka\Local Settings\Application Data\Opera
2009-04-28 00:27 . 2009-04-28 00:27   --------   d-----w   c:\program files\Opera
2009-04-28 00:21 . 2009-04-28 00:21   --------   d-----w   c:\windows\system32\Lang
2009-04-28 00:16 . 2009-04-28 00:25   101287   ----a-w   c:\windows\system32\drivers\klin.dat
2009-04-28 00:16 . 2009-04-28 00:25   89601   ----a-w   c:\windows\system32\drivers\klick.dat
2009-04-28 00:15 . 2009-04-28 20:56   1519648   --sha-w   c:\windows\system32\drivers\fidbox.dat
2009-04-28 00:15 . 2009-04-28 20:56   286752   --sha-w   c:\windows\system32\drivers\fidbox2.dat
2009-04-28 00:15 . 2009-04-28 00:15   --------   d-----w   c:\program files\Kaspersky Lab
2009-04-28 00:15 . 2009-04-28 20:56   --------   d-----w   c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-28 00:15 . 2009-04-28 00:15   --------   d-----w   c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-28 00:14 . 2009-04-28 14:50   --------   d-----w   c:\program files\Windows Live
2009-04-28 00:09 . 2009-04-28 00:09   0   ----a-w   c:\windows\nsreg.dat
2009-04-28 00:09 . 2009-04-28 00:09   --------   d-----w   c:\documents and settings\Beka and Jeka\Local Settings\Application Data\Mozilla

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-28 20:56 . 2009-04-28 00:15   14000   --sha-w   c:\windows\system32\drivers\fidbox.idx
2009-04-28 20:56 . 2009-04-28 00:15   3108   --sha-w   c:\windows\system32\drivers\fidbox2.idx
2009-04-28 14:51 . 2009-04-27 23:40   69232   ----a-w   c:\documents and settings\Beka and Jeka\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-28 00:25 . 2008-01-29 15:29   33808   ----a-w   c:\windows\system32\drivers\klbg.sys
2009-04-27 23:55 . 2009-04-27 23:47   --------   d-----w   c:\program files\Mv2Player
2009-04-27 23:54 . 2009-04-27 23:45   --------   d-----w   c:\program files\The KMPlayer
2009-04-27 23:50 . 2009-04-27 23:50   --------   d-----w   c:\program files\Common Files\Adobe AIR
2009-04-27 23:50 . 2009-04-27 22:10   --------   d-----w   c:\program files\Common Files\Adobe
2009-04-27 23:49 . 2009-04-27 23:49   --------   d-----w   c:\program files\CCleaner
2009-04-27 23:49 . 2009-04-27 23:48   --------   d-----w   c:\program files\K-Lite Codec Pack
2009-04-27 23:47 . 2009-04-27 23:47   --------   d-----w   c:\program files\Webteh
2009-04-27 23:46 . 2009-04-27 23:46   --------   d-----w   c:\program files\Winamp
2009-04-27 23:44 . 2009-04-27 23:44   --------   d-----w   c:\program files\Windows Media Connect 2
2009-04-27 23:38 . 2009-04-27 23:38   106928   ----a-w   c:\windows\PCHealth\HelpCtr\Config\Cache\Professional_32_1033.dat
2009-04-27 23:38 . 2009-04-27 21:37   80007   ----a-w   c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-27 23:30 . 2009-04-27 23:30   --------   d-----w   c:\program files\DAEMON Tools Pro
2009-04-27 23:28 . 2009-04-27 23:28   685816   ----a-w   c:\windows\system32\drivers\sptd.sys
2009-04-27 23:21 . 2009-04-27 23:21   --------   d-----w   c:\program files\7-Zip
2009-04-27 22:11 . 2009-04-27 22:11   --------   d-----w   c:\program files\Common Files\Adobe Systems Shared
2009-04-27 22:08 . 2009-04-27 22:03   --------   d-----w   c:\program files\Common Files\Ahead
2009-04-27 22:03 . 2009-04-27 22:03   --------   d-----w   c:\program files\Nero
2009-04-27 21:38 . 2009-04-27 21:38   --------   d-----w   c:\program files\microsoft frontpage
2009-04-27 21:38 . 2009-04-27 21:38   2678   ----a-w   c:\windows\java\Packages\Data\4IB97J37.DAT
2009-04-27 21:38 . 2009-04-27 21:38   558142   ----a-w   c:\windows\java\Packages\75RVTJ3N.ZIP
2009-04-27 21:38 . 2009-04-27 21:38   2678   ----a-w   c:\windows\java\Packages\Data\MON35N1B.DAT
2009-04-27 21:37 . 2009-04-27 21:37   2678   ----a-w   c:\windows\java\Packages\Data\U4UAEU71.DAT
2009-04-27 21:37 . 2009-04-27 21:37   2678   ----a-w   c:\windows\java\Packages\Data\F1JJB5BB.DAT
2009-04-27 21:37 . 2009-04-27 21:37   2678   ----a-w   c:\windows\java\Packages\Data\D7NB5N3X.DAT
2009-04-27 21:37 . 2009-04-27 21:37   155995   ----a-w   c:\windows\java\Packages\RFFRRXZ7.ZIP
2009-04-27 21:37 . 2001-08-23 11:00   67   --sha-w   c:\windows\Fonts\desktop.ini
2009-04-27 21:35 . 2009-04-27 21:35   21640   ----a-w   c:\windows\system32\emptyregdb.dat
2009-03-08 02:34 . 2002-08-29 01:41   914944   ----a-w   c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2002-08-29 01:41   43008   ----a-w   c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2001-08-23 11:00   18944   ----a-w   c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2002-08-29 01:41   420352   ----a-w   c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2001-08-23 11:00   72704   ----a-w   c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2002-08-29 01:40   71680   ----a-w   c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2002-08-29 01:40   34816   ----a-w   c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2002-08-29 01:39   48128   ----a-w   c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2001-08-23 11:00   45568   ----a-w   c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2001-08-23 11:00   156160   ----a-w   c:\windows\system32\msls31.dll
2009-02-09 18:56 . 2009-04-27 23:49   67584   ----a-w   c:\windows\system32\ff_vfw.dll
2009-02-06 16:52 . 2009-02-06 16:52   49504   ----a-w   c:\windows\system32\sirenacm.dll
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-08-30 139264]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-04-28 269616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-05-10 8429568]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-05-10 81920]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-28 206088]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-05-10 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-05-10 16342528]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Beka and Jeka^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Beka and Jeka\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=

S0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2009-04-28 33808]
S3 KLFLTDEV;Kaspersky Lab KLFltDev;c:\windows\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2008-04-30 24592]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-NWEReboot - (no file)


.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Beka and Jeka\Application Data\Mozilla\Firefox\Profiles\ri7ovlxy.default\
FF - prefs.js: browser.startup.homepage - www.google.com
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-28 22:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1340)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\savedump.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-28 22:58 - machine was rebooted
ComboFix-quarantined-files.txt  2009-04-28 20:58

Pre-Run: 41,505,640,448 bytes free
Post-Run: 41,500,921,856 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
197




to je to.. je l treba nesto da se fix-uje ili je sve ok?


IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Moderator
Svedok stvaranja istorije


necu da ti kazem, chelavi...

Zodijak Libra
Pol Muškarac
Poruke 22017
Zastava La45.2590  Lo19.8330
OS
Windows XP
Browser
Mozilla Firefox 3.0.10
mob
Apple iPhone 12, S21
ponekad ostanem bez reci...zaista...
procitaj moj prethodni post i reci mi gde sam pomenuo da pokreces ComboFix??  Smile Smile

upravo si ubio komarca  tako sto si bacio bombu na njega...

kakvo ti je stanje sada?
« Poslednja izmena: 28. Apr 2009, 23:39:23 od chelavi1 »
IP sačuvana
social share
- A robot may not injure a human being or, through inaction, allow a human being to come to harm
- A robot must obey the orders given to it by human beings, except where such orders would conflict with the First Law
- A robot must protect its own existence as long as such protection does not conflict with the First or Second Laws
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Svakodnevni prolaznik


Ne diraj me, krele! ;)

Zodijak
Pol Muškarac
Poruke 221
OS
Windows XP
Browser
Mozilla Firefox 3.0.9
 Smile
prijatelju ja sam odradio sve to jos pre nego sto sam postavio pitanje...
samo mi kazi da je sve okay  Smile

p.s. meni sve izgleda normalno... ali da pitam za svaki slucaj
« Poslednja izmena: 28. Apr 2009, 23:41:28 od p1ay80y »
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Trenutno vreme je: 15. Jul 2025, 10:26:28
nazadnapred
Prebaci se na:  

Poslednji odgovor u temi napisan je pre više od 6 meseci.  

Temu ne bi trebalo "iskopavati" osim u slučaju da imate nešto važno da dodate. Ako ipak želite napisati komentar, kliknite na dugme "Odgovori" u meniju iznad ove poruke. Postoje teme kod kojih su odgovori dobrodošli bez obzira na to koliko je vremena od prošlog prošlo. Npr. teme o određenom piscu, knjizi, muzičaru, glumcu i sl. Nemojte da vas ovaj spisak ograničava, ali nemojte ni pisati na teme koje su završena priča.

web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Nova godina Beograd :: nova godina restorani :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Sudski tumač Novi Beograd

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.083 sec za 14 q. Powered by: SMF. © 2005, Simple Machines LLC.