DVD video

1

DVD video

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Od kako sam instalirao ms update preko autopatchera ne mogu da pokrenem ni jedan dvd video :S
evo log-a

Logfile of HijackThis v1.99.1
Scan saved at 8:40:27 AM, on 12/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lock My PC 4\LmpcServ.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Nettalk6\Nettalk.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Opera 9\Opera.exe
C:\Documents and Settings\Dejan\Desktop\New Folder\TR3.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Save Flash - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files\Save Flash\SaveFlash.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: Append to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - [Link mogu videti samo ulogovani korisnici]\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra 'Tools' menuitem: Flash Saver - {09EA1F80-F40A-11D1-B792-444553540001} - C:\PROGRA~1\FLASHS~1\save.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - [Link mogu videti samo ulogovani korisnici]
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - [Link mogu videti samo ulogovani korisnici]
O17 - HKLM\System\CCS\Services\Tcpip\..\{F0DCE0F0-10E9-4651-AF14-5D9026F052B0}: NameServer = 77.105.0.19 77.105.0.18
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: fsp_lmwl - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" -r (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lock My PC Service (LmpcService) - Unknown owner - C:\Program Files\Lock My PC 4\LmpcServ.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...

Pomenuti problem nema veze sa malware-om, no u postavljenom logu se vide tragovi infekcije.


Upload-uj mi: C:\WINDOWS\system32\__c0021F10.dat

preko sledeće forme: [Link mogu videti samo ulogovani korisnici]


-------------------------------------------------------------------------------------


Skini ComboFix sa jedne od sledecih adresa:
[Link mogu videti samo ulogovani korisnici]
[Link mogu videti samo ulogovani korisnici]

Startuj ga i ne diraj prozor programa dok skenira.
Sledi uputstva na ekranu. Kada zavrsi pojavice se log koji ces nam ovde iskopirati.



offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

nemam taj fajl...

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Isprati ostatak uputstva kako bi bili sigurni u to.

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

sad sam pretrazio ceo hard, nema __c0021F10.dat

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

U redu.

Hoće li biti nešto od ComboFix loga?

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

ComboFix 07-12-19.2 - Dejan 2007-12-19 8:22:44.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.73 [GMT 1:00]
Running from: C:\Documents and Settings\Dejan\Desktop\New Folder (2)\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\drivers\sfsync02.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_SFSYNC02
-------\sfsync02


((((((((((((((((((((((((( Files Created from 2007-11-19 to 2007-12-19 )))))))))))))))))))))))))))))))
.

2007-12-18 10:12 . 2007-12-18 10:20 <DIR> d-------- C:\Program Files\Your Uninstaller 2008
2007-12-18 09:50 . 2007-12-18 09:50 <DIR> d-------- C:\Your.Uninstaller_.2008.PRO
2007-12-18 09:47 . 2007-12-18 09:48 3,783,357 --a------ C:\Your.Uninstaller_.2008.PRO.rar
2007-12-16 18:07 . 2007-12-16 18:07 <DIR> d-------- C:\Program Files\General
2007-12-16 15:25 . 2007-12-16 15:25 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-12-16 09:12 . 2007-12-16 09:12 <DIR> d-------- C:\Program Files\Hotfix Manager
2007-12-16 08:46 . 2007-12-16 08:46 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-12-16 08:46 . 2007-12-16 08:46 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2007-12-16 08:15 . 2007-12-16 08:15 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-12-16 08:13 . 2007-12-16 08:13 <DIR> d-------- C:\Program Files\Malicious Software Removal Tool
2007-12-16 08:13 . 2007-03-07 18:45 6,054,400 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-16 08:13 . 2007-04-03 05:36 2,453,952 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-16 08:13 . 2007-01-31 07:47 991,232 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-16 08:13 . 2007-03-07 18:45 458,752 --a--c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-16 08:13 . 2007-04-03 15:46 383,488 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-16 08:13 . 2007-03-07 18:45 266,752 --a--c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-16 08:13 . 2007-03-07 18:45 51,712 --a--c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-16 08:13 . 2007-02-27 09:20 13,824 --a--c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-16 08:05 . 2007-12-16 08:05 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-12-16 07:45 . 2007-12-16 07:45 <DIR> d-------- C:\WINDOWS\system32\XPSViewer
2007-12-16 07:44 . 2007-12-16 07:44 <DIR> d-------- C:\Program Files\Reference Assemblies
2007-12-16 07:44 . 2006-06-29 13:07 14,048 --a------ C:\WINDOWS\system32\spmsg2.dll
2007-12-16 07:39 . 2007-12-16 07:39 <DIR> d--h-c--- C:\WINDOWS\$SQLUninstallMSXML2SP6-KB887606-x86-ENU$
2007-12-16 07:39 . 2007-12-16 09:20 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-16 07:38 . 2007-12-16 07:38 <DIR> d-------- C:\Program Files\PowerMenu
2007-12-16 07:24 . 2007-03-12 16:16 10,752 --a------ C:\WINDOWS\system32\aamd532.dll
2007-12-16 07:18 . 2007-12-16 07:24 <DIR> d-------- C:\Program Files\AutoPatcher
2007-12-15 22:28 . 2007-12-16 01:07 319,507,151 --a------ C:\AutoPatcher_WinXP_May07_x86_ENU_Core.exe
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Program Files\OrphansRemover
2007-12-15 15:37 . 2007-12-15 15:37 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\OrphansRemover
2007-12-15 14:17 . 2003-09-12 04:26 646,784 --a------ C:\WINDOWS\system32\drivers\CnxEtU.sys
2007-12-15 14:17 . 2003-10-29 08:07 163,840 --a------ C:\WINDOWS\system32\CnxHwIo.dll
2007-12-15 14:17 . 2002-08-06 08:59 118,784 --a------ C:\WINDOWS\system32\CnxMfdCo.dll
2007-12-15 14:17 . 2001-10-03 08:08 118,784 --a------ C:\WINDOWS\system32\CnxClsCo.dll
2007-12-15 14:17 . 2003-10-29 08:02 108,675 --a------ C:\WINDOWS\system32\drivers\CnxTgN.sys
2007-12-15 14:17 . 2003-09-12 04:26 60,288 --a------ C:\WINDOWS\system32\drivers\CnxEtP.sys
2007-12-15 13:46 . 2003-10-29 14:11 233,472 --a------ C:\WINDOWS\system32\CnxUnist.exe
2007-12-13 18:55 . 2005-04-30 23:41 200,704 --a------ C:\WINDOWS\system32\IfsDrives.dll
2007-12-13 18:55 . 2006-10-23 18:20 132,736 --a------ C:\WINDOWS\system32\drivers\ext2fs.sys
2007-12-13 18:55 . 2005-02-04 15:35 57,344 --a------ C:\WINDOWS\system32\IfsDrives.cpl
2007-12-13 18:55 . 2004-09-25 00:28 4,608 --a------ C:\WINDOWS\system32\drivers\IfsDrives.sys
2007-12-12 21:40 . 2007-12-12 21:41 <DIR> d-------- C:\Program Files\PC Connectivity Solution
2007-12-12 21:37 . 2007-02-22 10:15 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-12-12 21:37 . 2007-02-22 10:15 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-12-12 21:37 . 2007-02-22 10:15 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-12-12 21:37 . 2007-02-22 10:15 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-12-11 17:58 . 2007-12-11 17:58 <DIR> d-------- C:\Program Files\Hirc
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Program Files\SystemRequirementsLab
2007-12-09 09:35 . 2007-12-09 09:35 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\SystemRequirementsLab
2007-12-06 19:17 . 2007-12-13 20:13 90,980 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-06 19:17 . 2007-12-13 20:13 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-06 19:16 . 2007-12-19 08:33 19,995,168 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-06 19:16 . 2007-12-19 08:32 268,844 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-06 19:16 . 2007-12-19 08:33 205,600 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-06 19:16 . 2007-12-19 08:32 20,324 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-05 10:03 . 2007-12-11 12:34 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\gtk-2.0
2007-12-05 09:56 . 2007-12-05 09:56 <DIR> d-------- C:\Documents and Settings\Dejan\Application Data\Inkscape
2007-12-05 09:51 . 2007-12-05 09:55 <DIR> d-------- C:\Program Files\Inkscape
2007-11-25 19:26 . 2007-11-25 19:26 697 --a------ C:\WINDOWS\EReg515.dat
2007-11-25 18:00 . 1998-09-02 09:02 194,320 --a------ C:\WINDOWS\system32\qcut.dll
2007-11-25 18:00 . 1998-08-17 10:21 11,776 --a------ C:\WINDOWS\system32\mciqtz.drv
2007-11-25 18:00 . 1998-08-17 10:21 10,240 --a------ C:\WINDOWS\system32\vidx16.dll
2007-11-25 18:00 . 1998-08-17 10:21 5,672 --a------ C:\WINDOWS\system32\quartz.vxd
2007-11-25 18:00 . 2007-11-25 18:00 4,608 --a------ C:\WINDOWS\system32\w95inf32.dll
2007-11-25 18:00 . 2007-11-25 18:00 2,272 --a------ C:\WINDOWS\system32\w95inf16.dll
2007-11-25 17:56 . 2007-11-26 20:25 1,477 --a------ C:\WINDOWS\disney.ini
2007-11-21 09:34 . 2006-11-12 11:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-19 06:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-18 19:06 --------- d-----w C:\Program Files\MSN Messenger
2007-12-18 19:06 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-12-18 10:33 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-18 09:36 --------- d-----w C:\Program Files\Paint.NET
2007-12-16 14:25 --------- d-----w C:\Program Files\Stardock
2007-12-16 06:55 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-16 06:50 --------- d-----w C:\Program Files\MSBuild
2007-12-15 17:15 --------- d-----w C:\Program Files\mIRC
2007-12-15 15:36 --------- d-----w C:\Documents and Settings\Dejan\Application Data\uTorrent
2007-12-15 14:24 --------- d-----w C:\Program Files\Blaze Media Pro
2007-12-15 13:04 --------- d-----w C:\Program Files\eMule
2007-12-15 12:54 --------- d-----w C:\Program Files\Gigatron
2007-12-15 12:51 --------- d-----w C:\Program Files\ConTEXT
2007-12-15 12:45 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-12-15 12:15 --------- d--h--w C:\Documents and Settings\All Users\Application Data\{9EEC710E-58B9-4B76-93C5-36D01182487C}
2007-12-15 12:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-12 20:44 --------- d-----w C:\Program Files\Nokia
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\PCSuite
2007-12-12 20:44 --------- d-----w C:\Program Files\Common Files\Nokia
2007-12-12 20:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Installations
2007-12-06 18:16 --------- d-----w C:\Program Files\Kaspersky Lab
2007-11-30 12:21 --------- d-----w C:\Documents and Settings\Dejan\Application Data\Nokia
2007-11-22 19:14 --------- d-----w C:\Program Files\Trillian
2007-11-20 09:10 --------- d-----w C:\Documents and Settings\Dejan\Application Data\LimeWire
2007-11-14 20:56 --------- d-----w C:\Program Files\Common Files\SWF Studio
2007-11-13 05:37 11,264 --sha-w C:\Program Files\Thumbs.db
2007-11-13 05:37 --------- d-----w C:\Program Files\XviD
2007-11-13 05:37 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-11-13 05:37 --------- d-----w C:\Program Files\mpegable
2007-11-12 18:35 --------- d-----w C:\Program Files\Nettalk6
2007-11-08 14:21 720,896 ----a-w C:\WINDOWS\iun6002.exe
2007-10-30 12:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Stardock
2007-10-23 10:31 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-10-23 10:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-23 10:25 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-21 06:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-20 14:47 --------- d-----w C:\Program Files\Opera 9
2007-06-25 14:58 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45819 PM).mht
2007-06-25 14:57 141,577 ----a-w C:\Program Files\Nettalk - (6-25-2007 45656 PM).mht
2007-05-08 21:05 80 --sha-r C:\WINDOWS\system32\AAF32A9973.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" [2007-12-10 10:12]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe" [2003-10-29 08:11]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-03 23:56]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-11-07 17:35]

C:\Documents and Settings\Dejan\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-12-16 15:25:54]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-12-16 07:38:06]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"DisallowRun"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\fsp_lmwl]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll 2007-09-23 10:10 229376 C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Uniblue RegistryBooster 2"=C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"CnxDslTaskBar"="C:\Program Files\Conexant\AccessRunner ADSL\CnxDslTb.exe"
"PCSuiteTrayApplication"=C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"

R1 Ext2fs;Ext2fs;C:\WINDOWS\system32\DRIVERS\ext2fs.sys [2006-10-23 18:20]
R1 IfsDrives;IfsDrives;C:\WINDOWS\system32\DRIVERS\IfsDrives.sys [2004-09-25 00:28]
R2 LmpcService;Lock My PC Service;C:\Program Files\Lock My PC 4\LmpcServ.exe [2007-03-18 11:51]
R3 CnxEtP;Conexant AccessRunner USB ADSL WAN Adapter Filter Driver;C:\WINDOWS\system32\DRIVERS\CnxEtP.sys [2003-09-12 04:26]
R3 CnxEtU;Conexant AccessRunner USB ADSL Interface Device Driver;C:\WINDOWS\system32\DRIVERS\CnxEtU.sys [2003-09-12 04:26]
R3 CnxTgN;Conexant AccessRunner USB ADSL WAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\CnxTgN.sys [2003-10-29 08:02]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-04-04 14:58]

.
Contents of the 'Scheduled Tasks' folder
"2006-07-03 16:18:24 C:\WINDOWS\Tasks\Low Battery Alarm Program.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2007-12-19 08:34:40
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\Stardock\Object Desktop\WindowBlinds\tray.dll
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
Completion time: 2007-12-19 8:37:35 - machine was rebooted

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Uploaduj mi sledeći file:
C:\WINDOWS\system32\actskn45.ocx


Upload link: [Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 29 Avg 2005
  • Poruke: 720
  • Gde živiš: Beograd

Vas fajl je uspesno uploadovan. Smile

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pokreni HijackThis, skeniraj i čekiraj sledeće linije:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)

Klikni Fix Checked.


-------------------------------------------------------------------------------------


Pronađi i obriši file: C:\WINDOWS\system32\actskn45.ocx

-------------------------------------------------------------------------------------


Klikni Start - Run i ukucaj:

regedit


Kada se Regedit pokrene, pronađi (u levom prozoru) i klikni na sledeći ključ:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows

U desnom prozoru će biti prikazane vrednosti koje se nalaze unutar toga ključa.
Dvoklik na vrednost AppInit_DLLs će otvoriti prozor u kome ćeš moći modifikovati sadržaj te stavke.

Pod Value data će se nalaziti sledeće:

C:\WINDOWS\system32\__c0021F10.dat,wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll

Potrebno je da obrišeš ono obeleženo crvenom bojom i da klikneš OK.

Znači, nakon promene, ta stavka treba da izgleda ovako:

wbsys.dll,C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll





Kada si odradio ovo gore, restartuj PC i postavi novi HT log.

Ko je trenutno na forumu
 

Ukupno su 996 korisnika na forumu :: 57 registrovanih, 7 sakrivenih i 932 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: alberto, alexbr, Andrija 1993, Asteker, bobomicek, Bobrock1, Borkanović, cinoeye, crnirocko, dejanbenkovic, Dekanovic, Demi87, Desmond, drale12, ele, g_g, Haris, Jovan1983, Kawasaki1000, Kobrim, Kotarle, krkalon, KUZMAR, Lep1na, ljuba, LostInSpaceandTime, Lucije Kvint, mat, mercedesamg, miki kv, mile23, MILJEVINAC, milutin134, Mldo, monomah, nebojsag, niksa517, ObelixSRB, ozzy, Papadubi, pceklic, Prašinar, PrincipL, samipag822, sekretar, Siti2, Sr.Stat., TheDictator, Tribal, vathra, vlahale, Vzor50, zgoljo, zmajognjeniivan, zoran77, Živković, Žoržo