Hendikepirana tastatura

Hendikepirana tastatura

offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

Na notebooku je tastatura prestala delimicno da funkcionise, buduci da nije bilo nikakvih udara, prosipanja tecnosti i sl. moguce da je u pitanju neki viruscic.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:20 PM, on 12/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\maja\Desktop\hike\hiki.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TouchPadHotKey] C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WirelessSelector.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 4574 bytes

Dopuna: 20 Dec 2008 14:33

Ne znam da li sam pogresila, ali pustila sam i ComboFix da odradi, ali se ni nakon njegovog rada nista nije promenilo, evo i taj log:

ComboFix 08-12-18.03 - maja 2008-12-20 14:13:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1789.1247 [GMT 1:00]
Running from: c:\documents and settings\maja\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-11-20 to 2008-12-20 )))))))))))))))))))))))))))))))
.

2008-12-18 00:07 . 2008-12-18 23:32 20 --a------ c:\windows\(zabranjeno)pdf.INI
2008-12-18 00:03 . 2008-12-18 23:32 <DIR> d-------- c:\program files\PDF Password (zabranjeno)er v3.0
2008-12-17 23:55 . 2008-12-17 23:55 <DIR> d-------- c:\program files\Matrix
2008-12-02 01:35 . 2008-12-02 01:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-27 21:49 . 2008-11-27 21:49 <DIR> d-------- c:\documents and settings\maja\Application Data\Media Player Classic
2008-11-27 21:49 . 2008-12-19 15:21 69 --a------ c:\windows\NeroDigital.ini
2008-11-27 14:32 . 2008-12-04 14:48 <DIR> d-------- c:\documents and settings\maja\Application Data\uTorrent
2008-11-27 14:29 . 2008-11-27 14:29 <DIR> d-------- c:\documents and settings\maja\Application Data\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\program files\Common Files\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\program files\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2008-11-27 14:16 . 2008-11-27 14:32 <DIR> d-------- c:\program files\uTorrent
2008-11-27 14:03 . 2008-11-27 14:04 <DIR> d-------- c:\program files\Exact Audio Copy
2008-11-27 14:03 . 2008-11-27 14:03 <DIR> d-------- c:\program files\CCleaner
2008-11-27 14:02 . 2008-11-27 14:02 <DIR> d-------- c:\windows\PrimoPDF
2008-11-27 14:02 . 2008-11-27 14:02 <DIR> d-------- c:\program files\activePDF
2008-11-27 14:02 . 2006-08-31 18:46 176,235 --a------ c:\windows\system32\Primomonnt.dll
2008-11-27 13:59 . 2008-11-27 13:59 <DIR> d-------- c:\windows\Downloaded Installations
2008-11-27 13:59 . 2008-11-28 13:56 <DIR> d-------- c:\program files\The KMPlayer
2008-11-27 13:58 . 2008-11-27 13:58 <DIR> d-------- c:\program files\YouTube Downloader
2008-11-27 13:55 . 2003-06-18 17:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-11-27 13:55 . 2008-11-27 13:55 376 --a------ c:\windows\ODBC.INI
2008-11-27 13:54 . 2008-11-27 13:54 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-27 13:54 . 2008-11-27 13:54 <DIR> d-------- c:\program files\Common Files\L&H
2008-11-27 13:53 . 2008-11-27 13:54 <DIR> d-------- c:\windows\SHELLNEW
2008-11-27 13:53 . 2008-11-27 13:53 <DIR> d-------- c:\program files\Microsoft Works
2008-11-27 13:51 . 2008-11-27 13:51 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-27 13:14 . 2008-11-27 14:02 <DIR> d-------- c:\documents and settings\maja\Application Data\Winamp
2008-11-27 13:08 . 2008-11-27 13:08 0 --a------ c:\windows\nsreg.dat
2008-11-27 07:43 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-27 07:43 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-27 07:43 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-11-27 07:43 . 2001-08-17 14:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-11-26 20:13 . 2008-11-26 20:13 <DIR> d-------- c:\program files\Lavasoft
2008-11-26 20:13 . 2008-11-26 20:13 <DIR> d-------- c:\documents and settings\maja\Application Data\Lavasoft
2008-11-26 20:12 . 2008-12-20 14:10 <DIR> d-------- c:\program files\mIRC
2008-11-26 18:19 . 2008-11-26 18:19 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-26 18:18 . 2008-11-26 18:53 <DIR> d-------- c:\windows\SxsCaPendDel
2008-11-26 18:13 . 2008-11-27 13:47 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-26 18:13 . 2008-11-27 13:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-26 17:03 . 2008-11-26 17:03 <DIR> d---s---- c:\documents and settings\maja\UserData
2008-11-26 17:03 . 2008-11-26 17:09 <DIR> d-------- c:\documents and settings\maja\Application Data\Yahoo!
2008-11-26 16:59 . 2008-11-26 17:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-26 16:57 . 2008-11-30 22:56 <DIR> d-------- c:\program files\Yahoo!
2008-11-26 13:47 . 2008-11-26 13:47 <DIR> d-------- c:\documents and settings\maja\Application Data\CyberLink
2008-11-26 03:23 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-26 03:19 . 2008-11-27 13:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-26 03:14 . 2008-02-22 12:30 334,792 --a------ c:\windows\system32\_AxShlEx.dll
2008-11-26 03:13 . 2008-11-26 03:13 <DIR> d-------- c:\program files\Alcohol Soft
2008-11-26 03:09 . 2008-11-26 03:09 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-26 02:53 . 2008-11-26 02:53 <DIR> d-------- c:\documents and settings\maja\Phone Browser
2008-11-26 01:06 . 2004-08-03 23:59 57,472 --a------ c:\windows\system32\drivers\redbook.sys
2008-11-26 01:06 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-11-26 01:05 . 2004-08-04 01:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-11-26 01:05 . 2004-08-03 23:07 44,672 --a------ c:\windows\system32\drivers\UAGP35.SYS
2008-11-26 01:05 . 2004-08-03 23:07 44,672 --a--c--- c:\windows\system32\dllcache\uagp35.sys
2008-11-26 01:05 . 2004-08-04 00:07 14,080 --a------ c:\windows\system32\drivers\CmBatt.sys
2008-11-26 01:05 . 2001-08-17 14:57 14,080 --a------ c:\windows\system32\drivers\battc.sys
2008-11-26 01:05 . 2001-08-17 14:58 9,344 --a------ c:\windows\system32\drivers\compbatt.sys
2008-11-26 01:03 . 2008-12-04 17:34 <DIR> d-------- c:\windows\system32\CatRoot2
2008-11-26 01:03 . 2008-11-26 00:10 <DIR> dr------- c:\documents and settings\All Users\Documents
2008-11-26 01:01 . 2008-11-26 00:15 261 --a------ c:\windows\system32\$winnt$.inf

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 13:00 --------- d-----w c:\program files\Winamp
2008-11-26 17:19 --------- d-----w c:\program files\Common Files\Adobe
2008-11-25 23:47 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-25 23:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-25 23:43 --------- d-----w c:\program files\CyberLink
2008-11-25 23:43 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-25 23:42 --------- d-----w c:\program files\Common Files\Ahead
2008-11-25 23:42 --------- d-----w c:\program files\Ahead
2008-11-25 23:36 --------- d-----w c:\program files\Alwil Software
2008-11-25 23:30 --------- d-----w c:\program files\FSC
2008-11-25 23:30 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-25 23:30 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-25 23:29 --------- d-----w c:\documents and settings\maja\Application Data\InstallShield
2008-11-25 23:28 --------- d-----w c:\program files\Synaptics
2008-11-25 23:28 --------- d-----w c:\program files\Motorola
2008-11-25 23:27 315,392 ----a-w c:\windows\HideWin.exe
2008-11-25 23:27 --------- d-----w c:\program files\sisagp
2008-11-25 23:27 --------- d-----w c:\program files\SiS VGA Utilities V3.82
2008-11-25 23:27 --------- d-----w c:\program files\Realtek
2008-11-25 23:13 --------- d-----w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-26 4608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-10 864256]
"TouchPadHotKey"="c:\program files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-08-13 364544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SiSPower"="SiSPower.dll" [2007-08-03 c:\windows\system32\SiSPower.dll]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2008-11-26 262144]
WirelessSelector.lnk - c:\program files\FSC\Wireless Utility\WirelessSelector.exe [2008-11-26 650752]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-26 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]

*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Device Detector - DevDetect.exe


.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\maja\Application Data\Mozilla\Firefox\Profiles\xfgz84wc.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2008-12-20 14:15:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-12-20 14:15:42
ComboFix-quarantined-files.txt 2008-12-20 13:15:40

Pre-Run: 97,082,306,560 bytes free
Post-Run: 97,072,541,696 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

164



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Izvini zbog čekanja. Postavljeni logovi su čisti i na tvom kompjuteru ne bi trebalo biti malware-a.



offline
  • Pridružio: 24 Feb 2006
  • Poruke: 435

Hvala vam. Nije vise ni fujitsu sto je bio Smile

Ko je trenutno na forumu
 

Ukupno su 1085 korisnika na forumu :: 78 registrovanih, 6 sakrivenih i 1001 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 9191vs, _Rade, acov34, ArchaBasha, arsa, Automaticar, Avalon015, Avangard, Ba4e, Black Luster Soldier, Boban0312, Bobrock1, bojcistv, Bojke549, bokisha253, bukefal, cojapop, cvrle312, dendrit86, dule10savic, FOX, Georgius, gomago, Hans Gajger, jodzula, kreker, Kubovac, kulus, Leonov, Lester Freamon, MarkoD, menk, mercedesamg, metallac777, miki kv, Miki01, mikrimaus, Milos ZA, Milos1389, mocnijogurt, N95, nebidrag, Nemanja.M, neutrino, nikoladim, Nmr, operniki, Pekman, pisac12, PMsnow, Povratak1912, PrincipL, probisic, procesor, rodoljub, S2M, SamostalniReferent, saputnik plavetnila, sasa87, Sass Drake, Simulink11000, Sr.Stat., sspp, stokssone, Stoorb, synergia, tmanda323, TripleTwo, TwinHeadedEagle, Vanderx, vathra, voja64, VOŽD, yiyi, zeka013, Zmaj001, zziko, 79693