offline
- Pridružio: 04 Avg 2009
- Poruke: 166
|
Napisano: 15 Avg 2009 10:26
Preskenirao sam racunar i Mcafe mi odjednom detektije trojan generic tako nesto nisam uspio dobro da vidim i ne moze da ga izbrise .
DDS (Ver_09-07-30.01) - NTFSx86
Run by SERVIS at 9:47:41.10 on Sat 08/15/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.592 [GMT 2:00]
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\WINDOWS\Mixer.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\VirusScan Enterprise\EngineServer.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\WINDOWS\System32\svchost.exe
svchost.exe
C:\WINDOWS\system32\braviax.exe
C:\Program Files\Opera\opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\SERVIS\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
mDefault_Search_URL = hxxp://www.google.com/ie
mSearch Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\udaterui.exe" /StartedFromRunKey
mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE
mRun: [AlcxMonitor] ALCXMNTR.EXE
mRun: [C-Media Mixer] Mixer.exe /startup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [Regedit32] c:\windows\system32\regedit.exe
mRun: [braviax]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [braviax]
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/common/asusTek_sys_ctrl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-8-6 340592]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-2-29 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-2-29 51440]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\mcafee\virusscan enterprise\EngineServer.exe [2008-9-29 19456]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-3-14 103744]
R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\Mcshield.exe [2008-9-29 143088]
R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\VsTskMgr.exe [2008-9-29 62800]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2009-8-6 67904]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-8-6 90360]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-8-6 42424]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2009-8-6 64432]
=============== Created Last 30 ================
2009-08-14 16:15 122,600 ----h--- C:\treeinfo.wc
2009-08-14 16:10 25,808 a------- c:\windows\system\CTL3DV2.DLL
2009-08-14 16:10 545 a------- c:\windows\UC.PIF
2009-08-14 16:10 545 a------- c:\windows\RAR.PIF
2009-08-14 16:10 545 a------- c:\windows\PKZIP.PIF
2009-08-14 16:10 545 a------- c:\windows\PKUNZIP.PIF
2009-08-14 16:10 545 a------- c:\windows\NOCLOSE.PIF
2009-08-14 16:10 545 a------- c:\windows\LHA.PIF
2009-08-14 16:10 545 a------- c:\windows\ARJ.PIF
2009-08-14 16:10 876 a------- c:\windows\wincmd.ini
2009-08-14 16:10 <DIR> --d----- C:\totalcmd
2009-08-14 12:32 11,264 a------- c:\windows\system32\braviax.exe
2009-08-14 12:01 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-14 12:01 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-14 12:01 <DIR> --d----- c:\docume~1\servis\applic~1\SUPERAntiSpyware.com
2009-08-14 12:00 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-14 12:00 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-14 11:54 <DIR> a-dshr-- C:\cmdcons
2009-08-14 11:53 216,064 a------- c:\windows\PEV.exe
2009-08-14 11:53 161,792 a------- c:\windows\SWREG.exe
2009-08-14 11:53 98,816 a------- c:\windows\sed.exe
2009-08-11 09:39 69 a------- c:\windows\NeroDigital.ini
2009-08-10 13:05 <DIR> --d----- c:\program files\Shutdown Timer
2009-08-08 13:39 3,686,454 a------- c:\windows\ACD Wallpaper.bmp
2009-08-08 11:08 <DIR> --d----- c:\program files\RAR Password (zabranjeno)er
2009-08-08 11:03 <DIR> --d----- c:\program files\Intelore
2009-08-08 11:02 <DIR> --d----- C:\QUARANTINE
2009-08-08 10:12 <DIR> --d----- c:\docume~1\servis\applic~1\ACD Systems
2009-08-08 10:11 <DIR> --d----- c:\docume~1\alluse~1\applic~1\ACD Systems
2009-08-08 10:11 <DIR> --d----- c:\program files\common files\ACD Systems
2009-08-08 10:11 <DIR> --d----- c:\program files\ACD Systems
2009-08-08 10:11 10,368 a------- c:\windows\system32\drivers\pfc.sys
2009-08-08 10:11 <DIR> --d----- c:\windows\Downloaded Installations
2009-08-08 09:40 <DIR> --d----- c:\program files\K-Lite Codec Pack
2009-08-08 09:25 <DIR> --d----- c:\program files\SpeedFan
2009-08-08 09:25 45 a------- c:\windows\system32\initdebug.nfo
2009-08-08 09:12 <DIR> --d----- c:\windows\pss
2009-08-07 10:43 344,064 a------- c:\windows\system32\msvcr70.dll
2009-08-07 10:43 <DIR> --d----- c:\program files\DVDVideoSoft
2009-08-07 10:43 <DIR> --d----- c:\program files\common files\DVDVideoSoft
2009-08-07 10:37 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
2009-08-07 10:15 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-07 10:15 73,728 a------- c:\windows\system32\javacpl.cpl
2009-08-07 09:09 22 a------- c:\windows\system32\ati64hlp.stb
2009-08-06 17:01 22 a------- c:\windows\system32\ati64hl2.stb
2009-08-06 16:59 <DIR> --d----- c:\program files\ATI Technologies
2009-08-06 15:23 376 a------- c:\windows\ODBC.INI
2009-08-06 15:23 17,920 a------- c:\windows\system32\mdimon.dll
2009-08-06 15:22 <DIR> --d----- c:\program files\common files\L&H
2009-08-06 15:22 <DIR> --d----- c:\program files\Microsoft ActiveSync
2009-08-06 15:20 <DIR> --d----- c:\windows\SHELLNEW
2009-08-06 15:09 516,768 ac------ c:\windows\system32\dllcache\ativvaxx.dll
2009-08-06 15:09 516,768 a------- c:\windows\system32\ativvaxx.dll
2009-08-06 15:09 1,888,992 ac------ c:\windows\system32\dllcache\ati3duag.dll
2009-08-06 15:09 1,888,992 a------- c:\windows\system32\ati3duag.dll
2009-08-06 15:08 701,440 ac------ c:\windows\system32\dllcache\ati2mtag.sys
2009-08-06 15:08 701,440 a------- c:\windows\system32\drivers\ati2mtag.sys
2009-08-06 15:08 870,784 ac------ c:\windows\system32\dllcache\ati3d1ag.dll
2009-08-06 15:08 870,784 a------- c:\windows\system32\ati3d1ag.dll
2009-08-06 15:08 229,376 ac------ c:\windows\system32\dllcache\ati2cqag.dll
2009-08-06 15:08 201,728 ac------ c:\windows\system32\dllcache\ati2dvag.dll
2009-08-06 15:08 229,376 a------- c:\windows\system32\ati2cqag.dll
2009-08-06 15:08 201,728 a------- c:\windows\system32\ati2dvag.dll
2009-08-06 15:07 0 a------- c:\windows\system32\SET2.tmp
2009-08-06 14:58 25 a------- c:\windows\mixerdef.ini
2009-08-06 14:47 2,317,696 a------- c:\windows\system32\drivers\ALCXWDM.SYS
2009-08-06 14:47 156,672 -------- c:\windows\system32\RtlCPAPI.dll
2009-08-06 14:47 57,344 a------- c:\windows\ALCXMNTR.EXE
2009-08-06 14:47 9,309,696 -------- c:\windows\system32\RTLCPL.exe
2009-08-06 14:47 141,016 -------- c:\windows\system32\alsndmgr.wav
2009-08-06 14:47 77,824 -------- c:\windows\soundman.exe
2009-08-06 14:47 40,960 -------- c:\windows\system32\ChCfg.exe
2009-08-06 14:47 18,694,144 a------- c:\windows\system32\ALSNDMGR.CPL
2009-08-06 14:47 294,912 -------- c:\windows\alcupd.exe
2009-08-06 14:47 200,704 -------- c:\windows\alcrmv.exe
2009-08-06 14:46 192,512 -------- c:\windows\RtlExUpd.dll
2009-08-06 14:43 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-08-06 14:43 57,600 a------- c:\windows\system32\drivers\redbook.sys
2009-08-06 14:43 6,400 a------- c:\windows\system32\drivers\enum1394.sys
2009-08-06 14:42 46,464 ac------ c:\windows\system32\dllcache\gagp30kx.sys
2009-08-06 14:42 46,464 a------- c:\windows\system32\drivers\GAGP30KX.SYS
2009-08-06 14:42 32,768 a------- c:\windows\system32\drivers\sisnic.sys
2009-08-06 14:42 74,240 a------- c:\windows\system32\usbui.dll
2009-08-06 14:41 <DIR> --d----- c:\program files\common files\ODBC
2009-08-06 14:41 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-08-06 14:41 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-08-06 14:39 144,484 ac------ c:\windows\system32\dllcache\netfx.cat
2009-08-06 14:38 786 a------- c:\windows\system32\$winnt$.inf
2009-08-06 14:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Hagel Technologies
2009-08-06 13:27 <DIR> --d----- c:\program files\common files\Cisco Systems
2009-08-06 13:27 <DIR> --d----- c:\program files\McAfee
2009-08-06 13:27 <DIR> --d----- c:\program files\common files\McAfee
2009-08-06 13:15 <DIR> --d----- c:\program files\Nero
2009-08-06 13:03 <DIR> --ds---- c:\documents and settings\servis\UserData
2009-08-06 12:50 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-08-06 12:50 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-08-06 12:49 <DIR> --d----- c:\program files\common files\MSSoap
2009-08-06 12:48 <DIR> --d----- c:\program files\Online Services
2009-08-06 12:48 <DIR> --d----- c:\program files\Messenger
2009-08-06 12:48 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-08-06 12:47 <DIR> --d----- c:\program files\Windows NT
==================== Find3M ====================
2009-08-14 11:58 619,584 a------- c:\windows\system32\drivers\ntfs.sys
2009-08-07 15:48 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-06 12:48 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-06-02 18:11 85,504 a------- c:\windows\system32\ff_vfw.dll
2009-05-29 23:37 205,824 a------- c:\windows\system32\xvidvfw.dll
2009-05-29 23:31 881,664 a------- c:\windows\system32\xvidcore.dll
============= FINISH: 9:48:01.59 ===============
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
|