Poslao: 20 Okt 2010 20:39
|
offline
- t.mile
- Građanin
- Pridružio: 19 Feb 2009
- Poruke: 188
- Gde živiš: Kucevo
|
Juce sam jedan fles na kom je AV pronasao neke viruse i izbrisao. Medjutim racunar posle toga je poceo cudno da se ponasa. Na ekranu se pojavljuje prozor na kom pise:
FLV source filter
brought to you by
swishzone.com
Kad pokusavam da ga iskljucim pokazuje (not responding) i nikako ne mogu da ga uklonim.
deinstalirao sam bs player i opet sa pojavljuje.
E sad kad pokusavam da ponovo instaliram bs player racunar je jednostavno ugasi momentalno i ne pokrece se dok ga rucno ne pokrenem.
Evo loga kako izgleda.
DDS (Ver_10-10-10.03) - NTFSx86
Run by Mile at 20:23:13.37 on Wed 10/20/2010
Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_22
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2048.1253 [GMT 2:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\DU Meter\DUMeterSvc.exe
C:\Windows\Explorer.EXE
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Windows\vVX3000.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\A4Tech\Keyboard\Ikeymain.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\PROGRA~1\DUMETE~1\DUMeter.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\wbengine.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\System32\vds.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\werfault.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Mile\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.rs/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: ThumbnailsBHO Class: {1bd0befe-f697-4eee-b7e1-76b849a5cb84} - c:\program files\xmarks\thumbnails for ie\xmarksthumbnails.dll
BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - d:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\mif5ba~1\office14\URLREDIR.DLL
BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [DU Meter] c:\program files\du meter\DUMeter.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [VX3000] c:\windows\vVX3000.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [iKeyWorks] c:\progra~1\a4tech\keyboard\Ikeymain.exe
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &D&ownload &with BitComet - d:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - d:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - d:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\mif5ba~1\office14\ONBttnIE.dll/105
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://d:\program files\bitcomet\tools\BitCometBHO_1.3.3.2.dll/206
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: {C92E15CC-6518-41F4-B9E1-ED67E810D424} = 10.88.0.5,11.88.0.5
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - %SystemRoot%\system32\wpdshserviceobj.dll
SEH: {4F07DA45-8170-4859-9B5F-037EF2970034} - No File
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mif5ba~1\office14\GROOVEEX.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\mile\appdata\roaming\mozilla\firefox\profiles\ys3gjpy7.default\
FF - prefs.js: browser.startup.homepage - http:/google.rs
FF - component: c:\users\mile\appdata\roaming\mozilla\firefox\profiles\ys3gjpy7.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - component: c:\users\mile\appdata\roaming\mozilla\firefox\profiles\ys3gjpy7.default\extensions\dttoolbar@toolbarnet.com\components\DTToolbarFF.dll
FF - plugin: c:\progra~1\mif5ba~1\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\mif5ba~1\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npwachk.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - trued:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
============= SERVICES / DRIVERS ===============
R2 DUMeterSvc;DU Meter Service;c:\program files\du meter\DUMeterSvc.exe [2010-8-21 1411616]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-2-22 133512]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2010-2-22 810120]
R2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-2-22 41312]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2010-2-25 1047880]
R3 DUMeterDrv;Hagel Technologies DU Meter traffic accounting driver;c:\program files\du meter\DUMetr32.sys [2010-8-21 19368]
R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2010-2-25 10064]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
=============== Created Last 30 ================
2010-10-20 17:44:53 -------- d-----w- c:\progra~2\GroupPolicy
2010-10-19 17:36:48 6146896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{09202d00-fecf-4639-9362-9fa4cd25208a}\mpengine.dll
2010-10-15 19:34:19 -------- d-----w- c:\users\mile\appdata\roaming\FastStone
2010-10-15 19:34:06 -------- d-----w- c:\program files\FastStone Image Viewer
2010-10-01 18:41:17 -------- d-----w- c:\users\mile\appdata\local\Windows Live
2010-09-29 18:36:37 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 17:32:42 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-22 22:47:28 49016 ----a-w- c:\windows\system32\sirenacm.dll
2010-09-21 12:13:50 1564072 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDRES.DLL
2010-09-21 12:08:38 439168 ----a-w- c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
2010-09-21 12:06:02 853912 ----a-w- c:\program files\common files\microsoft shared\windows live\wlidcli.dll
2010-09-21 12:06:02 57752 ----a-w- c:\program files\common files\microsoft shared\windows live\msidcrl40.dll
2010-09-21 12:03:14 332160 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDCREDPROV.DLL
2010-09-21 12:03:14 237952 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDPROV.DLL
2010-09-21 12:03:14 208768 ----a-w- c:\windows\system32\LIVESSP.DLL
2010-09-21 12:03:14 193408 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDSVCM.EXE
2010-09-21 12:03:14 1710464 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE
2010-09-21 12:03:14 145280 ----a-w- c:\program files\common files\microsoft shared\windows live\WLIDNSP.DLL
==================== Find3M ====================
2010-09-15 02:50:37 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-03 14:26:50 3259392 ----a-w- c:\windows\fanflame.scr
2010-09-01 04:23:49 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-09-01 02:34:52 2327552 ----a-w- c:\windows\system32\win32k.sys
2010-08-31 22:46:36 1355264 ----a-w- c:\windows\system32\jscript9.dll
2010-08-31 22:44:32 367104 ----a-w- c:\windows\system32\html.iec
2010-08-31 22:44:30 1448448 ----a-w- c:\windows\system32\inetcpl.cpl
2010-08-31 22:44:24 1122304 ----a-w- c:\windows\system32\wininet.dll
2010-08-31 22:44:06 424960 ----a-w- c:\windows\system32\vbscript.dll
2010-08-31 22:43:22 23552 ----a-w- c:\windows\system32\licmgr10.dll
2010-08-31 22:43:12 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2010-08-31 22:43:12 114176 ----a-w- c:\windows\system32\iesysprep.dll
2010-08-31 22:43:10 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2010-08-31 22:43:10 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2010-08-31 22:42:58 51200 ----a-w- c:\windows\system32\admparse.dll
2010-08-31 22:42:54 75264 ----a-w- c:\windows\system32\iesetup.dll
2010-08-31 22:42:48 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2010-08-31 22:42:42 150016 ----a-w- c:\windows\system32\iexpress.exe
2010-08-31 22:42:42 149504 ----a-w- c:\windows\system32\wextract.exe
2010-08-31 22:42:20 33280 ----a-w- c:\windows\system32\imgutil.dll
2010-08-31 22:42:16 48640 ----a-w- c:\windows\system32\mshtmler.dll
2010-08-31 22:42:12 11264 ----a-w- c:\windows\system32\mshta.exe
2010-08-31 22:42:10 2381824 ----a-w- c:\windows\system32\mshtml.tlb
2010-08-31 22:42:04 63488 ----a-w- c:\windows\system32\tdc.ocx
2010-08-31 22:41:46 160768 ----a-w- c:\windows\system32\msls31.dll
2010-08-31 04:32:30 954752 ----a-w- c:\windows\system32\mfc40.dll
2010-08-31 04:32:30 954288 ----a-w- c:\windows\system32\mfc40u.dll
2010-08-27 05:46:48 168448 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-26 04:39:58 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-08-21 05:36:33 738816 ----a-w- c:\windows\system32\wmpmde.dll
2010-08-21 05:36:24 224256 ----a-w- c:\windows\system32\schannel.dll
2010-08-21 05:33:24 530432 ----a-w- c:\windows\system32\comctl32.dll
2010-08-21 05:32:37 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 06:15:05 804864 ----a-w- c:\windows\system32\FntCache.dll
2010-08-16 06:14:36 1076224 ----a-w- c:\windows\system32\DWrite.dll
2010-08-16 06:14:24 737280 ----a-w- c:\windows\system32\d2d1.dll
2010-08-16 06:14:24 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2010-08-16 06:14:24 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2010-08-03 11:40:00 217127 ----a-w- c:\windows\drv43260.dll
2010-08-03 11:40:00 208935 ----a-w- c:\windows\drv33260.dll
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-26 08:13:40 108032 ----a-w- c:\windows\system32\ff_vfw.dll
============= FINISH: 20:23:46.71 ===============
mycity.rs/must-login.png
|
|
|
|
Poslao: 20 Okt 2010 22:10
|
offline
- Bogdan-Tc
- Anti Malware Fighter
Rank 1
- Pridružio: 04 Jan 2009
- Poruke: 2168
|
Pozdrav...
Zamolio bih te da ponovo pročitaš uputstvo i postaviš mi Gmer log-ove.
|
|
|
|
|
|
Poslao: 21 Okt 2010 20:32
|
offline
- t.mile
- Građanin
- Pridružio: 19 Feb 2009
- Poruke: 188
- Gde živiš: Kucevo
|
Hvala!
Dobro je da nema neke posasti.
To mi je bilo problem. Verovatno je neka greska koju cu ja potraziti, a ako ne buem uspeo poseticu windows forum.
U svakom slucaju veliko hvala!
|
|
|
|