Spyboot- uvek isti 'spijuni'-kako ih zastalno ukloniti

1

Spyboot- uvek isti 'spijuni'-kako ih zastalno ukloniti

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

primetila sam da nakon 'ciscenja' sa Spyboot programom opet se skoro drugi dan pojave isti 'spijuni'
Casale Media -9 entries
adviva
double click
tradedoubler...i sl.

kako i gde da ih ja 'rucno' maknem..
izgleda da imaju negde ostatke koji im omoguce ponovno da zivnu..

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Pozdrav...

Citat:primetila sam

Ali nisi ovu temu:

http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html

Smile

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Napisano: 02 Okt 2010 18:32

izvinite sto sam upala bez bon-tona Razz u ambulantu.
(nisam citala pravila kako koristiti ambulantu...
evo pokusacu malo bolje:
racunar mi je spor..cistila sam sa Spyboot i primetila kao sto sam vec prije napisala da se isti 'spijuni' svaki put pronadju u tom ciscenju.
gore navedeni...i jos neki ..
koristila sam i Vit registry cleaner..

sada kad pitate..otkrila sam da me internet provider c-sam.se vjerojatno vara s isporukom brzine ..placam za 8Mbs
a sad vidim da je download 1.43 Mbs

imam 32 bitnu verziju windowsa i evo izvestaj
....
DDS (Ver_10-03-17.01) - NTFSx86
Run by zora at 18:15:30,70 on 2010-10-02
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_21
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1033.18.2813.1255 [GMT 2:00]

SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_499a67a913bde1c7\STacSV.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_499a67a913bde1c7\aestsrv.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Program Files\Application Updater\ApplicationUpdater.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\system32\IoctlSvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Personal\bin\Personal.exe
C:\Users\zora\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\DllHost.exe
C:\Windows\hh.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\prevhost.exe
C:\Windows\system32\prevhost.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
c:\program files\real\realplayer\RecordingManager.exe
C:\Program Files\Speccy\Speccy.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\zora\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskhost.exe
C:\Users\zora\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/

https://www.mycity.rs/must-login.png

Dopuna: 02 Okt 2010 18:57

hvala
bogdane, izvini na zbrci..
..........................
a sto da sad radim
onaj GMER se skinuo kao twilinzi Smile
1. r1kistv0.exe
2. 6tui6zwk.exe
na sta da kliknem..
i jos mi je bilo upozorenje da moze ostetiti kompjuter Wink
dobro onda sam skinula onaj drugi sa prvog mirrora
RootRepael.zip
lepo ga otpakovala i kliknula na exe ..i poceli su 'bang' Evil or Very Mad
crvena upozorenja greski
"could not initialize driver.Please contact author."
nemam pojma tko je author..
i kad sam htela sve lepo zatvoriti jos mi je par puta 'zarezao'
error dumping SSDT(0x0000024)
i evo okaciti cu vam RootRepal crash koji vidim sada
ima i rootRepeal dump koji ne mogu otvoriti pa vam ga saljem kakav je , nisam ga mogla zapakovati... Bebee Dol
eto sad znate zasto mi je bilo lakse preskociti ove radnje...

ali razumijem vi trebate podlogu za analizu..(otprilike kao krvni nalaz za doktora...)
i hvala na vasem vremenu i trudu da mi odgovorite.. Smile

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Nisi mi iskopirala ceo DDS.txt log... takođe su potrebni Gmer (alternativa RootRepeal) log-ovi.

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

molim kazi mi koji od ona 2 GMER-a da otvorim..zbunilo me..u uputi ne pise da ce se 2 pojaviti

i jos jednom izvini za moju brzopletost..nisam videla da je tako dugacko..evo nastavak ovaj puta do kraja..
ali sto sa GMER-om ,a RootRepeal ne moze..
?
hvala na tvom strpljenju...
(a ja imam feedback za moje nestrpljenje... Razz )

uURLSearchHooks: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\youtube downloader toolbar\SearchSettings.dll
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {e312764e-7706-43f1-8dab-fcdd2b1e416d} - c:\program files\youtube downloader toolbar\SearchSettings.dll
BHO: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\1.0\youtubedownloaderToolbarIE.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll
TB: YouTube Downloader Toolbar: {f3fee66e-e034-436a-86e4-9690573bee8a} - c:\program files\youtube downloader toolbar\ie\1.0\youtubedownloaderToolbarIE.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Google Update] "c:\users\zora\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [AmIcoSinglun] c:\program files\amicosinglun\AmIcoSinglun.exe
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SearchSettings] "c:\program files\youtube downloader toolbar\SearchSettings.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
StartupFolder: c:\users\zora\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\zora\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\zora\appdata\roaming\micros~1\windows\startm~1\programs\startup\skrmur~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bankid~1.lnk - c:\program files\personal\bin\Personal.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Append Link Target to Existing PDF
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: E&xportera till Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\zora\appdata\roaming\mozilla\firefox\profiles\iatjo3y8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - component: c:\program files\orbitdownloader\addons\oneclickyoutubedownloader\components\GrabXpcom.dll
FF - component: c:\program files\youtube downloader toolbar\ff\components\youtubedownloaderToolbarFF.dll
FF - component: c:\program files\youtube downloader toolbar\ssff\components\SearchSettingsFF.dll
FF - component: c:\programdata\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\zora\appdata\roaming\mozilla\firefox\profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\personal\bin\np_prsnl.dll
FF - plugin: c:\program files\tracker software\pdf viewer\npPDFXCviewNPPlugin.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\zora\appdata\local\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\zora\appdata\roaming\facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.visited_color", "#551A8B");
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.videoFeeds.handler", "ask");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-6-23 64288]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 151216]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_x86_neutral_499a67a913bde1c7\AEstSrv.exe [2010-9-13 81920]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-11 172032]
R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2010-2-19 380928]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1352832]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-8-5 1153368]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 42368]
R3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys [2010-2-14 31288]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-14 14336]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2010-8-24 323360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.sys [2009-7-3 25600]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2010-2-10 16456]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2010-2-10 11088]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-3-2 1343400]
S3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\drivers\vpcuxd.sys [2010-2-11 12800]
S3 zteusbser;ZTE USB Device for Legacy Serial Communication;c:\windows\system32\drivers\zteusbser.sys [2010-2-17 98432]

=============== Created Last 30 ================

2010-10-01 15:59:49 0 d-----w- c:\program files\VITSOFT
2010-09-30 20:55:08 0 d-----w- c:\program files\DirPrinter
2010-09-29 23:06:55 0 d-----r- c:\program files\Skype
2010-09-29 14:41:28 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 14:41:28 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 13:21:08 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 18:34:07 0 d-----w- c:\programdata\ATI
2010-09-27 18:32:20 0 d-----w- c:\program files\common files\ATI Technologies
2010-09-27 18:30:00 0 d-----w- C:\AMD
2010-09-27 17:57:33 9728 ----a-w- c:\windows\system32\yk62x86ver.dll
2010-09-27 11:47:03 50 ----a-w- c:\windows\cdplayer.ini
2010-09-27 11:44:18 0 d-----w- c:\program files\common files\xing shared
2010-09-22 23:07:02 0 d-----w- c:\program files\Application Updater
2010-09-22 23:07:00 0 d-----w- c:\program files\YouTube Downloader Toolbar
2010-09-19 21:19:01 0 d-----w- c:\program files\Pegasus Media Software
2010-09-19 20:58:59 0 d-----w- c:\program files\Free Video Joiner
2010-09-16 20:05:10 0 d-----w- c:\programdata\ALM
2010-09-16 12:26:39 0 d-----w- c:\users\zora\appdata\roaming\Sony Creative Software
2010-09-15 07:46:20 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 12:11:03 0 d-----w- c:\programdata\Adobe
2010-09-13 20:22:19 64000 ------w- c:\windows\system32\agrsmdel.exe
2010-09-13 20:22:19 14848 ------w- c:\windows\system32\agrsco64.dll
2010-09-13 20:22:12 0 d-----w- c:\program files\LSI SoftModem
2010-09-13 20:21:42 0 d-----w- c:\windows\Options
2010-09-13 19:43:36 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2010-09-13 19:43:28 0 d-----w- c:\program files\Synaptics
2010-09-13 18:20:37 1048812 ----a-w- c:\windows\system32\oem16.inf
2010-09-13 18:19:22 91376 ----a-w- c:\windows\system32\bcmwlcoi.dll
2010-09-13 18:19:22 6656 ----a-w- c:\windows\system32\bcmwlrc.dll
2010-09-13 18:19:22 3870720 ----a-w- c:\windows\system32\bcmihvsrv.dll
2010-09-13 18:19:22 3559424 ----a-w- c:\windows\system32\bcmihvui.dll
2010-09-13 18:19:22 2707448 ----a-w- c:\windows\system32\drivers\BCMWL6.SYS
2010-09-13 18:19:21 0 d-----w- c:\program files\Broadcom
2010-09-13 16:45:44 420864 ----a-w- c:\windows\system32\drivers\stwrt.sys
2010-09-13 16:45:43 916480 ----a-w- c:\windows\system32\stapo.dll
2010-09-13 16:45:43 492032 ------w- c:\windows\system32\stapi32.dll
2010-09-13 16:45:43 405504 ----a-w- c:\windows\system32\stcplx.dll
2010-09-13 16:45:34 0 d-----w- c:\program files\IDT
2010-09-13 16:45:19 0 d-----w- C:\SwSetup
2010-09-13 13:21:36 0 d-----w- c:\users\zora\appdata\roaming\Easeware
2010-09-13 13:21:02 0 d-----w- c:\program files\Easeware
2010-09-13 13:03:17 0 d-----w- c:\program files\WinASO
2010-09-13 12:59:50 0 d-----w- c:\program files\Next Video Converter
2010-09-12 22:56:54 2196 ----a-w- C:\hur använder man RTMPDUMP.rtf

==================== Find3M ====================

2010-09-27 11:43:51 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-08-24 07:33:18 374048 ----a-w- c:\windows\system32\yk62x86.dll
2010-08-24 07:33:18 323360 ----a-w- c:\windows\system32\drivers\yk62x86.sys
2010-07-29 06:30:49 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30:34 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-17 03:00:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-02-10 19:58:38 722 ----a-w- c:\program files\INSTALL.LOG
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 --sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
1999-06-25 09:55:30 149504 ----a-w- c:\program files\UNWISE.EXE
2009-06-10 21:26:35 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 18:16:23,84 ===============

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Nema nikakvih problema, samo polako, rešićemo problem. Smile


Kada preuzimaš Gmer njegov naziv je uvek drugačiji (random name).

Taj file sa "čudnim" nazivom pokreneš i pratiš onako kako je navedeno u uputstvu.

Ukoliko ti je još uvek nejasno videćeš u uputstvu Slikoviti prikaz postupka pa isprati po tome uputstvu.

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Napisano: 02 Okt 2010 20:42

jos da dodam..bas sam nepismena..dala sam vam brzinu interneta (a i to je razlicito kad mjerim sa raznim meracima..)

a mozda je trebalo reci karakteristike CPU

AMD Athlon x2 QL-64
core speed 2100 MHz
bus speed 201.MHz

Dopuna: 02 Okt 2010 21:11

huh, ovo je prava carolija..
evo sva tri izvestaja (ali samo s jednim GMER programom..)
i nista nisam zapakovala niste rekli..

pa ovo cete pregledati citavu noc.. Razz

Hvala na lepom objasnjenju kako uraditi..

Ziveli
https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Zora
  • Pridružio: 22 Okt 2004
  • Poruke: 1435
  • Gde živiš: ni na nebu ni na zemlji

Napisano: 03 Okt 2010 0:54

malo me uplasilo kad se u toku rada kompjuter restartovao (dobro da je bilo upozorenje ..zaista hvala na jasnim uputstvima..
evo i izvestaja:
ComboFix 10-10-01.07 - zora 2010-10-03 0:39.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.46.1033.18.2813.1588 [GMT 2:00]
Körs från: c:\users\zora\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
* Skapade en ny återställningspunkt
.

((((((((((((((((((((((((((((((((((((((( Andra raderingar ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\INSTALL.LOG
c:\program files\YouTube Downloader Toolbar\IE\1.0\yoUTubedownloadertoolbarie.dll
c:\program files\YouTube Downloader Toolbar\SeARchsettings.dll
c:\users\zora\AppData\Roaming\inst.exe
c:\windows\system32\oem16.inf

.
(((((((((((((((((((((((( Filer Skapade från 2010-09-02 till 2010-10-02 ))))))))))))))))))))))))))))))
.

2010-10-02 22:45 . 2010-10-02 22:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-02 22:34 . 2010-10-02 22:35 -------- d-----w- C:\32788R22FWJFW
2010-10-01 15:59 . 2010-10-01 15:59 -------- d-----w- c:\program files\VITSOFT
2010-09-30 20:55 . 2010-09-30 20:55 -------- d-----w- c:\program files\DirPrinter
2010-09-29 23:07 . 2010-09-29 23:07 -------- d-----w- c:\program files\Common Files\Skype
2010-09-29 23:06 . 2010-09-29 23:07 -------- d-----r- c:\program files\Skype
2010-09-29 14:41 . 2010-03-04 04:04 146304 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-09-29 14:41 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-09-29 13:21 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-27 18:34 . 2010-09-27 18:34 -------- d-----w- c:\users\zora\AppData\Roaming\ATI
2010-09-27 18:34 . 2010-09-27 18:34 -------- d-----w- c:\users\zora\AppData\Local\ATI
2010-09-27 18:34 . 2010-09-27 18:34 -------- d-----w- c:\programdata\ATI
2010-09-27 18:32 . 2010-09-27 18:32 -------- d-----w- c:\program files\Common Files\ATI Technologies
2010-09-27 18:30 . 2010-09-27 18:30 -------- d-----w- C:\AMD
2010-09-27 17:57 . 2010-09-27 17:57 9728 ----a-w- c:\windows\system32\yk62x86ver.dll
2010-09-27 11:37 . 2010-09-27 15:16 117639744 ----a-w- c:\users\zora\AppData\Roaming\Easeware\DriverEasy\drivers\hqiorrjt.cdv\8.663.1_Beta5_Hemlock_VistaWin7_Nov11.exe
2010-09-27 11:34 . 2010-09-27 11:34 497160 ----a-w- c:\users\zora\AppData\Roaming\Real\RealPlayer\setup\AU_setup17.exe
2010-09-26 19:16 . 2010-09-26 19:16 -------- d-----w- c:\users\zora\AppData\Roaming\Leadertech
2010-09-22 23:07 . 2010-09-22 23:07 -------- d-----w- c:\program files\Application Updater
2010-09-22 23:07 . 2010-10-02 22:45 -------- d-----w- c:\program files\YouTube Downloader Toolbar
2010-09-19 21:19 . 2010-09-19 21:19 -------- d-----w- c:\program files\Pegasus Media Software
2010-09-19 20:58 . 2010-09-19 21:12 -------- d-----w- c:\program files\Free Video Joiner
2010-09-19 15:14 . 2010-09-19 15:14 -------- d-----w- c:\users\zora\AppData\Local\Apps
2010-09-19 15:14 . 2010-09-19 15:20 -------- d-----w- c:\users\zora\AppData\Local\Deployment
2010-09-16 20:05 . 2010-09-16 20:05 -------- d-----w- c:\programdata\ALM
2010-09-16 12:26 . 2010-09-16 12:26 -------- d-----w- c:\users\zora\AppData\Roaming\Sony Creative Software
2010-09-15 07:46 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-14 12:11 . 2010-09-17 21:46 -------- d-----w- c:\program files\Common Files\Adobe
2010-09-14 12:11 . 2010-09-18 17:58 -------- d-----w- c:\users\zora\AppData\Local\Adobe
2010-09-13 20:22 . 2009-06-09 11:28 64000 ------w- c:\windows\system32\agrsmdel.exe
2010-09-13 20:22 . 2009-03-27 16:12 14848 ------w- c:\windows\system32\agrsco64.dll
2010-09-13 20:22 . 2010-09-13 20:22 -------- d-----w- c:\program files\LSI SoftModem
2010-09-13 20:21 . 2010-09-13 20:21 -------- d-----w- c:\windows\Options
2010-09-13 19:43 . 2010-09-13 19:43 -------- d-----w- c:\program files\Synaptics
2010-09-13 18:19 . 2010-09-13 18:19 6656 ----a-w- c:\windows\system32\bcmwlrc.dll
2010-09-13 18:19 . 2010-09-13 18:19 91376 ----a-w- c:\windows\system32\bcmwlcoi.dll
2010-09-13 18:19 . 2010-09-13 18:19 3870720 ----a-w- c:\windows\system32\bcmihvsrv.dll
2010-09-13 18:19 . 2010-09-13 18:19 3559424 ----a-w- c:\windows\system32\bcmihvui.dll
2010-09-13 18:19 . 2010-09-13 18:19 2707448 ----a-w- c:\windows\system32\drivers\BCMWL6.SYS
2010-09-13 18:19 . 2010-09-13 18:19 -------- d-----w- c:\program files\Broadcom
2010-09-13 16:46 . 2009-06-25 11:58 138240 ----a-w- c:\windows\system32\aestacap.dll
2010-09-13 16:46 . 2009-05-21 11:58 372736 ----a-w- c:\windows\system32\aestecap.dll
2010-09-13 16:46 . 2009-03-02 10:57 61440 ----a-w- c:\windows\system32\aestaren.dll
2010-09-13 16:46 . 2009-10-12 12:51 495708 ----a-w- c:\windows\sttray.exe
2010-09-13 16:46 . 2009-10-12 12:51 3043328 ----a-w- c:\windows\system32\stlang.dll
2010-09-13 16:46 . 2009-03-02 10:47 86016 ----a-w- c:\windows\system32\AESTCom.dll
2010-09-13 16:46 . 2009-10-12 12:51 175616 ----a-w- c:\windows\system32\staco.dll
2010-09-13 16:45 . 2009-10-12 12:51 420864 ----a-w- c:\windows\system32\drivers\stwrt.sys
2010-09-13 16:45 . 2009-10-12 12:51 916480 ----a-w- c:\windows\system32\stapo.dll
2010-09-13 16:45 . 2009-10-12 12:51 492032 ------w- c:\windows\system32\stapi32.dll
2010-09-13 16:45 . 2009-10-12 12:51 405504 ----a-w- c:\windows\system32\stcplx.dll
2010-09-13 16:45 . 2010-09-13 16:47 -------- d-----w- c:\program files\IDT
2010-09-13 16:45 . 2010-09-13 20:21 -------- d-----w- C:\SwSetup
2010-09-13 13:21 . 2010-09-13 13:21 -------- d-----w- c:\users\zora\AppData\Roaming\Easeware
2010-09-13 13:21 . 2010-09-13 13:21 -------- d-----w- c:\program files\Easeware
2010-09-13 13:03 . 2010-09-13 13:03 -------- d-----w- c:\program files\WinASO
2010-09-13 12:59 . 2010-09-13 13:00 -------- d-----w- c:\program files\Next Video Converter
2010-09-04 10:44 . 2010-08-30 12:34 1496064 ----a-w- c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-09-04 10:44 . 2010-08-30 12:33 43008 ----a-w- c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-09-04 10:44 . 2010-08-30 12:33 338944 ----a-w- c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-09-04 10:44 . 2010-08-30 12:33 346112 ----a-w- c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Rapport )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-02 20:43 . 2010-02-15 12:45 -------- d-----w- c:\users\zora\AppData\Roaming\vlc
2010-10-02 19:29 . 2010-02-11 19:57 -------- d-----w- c:\users\zora\AppData\Roaming\Dropbox
2010-10-01 15:59 . 2010-10-01 15:59 -------- d-----w- c:\program files\VITSOFT
2010-09-30 01:27 . 2010-02-15 22:59 -------- d-----w- c:\users\zora\AppData\Roaming\Skype
2010-09-30 00:59 . 2010-06-07 11:53 -------- d-----w- c:\program files\Avidemux 2.5
2010-09-29 23:07 . 2010-02-15 23:03 -------- d-----w- c:\users\zora\AppData\Roaming\skypePM
2010-09-29 23:07 . 2010-02-15 22:58 -------- d-----w- c:\programdata\Skype
2010-09-29 16:56 . 2010-06-23 10:20 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-27 23:32 . 2010-02-11 12:06 -------- d-----w- c:\users\zora\AppData\Roaming\Orbit
2010-09-27 18:34 . 2010-02-14 09:26 -------- d-----w- c:\program files\ATI Technologies
2010-09-27 11:44 . 2010-09-27 11:44 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-09-27 11:44 . 2010-09-27 11:44 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-09-27 11:44 . 2010-09-27 11:44 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-09-27 11:44 . 2010-09-27 11:44 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-09-27 11:44 . 2010-09-27 11:44 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-09-27 11:44 . 2010-09-27 11:44 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-09-27 11:44 . 2010-09-27 11:44 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-09-27 11:44 . 2010-09-27 11:44 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-09-27 11:44 . 2010-09-27 11:44 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-09-27 11:44 . 2010-04-08 06:53 -------- d-----w- c:\program files\Common Files\Real
2010-09-27 11:44 . 2010-04-08 06:53 -------- d-----w- c:\program files\Real
2010-09-27 11:44 . 2010-09-27 11:44 -------- d-----w- c:\program files\Common Files\xing shared
2010-09-27 11:43 . 2003-10-17 12:44 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-09-23 20:24 . 2010-07-26 23:38 -------- d-----w- c:\users\zora\AppData\Roaming\Sony
2010-09-23 01:05 . 2010-02-14 21:59 -------- d-----w- c:\users\zora\AppData\Roaming\uTorrent
2010-09-17 22:11 . 2010-02-07 18:48 69816 ----a-w- c:\users\zora\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-16 21:42 . 2010-02-13 11:03 -------- d-----w- c:\program files\Common Files\Common Share
2010-09-15 23:13 . 2010-07-27 20:55 -------- d-----w- c:\users\zora\AppData\Roaming\Publish Providers
2010-09-15 08:17 . 2010-02-10 16:28 -------- d-----w- c:\programdata\Microsoft Help
2010-09-13 23:55 . 2010-02-13 10:06 -------- d-----w- c:\users\zora\AppData\Roaming\dvdcss
2010-09-13 19:43 . 2010-09-13 19:43 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_SynTP_01007.Wdf
2010-09-13 16:45 . 2010-02-14 09:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-13 12:28 . 2010-02-14 00:54 -------- d-----w- c:\program files\ReviverSoft
2010-09-13 12:24 . 2010-08-04 23:05 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-09-13 12:11 . 2010-02-16 08:00 -------- d-----w- c:\program files\Your Uninstaller 2008
2010-09-12 11:04 . 2010-07-10 16:41 452104 ----a-w- c:\users\zora\AppData\Roaming\Real\Update\setup3.12\setup.exe
2010-09-08 21:23 . 2010-02-11 12:06 -------- d-----w- c:\users\zora\AppData\Roaming\GrabPro
2010-08-28 18:07 . 2010-08-28 17:46 -------- d-----w- c:\users\zora\AppData\Roaming\Spotify
2010-08-28 17:46 . 2010-08-28 17:46 655360 ----a-w- c:\users\zora\AppData\Roaming\Spotify\Gracenote\gnsdk_sdkmanager.dll
2010-08-28 17:46 . 2010-08-28 17:46 282624 ----a-w- c:\users\zora\AppData\Roaming\Spotify\Gracenote\gnsdk_musicid_file.dll
2010-08-28 17:46 . 2010-08-28 17:46 208896 ----a-w- c:\users\zora\AppData\Roaming\Spotify\Gracenote\gnsdk_dsp.dll
2010-08-28 17:45 . 2010-08-28 17:45 -------- d-----w- c:\program files\Spotify
2010-08-24 09:28 . 2010-08-24 09:28 2240664 ----a-w- c:\users\zora\AppData\Roaming\Easeware\DriverEasy\drivers\atzqjzec.vlt\setup_v11.28.6.3\setup.exe
2010-08-24 07:33 . 2010-08-24 07:33 374048 ----a-w- c:\windows\system32\yk62x86.dll
2010-08-24 07:33 . 2010-08-24 07:33 323360 ----a-w- c:\windows\system32\drivers\yk62x86.sys
2010-08-22 20:11 . 2010-08-22 20:11 -------- d-----w- c:\program files\Common Files\Java
2010-08-22 20:01 . 2010-05-23 20:07 -------- d-----w- c:\program files\Java
2010-08-22 12:13 . 2010-04-11 17:07 -------- d-----w- c:\users\zora\AppData\Roaming\Audacity
2010-08-22 11:05 . 2010-08-22 11:05 -------- d-----w- c:\program files\Recuva
2010-08-22 10:17 . 2010-02-17 20:40 -------- d-----w- c:\users\zora\AppData\Roaming\Media Player Classic
2010-08-21 21:35 . 2010-02-10 15:38 -------- d-----w- c:\program files\Oshobooks
2010-08-19 20:47 . 2010-08-19 20:47 -------- d-----w- c:\program files\Lame for Audacity
2010-08-16 08:42 . 2010-08-16 08:42 -------- d-----w- c:\users\zora\AppData\Roaming\ProgSense
2010-08-16 08:42 . 2010-08-16 06:37 -------- d-----w- c:\program files\Orbitdownloader
2010-08-15 20:46 . 2010-08-15 19:52 -------- d-----w- c:\program files\GetASFStream
2010-08-11 16:23 . 2010-04-21 07:24 -------- d-----w- c:\program files\Free PDF to Word Converter
2010-08-05 17:55 . 2010-02-22 15:20 -------- d-----w- c:\program files\Defraggler
2010-08-04 23:21 . 2010-08-04 23:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-29 06:30 . 2010-08-12 18:52 197632 ----a-w- c:\windows\system32\ir32_32.dll
2010-07-29 06:30 . 2010-08-12 18:52 82944 ----a-w- c:\windows\system32\iccvid.dll
2010-07-21 18:34 . 2010-02-26 05:39 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2010-07-21 18:33 . 2010-02-26 05:39 346944 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2010-07-17 03:00 . 2010-05-23 20:08 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-08 19:46 . 2010-07-08 19:46 0 ----a-w- c:\windows\nsreg.dat
1999-06-25 09:55 . 2010-02-10 19:58 149504 ----a-w- c:\program files\UNWISE.EXE
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
.

(((((((((((((((((((((((((((((((((( Startpunkter i registret )))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Not* Tomma poster & legitima standardposter visas inte.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2010-05-26 13:23 1385864 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-05-26 1385864]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\zora\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\zora\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 ----a-w- c:\users\zora\AppData\Roaming\Dropbox\bin\DropboxExt.13.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
"Google Update"="c:\users\zora\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-09-19 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"AmIcoSinglun"="c:\program files\AmIcoSingLun\AmIcoSinglun.exe" [2009-07-16 233472]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"dvd43"="c:\program files\dvd43\dvd43_tray.exe" [2009-10-23 827904]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-10 2221352]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-10-12 495708]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-29 1545512]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SearchSettings"="c:\program files\YouTube Downloader Toolbar\SearchSettings.exe" [2010-02-19 974848]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-09-27 202256]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-11-10 98304]

c:\users\zora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\zora\AppData\Roaming\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
Sk„rmurklipp och start f”r OneNote 2007.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BankID Security Application.lnk - c:\program files\Personal\bin\Personal.exe [2010-7-17 939920]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS [2009-07-03 25600]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2009-12-21 16456]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2009-12-21 11088]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-02 1343400]
R3 vpcuxd;USB Virtualization Stub Service;c:\windows\system32\DRIVERS\vpcuxd.sys [2009-09-23 12800]
R3 zteusbser;ZTE USB Device for Legacy Serial Communication;c:\windows\system32\DRIVERS\zteusbser.sys [2007-04-10 98432]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-04-05 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-23 64288]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_499a67a913bde1c7\aestsrv.exe [2009-03-02 81920]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-11-11 172032]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2010-02-19 380928]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-30 1352832]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys [2009-10-19 31288]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2010-08-24 323360]

.
Innehållet i mappen 'Schemalagda aktiviteter':

2010-10-02 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 10:47]

2010-09-13 c:\windows\Tasks\DriverEasy Scheduled Scan.job
- c:\program files\Easeware\DriverEasy\DriverEasy.exe [2010-09-13 18:29]

2010-10-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655287907-1841894106-2909972900-1000Core.job
- c:\users\zora\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-19 15:23]

2010-10-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1655287907-1841894106-2909972900-1000UA.job
- c:\users\zora\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-19 15:23]
.
.
------- Extra genomsökning -------
.
uStart Page = hxxp://www.yahoo.com/
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Append Link Target to Existing PDF
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xportera till Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - component: c:\program files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll
FF - component: c:\program files\YouTube Downloader Toolbar\FF\components\youtubedownloaderToolbarFF.dll
FF - component: c:\program files\YouTube Downloader Toolbar\SSFF\components\SearchSettingsFF.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Personal\bin\np_prsnl.dll
FF - plugin: c:\program files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\users\zora\AppData\Local\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\users\zora\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll

---- FIREFOX POLICY ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - FÖRÄLDRALÖSA POSTER SOM TAGITS BORT - - - -

AddRemove-LSI Soft Modem - c:\windows\agrsmdel


.
--------------------- LÅSTA REGISTERNYCKLAR ---------------------

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Sluttid: 2010-10-03 00:47:25
ComboFix-quarantined-files.txt 2010-10-02 22:47

Före genomsökningen: 9 063 100 416 bytes free
Efter genomsökningen: 9 106 669 568 bytes free

- - End Of File - - 9C21B300DCC4A49CFA47533321AA4AE1

Dopuna: 03 Okt 2010 12:34

hvala, jos jednom ako je ovime resen moj problem .
upravo proveravam sa spyboot-om i ako se ne javim opet..
onda Ziveli

da li da obrisem sve fajlove i programe koje smo koristili pri ciscenju.. Question
(preostali 'lijek i instrumente')

ako opet nekad zatreba postupak se moze ponoviti uz vase jasno uputstvo.. Smile

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Otvoriti Notepad i iskopirati sledeci tekst:

Firefox::
FF - ProfilePath - c:\users\zora\AppData\Roaming\Mozilla\Firefox\Profiles\iatjo3y8.default\
FF - component: c:\program files\YouTube Downloader Toolbar\SSFF\components\SearchSettingsFF.dll

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SearchSettings"=-

File::
c:\program files\YouTube Downloader Toolbar\SearchSettings.exe
c:\program files\YouTube Downloader Toolbar\SSFF\components\SearchSettingsFF.dll


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

Ko je trenutno na forumu
 

Ukupno su 1054 korisnika na forumu :: 36 registrovanih, 4 sakrivenih i 1014 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: bojcistv, bokisha253, cavatina, Dannyboy, Darko001, hyla, ILGromovnik, Joja, Karla, kolle.the.kid, Komentator, kybonacci, ladro, loon123, Lucije Kvint, M1los, mercedesamg, Metanoja, milenko crazy north, Milos ZA, mkukoleca, mnn2, nikoladim, Parker, procesor, RED4G-304, tubular, User98, vathra, Vlada78, vladaa012, voja64, Yellow Pinky, YU-UKI, zafon031, zhuki8