Poslao: 29 Mar 2013 18:30
|
offline
- ilija7
- Novi MyCity građanin
- Pridružio: 26 Jul 2008
- Poruke: 4
|
Ne znam kako da uklonim viruse iz računara. Dešava mi se da mi kompjuter totalno ukoči, da ne radi, da otvara stranicu 2 minuta. A najviše se to ispoljava kad hoću interenet da koristim. Uđem preko google chrom-a i tad je otvaranje kao večnost.
Ovaj problem sam primetio pre 20 dana kada sam ubacio USB memoriju u kompjuter i kada mi je na tom istom USB napravljena neka prečica. Od tad ja taj USB ne mogu da otvorim, avast antivirus mi to ne dozvoljava.
Sve što mi antivirus izbacio Avast antivirus ja sam navodno obrisao i tih datoteka nema više u računaru, međutim zamenio sam antivirus program i instalirao Nod32 i on mi je detektovao u windows-u virus Win32 koga ja ne mogu da obrišem jer je u sistemu. A detekciju je pokazao i na Java programu.
Probao sam da obrišem neke zaražene programe ali je virus bio i dalje tu. A inače imam bežični internet sa protokom od 1536/768 kb/s.
E sad ovo što sam uradio sa DDS i Attach.
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.2180
Run by pc at 17:44:53 on 2013-03-29
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1279.495 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SearchProtect\bin\CltMngSvc.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://searchfunmoods.com/?f=1&a=fmtgl&cd=2XzuyEtN2Y1L1QzutDtD0EtDtBtD0A0C0DtB0FtA0BtAtAyDtN0D0Tzu0CtAyBzztN1L2XzutN1L1Czu1O1H2Z1N1I&cr=1251408273&ir=
uSearch Bar = hxxp://dts.search-results.com/sidebar.html?src=ssb&appid=101&systemid=406&sr=0
mStart Page = hxxp://searchfunmoods.com/?f=1&a=fmtgl&cd=2XzuyEtN2Y1L1QzutDtD0EtDtBtD0A0C0DtB0FtA0BtAtAyDtN0D0Tzu0CtAyBzztN1L2XzutN1L1Czu1O1H2Z1N1I&cr=1251408273&ir=
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
mSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
uURLSearchHooks: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: HistoryTriggerBHO Class: {21A88CB9-84D2-4020-A2D1-B25A21034884} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: IE5BarLauncherBHO Class: {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - c:\program files\startsearch plugin\ssBarLcher.dll
BHO: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SweetIM Toolbar Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: iWin Toolbar: {CE0C2586-DA36-452B-ACDB-320D9BCB19BF} - c:\program files\iwin\prxtbiWi0.dll
TB: StartSearchToolBar: {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - c:\program files\startsearch plugin\ssBarLcher.dll
TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
TB: StartSearchToolBar: {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - c:\program files\startsearch plugin\ssBarLcher.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\pc\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - hxxp://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{95B6BD40-9C41-4D68-8723-AE03143A1514} : DHCPNameServer = 10.151.102.2 10.200.1.30 10.200.1.31
TCP: Interfaces\{ED7F5DBF-2D8F-44D8-B264-FC00A219EBA0} : NameServer = 10.151.102.2 10.151.102.2
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
AppInit_DLLs= c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-3-29 368176]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-3-29 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-3-29 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-3-29 45248]
R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\searchprotect\bin\CltMngSvc.exe [2012-12-26 87552]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2012-4-21 233472]
R3 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-29 164736]
R3 cmipci;CMI8738/8768 Audio Driver;c:\windows\system32\drivers\cmipci.sys [2011-4-6 37888]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-4-21 36608]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 slnt;Silan SC92031 PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [2011-4-6 18004]
R4 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys --> c:\windows\system32\drivers\ehdrv.sys [?]
R4 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-29 49248]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-3-29 765736]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-12-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-12-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-12-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-12-23 25088]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
S3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2012-7-23 15896]
S3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\drivers\zghsmdm.sys [2012-7-23 113688]
.
=============== Created Last 30 ================
.
2013-03-29 16:36:30 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-29 16:36:29 164736 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-29 16:36:28 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-29 16:36:28 49248 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-29 16:35:42 41664 ----a-w- c:\windows\avastSS.scr
2013-03-29 16:34:57 -------- d-----w- c:\program files\AVAST Software
2013-03-29 16:31:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-28 00:48:39 -------- d-----w- c:\documents and settings\pc\local settings\application data\Temp
2013-03-26 15:02:39 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\Repository
2013-03-17 23:53:47 -------- d-----w- c:\documents and settings\all users\application data\Norton
2013-03-13 11:03:47 77824 --sha-w- c:\documents and settings\all users\ms0055AC65.dat
2013-03-07 13:57:20 -------- d-----w- c:\documents and settings\all users\application data\Alwil Software
.
==================== Find3M ====================
.
.
============= FINISH: 17:45:31.51 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/5/2011 7:14:44 PM
System Uptime: 3/29/2013 9:54:33 AM (8 hours ago)
.
Motherboard: | | VT8366-8233
Processor: Unknown CPU Type | Socket A | 1799/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 18 GiB total, 6.453 GiB free.
D: is FIXED (FAT32) - 59 GiB total, 12.881 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP589: 3/25/2013 12:42:28 PM - System Checkpoint
RP590: 3/26/2013 7:43:32 PM - System Checkpoint
RP591: 3/27/2013 9:44:37 PM - System Checkpoint
RP592: 3/28/2013 1:22:15 AM - avast! Free Antivirus Setup
RP593: 3/28/2013 12:16:23 PM - Installed ESET NOD32 Antivirus
RP594: 3/29/2013 12:35:04 PM - System Checkpoint
RP595: 3/29/2013 5:30:18 PM - Removed ESET NOD32 Antivirus
RP596: 3/29/2013 5:34:57 PM - avast! Free Antivirus Setup
.
==== Installed Programs ======================
.
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.1.6)
Ahead Nero 6 Demo
Autodesk DWF Viewer
avast! Free Antivirus
Codec Pack - All In 1 6.0.3.0
Compatibility Pack for the 2007 Office system
Contrast PlanPlus 2006
FastStone Image Viewer 4.6
Free PDF to Word Doc Converter v1.1
GOM Player
Google Chrome
hp deskjet 3600
hp deskjet 3600 series
HP Memories Disc
HP Photo and Imaging 2.0 - Deskjet Series
hp print screen utility
Intel(R) 536EP Modem
iWin Toolbar
Java Auto Updater
Java(TM) 6 Update 30
Java(TM) SE Runtime Environment 6 Update 1
LG Bluetooth Drivers
LG United Mobile Drivers
LiveVDO plugin 1.3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Calculator Plus
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MPEG2 Codec(libmpeg2/mad)
MSVC80_x86_v2
MSXML 4.0 SP2 Parser and SDK
Nokia Connectivity Cable Driver
Nokia PC Suite
PC Connectivity Solution
PDF4Free 3.0
PhotoScape
Picasa 3
SAMSUNG Mobile Composite Device Software
Samsung Mobile Modem Device Software
SAMSUNG Mobile Modem Driver Set
SAMSUNG Mobile Modem V2 Software
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung New PC Studio
Samsung New PC Studio USB Driver Installer
SAMSUNG SYMBIAN USB Download Driver
SAMSUNG USB Mobile Device Software
SamsungConnectivityCableDriver
Search Protect by conduit
SweetIM for Messenger 3.4
SweetIM Toolbar for Internet Explorer 4.1
Total Commander (Remove or Repair)
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Driver Package - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0)
Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.8)
Windows Driver Package - Nokia Modem (10/07/2010 4.6)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinRAR archiver
YuRecnik
ZTE Handset USB Driver
.
==== Event Viewer Messages From Past Week ========
.
3/29/2013 4:13:35 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
3/27/2013 12:14:56 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Machine Debug Manager service to connect.
3/27/2013 12:14:56 PM, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/26/2013 9:47:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
3/26/2013 9:47:19 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/25/2013 11:02:34 AM, error: Service Control Manager [7000] - The hpdj service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================
|
|
|
|
|
Poslao: 29 Mar 2013 19:05
|
offline
- ilija7
- Novi MyCity građanin
- Pridružio: 26 Jul 2008
- Poruke: 4
|
Sačuvao sam GMER na desktop-u i prilikom pokretenja svaki put mi se kompjuter restartuje sam i to sam 3 puta probao da pokrenem i neće.
|
|
|
|
|
|
Poslao: 29 Mar 2013 19:47
|
offline
- TwinHeadedEagle
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
Na sistemu nije prisutan malware, ali je prisutno dosta "crap" softvera i dva antivirusa, tj. Avast i ostaci ESET-a, koje je potrebno ukloniti.
Korak 1.
* preuzmi avast! Uninstall Utility na Desktop
* restartuj racunar u Safe Mode po ovom uputstvu
* pokreni preuzeti alat i isprati uputstvo (maticni link je --> http://www.avast.com/uninstall-utility)
Korak 2.
Pokreni Control Panel --> Add or Remove Programs i obrisi sledece ukoliko ne koristis:
- iWin Toolbar
- Search Protect by conduit
- SweetIM for Messenger 3.4
- SweetIM Toolbar for Internet Explorer 4.1
Restartuj racunar!
Korak 3.
Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop
Dvoklikom pokreni program i klikni na dugme [Search] .
Kada program zavrsi analizu otvorice notepad sa izvestajem. Zatvori taj notepad.
Klikni na dugme [Delete] i pricekaj da program zavrsi.
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok
Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"
Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt
Korak 4.
Ponovo pokreni DDS i dostavi mi svez DDS.txt log...
|
|
|
|
Poslao: 29 Mar 2013 20:39
|
offline
- ilija7
- Novi MyCity građanin
- Pridružio: 26 Jul 2008
- Poruke: 4
|
U control panelu izbrisao sam samo Search Protect by conduit, ostale nisam mogao.
mycity.rs/must-login.png
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.2180
Run by pc at 20:36:08 on 2013-03-29
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1279.732 [GMT 1:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: HistoryTriggerBHO Class: {21A88CB9-84D2-4020-A2D1-B25A21034884} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\pc\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - hxxp://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{95B6BD40-9C41-4D68-8723-AE03143A1514} : DHCPNameServer = 10.151.102.2 10.200.1.30 10.200.1.31
TCP: Interfaces\{ED7F5DBF-2D8F-44D8-B264-FC00A219EBA0} : NameServer = 10.151.102.2 10.151.102.2
AppInit_DLLs= c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2012-4-21 233472]
R3 cmipci;CMI8738/8768 Audio Driver;c:\windows\system32\drivers\cmipci.sys [2011-4-6 37888]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-4-21 36608]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 slnt;Silan SC92031 PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [2011-4-6 18004]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;\??\c:\windows\system32\drivers\aswmonflt.sys --> c:\windows\system32\drivers\aswMonFlt.sys [?]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-12-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-12-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-12-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-12-23 25088]
S3 aswVmm;aswVmm; [x]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
S3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2012-7-23 15896]
S3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\drivers\zghsmdm.sys [2012-7-23 113688]
.
=============== Created Last 30 ================
.
2013-03-29 16:34:57 -------- d-----w- c:\program files\AVAST Software
2013-03-29 16:31:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-28 00:48:39 -------- d-----w- c:\documents and settings\pc\local settings\application data\Temp
2013-03-26 15:02:39 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\Repository
2013-03-17 23:53:47 -------- d-----w- c:\documents and settings\all users\application data\Norton
2013-03-13 11:03:47 77824 --sha-w- c:\documents and settings\all users\ms0055AC65.dat
2013-03-07 13:57:20 -------- d-----w- c:\documents and settings\all users\application data\Alwil Software
.
==================== Find3M ====================
.
.
============= FINISH: 20:36:23.72 ===============
mycity.rs/must-login.png
mycity.rs/must-login.png
|
|
|
|
|