offline
- biloxi
- Novi MyCity građanin
- Pridružio: 15 Jul 2009
- Poruke: 25
|
biloxi ::Evo za DDS
mycity.rs/must-login.png
Evo za RootRepeal
mycity.rs/must-login.png
Ovo nista nije dobro...
Evo sad je dobro:
Za DDS
DDS (Ver_09-06-26.01) - NTFSx86
Run by Bojan Suvajac at 14:47:05.81 on Sun 07/26/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.991.509 [GMT 2:00]
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalService
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\Bojan Suvajac\Desktop\dds(2).scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.ba/
uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076
uInternet Settings,ProxyServer = 421.420.422:80
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live pomagac za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
mRun: [nwiz] nwiz.exe /install
mRun: [WinampAgent] c:\program files\winamp\winampa.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [update.dll] c:\windows\system32\vsnpstd3.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: I&zvezi u program Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\bojans~1\applic~1\mozilla\firefox\profiles\ed19s0zo.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319744&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - RapidSerbia 2 Customized Web Search
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2319744&SearchSource=2&q=
FF - component: c:\documents and settings\bojan suvajac\application data\mozilla\firefox\profiles\ed19s0zo.default\extensions\{88b7dfed-4320-425d-a023-f224863916f0}\components\FFExternalAlert.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-7-24 28544]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-2-6 107256]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840]
R2 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2009-6-3 604416]
S2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
S2 gupdate1c9ef4c2f326b9a;Google Update Service (gupdate1c9ef4c2f326b9a);c:\program files\google\update\GoogleUpdate.exe [2009-6-17 133104]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2009-6-14 13224]
S3 gggen;Generic USB Flash Driver;c:\windows\system32\drivers\gggen.sys [2009-5-13 11648]
S3 kvpndev;Kerio VPN adapter;c:\windows\system32\drivers\kvpndrv.sys [2008-6-24 65024]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;c:\windows\system32\drivers\kwflower.sys --> c:\windows\system32\drivers\kwflower.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
=============== Created Last 30 ================
2009-07-26 12:54 98,304 a------- c:\windows\system32CmdLineExt.dll
2009-07-26 12:01 41,984 a------- c:\windows\system32\vsnpstd3.exe
2009-07-24 22:09 28,544 a------- c:\windows\system32\drivers\pavboot.sys
2009-07-24 22:07 <DIR> --d----- c:\program files\Panda Security
2009-07-24 20:12 93,669 a------- c:\windows\system32\drivers\explorer.exe
2009-07-21 11:21 1,696 a------- c:\windows\Ky5s96SF.csa
2009-07-21 11:21 566,784 a------- c:\windows\~de74bc.tmp
2009-07-21 11:21 697,884 a------- c:\windows\~df394b.tmp
2009-07-21 11:21 567,296 a------- c:\windows\n.tmp
2009-07-21 11:20 <DIR> --d----- c:\program files\common files\Autodata Limited Shared
2009-07-21 11:20 <DIR> --d----- C:\Adcda2
2009-07-17 21:15 <DIR> --d----- c:\windows\pss
2009-07-17 10:58 <DIR> --d----- c:\program files\Lavasoft
2009-07-17 10:56 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-07-17 10:52 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-07-17 10:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-07-15 14:00 <DIR> --dsh--- c:\documents and settings\bojan suvajac\IECompatCache
2009-07-15 12:47 <DIR> --dsh--- c:\documents and settings\bojan suvajac\PrivacIE
2009-07-15 12:45 <DIR> --dsh--- c:\documents and settings\bojan suvajac\IETldCache
2009-07-15 12:27 <DIR> --d----- c:\windows\ie8updates
2009-07-15 12:22 <DIR> -cd-h--- c:\windows\ie8
2009-07-15 12:12 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-07-15 12:11 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-07-15 12:11 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-07-15 11:58 218,624 a------- c:\windows\system32\uxtheme.dll.backup
2009-07-15 11:58 <DIR> --d-h--- c:\windows\NiwradSoft Shell Pack
2009-07-14 11:05 <DIR> --d----- c:\docume~1\bojans~1\applic~1\ESET
2009-07-14 11:04 <DIR> --d----- c:\program files\ESET
2009-07-09 14:26 <DIR> --d----- c:\program files\directx
2009-07-09 14:15 <DIR> --d----- c:\program files\TDK
2009-07-04 10:48 <DIR> --d----- c:\program files\UltraISO
2009-07-03 12:00 <DIR> --d----- c:\program files\Urban Jungle
2009-07-01 14:36 268,648 a------- c:\windows\system32\mucltui.dll
2009-07-01 14:36 208,744 a------- c:\windows\system32\muweb.dll
2009-07-01 14:36 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-07-01 14:10 1,897 a------- c:\windows\system32\BIN_STRSBW.SPT
2009-06-30 11:32 20,661 a------- c:\program files\config.dat
2009-06-30 11:22 41,472 a------- c:\program files\DrvMgt.dll
2009-06-30 11:22 12,528 a------- c:\program files\SECDRV.SYS
2009-06-30 11:22 3,985,408 -------- c:\program files\fifa2005.exe
2009-06-30 11:21 <DIR> --d----- c:\program files\Support
2009-06-30 11:21 <DIR> --d----- c:\program files\data
2009-06-29 11:21 <DIR> --d----- c:\program files\Elltube
2009-06-27 18:18 <DIR> --d----- c:\program files\UlisesSoft
==================== Find3M ====================
2009-07-17 14:58 218,624 a------- c:\windows\system32\uxtheme.dll
2009-07-15 13:12 2,320,640 a------- c:\windows\system32\TUKernel.exe
2009-06-25 12:28 6,028 a------- c:\windows\system32\drivers\kwflower.log
2009-06-25 12:26 2,965 a------- c:\windows\system32\drivers\kwfupper.log
2009-06-14 15:16 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01007.Wdf
2009-06-14 15:16 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-06-14 15:10 1,112,288 a------- c:\windows\system32\WdfCoInstaller01007.dll
2009-06-14 15:10 25,512 a------- c:\windows\system32\drivers\ggsemc.sys
2009-06-14 15:10 13,224 a------- c:\windows\system32\drivers\ggflt.sys
2009-06-03 09:38 604,416 a------- c:\windows\system32\TUProgSt.exe
2009-06-03 09:38 361,216 a------- c:\windows\system32\TuneUpDefragService.exe
2009-06-01 16:56 4,608 a------- c:\windows\system32\w95inf32.dll
2009-06-01 16:56 2,272 a------- c:\windows\system32\w95inf16.dll
2009-05-21 12:44 107,888 a------- c:\windows\system32\CmdLineExt.dll
2009-05-19 21:35 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-13 18:09 720,896 a------- c:\windows\iun6002.exe
2009-05-10 17:00 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-05-10 16:12 2,678 a------- c:\windows\java\packages\data\TR13DVRF.DAT
2009-05-10 16:12 558,142 a------- c:\windows\java\packages\5Z3TB97D.ZIP
2009-05-10 16:12 2,678 a------- c:\windows\java\packages\data\TBTFJVZ1.DAT
2009-05-10 16:12 155,995 a------- c:\windows\java\packages\3B9N5R1V.ZIP
2009-05-10 16:12 2,678 a------- c:\windows\java\packages\data\WCTRT7J7.DAT
2009-05-10 16:12 2,678 a------- c:\windows\java\packages\data\BP3PJPJR.DAT
2009-05-10 16:12 2,678 a------- c:\windows\java\packages\data\NVB3TB79.DAT
2009-05-10 16:09 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-04-28 11:47 499,712 a------- c:\windows\system32\msvcp71.dll
2009-04-28 11:47 348,160 a------- c:\windows\system32\msvcr71.dll
2007-03-15 18:03 215,453 a------- c:\documents and settings\bojan suvajac\we07keygen.exe
2004-08-04 00:56 24,804 ----h--- c:\docume~1\bojans~1\applic~1\addons.dat
============= FINISH: 14:47:41.65 ===============
mycity.rs/must-login.png
Za RootRepeal
mycity.rs/must-login.png
|