problem sa zamrzavanjem i restartom

1

problem sa zamrzavanjem i restartom

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

skoro sam odradio reinstalaciju winXP na particiji C, i do jutros je sve bilo u redu.

u poslednjih pet ili šest sati računar se zamrzavao iz čista mira, a par puta je nešto jako brzo ispisao na plavom ekranu i krenuo u restartovanje.

zatim je tražio da se odradi provera particije C , obrisao je jedan .tmp fajl i podigao xp normalno.

posle desetak minuta rada, ponovo se zamrzao, stojao tako nekih 30 sekundi i nastavio sa radom.

evo izveštaja po upustvu ( radjeno DDS-om)


DDS (Ver_09-07-30.01) - NTFSx86
Run by tamara at 17:05:45,14 on pon 21.09.2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.491 [GMT 2:00]

AV: avast! antivirus 4.8.1351 [VPS 090920-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\PROGRA~1\MICROS~2\Office14\GROOVEMN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft Office\Office14\OfficeSAS\officeSASscheduler.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSAS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\tamara\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = [Link mogu videti samo ulogovani korisnici]
uSearch Bar = [Link mogu videti samo ulogovani korisnici]
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchAssistant = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Windows Live pomagac za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [EasyTuneVPro] c:\program files\gigabyte\et5pro\ETcall.exe
mRun: [Gainward] c:\program files\vdotool\TBPanel.exe /A
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [GrooveMonitor] c:\progra~1\micros~2\office14\GROOVEMN.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Version Cue CS2] "c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [<NO NAME>]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office14\officesas\officeSASscheduler.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: DirectAnimation Java Classes - [Link mogu videti samo ulogovani korisnici]\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\java\classes\xmldso.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [Link mogu videti samo ulogovani korisnici]
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - [Link mogu videti samo ulogovani korisnici]
TCP: {F496BBB4-C9DA-4E2B-BD43-01782ADDF1CB} = 212.200.190.166 212.200.191.166
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tamara\applic~1\mozilla\firefox\profiles\r7q9c9jt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-9-12 138680]
R2 osppsvc;Office Software Protection Platform;c:\windows\system32\OSPPSVC.EXE [2009-4-8 4319136]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-9-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-9-12 352920]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2009-9-7 24944]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2009-4-25 33480048]

=============== Created Last 30 ================

2009-09-18 09:16 <DIR> --d----- c:\windows\system32\scripting
2009-09-18 09:16 <DIR> --d----- c:\windows\system32\en
2009-09-18 09:16 <DIR> --d----- c:\windows\system32\bits
2009-09-18 09:16 <DIR> --d----- c:\windows\l2schemas
2009-09-18 09:13 <DIR> --d----- c:\windows\network diagnostic
2009-09-15 21:59 <DIR> --d----- c:\windows\Zuma's Revenge!
2009-09-15 21:59 <DIR> --d----- c:\program files\Zuma's Revenge!
2009-09-15 21:15 <DIR> --dsh--- c:\documents and settings\tamara\IECompatCache
2009-09-15 10:13 <DIR> --d----- c:\docume~1\tamara\applic~1\AVS4YOU
2009-09-15 08:33 <DIR> --dsh--- c:\documents and settings\tamara\PrivacIE
2009-09-14 22:18 <DIR> --dsh--- c:\documents and settings\tamara\IETldCache
2009-09-14 21:49 100,352 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-09-14 21:49 <DIR> --d----- c:\windows\ie8updates
2009-09-14 21:48 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-14 21:48 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-09-14 21:48 11,067,392 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-09-14 21:48 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-09-14 21:48 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll
2009-09-14 21:48 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-09-14 21:47 <DIR> -cd-h--- c:\windows\ie8
2009-09-14 10:51 <DIR> --d----- c:\program files\IrfanView
2009-09-14 09:57 397,312 -------- c:\windows\system32\mmcex.dll
2009-09-13 16:17 50 a------- c:\windows\cdplayer.ini
2009-09-11 22:26 68,096 a------- c:\windows\ScUnin.exe
2009-09-11 22:26 12,264 a------- c:\windows\scunin.dat
2009-09-11 22:26 967 a------- c:\windows\ScUnin.pif
2009-09-11 22:26 <DIR> --d----- c:\program files\Starcraft
2009-09-11 21:44 <DIR> --d----- c:\docume~1\tamara\applic~1\AIMP
2009-09-11 21:43 <DIR> --d----- c:\program files\AIMP2
2009-09-10 21:58 152 a------- c:\windows\system32\FOLESVR.DLL
2009-09-10 21:46 0 a------- c:\windows\PlayList.Fpl
2009-09-10 21:45 389,120 a------- c:\windows\system32\ACTSKN43.OCX
2009-09-10 21:45 <DIR> --d----- c:\windows\tmp
2009-09-10 21:45 3,286 a------- c:\windows\FantasyDVD.ini
2009-09-10 21:45 2,417 a------- c:\windows\ShortCutInf.ini
2009-09-10 21:45 544,768 a------- c:\windows\system32\CLVSD.ax
2009-09-10 21:45 45,056 a------- c:\windows\system32\ogg.dll
2009-09-10 21:45 <DIR> --d----- c:\windows\system32\FTCodecs
2009-09-10 21:45 <DIR> --d----- c:\program files\Fantasysoft-Studio
2009-09-10 21:35 <DIR> --d----- c:\program files\uTorrent
2009-09-10 21:34 <DIR> --d----- c:\docume~1\tamara\applic~1\uTorrent
2009-09-10 21:09 23 a------- c:\windows\ZDPLUSSEARCH.INI
2009-09-10 21:08 <DIR> --d----- c:\docume~1\tamara\applic~1\Zeon
2009-09-10 21:08 294 a------- c:\windows\dorp.dat
2009-09-10 21:07 <DIR> --d----- c:\program files\Nitro PDF
2009-09-10 21:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zeon
2009-09-10 16:45 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-09-10 16:44 <DIR> --d----- c:\windows\system32\LogFiles
2009-09-10 16:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-09-10 16:41 <DIR> --d----- c:\program files\common files\AVSMedia
2009-09-10 16:41 221,215 a------- c:\windows\system32\divxdec.ax
2009-09-10 16:41 82,944 a------- c:\windows\system32\vct3216.acm
2009-09-10 16:41 81,920 a------- c:\windows\system32\AC3ACM.acm
2009-09-10 16:41 53,248 a------- c:\windows\system32\xvid.ax
2009-09-10 16:41 38,912 a------- c:\windows\system32\alf2cd.acm
2009-09-10 16:41 13,239 a------- c:\windows\system32\Scg726.acm
2009-09-10 16:40 1,700,352 a------- c:\windows\system32\GdiPlus.dll
2009-09-10 16:40 974,848 a------- c:\windows\system32\mfc70.dll
2009-09-10 16:40 638,976 a------- c:\windows\system32\divx.dll
2009-09-10 16:40 524,288 a------- c:\windows\system32\xvidcore.dll
2009-09-10 16:40 487,424 a------- c:\windows\system32\msvcp70.dll
2009-09-10 16:40 413,760 a------- c:\windows\system32\mpg4c32.dll
2009-09-10 16:40 344,064 a------- c:\windows\system32\msvcr70.dll
2009-09-10 16:40 261,632 a------- c:\windows\system32\mcdvd_32.dll
2009-09-10 16:40 156,910 a------- c:\windows\WMSysPr8.prx
2009-09-10 16:40 139,264 a------- c:\windows\system32\xvidvfw.dll
2009-09-10 16:40 24,576 a------- c:\windows\system32\msxml3a.dll
2009-09-10 16:40 <DIR> --d----- c:\program files\AVS4YOU
2009-09-10 16:28 <DIR> --d----- c:\program files\common files\xing shared
2009-09-10 16:28 <DIR> --d----- c:\program files\common files\Real
2009-09-10 15:32 <DIR> --d----- c:\program files\The KMPlayer
2009-09-10 11:04 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-09-10 11:02 <DIR> --d----- c:\program files\common files\Corel
2009-09-10 11:00 <DIR> --d----- c:\program files\Corel
2009-09-10 10:05 3,244 a------- c:\windows\system32\wbem\Outlook_01ca31ed68a6c310.mof
2009-09-10 08:47 208,744 a------- c:\windows\system32\muweb.dll
2009-09-10 08:47 268,648 a------- c:\windows\system32\mucltui.dll
2009-09-10 08:47 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-09-09 11:37 <DIR> --d----- c:\windows\Downloaded Installations
2009-09-09 11:33 <DIR> --d----- c:\docume~1\tamara\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-09-09 11:33 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-09-08 23:02 <DIR> --d----- c:\program files\IVT Corporation
2009-09-08 23:02 32 a------- c:\windows\0
2009-09-08 23:02 0 a------- c:\windows\system32\0
2009-09-08 23:01 151,552 a------- c:\windows\system32\irftp.exe
2009-09-08 23:01 28,160 a------- c:\windows\system32\irmon.dll
2009-09-08 23:01 8,192 a------- c:\windows\system32\wshirda.dll
2009-09-08 22:04 <DIR> --d----- c:\documents and settings\tamara\Tracing
2009-09-08 21:31 <DIR> --d----- c:\program files\Microsoft
2009-09-08 21:31 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-09-08 21:18 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-08 21:06 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-09-08 21:05 730,112 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-09-08 21:05 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-09-08 21:05 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-09-08 21:05 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-09-08 21:05 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-08 21:05 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-09-08 21:05 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-09-08 21:05 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-09-08 21:05 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-09-08 21:05 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-08 21:05 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-08 21:05 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-08 21:04 153,088 -c------ c:\windows\system32\dllcache\triedit.dll
2009-09-08 21:00 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-09-08 20:58 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-09-08 20:58 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-09-08 20:58 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-09-08 20:58 331,776 -c------ c:\windows\system32\dllcache\msadce.dll
2009-09-08 20:58 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-09-08 20:57 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-09-08 20:57 2,066,432 -c------ c:\windows\system32\dllcache\mstscax.dll
2009-09-08 20:57 247,326 -c------ c:\windows\system32\dllcache\strmdll.dll
2009-09-08 20:56 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-09-08 20:55 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-09-08 20:55 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-09-08 20:55 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-09-07 22:13 16,384 a------- c:\windows\system32\FileOps.exe
2009-09-07 22:13 <DIR> --d----- c:\windows\system32\Adobe
2009-09-07 22:10 <DIR> --d----- c:\program files\common files\Adobe Systems Shared
2009-09-07 21:20 116 a------- c:\windows\NeroDigital.ini
2009-09-07 19:10 <DIR> --d----- c:\windows\system32\AGEIA
2009-09-07 19:10 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-09-07 19:10 201,050 a------- c:\windows\system32\nvapps.nvb
2009-09-07 19:10 <DIR> --d----- C:\NVIDIA
2009-09-07 17:18 <DIR> --d----- c:\documents and settings\all users\Microsoft
2009-09-07 17:16 <DIR> --d----- c:\windows\SHELLNEW
2009-09-07 17:16 <DIR> --d----- c:\program files\Microsoft Analysis Services
2009-09-07 17:14 <DIR> --d----- c:\program files\MSXML 6.0
2009-09-07 17:08 <DIR> --d----- c:\program files\MSXML 4.0
2009-09-07 15:20 <DIR> --d----- c:\program files\CCleaner
2009-09-07 14:39 86,094 a------- c:\windows\system32\ImageDrive.cpl
2009-09-07 12:23 656 a------- c:\windows\WINCMD.INI
2009-09-07 12:19 125,184 -------- c:\windows\system32\drivers\imagesrv.sys
2009-09-07 12:19 5,504 -------- c:\windows\system32\drivers\imagedrv.sys
2009-09-07 12:19 106,496 a------- c:\windows\system32\TwnLib20.dll
2009-09-07 12:19 1,568,768 -------- c:\windows\system32\ImagX7.dll
2009-09-07 12:19 476,320 -------- c:\windows\system32\ImagXpr7.dll
2009-09-07 12:19 471,040 -------- c:\windows\system32\ImagXRA7.dll
2009-09-07 12:19 262,144 -------- c:\windows\system32\ImagXR7.dll
2009-09-07 12:19 155,648 a------- c:\windows\system32\NeroCheck.exe
2009-09-07 11:46 <DIR> --d----- c:\windows\system32\PreInstall
2009-09-07 11:46 <DIR> --d-h--- c:\windows\$hf_mig$
2009-09-07 11:34 193,207 a------- c:\windows\system32\nvapps.xml
2009-09-07 11:34 453,152 a------- c:\windows\system32\nvudisp.exe
2009-09-07 11:34 18,394 a------- c:\windows\system32\nvdisp.nvu
2009-09-07 11:34 <DIR> --d----- c:\windows\nview
2009-09-07 11:25 <DIR> --d----- c:\docume~1\tamara\applic~1\GetRightToGo
2009-09-07 11:12 <DIR> --d----- c:\windows\system32\wbem\AutoRecover
2009-09-07 10:35 <DIR> --d----- c:\windows\ServicePackFiles
2009-09-07 10:34 2,897,920 -------- c:\windows\system32\xpsp2res.dll
2009-09-07 10:34 19,528 a------- c:\windows\002252_.tmp
2009-09-07 10:33 <DIR> --d----- c:\windows\EHome
2009-09-07 10:29 <DIR> --d----- c:\program files\PCPitstop
2009-09-07 10:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PCPitstop
2009-09-07 10:16 13,696 a------- c:\windows\system32\wpa.bak
2009-09-07 10:13 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-09-07 08:26 213,528 a------- c:\windows\system32\wuaucpl.cpl
2009-09-07 08:26 183,296 a------- c:\windows\system32\wuaueng1.dll
2009-09-07 08:26 165,888 a------- c:\windows\system32\wuauclt1.exe
2009-09-07 08:25 <DIR> --dsh--- c:\documents and settings\tamara\UserData
2009-09-07 06:43 558 a------- c:\windows\DFC.INI
2009-09-07 06:41 12,256 a------- c:\windows\system32\drivers\TBPanel.sys
2009-09-07 06:41 <DIR> --d----- c:\program files\VDOTool
2009-09-07 06:40 24,944 a------- c:\windows\system32\drivers\GVTDrv.sys
2009-09-07 06:40 4 a------- c:\windows\system32\GVTunner.ref
2009-09-07 06:40 40,136 a------- c:\windows\system32\drivers\ET5Drv.sys
2009-09-07 06:38 327,168 a------- c:\windows\IsUninst.exe
2009-09-07 06:38 <DIR> --d----- c:\program files\Gigabyte
2009-09-07 02:24 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-09-07 02:24 57,600 a------- c:\windows\system32\drivers\redbook.sys
2009-09-07 02:23 <DIR> --d----- c:\program files\common files\ODBC
2009-09-07 02:23 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-09-07 02:22 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-09-07 02:22 390,168 ac------ c:\windows\system32\dllcache\WFC.CAT
2009-09-07 02:21 261 a------- c:\windows\system32\$winnt$.inf
2009-09-07 00:37 <DIR> --d----- c:\program files\Realtek
2009-09-07 00:29 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-09-07 00:28 <DIR> --d----- c:\program files\common files\MSSoap
2009-09-07 00:27 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-09-07 00:27 <DIR> --d----- c:\program files\Online Services
2009-09-07 00:27 <DIR> --d----- c:\program files\Messenger
2009-09-07 00:27 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-09-07 00:26 <DIR> --d----- c:\program files\Windows NT

==================== Find3M ====================

2009-09-18 09:17 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-09-10 16:28 499,712 a------- c:\windows\system32\msvcp71.dll
2009-09-10 16:28 348,160 a------- c:\windows\system32\msvcr71.dll
2009-09-07 06:36 15,600 a------- c:\windows\gdrv.sys
2009-09-07 00:37 315,392 a------- c:\windows\HideWin.exe
2009-09-07 00:29 558,142 a------- c:\windows\java\packages\M2TND7BP.ZIP
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\OBDVB1BZ.DAT
2009-09-07 00:29 155,995 a------- c:\windows\java\packages\AU9JBTVX.ZIP
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\6ZHNTVBP.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\ZZ3VP7RD.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\SJTFFFVH.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\EBV3R579.DAT
2009-09-07 00:27 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-29 06:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\wmpdxm.dll
2009-07-03 19:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-25 10:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 10:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 10:25 54,272 a------- c:\windows\system32\wdigest.dll

============= FINISH: 17:05:57,20 ===============

[Link mogu videti samo ulogovani korisnici]


zbunjen sam sasvim. ne sećam se da sam uradio ništa loše u poslednjih 24 sata..



offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Pozdrav.


Nisi dobro ispratio uputstvo za Gmer.

Pročitaj ponovo uputstvo vezano za Gmer i postavi logove koji se navode u uputstvu.



offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

ostao sam dužan ostatak rezultata skeniranja..

evo ih :
[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

nadam se da je sad ok

u medjuvremenu je došlo čak i do toga da računar ne mogu uopšte da ugasim na neki normalan način :-/

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

ok, uradio, prijavio je brisanje 2 fajla, ali nisam stigao da pročitam njihove nazive..

evo izveštaja:

ComboFix 09-09-21.03 - tamara 22.09.2009 16:24.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.421 [GMT 2:00]
Running from: c:\documents and settings\tamara\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090921-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Alcmtr.exe
c:\windows\system32\FOLESVR.DLL

.
((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.

2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\scripting
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\en
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\bits
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\l2schemas
2009-09-15 20:00 . 2009-09-21 11:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-15 19:59 . 2009-09-15 19:59 -------- d-----w- c:\windows\Zuma's Revenge!
2009-09-15 19:59 . 2009-09-15 20:08 -------- d-----w- c:\program files\Zuma's Revenge!
2009-09-15 19:15 . 2009-09-15 19:15 -------- d-sh--w- c:\documents and settings\tamara\IECompatCache
2009-09-15 08:13 . 2009-09-15 08:13 -------- d-----w- c:\documents and settings\tamara\Application Data\AVS4YOU
2009-09-15 06:33 . 2009-09-15 06:33 -------- d-sh--w- c:\documents and settings\tamara\PrivacIE
2009-09-14 20:18 . 2009-09-14 20:18 -------- d-sh--w- c:\documents and settings\tamara\IETldCache
2009-09-14 19:49 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-14 19:49 . 2009-09-15 13:42 -------- d-----w- c:\windows\ie8updates
2009-09-14 19:48 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-14 19:48 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-14 19:48 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-09-14 19:48 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-14 19:48 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-14 19:48 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-14 19:47 . 2009-09-14 19:48 -------- dc-h--w- c:\windows\ie8
2009-09-14 08:51 . 2009-09-14 08:51 -------- d-----w- c:\program files\IrfanView
2009-09-14 07:57 . 2008-04-14 00:12 33792 ------w- c:\windows\system32\mmcperf.exe
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\program files\QuickTime
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\program files\Common Files\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\program files\Apple Software Update
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Apple Computer
2009-09-11 22:10 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-11 22:10 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-11 22:10 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-11 22:10 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-11 22:10 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-11 22:10 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-11 22:10 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-11 22:10 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-11 22:10 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-11 22:10 . 2009-09-11 22:10 -------- d-----w- c:\program files\Alwil Software
2009-09-11 20:26 . 2009-09-11 20:26 967 ----a-w- c:\windows\ScUnin.pif
2009-09-11 20:26 . 2009-09-11 20:26 68096 ----a-w- c:\windows\ScUnin.exe
2009-09-11 20:26 . 2009-09-11 20:26 12264 ----a-w- c:\windows\scunin.dat
2009-09-11 20:26 . 2009-09-12 07:22 -------- d-----w- c:\program files\Starcraft
2009-09-11 19:44 . 2009-09-18 21:32 -------- d-----w- c:\documents and settings\tamara\Application Data\AIMP
2009-09-11 19:43 . 2009-09-11 19:44 -------- d-----w- c:\program files\AIMP2
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\windows\tmp
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\windows\system32\FTCodecs
2009-09-10 19:45 . 2003-03-25 03:49 45056 ----a-w- c:\windows\system32\ogg.dll
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\program files\Fantasysoft-Studio
2009-09-10 19:35 . 2009-09-10 19:35 -------- d-----w- c:\program files\uTorrent
2009-09-10 19:34 . 2009-09-17 05:50 -------- d-----w- c:\documents and settings\tamara\Application Data\uTorrent
2009-09-10 19:08 . 2009-09-10 19:08 -------- d-----w- c:\documents and settings\tamara\Application Data\Zeon
2009-09-10 19:08 . 2009-09-10 19:08 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Zeon
2009-09-10 19:08 . 2009-09-10 19:14 294 ----a-w- c:\windows\dorp.dat
2009-09-10 19:07 . 2009-09-10 19:07 -------- d-----w- c:\program files\Nitro PDF
2009-09-10 19:07 . 2009-09-10 19:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Zeon
2009-09-10 14:45 . 2009-09-10 14:45 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-10 14:44 . 2009-09-10 14:44 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-09-10 14:44 . 2009-09-10 14:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-10 14:41 . 2009-09-10 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-09-10 14:41 . 2009-09-10 14:53 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-10 14:40 . 2009-09-10 14:53 -------- d-----w- c:\program files\AVS4YOU
2009-09-10 14:40 . 2007-09-27 12:22 638976 ----a-w- c:\windows\system32\divx.dll
2009-09-10 14:40 . 2007-09-27 12:22 524288 ----a-w- c:\windows\system32\xvidcore.dll
2009-09-10 14:40 . 2007-09-27 12:22 413760 ----a-w- c:\windows\system32\mpg4c32.dll
2009-09-10 14:40 . 2007-09-27 12:22 261632 ----a-w- c:\windows\system32\mcdvd_32.dll
2009-09-10 14:40 . 2007-09-27 12:22 139264 ----a-w- c:\windows\system32\xvidvfw.dll
2009-09-10 14:40 . 2003-05-21 21:50 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-09-10 14:40 . 2003-05-21 10:50 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-10 14:40 . 2002-01-05 13:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-09-10 14:40 . 2002-01-05 12:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-09-10 14:40 . 2002-01-05 00:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Common Files\Real
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Real
2009-09-10 13:32 . 2009-09-10 13:35 -------- d-----w- c:\program files\The KMPlayer
2009-09-10 12:41 . 2009-09-10 12:41 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\GHISLER
2009-09-10 09:04 . 2009-09-10 09:09 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-10 09:04 . 2009-09-10 09:04 -------- d-----w- c:\documents and settings\tamara\Application Data\Corel
2009-09-10 09:02 . 2009-09-10 09:02 -------- d-----w- c:\program files\Common Files\Corel
2009-09-10 09:00 . 2009-09-10 09:02 -------- d-----w- c:\program files\Corel
2009-09-10 06:47 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-09-10 06:47 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-09-09 09:37 . 2009-09-09 09:37 -------- d-----w- c:\windows\Downloaded Installations
2009-09-09 09:33 . 2009-09-09 09:33 -------- d-----w- c:\documents and settings\tamara\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-09-09 09:33 . 2009-09-15 07:53 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Google
2009-09-09 09:33 . 2009-09-09 09:33 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-09-09 09:33 . 2009-09-15 07:53 -------- d-----w- c:\program files\Google
2009-09-09 09:28 . 2009-09-09 09:28 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-09-09 09:24 . 2009-09-11 02:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-09 09:21 . 2009-09-14 09:12 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Adobe
2009-09-08 21:03 . 2009-09-08 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-09-08 21:02 . 2009-09-08 21:02 -------- d-----w- c:\program files\IVT Corporation
2009-09-08 21:01 . 2008-04-14 00:12 151552 ----a-w- c:\windows\system32\irftp.exe
2009-09-08 21:01 . 2008-04-14 00:12 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-09-08 21:01 . 2008-04-14 00:11 28160 ----a-w- c:\windows\system32\irmon.dll
2009-09-08 20:04 . 2009-09-22 11:25 -------- d-----w- c:\documents and settings\tamara\Tracing
2009-09-08 19:31 . 2009-09-08 19:31 -------- d-----w- c:\program files\Microsoft
2009-09-08 19:31 . 2009-09-08 19:31 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-08 19:18 . 2009-09-08 19:18 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-08 19:14 . 2009-09-08 19:31 -------- d-----w- c:\program files\Windows Live
2009-09-08 19:06 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-08 19:05 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-09-08 19:05 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-09-08 19:05 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-09-08 19:05 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-09-08 19:05 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-09-08 19:05 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-08 19:05 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-09-08 19:05 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-09-08 19:05 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-09-08 19:05 . 2009-02-06 11:08 2189056 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-08 19:05 . 2009-02-06 11:06 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-08 19:05 . 2009-02-06 10:32 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-08 19:04 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-08 18:58 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-09-08 18:58 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-08 18:58 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-09-08 18:58 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-09-08 18:58 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-09-08 18:57 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-09-08 18:57 . 2009-06-10 07:19 2066432 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-09-08 18:57 . 2008-10-03 10:02 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2009-09-08 18:56 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-09-08 18:55 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 13:25 . 2009-09-22 13:25 -------- d-----w- c:\program files\ESET
2009-09-18 12:21 . 2009-09-18 12:21 -------- d-----w- c:\documents and settings\tamara\Application Data\Media Player Classic
2009-09-10 14:28 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-10 14:28 . 2003-02-21 02:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-07 19:58 . 2009-09-06 22:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-07 04:38 . 2009-09-06 22:37 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-07 04:36 . 2009-09-06 22:35 15600 ----a-w- c:\windows\gdrv.sys
2009-09-06 22:40 . 2009-09-06 22:37 -------- d-----w- c:\program files\Realtek
2009-09-06 22:39 . 2009-09-06 22:39 -------- d-----w- c:\documents and settings\tamara\Application Data\InstallShield
2009-09-06 22:37 . 2009-09-06 22:37 315392 ----a-w- c:\windows\HideWin.exe
2009-09-06 22:35 . 2009-09-06 22:35 -------- d-----w- c:\program files\Intel
2009-09-06 22:30 . 2009-09-06 22:30 -------- d-----w- c:\program files\microsoft frontpage
2009-09-06 22:27 . 2009-09-06 22:27 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-05 09:01 . 2009-09-07 04:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2002-08-29 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2002-08-29 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:01 . 2002-08-29 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2009-09-07 08:36 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2002-08-29 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2002-08-29 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-08-29 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-08-29 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-08-29 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2002-08-29 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-08-29 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-04-08 14:05 739688 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyTuneVPro"="c:\program files\Gigabyte\ET5Pro\ETcall.exe" [2007-07-26 20480]
"Gainward"="c:\program files\VDOTool\TBPanel.exe" [2007-11-01 2165272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\progra~1\MICROS~2\Office14\GROOVEMN.EXE" [2009-04-25 875392]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-10 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-07-05 16380416]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-9-14 25214]
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OfficeSAS.lnk - c:\program files\Microsoft Office\Office14\OfficeSAS\officeSASscheduler.exe [2009-4-8 122264]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\INSTALACIJE\\mirc\\mirc.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12.9.2009 0:10 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12.9.2009 0:10 20560]
R2 osppsvc;Office Software Protection Platform;c:\windows\system32\OSPPSVC.EXE [8.4.2009 15:37 4319136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [25.4.2009 18:18 33480048]
SUnknown GVTDrv;GVTDrv; [x]

--- Other Services/Drivers In Memory ---

*Deregistered* - pxtdapob

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]
IE: {{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: {F496BBB4-C9DA-4E2B-BD43-01782ADDF1CB} = 212.200.191.166 212.200.190.166
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: DirectAnimation Java Classes - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - [Link mogu videti samo ulogovani korisnici]\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\tamara\Application Data\Mozilla\Firefox\Profiles\r7q9c9jt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - [Link mogu videti samo ulogovani korisnici]
FF - prefs.js: keyword.URL - [Link mogu videti samo ulogovani korisnici]
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2009-09-22 16:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-22 16:31
ComboFix-quarantined-files.txt 2009-09-22 14:31

Pre-Run: 33.754.243.072 bytes free
Post-Run: 33.718.435.840 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

284 --- E O F --- 2009-09-19 05:58

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Pronađi C:\Qoobox\Quarantine

Zapakuj (zip) i izvrši upload preko ovog linka...

[Link mogu videti samo ulogovani korisnici]


Javi kad odradiš.

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

evo zapakovanog fajla:


[Link mogu videti samo ulogovani korisnici]

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Otvoriti Notepad i iskopirati sledeci tekst:


DEQUARANTINE::
C:\Qoobox\Quarantine\C\windows\Alcmtr.exe.vir
QUIT::



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.



Preuzmi ovaj reg file na desktop i pokreni ga dvoklikom na ikonu.

Kada se pojavi message box klikni Yes pa Ok

[Link mogu videti samo ulogovani korisnici]



Javi kakvo je stanje...

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

Napisano: 23 Sep 2009 9:38

evo fajla...

[Link mogu videti samo ulogovani korisnici]

uneo sam i ovaj "regfix", ali se računar restartovao nekih 7, 8 minuta

i pri startu traži da se proveri particija C ( konzistentnost)

meni sve ovo miriše na ponovni reinstal :-(

mozilla mi jako sporo radi..

pretpostavljam da je XP oštećen

čekam dalje uputstvo :-)

Dopuna: 23 Sep 2009 12:55

posle par restarta opet je sve valjda normalno, restartuje se normalno, ne traži više ni proveru particije C

valjda je ok...

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Što se tiče malware_a, sistem je čist tako da problem nije vezan za infekciju.

Ovo zadnje što si napisao te nisam baš razumeo, da li se i dalje sam restartuje?

Ako se i dalje sam restartuje otvori temu u Windows potforumu i opiši problem pa će neko pomoći.


Isprati još sledeće...


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

combofix /u

Primeti da postoji razmak između "ComboFix" i "/u".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

Ko je trenutno na forumu
 

Ukupno su 1123 korisnika na forumu :: 91 registrovanih, 11 sakrivenih i 1021 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, acatomic, acov34, AMCXXL, Andrija 1993, Andrija357, B61, babaroga, bojank, Bokiboks, boracbl1389, Boris90, Borkanović, boromir, BORUTUS, BOXRR, Bozjidar87, cezar67, Chainsaw, Cian, CrazyNorth, Crazzer, Denaya, Dimitrise93, Djordje__________, Dogma21, drimer, dukajov, Džekson, Egzekutor13, FOX, Gerila015, goxin, Hardenberg, HrcAk47, ILGromovnik, IQ116, Jaz, Kawasaki1000, Kruger, Krusarac, Kubovac, kubura91, Kukuvaja, kunktator, Kuroje, laurusri, Lelemood, Lester Freamon, mack8, maiden6657, MakiMaki02, markolopin, markoni.slo, Mcdado, medaTT, mercedesamg, miki kv, mikrimaus, milenko crazy north, mir, moldway, mux, nelezele, nnnnnnnnnn, novator, Pantelejmon, Pekman, pisac12, Polemarchoi, Povratak1912, Prečanin30, raketaš, romark, sap, sekretar, semity, Semprini, septembar, sluga, smerch, Tafocus, Tas011, theNedjeljko, trutcina, vathra, yiyi, Yugol33, Zdenko, Čivi, 79693