  • Pridružio: 29 Apr 2012
  • Poruke: 127

Otvorio sam ovu temu u podforumu Windows, jer mi kartica preskace sa signalom za internet.
Probelm se ispoljava tako sto, mi u donjem desnom uglu stoji da nema konekcije (crveni x preko monitora), kada kliknem Repair, neretko se desi da komp zablokira potpuno. Pa sam onda poceo da sumnjam da nisam mozda ubacio neki virus, mada je komp cist cist s obzirom da sam pre neki dan uradio re-install sistema, ali sam mozda uneo neki virus preko programa koje sam instalirao.
Tekst za link

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512
Run by Gost at 0:43:36 on 2013-05-16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1476 [GMT 2:00]
============== Running Processes ================
C:\Program Files\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files\TeamViewer\Version8\TeamViewer.exe
C:\Program Files\TeamViewer\Version8\tv_w32.exe
C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
C:\Program Files\ASUS\AASP\1.00.59\aaCenter.exe
C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe
C:\Program Files\ROCCAT\Kone Mouse\KoneHID.EXE
C:\Program Files\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe
C:\Program Files\ROCCAT\Kone Mouse\osd.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
============== Pseudo HJT Report ===============
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: <No Name>: {9EBF5C54-224C-48A2-BC86-A5EDA9F8ABF9} - c:\windows\system32\mlJBRHwu.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: SmartSelect Class: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [HKCU] c:\windows\system32\windir\svchost.exe
mRun: [Ai Nap] "c:\program files\asus\ai suite\ainap\AiNap.exe"
mRun: [CPU Power Monitor] "c:\program files\asus\ai suite\aigear3\CpuPowerMonitor.exe"
mRun: [Cpu Level Up help] c:\program files\asus\ai suite\CpuLevelUpHelp.exe
mRun: [ASUS Energy Saving] "c:\program files\asus\ai suite\energysaving\PwSave.exe"
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RUSB3MON] "c:\program files\renesas electronics\usb 3.0 host controller driver\application\rusb3mon.exe"
mRun: [Alcmtr] ALCMTR.EXE
mRun: [HKLM] c:\windows\system32\windir\svchost.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Acrobat Speed Launcher] "c:\program files\adobe\acrobat 10.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 10.0\acrobat\Acrotray.exe"
mRun: [Kone] "c:\program files\roccat\kone mouse\KoneHID.EXE"
uExplorerRun: [Policies] c:\windows\system32\windir\svchost.exe
mExplorerRun: [Policies] c:\windows\system32\windir\svchost.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\realte~1.lnk - c:\program files\realtek rtl8185 wireless lan driver and utility\RtWLan.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: NameServer =
TCP: Interfaces\{50DE23D2-F1AF-4151-9D8D-A957552880A2} : DHCPNameServer =
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Notify: mlJBRHwu - mlJBRHwu.dll
SEH: <No Name> - {9EBF5C54-224C-48A2-BC86-A5EDA9F8ABF9} - c:\windows\system32\mlJBRHwu.dll
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\26.0.1410.64\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
mASetup: {SJ447BF0-J621-VFYM-DTX3-02QL2N80FMM3} - c:\windows\system32\windir\svchost.exe
============= SERVICES / DRIVERS ===============
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2013-5-15 21664]
R1 raddrvv3;raddrvv3;c:\windows\system32\rserver30\raddrvv3.sys [2010-4-21 46280]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [2013-5-14 38144]
R2 RServer3;Radmin Server V3;c:\windows\system32\rserver30\rserver3.exe [2010-4-21 1242480]
R2 TeamViewer8;TeamViewer 8;c:\program files\teamviewer\version8\TeamViewer_Service.exe [2013-5-14 3574624]
R3 KoneFltr;ROCCAT Kone;c:\windows\system32\drivers\Kone.sys [2013-5-13 13056]
R3 mirrorv3;mirrorv3;c:\windows\system32\drivers\rminiv3.sys [2010-4-21 3328]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\drivers\rusb3hub.sys [2013-5-14 80256]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\drivers\rusb3xhc.sys [2013-5-14 171520]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2013-05-15 22:38:56 -------- d-----w- c:\documents and settings\gost\local settings\application data\Google
2013-05-15 22:38:47 -------- d-----w- c:\documents and settings\gost\local settings\application data\Adobe
2013-05-15 22:38:43 -------- d-----w- c:\documents and settings\gost\application data\ROCCAT
2013-05-14 23:43:47 21664 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
2013-05-14 23:43:32 -------- d-----w- c:\program files\HWiNFO32
2013-05-14 20:32:17 -------- d-----w- c:\windows\system32\SoftwareDistribution
2013-05-14 06:07:43 80256 ----a-w- c:\windows\system32\drivers\rusb3hub.sys
2013-05-14 06:06:39 -------- d-----w- c:\program files\Realtek WLAN Driver
2013-05-14 06:02:53 356352 ----a-w- c:\windows\system32\nvudisp.exe
==================== Find3M ====================
2013-05-14 06:16:34 315392 ----a-w- c:\windows\HideWin.exe
2013-05-14 06:16:19 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2013-05-13 21:26:23 58368 ----a-w- c:\windows\system32\mlJBRHwu.dll
2005-09-27 02:56:07 401478 --sh--r- c:\windows\system32\windir\svchost.exe
============= FINISH: 0:44:07.17 ===============

[Link mogu videti samo ulogovani korisnici]

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd


Preuzmi program GMER sa donjeg linka na Desktop:

GMER download
Klikni dati link;
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.

Dvoklikom pokrenite GMER.
Sačekaj da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, klikni No;

klikni Scan i sačekaj da skeniranje bude završeno;

klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer1);

klikni desnim tasterom u prozor programa Gmer i odaberi Options > 3rd party - klikni Scan;

po završetku skeniranja klikni Save ... - izveštaj sačuvaj na Desktop (pod nazivom Gmer2);

klikni taster >>> i odaberi Autostart karticu;

po završetku kratkotrajnog skeniranja, klikni Copy;

otvori Notepad i u njega postavi kopirani tekst - izveštaj sačuvaj na Desktop (pod nazivom Gmer3);

Slikoviti prikaz postupka

Priloži sva tri izveštaja uz poruku korišćenjem opcije Prikači fajl.

  • Pridružio: 29 Apr 2012
  • Poruke: 127

Izaslo mi je nesto prilikom skeniranja..kliknuo sam continiue:

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Arrow Da li si ti instalirao Radmin na racunar?

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:

Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.

Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.

Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku;
Nemoj kliktati u okviru ComboFix prozora dok radi jer to može usporiti rad alata;
Nemoj ponovo pokretati ComboFix na svoju ruku - javi se u temi bilo kakav problem da imaš tokom prvog pokretanja alata;
Ako nakon restarta dobijaš grešku prilikom startovanja pojedinih programa da su označeni za brisanje (Illegal operation attempted on a registry key that has been marked for deletion), onda ponovo restartuj sistem i to ce rešiti problem.

  • Pridružio: 29 Apr 2012
  • Poruke: 127

Napisano: 15 Maj 2013 13:21

ja sam instalirao radmin. sad cu da pokrenem skeniranje.

Dopuna: 15 Maj 2013 13:34

Prilikom skeniranja comboFix-a pojavio se Blue Screen Of Death...Very Happy kaze da je greska nastala zbog plug and play uredjaja...zaboravio sam da izvadim usb hdd. samo da ti kazem, da znas Very Happy sad cu oept da pokrenem combofix

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

OK, izvadi sve prenosive uredjaje koje imas i nemoj ih ukljucivati dok ti ne kazem...

Nastavi sa ComboFix-om...

  • Pridružio: 29 Apr 2012
  • Poruke: 127

ComboFix 13-05-14.01 - Stefan 05/16/2013 1:35.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1542 [GMT 2:00]
Running from: c:\documents and settings\Stefan\My Documents\Downloads\ComboFix.exe
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
c:\documents and settings\Stefan\Application Data\Stefanlog.dat
((((((((((((((((((((((((( Files Created from 2013-04-15 to 2013-05-15 )))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
"Ai Nap"="c:\program files\ASUS\AI Suite\AiNap\AiNap.exe" [2008-01-28 1413120]
"CPU Power Monitor"="c:\program files\ASUS\AI Suite\AiGear3\CpuPowerMonitor.exe" [2008-01-09 627200]
"Cpu Level Up help"="c:\program files\ASUS\AI Suite\CpuLevelUpHelp.exe" [2007-12-01 881152]
"ASUS Energy Saving"="c:\program files\ASUS\AI Suite\EnergySaving\PwSave.exe" [2008-01-28 1352704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-10 8429568]
"nwiz"="nwiz.exe" [2007-05-10 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-10 81920]
"RUSB3MON"="c:\program files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe" [2011-09-20 115048]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16126464]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-01-03 36760]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-01-03 815512]
"Kone"="c:\program files\ROCCAT\Kone Mouse\KoneHID.EXE" [2011-02-18 1666560]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
REALTEK RTL8185 Wireless LAN Utility.lnk - c:\program files\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe [2013-5-14 770048]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer.exe"=
"c:\\Program Files\\TeamViewer\\Version8\\TeamViewer_Service.exe"=
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [5/15/2013 1:43 AM 21664]
R1 raddrvv3;raddrvv3;c:\windows\system32\rserver30\raddrvv3.sys [4/21/2010 3:02 PM 46280]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [5/14/2013 8:16 AM 38144]
R2 RServer3;Radmin Server V3;c:\windows\system32\rserver30\rserver3.exe [4/21/2010 3:02 PM 1242480]
R2 TeamViewer8;TeamViewer 8;c:\program files\TeamViewer\Version8\TeamViewer_Service.exe [5/14/2013 12:00 AM 3574624]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [5/16/2013 12:50 AM 38656]
R3 KoneFltr;ROCCAT Kone;c:\windows\system32\drivers\Kone.sys [5/13/2013 11:51 PM 13056]
R3 rusb3hub;Renesas Electronics USB 3.0 Hub Driver (Version 3.0);c:\windows\system32\drivers\rusb3hub.sys [5/14/2013 8:07 AM 80256]
R3 rusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver (Version 3.0);c:\windows\system32\drivers\rusb3xhc.sys [5/14/2013 8:07 AM 171520]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-05-13 21:33 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
Contents of the 'Scheduled Tasks' folder
2013-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-05-13 21:32]
2013-05-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-05-13 21:32]
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [Link mogu videti samo ulogovani korisnici]
Rootkit scan 2013-05-16 01:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(152)
------------------------ Other Running Processes ------------------------
c:\program files\TeamViewer\Version8\TeamViewer.exe
c:\program files\ASUS\AASP\1.00.59\aaCenter.exe
c:\program files\TeamViewer\Version8\tv_w32.exe
c:\program files\ROCCAT\Kone Mouse\osd.exe
Completion time: 2013-05-16 01:42:01 - machine was rebooted
ComboFix-quarantined-files.txt 2013-05-15 23:41
Pre-Run: 94,859,382,784 bytes free
Post-Run: 94,997,442,560 bytes free
- - End Of File - - 8375021802CF1FA9A5CAF5B06475A76B

[Link mogu videti samo ulogovani korisnici]

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Preuzmi MCShield sa sljedeće adrese:

[Link mogu videti samo ulogovani korisnici]

Instaliraj MCShield i sačekaj da se završi uvodno skeniranje.

Kad se završi uvodno skeniranje, ubacuj sve USB memorijske uređaje redom u USB port i svaki zadrži u portu dok MCShield ne izbaci poruku da je skeniranje završeno. Ukoliko imaš više USB uređaja, zabilježi negdje kojim su redom ubacivani.

Objašnjenje: U USB memorijske uređaje spadaju svi oni uređaji koji po priključivanju na kompjuter dobijaju svoju oznaku particije. Tu spadaju USB flash drajvovi, eksterni hard-diskovi, memorijske kartice, MP3 i MP4 plejeri, neki mobilni telefoni, neki GPS (navigacioni) uređaji itd.

Idi na Start -> All Programs -> MCShield -> Logs -> AllScans

Otvoriće ti se izvještaj u Notepad-u čiji sadržaj treba da postaviš u poruku

  • Pridružio: 29 Apr 2012
  • Poruke: 127

>>> MCShield AllScans.txt <<<

>>> MCShield ::Anti-Malware Tool:: v / DB: 2013.5.12.1 / Windows XP <<<

5/16/2013 1:59:13 AM > Drive C: - scan started (no label ~98 GB, NTFS HDD )...

=> The drive is clean.

5/16/2013 1:59:13 AM > Drive D: - scan started (no label ~200 GB, NTFS HDD )...

=> The drive is clean.

5/16/2013 1:59:13 AM > Drive E: - scan started (no label ~298 GB, NTFS HDD )...

=> The drive is clean.

>>> MCShield ::Anti-Malware Tool:: v / DB: 2013.5.12.1 / Windows XP <<<

5/16/2013 2:00:42 AM > Disk G: - skeniranje započeto (Transcend ~932 GB, NTFS HDD )...

=> Disk je čist.

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Malware je uklonjen sa sistema, kazi mi kakvo je sada stanje?

