Gore pomenute napasti mi je detektovao SpybotSD kao i Nod32, uklonili su ih i sada se nalaze u karantinu. Citajuci malo o ovim napastima, video sam da se neki zale da ne mogu da ih se rese, tj. i posle pronalazenja od strane istih ili slicnih programa koje ja imam oni se vracaju ili ne mogu da ih obrisu.
Posle nadam se uspesnog brisanja, hteo bi sa vama da proverim da nije nesto ostalo. Inace nisam primetio nikakav pad performansi racunara, jedino sto se desava u zadnje vreme je to da mi se ne pojavljuju sve ikonice u tray-u iako su procesi aktivni u Task Manageru, znaci samo su nevidljive, uglavno ne vidim ikonice, zvucnika, safe remove hardware, nod32, daemon, status modema ... neki put se vide neki put ne, ali uglavnom ne, pa onda ako mi treba neka od njih moram da idem na start pa programs i da je trazim i posle toga ona postaje vidljiva u tray-u.
Konekcija mi je ADSL 1024/128.
DDS (Ver_09-10-26.01) - NTFSx86
Run by VLADA at 14:33:39,18 on ыЁе 05.11.2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.2.1251.381.1033.18.1535.850 [GMT 1:00]
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Kerio Personal Firewall *enabled* {A990EAA7-8941-4621-BC27-4F16261D3180}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\Conexant\Adsl\dslstat.exe
C:\Program Files\Conexant\Adsl\dslagent.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\DU Meter\DUMeter.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\Program Files\gigabyte\RCService\RCService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\explorer.exe
C:\Documents and Settings\VLADA\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.sezampro.rs/
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [PCMService] "c:\program files\cyberlink\powercinema\PCMService.exe"
mRun: [DSLSTATEXE] c:\program files\conexant\adsl\dslstat.exe icon
mRun: [DSLAGENTEXE] c:\program files\conexant\adsl\dslagent.exe
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [ASUS Probe] c:\program files\asus\probe\AsusProb.exe
mRun: [DU Meter] c:\program files\du meter\DUMeter.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\imon.dll
Trusted Zone:
DPF: {22272CAC-E859-4523-B505-7ECF74469A1B} - hxxp://www.veka.de/__C1257308002B1CFE.nsf/files/mdview3d.cab/$FILE/mdview3d.cab
DPF: {4A1C2485-1F68-11D5-BD5C-0080ADB635EE} - hxxp://www.veka.de/__C1257308002B1CFE.nsf/files/relaunch_AVClientProj.cab/$FILE/relaunch_AVClientProj.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1249757307832
DPF: {7A953F4A-841C-4A4C-A7C1-40566070ECC2} - hxxp://sit.sezampro.rs/includes/DigitalkSIPCab.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\vlada\applic~1\mozilla\firefox\profiles\3uoxa5dt.default\
FF - prefs.js: browser.search.selectedEngine - eBay
FF - prefs.js: browser.startup.homepage - hxxp://www.sezampro.rs/
FF - component: c:\documents and settings\vlada\application data\mozilla\firefox\profiles\3uoxa5dt.default\extensions\{13e0b548-6fc9-47e9-9874-470915f46548}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\vlada\application data\mozilla\firefox\profiles\3uoxa5dt.default\extensions\{b371cbc0-e676-430f-ba04-122aff6b20d6}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\vlada\application data\mozilla\firefox\profiles\3uoxa5dt.default\extensions\piclens@cooliris.com\components\cooliris.dll
FF - plugin: c:\documents and settings\vlada\application data\mozilla\firefox\profiles\3uoxa5dt.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\common files\parallelgraphics\cortona\npCortona.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCortona.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R0 FSProFilter;FSPro File Filter;c:\windows\system32\drivers\FSPFltd.sys [2009-8-9 43792]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-8-9 64160]
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2009-8-8 77056]
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [2005-12-15 274432]
R1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [2005-12-15 81920]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2009-8-9 15424]
R2 RCService;RCService;c:\program files\gigabyte\rcservice\RCService.exe [2006-4-26 538624]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 3xHybrid;3xHybrid service;c:\windows\system32\drivers\3xHybrid.sys [2006-3-22 826752]
S2 FlexService;Remote Connections Service;"c:\program files\rapidbit\cisvc.exe" --> c:\program files\rapidbit\cisvc.exe [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
S3 kvnet;Kerio Virtual Network Adapter;c:\windows\system32\drivers\kvnet.sys [2009-3-23 29696]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;c:\windows\system32\drivers\kwflower.sys --> c:\windows\system32\drivers\kwflower.sys [?]
S4 fsproflt;FSPro Filter Service;c:\windows\system32\fsproflt.exe [2009-8-9 73392]
=============== Created Last 30 ================
2009-11-05 13:22:54 176987 ------w- C:\SB1.png
2009-11-05 13:21:53 38084 ------w- C:\SB.png
2009-11-05 00:26:07 26186 ----a-w- C:\perfect disk3.PNG
2009-11-04 23:25:24 26701 ----a-w- C:\perfect disk2.PNG
2009-11-04 23:20:38 24755 ----a-w- C:\perfect disk1.PNG
2009-11-04 22:41:39 23797 ----a-w- C:\perfect disk0.png
2009-11-04 22:38:48 280 ----a-w- c:\windows\system32\PDBootState
2009-11-04 18:25:08 0 d-----w- c:\program files\Raxco
2009-11-04 01:46:11 165 ----a-w- c:\windows\system32\drivers\fwdrv.err
2009-11-04 00:37:17 106940 ------w- C:\Ambulanta.png
2009-11-04 00:02:25 16336 ------w- C:\4.11.png
2009-11-03 17:21:57 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2009-11-01 01:20:08 0 d--h--w- c:\windows\PIF
2009-11-01 00:46:10 0 d-----w- c:\program files\Lavalys
2009-10-31 01:29:42 0 d-----w- c:\windows\system32\NtmsData
2009-10-31 00:53:15 0 d-----w- c:\program files\Sunbelt Software
2009-10-30 02:11:47 6 ---ha-w- C:\SA.DAT
2009-10-28 17:05:59 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-10-28 17:05:59 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-10-27 18:39:51 1609396224 ----a-w- c:\windows\MEMORY.DMP
2009-10-27 14:10:35 0 d-----w- c:\docume~1\vlada\applic~1\URSoft
2009-10-27 14:09:45 0 d-----w- c:\program files\Your Uninstaller 2008
2009-10-25 22:23:29 593920 ------w- c:\windows\system32\ati2sgag.exe
2009-10-25 22:22:56 0 d-----w- c:\program files\ATI Technologies
2009-10-25 22:12:32 82 ----a-w- c:\windows\WININIT.INI
2009-10-24 21:24:31 0 d-----w- c:\program files\TMbot
2009-10-20 00:22:52 0 d-----w- c:\program files\Garmin
2009-10-13 21:43:35 10022 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-13 14:04:24 0 d-----w- c:\program files\Windows Live SkyDrive
2009-10-07 10:05:14 232712 ----a-w- c:\windows\system32\PDBoot.exe
==================== Find3M ====================
2009-09-23 09:41:58 26176 ---ha-w- c:\windows\system32\drivers\hamachi.sys
2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-08 18:52:43 20 ---h--w- c:\docume~1\alluse~1\applic~1\PKP_DLec.DAT
2009-09-08 18:52:43 20 ---h--w- c:\docume~1\alluse~1\applic~1\PKP_DLds.DAT
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08:21 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-09 10:22:21 298104 ----a-w- c:\windows\system32\imon.dll
2009-08-08 23:29:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-08-08 16:26:56 21640 -c--a-w- c:\windows\system32\emptyregdb.dat
============= FINISH: 14:35:11,68 ===============
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
To bi trebalo da bude sve po uputstvu.
Pozdrav!
|