|
|
|
|
|
Poslao: 13 Jan 2013 12:05
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Pita te da li hoces da ga uklonis, sta se desi kad kliknes Yes?
Ovo je Holandski, pa preko translate koliko mogu da vidim sa slike.
|
|
|
|
Poslao: 13 Jan 2013 12:36
|
offline
- njuskalo75
- Ugledni građanin
- Pridružio: 03 Feb 2011
- Poruke: 445
- Gde živiš: Nemačka
|
Kada kliknem JES otvori mi se prozor na kome ima samo opcija OK to je ta slika u sredini i kada kliknem OK program mi se zatvori
|
|
|
|
Poslao: 13 Jan 2013 14:52
|
rip
- argus
- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Pokreni ponovo DDS i postavi mi samo DDS.txt log fajl.
|
|
|
|
Poslao: 13 Jan 2013 15:16
|
offline
- njuskalo75
- Ugledni građanin
- Pridružio: 03 Feb 2011
- Poruke: 445
- Gde živiš: Nemačka
|
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 10.2.0
Run by Dalibor at 15:13:55 on 2013-01-13
Microsoft Windows XP Professional 5.1.2600.3.1251.381.1033.18.254.27 [GMT 1:00]
.
AV: Avira Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MCShield\mcshieldrtm.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\Program Files\Maxthon3\Bin\Maxthon.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k bthsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.spacialnet.com/
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{6E0F2453-FC75-4D33-A0FB-D0DBDEBC236B} : DHCPNameServer = 192.168.1.1
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R1 avkmgr;avkmgr;c:\windows\system32\drivers\avkmgr.sys [2012-12-31 36552]
R2 AntiVirSchedulerService;Avira Scheduler;c:\program files\avira\antivir desktop\sched.exe [2012-12-31 85280]
R2 AntiVirService;Avira Real-Time Protection;c:\program files\avira\antivir desktop\avguard.exe [2012-12-31 109344]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2012-12-31 83944]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;"c:\program files\firebird\firebird_2_5\bin\fbserver.exe" -s defaultinstance --> c:\program files\firebird\firebird_2_5\bin\fbserver.exe [?]
.
=============== Created Last 30 ================
.
2013-01-13 09:23:37 -------- d-----w- c:\program files\Defraggler
2013-01-13 09:16:39 -------- d-sh--w- c:\documents and settings\all users\application data\{32364CEA-7855-4A3C-B674-53D8E9B97936}
2013-01-12 12:54:42 -------- d-----w- c:\documents and settings\dalibor\application data\Maxthon3
2013-01-12 12:54:04 -------- d-----w- c:\program files\Maxthon3
2013-01-12 09:57:28 34816 ----a-w- c:\windows\system32\drivers\.sys
2013-01-09 15:39:29 -------- d-----w- c:\program files\VideoLAN
2012-12-31 18:55:51 -------- d-----w- c:\documents and settings\dalibor\application data\Avira
2012-12-31 18:39:14 36552 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-12-31 18:39:13 83944 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-12-31 18:39:00 -------- d-----w- c:\program files\Avira
2012-12-31 18:39:00 -------- d-----w- c:\documents and settings\all users\application data\Avira
.
==================== Find3M ====================
.
2013-01-12 21:40:50 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-12 21:40:48 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-12 13:13:37 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
.
============= FINISH: 15:15:20.76 ===============
https://www.mycity.rs/must-login.png
|
|
|
|
|