Hendikepirana tastatura

Hendikepirana tastatura

  • Pridružio: 24 Feb 2006
  • Poruke: 435

Na notebooku je tastatura prestala delimicno da funkcionise, buduci da nije bilo nikakvih udara, prosipanja tecnosti i sl. moguce da je u pitanju neki viruscic.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:20 PM, on 12/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\FSC\Wireless Utility\WirelessSelector.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Documents and Settings\maja\Desktop\hike\hiki.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TouchPadHotKey] C:\Program Files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: WirelessSelector.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

End of file - 4574 bytes

Dopuna: 20 Dec 2008 14:33

Ne znam da li sam pogresila, ali pustila sam i ComboFix da odradi, ali se ni nakon njegovog rada nista nije promenilo, evo i taj log:

ComboFix 08-12-18.03 - maja 2008-12-20 14:13:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1789.1247 [GMT 1:00]
Running from: c:\documents and settings\maja\Desktop\ComboFix.exe
* Created a new restore point

((((((((((((((((((((((((( Files Created from 2008-11-20 to 2008-12-20 )))))))))))))))))))))))))))))))

2008-12-18 00:07 . 2008-12-18 23:32 20 --a------ c:\windows\(zabranjeno)pdf.INI
2008-12-18 00:03 . 2008-12-18 23:32 <DIR> d-------- c:\program files\PDF Password (zabranjeno)er v3.0
2008-12-17 23:55 . 2008-12-17 23:55 <DIR> d-------- c:\program files\Matrix
2008-12-02 01:35 . 2008-12-02 01:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-27 21:49 . 2008-11-27 21:49 <DIR> d-------- c:\documents and settings\maja\Application Data\Media Player Classic
2008-11-27 21:49 . 2008-12-19 15:21 69 --a------ c:\windows\NeroDigital.ini
2008-11-27 14:32 . 2008-12-04 14:48 <DIR> d-------- c:\documents and settings\maja\Application Data\uTorrent
2008-11-27 14:29 . 2008-11-27 14:29 <DIR> d-------- c:\documents and settings\maja\Application Data\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\program files\Common Files\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\program files\ACD Systems
2008-11-27 14:28 . 2008-11-27 14:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\ACD Systems
2008-11-27 14:16 . 2008-11-27 14:32 <DIR> d-------- c:\program files\uTorrent
2008-11-27 14:03 . 2008-11-27 14:04 <DIR> d-------- c:\program files\Exact Audio Copy
2008-11-27 14:03 . 2008-11-27 14:03 <DIR> d-------- c:\program files\CCleaner
2008-11-27 14:02 . 2008-11-27 14:02 <DIR> d-------- c:\windows\PrimoPDF
2008-11-27 14:02 . 2008-11-27 14:02 <DIR> d-------- c:\program files\activePDF
2008-11-27 14:02 . 2006-08-31 18:46 176,235 --a------ c:\windows\system32\Primomonnt.dll
2008-11-27 13:59 . 2008-11-27 13:59 <DIR> d-------- c:\windows\Downloaded Installations
2008-11-27 13:59 . 2008-11-28 13:56 <DIR> d-------- c:\program files\The KMPlayer
2008-11-27 13:58 . 2008-11-27 13:58 <DIR> d-------- c:\program files\YouTube Downloader
2008-11-27 13:55 . 2003-06-18 17:31 17,920 --a------ c:\windows\system32\mdimon.dll
2008-11-27 13:55 . 2008-11-27 13:55 376 --a------ c:\windows\ODBC.INI
2008-11-27 13:54 . 2008-11-27 13:54 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-11-27 13:54 . 2008-11-27 13:54 <DIR> d-------- c:\program files\Common Files\L&H
2008-11-27 13:53 . 2008-11-27 13:54 <DIR> d-------- c:\windows\SHELLNEW
2008-11-27 13:53 . 2008-11-27 13:53 <DIR> d-------- c:\program files\Microsoft Works
2008-11-27 13:51 . 2008-11-27 13:51 <DIR> d-------- c:\program files\Microsoft.NET
2008-11-27 13:14 . 2008-11-27 14:02 <DIR> d-------- c:\documents and settings\maja\Application Data\Winamp
2008-11-27 13:08 . 2008-11-27 13:08 0 --a------ c:\windows\nsreg.dat
2008-11-27 07:43 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-27 07:43 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-27 07:43 . 2001-08-17 14:02 9,600 --a------ c:\windows\system32\drivers\hidusb.sys
2008-11-27 07:43 . 2001-08-17 14:02 9,600 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-11-26 20:13 . 2008-11-26 20:13 <DIR> d-------- c:\program files\Lavasoft
2008-11-26 20:13 . 2008-11-26 20:13 <DIR> d-------- c:\documents and settings\maja\Application Data\Lavasoft
2008-11-26 20:12 . 2008-12-20 14:10 <DIR> d-------- c:\program files\mIRC
2008-11-26 18:19 . 2008-11-26 18:19 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-11-26 18:18 . 2008-11-26 18:53 <DIR> d-------- c:\windows\SxsCaPendDel
2008-11-26 18:13 . 2008-11-27 13:47 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-26 18:13 . 2008-11-27 13:47 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-26 17:03 . 2008-11-26 17:03 <DIR> d---s---- c:\documents and settings\maja\UserData
2008-11-26 17:03 . 2008-11-26 17:09 <DIR> d-------- c:\documents and settings\maja\Application Data\Yahoo!
2008-11-26 16:59 . 2008-11-26 17:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-11-26 16:57 . 2008-11-30 22:56 <DIR> d-------- c:\program files\Yahoo!
2008-11-26 13:47 . 2008-11-26 13:47 <DIR> d-------- c:\documents and settings\maja\Application Data\CyberLink
2008-11-26 03:23 . 2006-10-26 19:56 32,592 --a------ c:\windows\system32\msonpmon.dll
2008-11-26 03:19 . 2008-11-27 13:43 <DIR> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-26 03:14 . 2008-02-22 12:30 334,792 --a------ c:\windows\system32\_AxShlEx.dll
2008-11-26 03:13 . 2008-11-26 03:13 <DIR> d-------- c:\program files\Alcohol Soft
2008-11-26 03:09 . 2008-11-26 03:09 716,272 --a------ c:\windows\system32\drivers\sptd.sys
2008-11-26 02:53 . 2008-11-26 02:53 <DIR> d-------- c:\documents and settings\maja\Phone Browser
2008-11-26 01:06 . 2004-08-03 23:59 57,472 --a------ c:\windows\system32\drivers\redbook.sys
2008-11-26 01:06 . 2001-08-17 14:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-11-26 01:05 . 2004-08-04 01:56 74,240 --a------ c:\windows\system32\usbui.dll
2008-11-26 01:05 . 2004-08-03 23:07 44,672 --a------ c:\windows\system32\drivers\UAGP35.SYS
2008-11-26 01:05 . 2004-08-03 23:07 44,672 --a--c--- c:\windows\system32\dllcache\uagp35.sys
2008-11-26 01:05 . 2004-08-04 00:07 14,080 --a------ c:\windows\system32\drivers\CmBatt.sys
2008-11-26 01:05 . 2001-08-17 14:57 14,080 --a------ c:\windows\system32\drivers\battc.sys
2008-11-26 01:05 . 2001-08-17 14:58 9,344 --a------ c:\windows\system32\drivers\compbatt.sys
2008-11-26 01:03 . 2008-12-04 17:34 <DIR> d-------- c:\windows\system32\CatRoot2
2008-11-26 01:03 . 2008-11-26 00:10 <DIR> dr------- c:\documents and settings\All Users\Documents
2008-11-26 01:01 . 2008-11-26 00:15 261 --a------ c:\windows\system32\$winnt$.inf

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2008-11-27 13:00 --------- d-----w c:\program files\Winamp
2008-11-26 17:19 --------- d-----w c:\program files\Common Files\Adobe
2008-11-25 23:47 --------- d-----w c:\program files\K-Lite Codec Pack
2008-11-25 23:43 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-25 23:43 --------- d-----w c:\program files\CyberLink
2008-11-25 23:43 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-11-25 23:42 --------- d-----w c:\program files\Common Files\Ahead
2008-11-25 23:42 --------- d-----w c:\program files\Ahead
2008-11-25 23:36 --------- d-----w c:\program files\Alwil Software
2008-11-25 23:30 --------- d-----w c:\program files\FSC
2008-11-25 23:30 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-25 23:30 --------- d-----w c:\documents and settings\All Users\Application Data\InstallShield
2008-11-25 23:29 --------- d-----w c:\documents and settings\maja\Application Data\InstallShield
2008-11-25 23:28 --------- d-----w c:\program files\Synaptics
2008-11-25 23:28 --------- d-----w c:\program files\Motorola
2008-11-25 23:27 315,392 ----a-w c:\windows\HideWin.exe
2008-11-25 23:27 --------- d-----w c:\program files\sisagp
2008-11-25 23:27 --------- d-----w c:\program files\SiS VGA Utilities V3.82
2008-11-25 23:27 --------- d-----w c:\program files\Realtek
2008-11-25 23:13 --------- d-----w c:\program files\microsoft frontpage

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown

"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-26 4608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 4670704]

"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-05-10 864256]
"TouchPadHotKey"="c:\program files\FSC\TouchPad HotKey Utility\TouchPad_HotKey.exe" [2007-08-13 364544]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SiSPower"="SiSPower.dll" [2007-08-03 c:\windows\system32\SiSPower.dll]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2008-11-26 262144]
WirelessSelector.lnk - c:\program files\FSC\Wireless Utility\WirelessSelector.exe [2008-11-26 650752]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"EnableFirewall"= 0 (0x0)

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-11-26 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]

*Newly Created Service* - PROCEXP90
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Device Detector - DevDetect.exe

------- Supplementary Scan -------
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\maja\Application Data\Mozilla\Firefox\Profiles\xfgz84wc.default\
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll


catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-20 14:15:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

Completion time: 2008-12-20 14:15:42
ComboFix-quarantined-files.txt 2008-12-20 13:15:40

Pre-Run: 97,082,306,560 bytes free
Post-Run: 97,072,541,696 bytes free

[boot loader]
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect


  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE


Izvini zbog čekanja. Postavljeni logovi su čisti i na tvom kompjuteru ne bi trebalo biti malware-a.

  • Pridružio: 24 Feb 2006
  • Poruke: 435

Hvala vam. Nije vise ni fujitsu sto je bio Smile

Ko je trenutno na forumu

Ukupno su 926 korisnika na forumu :: 11 registrovanih, 2 sakrivenih i 913 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Battlehammer, bigfoot, GandorCC, ivan979, Kibice, kolle.the.kid, ladro, lcc, procesor, Sir Budimir, Trpe Grozni