Problem zvani svchost.exe

2

Problem zvani svchost.exe

offline
  • Gvelf  Male
  • Novi MyCity građanin
  • Pridružio: 09 Nov 2007
  • Poruke: 18

Evo, zavrsio sam!

ComboFix 07-11-19.4C - Administrator 2007-11-30 23:15:11.1 - NTFSx86

Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-30 )))))))))))))))))))))))))))))))
.

2007-11-30 02:15 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-11-30 02:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-11-30 02:15 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2007-11-30 02:14 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-29 03:55 <DIR> d-------- C:\Program Files\DivX
2007-11-28 20:50 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2007-11-28 20:50 63,040 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2007-11-28 20:33 <DIR> d-------- C:\Program Files\Electronic Arts
2007-11-28 20:33 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-11-27 00:46 <DIR> d-------- C:\Program Files\Common Files\System32
2007-11-24 12:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-23 04:46 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Autodesk
2007-11-23 04:45 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2007-11-23 03:41 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2007-11-21 23:27 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\vlc
2007-11-21 23:25 <DIR> d-------- C:\Program Files\VideoLAN
2007-11-21 20:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Azureus
2007-11-21 16:13 <DIR> d-------- C:\Program Files\uTorrent
2007-11-21 16:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2007-11-20 22:39 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-20 22:34 106 --a------ C:\delete.bat
2007-11-20 20:42 1,104,896 -----c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-11-20 20:41 3,064,320 -----c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-11-20 20:41 1,498,112 -----c--- C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-11-20 20:41 1,022,976 -----c--- C:\WINDOWS\system32\dllcache\browseui.dll
2007-11-20 20:41 616,960 -----c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-11-20 20:41 532,480 -----c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-11-20 20:41 474,112 -----c--- C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-11-20 20:41 449,024 -----c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-11-20 20:41 151,040 -----c--- C:\WINDOWS\system32\dllcache\cdfview.dll
2007-11-20 20:41 146,432 -----c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-11-20 20:41 96,256 -----c--- C:\WINDOWS\system32\dllcache\inseng.dll
2007-11-20 20:41 39,424 -----c--- C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-11-20 20:41 16,384 -----c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-11-20 20:40 1,314,816 -----c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-11-20 20:40 86,528 -----c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-11-20 20:39 185,344 -----c--- C:\WINDOWS\system32\dllcache\upnphost.dll
2007-11-20 20:39 144,896 -----c--- C:\WINDOWS\system32\dllcache\schannel.dll
2007-11-20 20:38 8,453,632 -----c--- C:\WINDOWS\system32\dllcache\shell32.dll
2007-11-20 20:38 536,576 -----c--- C:\WINDOWS\system32\dllcache\msado15.dll
2007-11-20 20:38 134,656 -----c--- C:\WINDOWS\system32\dllcache\shsvcs.dll
2007-11-20 20:38 40,960 -----c--- C:\WINDOWS\system32\dllcache\mf3216.dll
2007-11-20 20:37 256,512 -----c--- C:\WINDOWS\system32\dllcache\agentsvr.exe
2007-11-20 20:37 200,704 -----c--- C:\WINDOWS\system32\dllcache\msadox.dll
2007-11-20 20:37 180,224 -----c--- C:\WINDOWS\system32\dllcache\msadomd.dll
2007-11-20 20:37 102,400 -----c--- C:\WINDOWS\system32\dllcache\msjro.dll
2007-11-20 20:37 57,344 --a--c--- C:\WINDOWS\system32\dllcache\agentdpv.dll
2007-11-20 20:37 42,496 -----c--- C:\WINDOWS\system32\dllcache\agentdp2.dll
2007-11-20 20:36 225,664 -----c--- C:\WINDOWS\system32\dllcache\tcpip6.sys
2007-11-20 20:36 100,352 -----c--- C:\WINDOWS\system32\dllcache\6to4svc.dll
2007-11-20 20:34 453,120 -----c--- C:\WINDOWS\system32\dllcache\mrxsmb.sys
2007-11-20 20:34 148,480 -----c--- C:\WINDOWS\system32\dllcache\dnsapi.dll
2007-11-20 20:34 111,616 -----c--- C:\WINDOWS\system32\dllcache\dhcpcsvc.dll
2007-11-20 20:34 94,720 -----c--- C:\WINDOWS\system32\dllcache\iphlpapi.dll
2007-11-20 20:30 <DIR> d-------- C:\Program Files\PowerMenu
2007-11-20 20:30 81,920 --a------ C:\WINDOWS\system32\Startup.cpl
2007-11-20 20:30 77,824 --a------ C:\WINDOWS\system32\StartupCPL.exe
2007-11-18 00:46 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2007-11-18 00:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2007-11-17 18:10 200 --a------ C:\sccfg.sys
2007-11-15 04:39 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2007-11-15 03:46 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-15 03:46 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2007-11-15 03:46 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2007-11-15 03:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-11-12 11:11 344 --a------ C:\WINDOWS\system32\USER.SCP
2007-11-10 19:04 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2007-11-10 04:12 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2007-11-09 23:32 <DIR> d-------- C:\Program Files\Stardock
2007-11-09 23:32 <DIR> d-------- C:\Program Files\Common Files\Stardock
2007-11-09 04:31 <DIR> d-------- C:\Program Files\FLVPlayer
2007-11-08 20:46 359,040 --a------ C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2007-11-03 22:35 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\VSRevoGroup
2007-11-03 22:25 <DIR> d-------- C:\Program Files\VS Revo Group
2007-11-01 17:56 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2007-11-01 15:49 <DIR> d-------- C:\Program Files\MSXML 6.0
2007-11-01 15:49 <DIR> d-------- C:\Program Files\MSXML 4.0
2007-11-01 15:45 <DIR> d-------- C:\WINDOWS\system32\bits
2007-11-01 15:45 49,536 --a------ C:\WINDOWS\system32\drivers\cdrom.sys
2007-11-01 15:45 8,192 -----c--- C:\WINDOWS\system32\dllcache\bitsprx2.dll
2007-11-01 15:45 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2007-11-01 15:45 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx3.dll
2007-11-01 15:45 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
2007-11-01 15:44 <DIR> d-------- C:\Program Files\MSECache
2007-11-01 15:44 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-01 15:44 683,520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-11-01 15:44 574,464 -----c--- C:\WINDOWS\system32\dllcache\ntfs.sys
2007-11-01 15:43 <DIR> d-------- C:\Program Files\Microsoft
2007-11-01 15:41 981,760 -----c--- C:\WINDOWS\system32\dllcache\mfc42u.dll
2007-11-01 15:41 539,136 -----c--- C:\WINDOWS\system32\dllcache\msftedit.dll
2007-11-01 15:39 <DIR> d-------- C:\WINDOWS\system32\DRM
2007-11-01 15:39 <DIR> d-------- C:\WINDOWS\l2schemas
2007-11-01 15:39 143,488 -----c--- C:\WINDOWS\system32\dllcache\usbport.sys
2007-11-01 15:39 62,336 --------- C:\WINDOWS\system32\drivers\rspndr.sys
2007-11-01 15:39 59,264 -----c--- C:\WINDOWS\system32\dllcache\usbhub.sys
2007-11-01 15:39 30,208 -----c--- C:\WINDOWS\system32\dllcache\usbehci.sys
2007-11-01 15:39 20,608 -----c--- C:\WINDOWS\system32\dllcache\usbuhci.sys
2007-11-01 15:39 17,152 -----c--- C:\WINDOWS\system32\dllcache\usbohci.sys
2007-11-01 15:38 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2007-11-01 15:38 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 22:16 758,816 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2007-11-30 22:16 12,475,936 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-30 03:09 79,232 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-11-30 03:09 175,724 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-28 19:50 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-11-28 17:57 3,400 ----a-w C:\WINDOWS\system32\winxtm.dll
2007-11-24 09:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 18:11 --------- d-----w C:\Documents and Settings\Administrator\Application Data\.BitZip
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-17 22:35 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-12 16:24 14,656 ----a-w C:\WINDOWS\gdrv.sys
2007-10-11 22:36 82,061 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2007-10-11 22:36 81,549 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-10-10 21:25 720,896 ----a-w C:\WINDOWS\iun6002.exe
2007-10-10 21:02 32,768 ----a-w C:\WINDOWS\closewnd.exe
2007-10-10 20:29 --------- d-----w C:\Program Files\AvRack
2007-10-10 20:09 --------- d-----w C:\Program Files\Common Files\InstallShield
2007-10-10 16:27 --------- d-----w C:\Program Files\VIA
2007-10-10 16:26 --------- d-----w C:\Program Files\Realtek Sound Manager
2007-10-10 16:16 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-04 09:58 33,792 ----a-w C:\WINDOWS\system32\drivers\maplom.sys
2007-09-17 00:10 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-09-17 00:10 356,352 ----a-w C:\WINDOWS\system32\nvudisp.exe
2007-09-16 23:07 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-09-16 23:07 81,920 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-09-16 23:07 8,491,008 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-09-16 23:07 753,664 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-09-16 23:07 6,746,112 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-09-16 23:07 6,344,704 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-09-16 23:07 5,783,040 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-09-16 23:07 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-09-16 23:07 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-09-16 23:07 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-09-16 23:07 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-09-16 23:07 364,544 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-09-16 23:07 36,864 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-09-16 23:07 36,864 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-09-16 23:07 307,200 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-09-16 23:07 3,551,232 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-09-16 23:07 3,334,144 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-09-16 23:07 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-16 23:07 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-09-16 23:07 2,371,584 ----a-w C:\WINDOWS\system32\nvwss.dll
2007-09-16 23:07 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-09-16 23:07 155,716 ----a-w C:\WINDOWS\system32\nvsvc32.exe
2007-09-16 23:07 147,456 ----a-w C:\WINDOWS\system32\nvcolor.exe
2007-09-16 23:07 1,703,936 ----a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-16 23:07 1,626,112 ----a-w C:\WINDOWS\system32\nwiz.exe
2007-09-16 23:07 1,478,656 ----a-w C:\WINDOWS\system32\nview.dll
2007-09-16 23:07 1,339,392 ----a-w C:\WINDOWS\system32\nvdspsch.exe
2007-09-16 23:07 1,150,976 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-09-16 23:07 1,019,904 ----a-w C:\WINDOWS\system32\nvwimg.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 16:49]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-03 23:56 C:\WINDOWS\system32\rundll32.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"= 0 (0x0)
"NoChangeKeyboardNavigationIndicators"= 0 (0x0)
"NoSharedDocuments"= 1 (0x1)

[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
C:\WINDOWS\system32\klogon.dll 2007-06-28 11:51 206088 C:\WINDOWS\system32\klogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^Scheduler.lnk]
path=C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Scheduler.lnk
backup=C:\WINDOWS\pss\Scheduler.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Privacy Auditor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Privacy Auditor.lnk
backup=C:\WINDOWS\pss\Privacy Auditor.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quick Shelf.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Quick Shelf.lnk
backup=C:\WINDOWS\pss\Quick Shelf.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpyCatcher Protector.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpyCatcher Protector.lnk
backup=C:\WINDOWS\pss\SpyCatcher Protector.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP]
2007-06-28 11:51 218376 --a------ C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostSurf Reminder]
C:\Program Files\GhostSurf Platinum\Privacy Control Center.exe reminder

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostSurfDelSatellite]
C:\Program Files\GhostSurf Platinum\DeleteSatellite.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HDInspector.exe]
C:\Program Files\Hard Drive Inspector\HDInspector.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICOOL]
C:\Program Files\GIGABYTE\I-Cool\run.exe HIDE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
C:\Program Files\MSN Messenger\MsnMsgr.Exe /background

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OODefragTray]
C:\WINDOWS\system32\oodtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2007-10-10 21:21 77824 --a------ C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe


*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2007-11-30 23:16:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-30 23:17:43
.
--- E O F ---

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Imas li instaliran program FolderLock?

Sledeci fajl je sporan:
C:\WINDOWS\system32\winxtm.dll
kao i sledeci folder:
C:\Program Files\XSoft\

Zamolio bih te da mi uploadujes taj winxtm.dll preko iste one forme od malopre.
Nakon toga cu ti napisati uputstvo za brisanje. Ukoliko se oduzi analiza, onda cu morati pisanje uputstva da ti odlozim za sutra ujutru, posto mi se kapci vec sklapaju.

offline
  • Gvelf  Male
  • Novi MyCity građanin
  • Pridružio: 09 Nov 2007
  • Poruke: 18

Imao sam instaliran Folder Lock, ali sam ga izbrisao!
Uploudovao sam.
Ne mogu da nadjem C:\Program Files\XSoft\, kao da ne postoji!
Nema problema, sutra cemo ( danas ).

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Jos nesto pre nego sto podjemo na spavanje.
Uradi sledeće:
Preuzmi fajl gmer.zip sa ovog linka i sačuvaj na Desktop-u.
Raspakuj ga u neki folder.

Dupli klik na gmer.exe za početak: Izaberi Rootkit Tab na vrhu.
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati to u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao file1.txt.
Ponovi ovo isto sa Autostart Tab-om. Snimi taj tekst iz Notepada kao file2.txt.


Iskopiraj nam ovde sadrzaj ta dva fajla koja smo malopre snimili.
Ukoliko su previse veliki, pa ne mogu stati u poruku (to mozes proveriti tek nakon sto objavis poruku, videces da je log isecen), onda iskoristi opciju Prikaci fajl da logove uploadujes kao fajlove uz poruku.

offline
  • Gvelf  Male
  • Novi MyCity građanin
  • Pridružio: 09 Nov 2007
  • Poruke: 18

Bobby, ich habe ein Problem!!!
Skinuo sam gmer i krenuo sam da skeniram i najednom se : Blue screen of death!
Imam osecaj da ce se ovo bas oduziti, hoces da ostavimo za popodne?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Probaj ponovo. Desava se da BSODuje po nekad.

offline
  • Gvelf  Male
  • Novi MyCity građanin
  • Pridružio: 09 Nov 2007
  • Poruke: 18

Probao sam par puta, probao sam iz safe moda, al se restartuje svaki put!
Mogu samo da skeniram autostart!

GMER 1.0.13.12551 - gmer.net
Autostart scan 2007-12-01 14:24:30
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
!SASWinLogon@DLLName = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
klogon@DLLName = C:\WINDOWS\system32\klogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ANIWZCSdService /*ANIWZCSd Service*/@ = C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
ET5Drv@ = \??\C:\WINDOWS\system32\Drivers\ET5Drv.sys /*file not found*/
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ANIWZCS2ServiceC:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe = C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
@NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run@NTSpool = NTSpool.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\WPDShServiceObj.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} = C:\Program Files\SUPERAntiSpyware\SASSEH.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Compressed (zipped) Folder*/(null) =
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\System32\extmgr.dll = C:\WINDOWS\System32\extmgr.dll
@{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
@{E0D79304-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79305-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79306-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{E0D79307-84BE-11CE-9641-444553540000} /*WinZip*/C:\PROGRA~1\WINZIP\WZSHLSTB.DLL = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/(null) =
@{85E0B171-04FA-11D1-B7DA-00A0C90348D6} /*Web Anti-Virus statistics*/C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll = C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
@{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll"
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL = C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
@{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{BD88A479-9623-4897-8546-BC62B9628F44} /*SPTHandler*/(null) =
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll = C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll
@{51131DA7-1D24-40e5-AE07-5E3750F5DE3C} /*ContextMenuExt Extension*/C:\WINDOWS\ContextMenuExt.dll = C:\WINDOWS\ContextMenuExt.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
CopyMoveTo@{51131DA7-1D24-40e5-AE07-5E3750F5DE3C} = C:\WINDOWS\ContextMenuExt.dll
DAP_Menu@{BED4C38B-F765-45AC-8C56-613F76BBF43E} =
DAP_ShredMenu@{BED4C38B-F765-45AC-8C56-613F76BBF43E} =
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
CopyMoveTo@{51131DA7-1D24-40e5-AE07-5E3750F5DE3C} = C:\WINDOWS\ContextMenuExt.dll
DAP_ShredMenu@{BED4C38B-F765-45AC-8C56-613F76BBF43E} =
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
CopyMoveTo@{51131DA7-1D24-40e5-AE07-5E3750F5DE3C} = C:\WINDOWS\ContextMenuExt.dll
Kaspersky Anti-Virus@{dd230880-495a-11d1-b064-008048ec2fc5} = C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ShellEx.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
WinZip@{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll = C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
@Local PageC:\windows\system32\blank.htm = C:\windows\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
ms-itss@CLSID = C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
msencarta@CLSID = C:\Program Files\Common Files\Microsoft Shared\Reference 2001\MSREF.DLL
msero@CLSID = C:\Program Files\Common Files\Microsoft Shared\Reference 2001\msero.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
msref@CLSID = C:\Program Files\Common Files\Microsoft Shared\Reference 2001\MSREF.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
wia@CLSID = C:\WINDOWS\System32\wiascr.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2F507796-9AE2-42B9-90B6-E1B4BBEEADD0} /*Wireless Network Connection*/ >>>
*[mod by bobby] par poverljivih podataka izbrisano*

---- EOF - GMER 1.0.13 ----

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Probaj da obrises taj NTSpool.exe iz Safe Moda.
Ukoliko nece, onda mi daj tacnu putanju do fajla da bih ti napisao skript za Avenger kojim cemo ga obrisati.

offline
  • Gvelf  Male
  • Novi MyCity građanin
  • Pridružio: 09 Nov 2007
  • Poruke: 18

Izbrisao sam ga i za divno cudo ne pali se vise famozni svchost.exe i ne konektuje se na ns.justicia.gov.bo
Znaci NTSpool.exe je bio problem, mada ti nisi nasao nista cudno u njemu?
Jel ima jos nesto sto bih mogao da uradim?

offline
  • Pridružio: 04 Sep 2003
  • Poruke: 24135
  • Gde živiš: Wien

Nasao sam bio da je NTSpooler maliciozan, ali tek u ovom zadnjem logu koji si postavio se videlo da se on stvarno ucitava, tj. startuje.
Zeleo sam da znam da li je aktivan, ili je zaostao nakon nekog nepotpunog ciscenja od strane nekog AV programa.
Desava se da na disku covek ima maliciozan fajl, ali da je neaktivan, tj. obrisan je reg. kljuc odakle se taj fajl startovao. Takav fajl je bezopasan i ne moze biti uzrok problema. Meni je trebao indikator da li se nas NTSpooler uopste startuje, i gore se vidi da se startuje zajedno sa Explorerom, tj. sa Desktopom. To je ono sto sam zeleo da znam.

Drugo nisam nasao nista sporno.

Ko je trenutno na forumu
 

Ukupno su 765 korisnika na forumu :: 2 registrovanih, 0 sakrivenih i 763 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Dorcolac, stegonosa