Poslao: 19 Sep 2008 20:56
|
offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
Komp u poslednje vreme radi nesto sporije.
Evo loga
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:50:00 PM, on 9/19/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
D:\BACKUP\PROGRAMI\install\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ptec/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ptec/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Update Helper - {77D7E795-33C5-4323-974D-A2A49AB75517} - C:\Program Files\Google\Update\1.2.131.11\GoopdateBho.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: CodecPlugin Class - {e161c562-11aa-4eae-9d60-0e18ebb4b0fc} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKCU\..\Run: [msnmsgr] "C:\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSfox000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
--
End of file - 5058 bytes
|
|
|
|
Poslao: 19 Sep 2008 22:04
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Poz...
U logu postoje tragovi nekih ranijih infekcija, no ne bi se reklo da je išta aktivno.
Pokreni HijackThis, skeniraj i čekiraj sledeće linije:
O2 - BHO: CodecPlugin Class - {e161c562-11aa-4eae-9d60-0e18ebb4b0fc} - (no file)
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSfox000
Klikni Fix checked.
-------------------------------------------------------------------------------------
Izvršićemo još jednu proveru...
Preuzmi gmer.zip sa ovog linka i sačuvaj na Desktopu.
Raspakuj ga u neki folder.
Dupli klik na gmer.exe za početak: Izaberi Rootkit/Malware Tab na vrhu.
Desni klik na sred forme programa. Pojaviće se menij u kojem je potrebno otići na Options i tu štiklirati opciju Only non MS files
Klikni na Scan.
Kada je skeniranje završeno, klik na Copy dugme ispod - ovo će sačuvati rezultate skeniranja u Clipboard.
Iskoristi opciju Paste u Notepad-u da bi to prebacio u tekst. Snimi taj tekst iz Notepada kao fajl logfile.txt
Iskoristi opciju Prikači fajl ispod polja za pisanje poruke na forumu, i prikači nam ovde fajl koji smo malopre snimili.
|
|
|
|
Poslao: 20 Sep 2008 08:17
|
offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-09-20 08:13:10
Windows 5.1.2600 Service Pack 2
---- Modules - GMER 1.0.14 ----
Module sptd.sys BA6BD000-BA7A7000 (958464 bytes)
Module jraid.sys (JMicron JMB36X RAID Driver/JMicron Technology Corp.) BA8D8000-BA8E8000 (65536 bytes)
Module PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) BA908000-BA911000 (36864 bytes)
Module speedfan.sys (SpeedFan Device Driver/Windows (R) 2000 DDK provider) BADAE000-BADB0000 (8192 bytes)
Module giveio.sys BAE71000-BAE72000 (4096 bytes)
Module \SystemRoot\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.19 /NVIDIA Corporation) B967A000-B9CBB000 (6557696 bytes)
Module \SystemRoot\system32\DRIVERS\HDAudBus.sys (High Definition Audio Bus Driver v1.0a/Windows (R) Server 2003 DDK provider) B961E000-B9643000 (151552 bytes)
Module \SystemRoot\system32\DRIVERS\Rtenicxp.sys (Realtek 10/100/1000 NDIS 5.1 Driver /Realtek Semiconductor Corporation ) B9605000-B961E000 (102400 bytes)
Module \SystemRoot\system32\drivers\cx88vid.sys (CX2388x Video Capture Driver/Leadtek Research Inc.) B95DD000-B9605000 (163840 bytes)
Module \SystemRoot\System32\Drivers\aw6epvqr.SYS B953F000-B95A6000 (421888 bytes)
Module \SystemRoot\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) BABD8000-BABDD000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\hamachi.sys (Hamachi Virtual Network Interface Driver/LogMeIn, Inc.) BABE8000-BABED000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\VClone.sys (VirtualCloneCD Driver/Elaborate Bytes AG) BAB08000-BAB13000 (45056 bytes)
Module \SystemRoot\system32\drivers\RtkHDAud.sys (Realtek(r) High Definition Audio Function Driver/Realtek Semiconductor Corp.) B6E65000-B7314000 (4911104 bytes)
Module \SystemRoot\system32\drivers\cxavxbar.sys (CX2388x AVStream Crossbar Driver/Leadtek Research Inc.) B9438000-B943B000 (12288 bytes)
Module \SystemRoot\system32\drivers\CX88TUNE.sys (CX2388x Tuner Driver/Leadtek Research Inc.) BA9B8000-BA9C5000 (53248 bytes)
Module \SystemRoot\System32\Drivers\aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software) BA9C8000-BA9D1000 (36864 bytes)
Module \SystemRoot\System32\Drivers\PQNTDrv.SYS (PowerQuest Boot Mode Driver./PowerQuest Corporation) BAF98000-BAF99000 (4096 bytes)
Module \SystemRoot\System32\Drivers\ElbyCDIO.sys (ElbyCD Windows NT/2000/XP I/O driver/Elaborate Bytes AG) BAC48000-BAC4D000 (20480 bytes)
Module \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) B5C23000-B5C3A000 (94208 bytes)
Module \SystemRoot\System32\Drivers\Aavmker4.SYS (avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP/ALWIL Software) BAC50000-BAC55000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\netrcacm.sys (RCA USB Digital Cable Modem Driver/Thomson Inc.) BAC58000-BAC5D000 (20480 bytes)
Module \SystemRoot\System32\nv4_disp.dll (NVIDIA Compatible Windows 2000 Display driver, Version 175.19 /NVIDIA Corporation) BF9D3000-BFFA7000 (6111232 bytes)
Module \SystemRoot\system32\DRIVERS\aswFsBlk.sys (avast! File System Access Blocking Driver/ALWIL Software) BABA0000-BABA8000 (32768 bytes)
Module \SystemRoot\System32\Drivers\aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software) B56AD000-B56C3000 (90112 bytes)
Module \SystemRoot\system32\DRIVERS\atksgt.sys B50B1000-B50F4000 (274432 bytes)
Module \SystemRoot\system32\DRIVERS\lirsgt.sys BAC98000-BAC9D000 (20480 bytes)
Module \SystemRoot\system32\DRIVERS\secdrv.sys B5531000-B5534000 (12288 bytes)
Module \SystemRoot\System32\Drivers\aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software) B4E52000-B4E56000 (16384 bytes)
Module \SystemRoot\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) B4A8E000-B4AA3000 (86016 bytes)
Module \Program_Files\DAEMON_Tools\daemon.dll (Virtual DAEMON control library/DT Soft Ltd.) 10000000-100F4000 (999424 bytes)
---- Processes - GMER 1.0.14 ----
Process C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (avast! Antivirus updating service/ALWIL Software) 236
Library C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (avast! Antivirus updating service/ALWIL Software) 0x00400000
Library C:\Program Files\Alwil Software\Avast4\aswCmnS.dll (Common non-portable functions/ALWIL Software) 0x64100000
Library C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll (Antivirus HW dependent library/ALWIL Software) 0x64000000
Library C:\Program Files\Alwil Software\Avast4\aswCmnB.dll (High level portable functions/ALWIL Software) 0x64080000
Process C:\Program Files\Alwil Software\Avast4\ashServ.exe (avast! antivirus service/ALWIL Software) 300
Library C:\Program Files\Alwil Software\Avast4\ashServ.exe (avast! antivirus service/ALWIL Software) 0x00400000
Library C:\Program Files\Alwil Software\Avast4\aswAux.dll (avast! Auxiliary Library/ALWIL Software) 0x64580000
Library C:\Program Files\Alwil Software\Avast4\aswCmnB.dll (High level portable functions/ALWIL Software) 0x64080000
Library C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll (Antivirus HW dependent library/ALWIL Software) 0x64000000
Library C:\Program Files\Alwil Software\Avast4\aswEngin.dll (High level antivirus engine/ALWIL Software) 0x64280000
Library C:\Program Files\Alwil Software\Avast4\aswScan.dll (Low level antivirus engine/ALWIL Software) 0x64200000
Library C:\Program Files\Alwil Software\Avast4\aswCmnS.dll (Common non-portable functions/ALWIL Software) 0x64100000
Library C:\Program Files\Alwil Software\Avast4\ashBase.dll (Basic Functionality Module/ALWIL Software) 0x64500000
Library C:\Program Files\Alwil Software\Avast4\ashTask.dll (Task Handling Module/ALWIL Software) 0x64800000
Library C:\Program Files\Alwil Software\Avast4\aswInteg.dll (Integrity checking implementation/ALWIL Software) 0x64400000
Library C:\Program Files\Alwil Software\Avast4\aswIdle.dll (avast! Idle Hook Library/ALWIL Software) 0x64A00000
Library C:\Program Files\Alwil Software\Avast4\Aavm4h.dll (avast! Asynchronous Virus Monitor (AAVM)/ALWIL Software) 0x65000000
Library C:\Program Files\Alwil Software\Avast4\AavmRpch.dll (avast! AAVM Remote Procedure Call Library/ALWIL Software) 0x65100000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\Alwil Software\Avast4\English\Base.dll (avast! English Basic Module/ALWIL Software) 0x66080000
Library C:\Program Files\Alwil Software\Avast4\AhResMai.dll (avast! e-Mail Scanner AAVM Provider Library/ALWIL Software) 0x65380000
Library C:\Program Files\Alwil Software\Avast4\ahResMes.dll (avast!4 Messenger scanner AAVM Provider Library/ALWIL Software) 0x65880000
Library C:\Program Files\Alwil Software\Avast4\AhResNS.dll (avast!4 Network Shield AAVM Provider Library/ALWIL Software) 0x65980000
Library C:\Program Files\Alwil Software\Avast4\AhResOut.dll (avast! MS Outlook/Exchange AAVM Provider Library/ALWIL Software) 0x65280000
Library C:\Program Files\Alwil Software\Avast4\ahResP2P.dll (avast!4 P2P Shield AAVM Provider Library/ALWIL Software) 0x658C0000
Library C:\Program Files\Alwil Software\Avast4\AhResStd.dll (avast! Standard Shield AAVM Provider Library/ALWIL Software) 0x65180000
Library C:\Program Files\Alwil Software\Avast4\AhResWS.dll (avast! HTTP Scanner AAVM Provider Library/ALWIL Software) 0x65A00000
Library C:\Program Files\Alwil Software\Avast4\ashSSqlt.dll (avast! Sqlt Storage Module/ALWIL Software) 0x64880000
Process C:\WINDOWS\system32\winlogon.exe (Windows NT Logon Application/Microsoft Corporation) 916
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\fastload.dll (fLoad/Stardock) 0x10000000
Process C:\WINDOWS\system32\services.exe (Services and Controller app/Microsoft Corporation) 960
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\system32\lsass.exe (LSA Shell (Export Version)/Microsoft Corporation) 980
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\system32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1160
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\system32\spoolsv.exe (Spooler SubSystem App/Microsoft Corporation) 1188
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\WINDOWS\system32\HPBMMON.DLL (Win32 Master Monitor/Hewlett-Packard) 0x10000000
Library C:\WINDOWS\system32\hppamon0.dll (Wrapper for Dot4 Monitor /HP) 0x00A80000
Library C:\WINDOWS\system32\hpdomon.dll (Win32 Language Monitor for direct connect HP printers/Hewlett-Packard) 0x00F30000
Library C:\WINDOWS\system32\HPBHealr.dll 0x67200000
Library C:\WINDOWS\System32\spool\PRTPROCS\W32X86\IMFPrint.DLL (Intelligent MetaFile Print Processor/Zenographics, Inc.) 0x715E0000
Library C:\WINDOWS\system32\Imf32.dll (IMF32/Zenographics, Inc.) 0x71600000
Library C:\WINDOWS\system32\ZTAG32.dll (ZTag/Zenographics, Inc.) 0x715D0000
Library C:\WINDOWS\system32\ZSPOOL.dll (ZSpool/Zenographics, Inc.) 0x71130000
Process C:\WINDOWS\system32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1248
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 175.19/NVIDIA Corporation) 1416
Library C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 175.19/NVIDIA Corporation) 0x00400000
Library C:\WINDOWS\system32\nvapi.dll (NVIDIA NVAPI Library, Version 175.19 /NVIDIA Corporation) 0x009F0000
Process C:\WINDOWS\system32\PnkBstrA.exe 1440
Library C:\WINDOWS\system32\PnkBstrA.exe 0x00400000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\Explorer.EXE (Windows Explorer/Microsoft Corporation) 1456
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc) 0x66600000
Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe PDF Helper for Internet Explorer/Adobe Systems Incorporated) 0x10000000
Library C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll (Sun Microsystems, Inc.) 0x61310000
Library C:\Program Files\OpenOffice.org 2.4\program\stlport_vc7145.dll (STLport/STLport Consulting, Inc.) 0x60E20000
Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll (PDF Shell Extension/Adobe Systems, Inc.) 0x01EE0000
Library C:\Program Files\Alwil Software\Avast4\ashShell.dll (avast! Shell Extension/ALWIL Software) 0x64F00000
Library C:\Program Files\WinRAR\rarext.dll 0x020F0000
Library C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll (TuneUp Shredder Shell Extension/TuneUp Software GmbH) 0x01FC0000
Library C:\Program Files\JetAudio\JetFlExt.dll (Shell Extension for jetAudio/COWON America) 0x02120000
Library C:\WINDOWS\BricoPacks\Vista Inspirat 2\iColorFolder\CMExt.dll (CMenuExtender/Revenger inc.) 0x02BC0000
Library C:\PROGRA~1\AIMP2\System\AIMP_S~1.DLL (AIMP ShellExt/AIMP DevTeam) 0x02CF0000
Library C:\WINDOWS\system32\nvcpl.dll (NVIDIA Display Properties Extension/NVIDIA Corporation) 0x03650000
Library C:\WINDOWS\system32\nvapi.dll (NVIDIA NVAPI Library, Version 175.19 /NVIDIA Corporation) 0x01660000
Library C:\WINDOWS\system32\nvshell.dll 0x01AA0000
Process C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (avast! service GUI component/ALWIL Software) 1552
Library C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (avast! service GUI component/ALWIL Software) 0x00400000
Library C:\PROGRA~1\ALWILS~1\Avast4\aswCmnOS.dll (Antivirus HW dependent library/ALWIL Software) 0x64000000
Library C:\PROGRA~1\ALWILS~1\Avast4\ashBase.dll (Basic Functionality Module/ALWIL Software) 0x64500000
Library C:\PROGRA~1\ALWILS~1\Avast4\aswCmnB.dll (High level portable functions/ALWIL Software) 0x64080000
Library C:\PROGRA~1\ALWILS~1\Avast4\aswCmnS.dll (Common non-portable functions/ALWIL Software) 0x64100000
Library C:\PROGRA~1\ALWILS~1\Avast4\ashTask.dll (Task Handling Module/ALWIL Software) 0x64800000
Library C:\PROGRA~1\ALWILS~1\Avast4\aswAux.dll (avast! Auxiliary Library/ALWIL Software) 0x64580000
Library C:\PROGRA~1\ALWILS~1\Avast4\Aavm4h.dll (avast! Asynchronous Virus Monitor (AAVM)/ALWIL Software) 0x65000000
Library C:\PROGRA~1\ALWILS~1\Avast4\AavmRpch.dll (avast! AAVM Remote Procedure Call Library/ALWIL Software) 0x65100000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc) 0x66600000
Library C:\Program Files\Alwil Software\Avast4\English\Base.dll (avast! English Basic Module/ALWIL Software) 0x66080000
Library C:\Program Files\Alwil Software\Avast4\English\Lang.dll (avast! Main English Module/ALWIL Software) 0x66100000
Library c:\program files\alwil software\avast4\ahruimai.dll (avast! e-Mail Scanner provider GUI/ALWIL Software) 0x65400000
Library C:\PROGRA~1\ALWILS~1\Avast4\ashUInt.dll (avast! User Interface Common Module/ALWIL Software) 0x64B00000
Library C:\PROGRA~1\ALWILS~1\Avast4\XT1922.dll (Xtreme Toolkit Library DLL/Codejock Software) 0x64C80000
Library c:\program files\alwil software\avast4\ahruimes.dll (avast!4 Messenger scanner AAVM Provider GUI Library/ALWIL Software) 0x65900000
Library c:\program files\alwil software\avast4\ahruins.dll (avast!4 Network Shield AAVM Provider GUI Library/ALWIL Software) 0x659C0000
Library c:\program files\alwil software\avast4\ahruiout.dll (avast! MS Outlook/Exchange AAVM Provider GUI Library/ALWIL Software) 0x65300000
Library c:\program files\alwil software\avast4\ahruip2p.dll (avast!4 P2P Shield AAVM Provider GUI Library/ALWIL Software) 0x65940000
Library c:\program files\alwil software\avast4\ahruistd.dll (avast! Standard Shield AAVM Provider GUI Library/ALWIL Software) 0x65200000
Library c:\program files\alwil software\avast4\ahruiws.dll (Avast! WWW Scanner AAVM Provider GUI Library/ALWIL Software) 0x65A40000
Process C:\Program Files\Google\Google Talk\googletalk.exe (Google Talk/Google) 1584
Library C:\Program Files\Google\Google Talk\googletalk.exe (Google Talk/Google) 0x00400000
Process C:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1600
Library C:\WINDOWS\System32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library c:\windows\system32\uxtuneup.dll (TuneUp Theme Extension/TuneUp Software GmbH) 0x55580000
Process C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Virtual CloneDrive Daemon/Elaborate Bytes AG) 1632
Library C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Virtual CloneDrive Daemon/Elaborate Bytes AG) 0x00400000
Library C:\WINDOWS\system32\ElbyVCD.dll (VirtualCloneDrive/Elaborate Bytes AG) 0x10000000
Library C:\WINDOWS\system32\ElbyCDIO.dll (ElbyCDIO DLL/Elaborate Bytes AG) 0x00320000
Process C:\Windows Live\Messenger\msnmsgr.exe (Windows Live Messenger/Microsoft Corporation) 1656
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc) 0x66600000
Library C:\WINDOWS\system32\devenum.dll 0x75F40000
Library C:\WINDOWS\system32\msdmo.dll 0x736B0000
Process C:\WINDOWS\system32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1724
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (avast! e-Mail Scanner Service/ALWIL Software) 1844
Library C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (avast! e-Mail Scanner Service/ALWIL Software) 0x00400000
Library C:\Program Files\Alwil Software\Avast4\ashBase.dll (Basic Functionality Module/ALWIL Software) 0x64500000
Library C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll (Antivirus HW dependent library/ALWIL Software) 0x64000000
Library C:\Program Files\Alwil Software\Avast4\aswCmnB.dll (High level portable functions/ALWIL Software) 0x64080000
Library C:\Program Files\Alwil Software\Avast4\aswCmnS.dll (Common non-portable functions/ALWIL Software) 0x64100000
Library C:\Program Files\Alwil Software\Avast4\ashTask.dll (Task Handling Module/ALWIL Software) 0x64800000
Library C:\Program Files\Alwil Software\Avast4\aswAux.dll (avast! Auxiliary Library/ALWIL Software) 0x64580000
Library C:\Program Files\Alwil Software\Avast4\Aavm4h.dll (avast! Asynchronous Virus Monitor (AAVM)/ALWIL Software) 0x65000000
Library C:\Program Files\Alwil Software\Avast4\AavmRpch.dll (avast! AAVM Remote Procedure Call Library/ALWIL Software) 0x65100000
Library C:\Program Files\Alwil Software\Avast4\AhResMai.dll (avast! e-Mail Scanner AAVM Provider Library/ALWIL Software) 0x65380000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\Alwil Software\Avast4\English\Base.dll (avast! English Basic Module/ALWIL Software) 0x66080000
Library C:\Program Files\Alwil Software\Avast4\aswEngin.dll (High level antivirus engine/ALWIL Software) 0x64280000
Library C:\Program Files\Alwil Software\Avast4\aswScan.dll (Low level antivirus engine/ALWIL Software) 0x64200000
Library C:\Program Files\Alwil Software\Avast4\English\Lang.dll (avast! Main English Module/ALWIL Software) 0x66100000
Library C:\Program Files\Alwil Software\Avast4\English\langmai.dll (English language DLL for avast! e-Mail Scanner/ALWIL Software) 0x003E0000
Process C:\WINDOWS\system32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation) 1892
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\WINDOWS\system32\wdfmgr.exe (Windows User Mode Driver Manager/Microsoft Corporation) 1932
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Process C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (avast! Web Scanner/ALWIL Software) 2064
Library C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (avast! Web Scanner/ALWIL Software) 0x00400000
Library C:\Program Files\Alwil Software\Avast4\ashBase.dll (Basic Functionality Module/ALWIL Software) 0x64500000
Library C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll (Antivirus HW dependent library/ALWIL Software) 0x64000000
Library C:\Program Files\Alwil Software\Avast4\aswCmnB.dll (High level portable functions/ALWIL Software) 0x64080000
Library C:\Program Files\Alwil Software\Avast4\aswCmnS.dll (Common non-portable functions/ALWIL Software) 0x64100000
Library C:\Program Files\Alwil Software\Avast4\Aavm4h.dll (avast! Asynchronous Virus Monitor (AAVM)/ALWIL Software) 0x65000000
Library C:\Program Files\Alwil Software\Avast4\AavmRpch.dll (avast! AAVM Remote Procedure Call Library/ALWIL Software) 0x65100000
Library C:\Program Files\Alwil Software\Avast4\ashTask.dll (Task Handling Module/ALWIL Software) 0x64800000
Library C:\Program Files\Alwil Software\Avast4\aswAux.dll (avast! Auxiliary Library/ALWIL Software) 0x64580000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\Alwil Software\Avast4\English\Base.dll (avast! English Basic Module/ALWIL Software) 0x66080000
Library C:\Program Files\Alwil Software\Avast4\aswEngin.dll (High level antivirus engine/ALWIL Software) 0x64280000
Library C:\Program Files\Alwil Software\Avast4\aswScan.dll (Low level antivirus engine/ALWIL Software) 0x64200000
Library C:\Program Files\Alwil Software\Avast4\ashWsFtr.dll (avast! Web Shield Filter Module/ALWIL Software) 0x68300000
Library C:\PROGRA~1\ALWILS~1\Avast4\AhResWs.dll (avast! HTTP Scanner AAVM Provider Library/ALWIL Software) 0x65A00000
Process C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 2740
Library C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation) 0x00400000
Library C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation) 0x60490000
Library C:\Program Files\Mozilla Firefox\sqlite3.dll (SQLite Database Library/sqlite.org) 0x60210000
Library C:\Program Files\Mozilla Firefox\MOZCRT19.dll (User-Generated Microsoft (R) C/C++ Runtime Library/Mozilla Foundation) 0x60000000
Library C:\Program Files\Mozilla Firefox\js3250.dll (Netscape 32-bit JavaScript Module/Netscape Communications Corporation) 0x60100000
Library C:\Program Files\Mozilla Firefox\nspr4.dll (NSPR Library/Mozilla Foundation) 0x600B0000
Library C:\Program Files\Mozilla Firefox\smime3.dll (NSS S/MIME Library/Mozilla Foundation) 0x60430000
Library C:\Program Files\Mozilla Firefox\nss3.dll (NSS Base Library/Mozilla Foundation) 0x60340000
Library C:\Program Files\Mozilla Firefox\nssutil3.dll (NSS Utility Library/Mozilla Foundation) 0x603F0000
Library C:\Program Files\Mozilla Firefox\plc4.dll (PLC Library/Mozilla Foundation) 0x600F0000
Library C:\Program Files\Mozilla Firefox\plds4.dll (PLDS Library/Mozilla Foundation) 0x600E0000
Library C:\Program Files\Mozilla Firefox\ssl3.dll (NSS SSL Library/Mozilla Foundation) 0x60410000
Library C:\Program Files\Mozilla Firefox\xpcom.dll (Mozilla Foundation) 0x60DF0000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc) 0x66600000
Library C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll (Mozilla Foundation) 0x601B0000
Library C:\Program Files\Mozilla Firefox\softokn3.dll (NSS PKCS #11 Library/Mozilla Foundation) 0x602F0000
Library C:\Program Files\Mozilla Firefox\nssdbm3.dll (Legacy Database Driver/Mozilla Foundation) 0x60320000
Library C:\Program Files\Mozilla Firefox\freebl3.dll (NSS freebl Library/Mozilla Foundation) 0x60450000
Library C:\Program Files\Mozilla Firefox\nssckbi.dll (NSS Builtin Trusted Root CAs/Mozilla Foundation) 0x602A0000
Library C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll (Mozilla Foundation) 0x601C0000
Library C:\Program Files\Mozilla Firefox\plugins\npnul32.dll (Default Plug-in/mozilla.org) 0x601F0000
Library C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll 0x30000000
Library C:\WINDOWS\system32\Macromed\Common\SwSupport.dll (Director Support/Adobe Systems, Inc.) 0x69000000
Process C:\Documents and Settings\FlAmE of HeLl\Desktop\New Folder\gmer.exe 2908
Library C:\Documents and Settings\FlAmE of HeLl\Desktop\New Folder\gmer.exe 0x00400000
Library C:\WINDOWS\system32\wbsys.dll (WindowBlinds/Stardock.Net, Inc) 0x66500000
Library C:\Program Files\AlienGUIse\wbhelp.dll (WindowBlinds Helper DLL/Stardock.Net, Inc) 0x66600000
Library C:\WINDOWS\gmer.dll 0x72000000
---- Services - GMER 1.0.14 ----
Service (avast! Base Kernel-Mode Device Driver for Windows NT/2000/XP/ALWIL Software) [SYSTEM] Aavmker4
Service C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (avast! File System Access Blocking Driver/ALWIL Software) [AUTO] aswFsBlk
Service (avast! File System Filter Driver for Windows XP/ALWIL Software) [AUTO] aswMon2
Service (avast! TDI RDR Driver/ALWIL Software) [MANUAL] aswRdr
Service (avast! self protection module/ALWIL Software) [SYSTEM] aswSP
Service (avast! TDI Filter Driver/ALWIL Software) [SYSTEM] aswTdi
Service C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (avast! Antivirus updating service/ALWIL Software) [AUTO] aswUpdSv
Service C:\WINDOWS\system32\DRIVERS\atksgt.sys [AUTO] atksgt
Service C:\Program Files\Alwil Software\Avast4\ashServ.exe (avast! antivirus service/ALWIL Software) [AUTO] avast! Antivirus
Service C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (avast! e-Mail Scanner Service/ALWIL Software) [MANUAL] avast! Mail Scanner
Service C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (avast! Web Scanner/ALWIL Software) [MANUAL] avast! Web Scanner
Service C:\WINDOWS\system32\drivers\cx88vid.sys (CX2388x Video Capture Driver/Leadtek Research Inc.) [AUTO] CX23880
Service C:\WINDOWS\system32\drivers\cxavxbar.sys (CX2388x AVStream Crossbar Driver/Leadtek Research Inc.) [AUTO] CXAVXBAR
Service C:\WINDOWS\system32\drivers\CX88TUNE.sys (CX2388x Tuner Driver/Leadtek Research Inc.) [AUTO] CXTUNE
Service C:\WINDOWS\System32\Drivers\ElbyCDIO.sys (ElbyCD Windows NT/2000/XP I/O driver/Elaborate Bytes AG) [SYSTEM] ElbyCDIO
Service C:\WINDOWS\system32\DRIVERS\ENTECH.sys (EnTech Taiwan) [MANUAL] ENTECH
Service C:\WINDOWS\system32\Drivers\ET5Drv.sys (Generic Port I/O/Windows (R) 2000 DDK provider) [MANUAL] ET5Drv
Service C:\WINDOWS\gdrv.sys (GIGABYTE Tools/Windows (R) 2000 DDK provider) [MANUAL] gdrv
Service C:\WINDOWS\system32\giveio.sys [BOOT] giveio
Service C:\WINDOWS\System32\DRIVERS\gmer.sys (GMER Driver http://www.gmer.net/GMER) [MANUAL] gmer
Service C:\Program Files\Google\Update\GoogleUpdate.exe (Google Installer/Google Inc.) [DISABLED] gupdate1c90b651dea8622
Service C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (gusvc/Google) [DISABLED] gusvc
Service C:\WINDOWS\system32\DRIVERS\hamachi.sys (Hamachi Virtual Network Interface Driver/LogMeIn, Inc.) [MANUAL] hamachi
Service C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (High Definition Audio Bus Driver v1.0a/Windows (R) Server 2003 DDK provider) [MANUAL] HDAudBus
Service iaStor
Service C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (IDriverT Module/Macrovision Corporation) [DISABLED] IDriverT
Service C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek(r) High Definition Audio Function Driver/Realtek Semiconductor Corp.) [MANUAL] IntcAzAudAddService
Service C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron JMB36X RAID Driver/JMicron Technology Corp.) [BOOT] JRAID
Service C:\WINDOWS\system32\DRIVERS\k750bus.sys (Sony Ericsson 750 Driver/MCCI) [MANUAL] k750bus
Service C:\WINDOWS\system32\DRIVERS\k750mdfl.sys (Sony Ericsson 750 USB WMC Modem Filter Driver/MCCI) [MANUAL] k750mdfl
Service C:\WINDOWS\system32\DRIVERS\k750mdm.sys (Sony Ericsson 750 USB WMC Modem WDM Driver/MCCI) [MANUAL] k750mdm
Service C:\WINDOWS\system32\DRIVERS\k750mgmt.sys (Sony Ericsson 750 USB WMC Device Management Driver/MCCI) [MANUAL] k750mgmt
Service C:\WINDOWS\system32\DRIVERS\k750obex.sys (Sony Ericsson 750 USB WMC OBEX Interface Device Driver/MCCI) [MANUAL] k750obex
Service C:\WINDOWS\system32\DRIVERS\lirsgt.sys [AUTO] lirsgt
Service C:\WINDOWS\system32\E.tmp [MANUAL] MEMSWEEP2
Service C:\Program [DISABLED] MONyog
Service C:\WINDOWS\system32\DRIVERS\netrcacm.sys (RCA USB Digital Cable Modem Driver/Thomson Inc.) [MANUAL] netrcacm
Service NMSAccess
Service C:\Program Files\CDBurnerXP\NMSAccessU.exe [DISABLED] NMSAccessU
Service C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Compatible Windows 2000 Miniport Driver, Version 175.19 /NVIDIA Corporation) [MANUAL] nv
Service C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Driver Helper Service, Version 175.19/NVIDIA Corporation) [AUTO] NVSvc
Service Outlook
Service C:\WINDOWS\system32\HPZipm12.exe (PML Driver/HP) [DISABLED] Pml Driver HPZ12
Service C:\WINDOWS\system32\PnkBstrA.exe [AUTO] PnkBstrA
Service (PowerQuest Boot Mode Driver./PowerQuest Corporation) [SYSTEM] PQNTDrv
Service C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies DirectParallel IO Library/Parallel Technologies, Inc.) [MANUAL] Ptilink
Service C:\WINDOWS\System32\Drivers\PxHelp20.sys (Px Engine Device Driver for Windows 2000/XP/Sonic Solutions) [BOOT] PxHelp20
Service C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek 10/100/1000 NDIS 5.1 Driver /Realtek Semiconductor Corporation ) [MANUAL] RTLE8023xp
Service C:\WINDOWS\system32\DRIVERS\secdrv.sys [AUTO] Secdrv
Service C:\WINDOWS\system32\speedfan.sys (SpeedFan Device Driver/Windows (R) 2000 DDK provider) [BOOT] speedfan
Service C:\WINDOWS\System32\Drivers\sptd.sys [BOOT] sptd
Service C:\WINDOWS\System32\TuneUpDefragService.exe (TuneUp Drive Defrag Service/TuneUp Software GmbH) [DISABLED] TuneUp.Defrag
Service C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (ULCDRSvr/Ulead Systems, Inc.) [DISABLED] UleadBurningHelper
Service C:\WINDOWS\system32\UAService7.exe [DISABLED] UserAccess7
Service C:\WINDOWS\system32\DRIVERS\VClone.sys (VirtualCloneCD Driver/Elaborate Bytes AG) [MANUAL] VClone
Service C:\Program Files\WinFast\WFDTV\WFIOCTL.SYS (WinFast MultiMedia Device Driver/Leadtek Research Inc.) [MANUAL] WFIOCTL
Service C:\WINDOWS\system32\drivers\wfeaglxt.sys (WinFast EagleXT Driver/Leadtek Research Inc.) [MANUAL] WFLR6654
---- EOF - GMER 1.0.14 ----
|
|
|
|
Poslao: 20 Sep 2008 16:58
|
offline
- dr_Bora
- Anti Malware Fighter
Rank 2
- Pridružio: 24 Jul 2007
- Poruke: 12280
- Gde živiš: Höganäs, SE
|
Ovo izgleda čisto.
Još samo nešto da proverimo.
Skini file sa sledećeg linka na Desktop:
https://www.mycity.rs/must-login.png
Dvoklikni na njega kako bi ga pokrenuo.
Otvoriće se Notepad - iskopiraj tekst iz Notepad-a u temu na forumu.
|
|
|
|
Poslao: 20 Sep 2008 19:41
|
offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
Evo ga.
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Outlook]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Outlook\Performance]
"Debug"=dword:00000000
"Collect"="CollectPerformanceData"
"Library"="C:\\PROGRA~1\\COMMON~1\\SYSTEM\\MSMAPI\\1033\\MSMAPI32.DLL"
"Version"=dword:0000000e
"Close"="ClosePerformanceData"
"Open"="OpenPerformanceData"
"Last Counter"=dword:00000aec
"Last Help"=dword:00000aed
"First Counter"=dword:00000ac8
"First Help"=dword:00000ac9
"WbemAdapFileSignature"=hex:ed,55,04,ea,ef,f7,37,86,22,ac,62,df,22,21,fd,8d
"WbemAdapFileTime"=hex:00,21,d9,4b,15,83,c5,01
"WbemAdapFileSize"=dword:001594c8
"WbemAdapStatus"=dword:00000000
潎桴湩潦湵⸮ഠ
|
|
|
|
|
|