offline
- vucko16
- Ugledni građanin
- Pridružio: 20 Nov 2007
- Poruke: 387
- Gde živiš: Novi Beograd
|
Okey,hvala.
Resio sam prvi problem.
Jesam,imam program "free hide folder" i u My Documents-u je sakriven jedan folder.
DDS (Ver_09-07-30.01) - NTFSx86
Run by Vuceta at 13:57:59,75 on ??? 04.09.2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.1023.510 [GMT 2:00]
AV: ESET Smart Security 4.0 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Vuceta\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = https://online.bancaintesabeograd.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = socks=
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
TB: BS.Player ControlBar: {2c688203-7eb3-4327-9995-1cb417ba23f9} - c:\program files\bs.player controlbar\BSToolbar.dll
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [COMODO Firewall Pro] "c:\program files\comodo\firewall\cfp.exe" -h
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [UnlockerAssistant] "c:\program files\unlocker\UnlockerAssistant.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\vuceta\startm~1\programs\startup\INTERN~1.LNK -
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dslmon.lnk - c:\program files\sagem\sagem f@st 800-840\dslmon.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - c:\program files\funnsystems yump3com-user-authorization\YuMp3ComLogin.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: bancaintesabeograd.com\online
DPF: {76326493-E84F-4D4B-939C-1E07B50037F2} - hxxps://online.bancaintesabeograd.com/RetailDLL/SGCMSCCD.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {A7C346A3-B076-46B3-97F0-D00F6B479451} - hxxps://online.bancaintesabeograd.com/RetailDLL/FSINT.dll
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
TCP: {4522FF65-4AB6-4376-A182-D7F9DF4F9C02} = 194.247.192.1 194.247.192.33
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\vuceta\applic~1\mozilla\firefox\profiles\qb727rbi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/firefox
FF - component: c:\program files\bs.player controlbar\firefoxdtt\components\BSToolbarFF.dll
FF - plugin: c:\documents and settings\vuceta\application data\mozilla\firefox\profiles\qb727rbi.default\extensions\moveplayer@movenetworks.com\platform\winnt_x86-msvc\plugins\npmnqmp07076007.dll
FF - plugin: c:\program files\google\google updater\2.4.1636.7222\npCIDetect13.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
FF - user.js: network.proxy.http_port - 0
FF - user.js: network.proxy.ssl -
FF - user.js: network.proxy.ssl_port - 0
FF - user.js: network.proxy.ftp -
FF - user.js: network.proxy.ftp_port - 0
FF - user.js: network.proxy.gopher -
FF - user.js: network.proxy.gopher_port - 0
FF - user.js: network.proxy.socks_version - 5
FF - user.js: network.proxy.socks -
FF - user.js: network.proxy.socks_port - 0
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox 3 beta 5\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox 3 beta 5\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox 3 beta 5\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2009-5-14 731840]
R2 FGUARD32;FGUARD32;c:\program files\folder guard pro\FGUARD32.SYS [2009-7-3 48896]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2008-6-1 34064]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2007-11-14 114616]
S1 atitray;atitray;\??\c:\program files\radeon omega drivers\v4.8.442\ati tray tools\atitray.sys --> c:\program files\radeon omega drivers\v4.8.442\ati tray tools\atitray.sys [?]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2007-11-14 63555]
S3 MarkFun_NT;MarkFun_NT;\??\c:\program files\gigabyte\@bios\markfun.w32 --> c:\program files\gigabyte\@bios\markfun.w32 [?]
S3 SE1008mdm;Sony Ericsson SE1008 Mobile Device Full USB Driver;c:\windows\system32\drivers\SE1008mdm.sys [2009-8-3 58536]
S3 tusbdbus;Incentive Pro USB Bus Driver;c:\windows\system32\drivers\tusbdbus.sys --> c:\windows\system32\drivers\tusbdbus.sys [?]
S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2007-11-17 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2007-11-19 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2007-11-19 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2007-11-20 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2007-11-20 86368]
=============== Created Last 30 ================
2009-09-02 20:28 <DIR> --d----- c:\docume~1\vuceta\applic~1\Desktopicon
2009-09-02 20:28 <DIR> --d----- c:\program files\Unlocker
2009-09-02 14:45 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-09-02 14:45 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-09-02 14:45 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-09-02 14:45 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-09-02 14:45 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-09-02 14:45 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-02 14:45 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-09-02 14:45 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-09-02 14:45 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-02 14:45 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-02 14:45 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-02 14:38 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-09-02 14:37 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-09-02 14:36 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-09-02 14:17 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-09-02 14:17 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-09-02 14:17 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-09-01 18:56 <DIR> --d----- c:\documents and settings\vuceta\DoctorWeb
2009-09-01 13:50 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-09-01 07:50 <DIR> --d----- c:\windows\CFEA4B7AD7564287A6627B56B1756AB9.TMP
2009-08-31 19:13 <DIR> --d----- c:\program files\Trend Micro
2009-08-31 18:29 389,120 a------- c:\windows\system32\CF26009.exe
2009-08-31 18:23 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-08-31 11:30 3,001 a--sh--- c:\documents and settings\vuceta\ppUser.dat
2009-08-31 11:30 <DIR> --d----- c:\docume~1\vuceta\applic~1\Contrast
2009-08-31 11:28 <DIR> --d----- c:\program files\Contrast
2009-08-31 11:28 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Contrast
2009-08-20 21:18 421,888 a------- c:\windows\system32\ac3filter.acm
2009-08-20 21:18 <DIR> --d----- c:\program files\XP Codec Pack
2009-08-20 21:02 815,104 a------- c:\windows\system32\xvidcore.dll
2009-08-20 21:02 180,224 a------- c:\windows\system32\xvidvfw.dll
2009-08-20 21:02 77,824 a------- c:\windows\system32\xvid.ax
2009-08-20 21:02 <DIR> --d----- c:\program files\Xvid
2009-08-20 20:19 <DIR> --d----- c:\program files\WinPcap
2009-08-19 10:59 <DIR> --d----- c:\program files\ESET
2009-08-17 23:07 <DIR> --d----- c:\program files\FDRLab
2009-08-17 23:00 <DIR> --d----- c:\program files\Photo DVD Creator
2009-08-11 12:33 1,024 a------- c:\windows\system32\gncontent.cch
2009-08-11 12:22 <DIR> --d----- c:\program files\common files\Sony Shared
2009-08-11 12:22 <DIR> --d----- c:\program files\Sony
2009-08-05 19:22 1,246,648 a------- c:\windows\system32\gdi32s.dat
==================== Find3M ====================
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-29 06:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-12 12:21 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-06-26 18:50 666,624 a------- c:\windows\system32\wininet.dll
2009-06-26 18:50 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-25 10:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 10:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 10:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-12 14:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 14:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-10 16:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 08:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-04-14 09:00 24,360 a------- c:\docume~1\vuceta\applic~1\GDIPFONTCACHEV1.DAT
2009-02-11 22:51 2,672 a--sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-02-11 22:51 88 ---shr-- c:\docume~1\alluse~1\applic~1\6A91D54700.sys
2007-11-27 14:01 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2005-09-11 23:48 185,344 a------- c:\documents and settings\vuceta\rt.exe
============= FINISH: 13:58:47,92 ===============
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
|