offline
- DuleRedStar
- Novi MyCity građanin
- Pridružio: 27 Sep 2009
- Poruke: 2
|
Napisano: 27 Sep 2009 13:48
Izvinite...
Evo log-a:
DDS (Ver_09-09-24.01) - NTFSx86
Run by Dule at 13:41:55,07 on ??? 27.09.2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_15
Microsoft Windows XP Professional 5.1.2600.3.1250.381.1033.18.2046.1250 [GMT 2:00]
AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSAgent.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\AVG\AVG8\IdentityProtection\agent\Bin\AVGIDSWatcher.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG8\IdentityProtection\agent\bin\AVGIDSMonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dule\Desktop\dds.pif
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: {500BCA15-57A7-4eaf-8143-8C619470B13D} - No File
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: EWPBrowseObject Class: {68f9551e-0411-48e4-9aaf-4bc42a6a46be} - c:\program files\canon\easy-webprint\EWPBrowseLoader.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
BHO: Windows Live pomagač za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [AVGIDS] "c:\program files\avg\avg8\identityprotection\agent\bin\AVGIDSUI.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dslmon.lnk - c:\program files\sagem\sagem f@st 800-840\dslmon.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\canon\easy-webprint\Toolband.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\canon\easy-webprint\Toolband.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\canon\easy-webprint\Toolband.dll/RC_Print.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
TCP: {2E54DAF8-75E0-4D83-B2D3-92918186EF7B} = 194.106.162.10 194.106.162.3
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~3\office12\GR99D3~1.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office12\GRA8E1~1.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\dule\applic~1\mozilla\firefox\profiles\trjktj2x.default\
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSErHr.sys [2009-7-22 25608]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-9-26 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-9-26 335240]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-9-26 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-9-26 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-9-26 297752]
R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2009-9-26 1370488]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg8\identityprotection\agent\bin\AVGIDSAgent.exe [2009-7-22 5641736]
R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\avg\avg8\identityprotection\agent\bin\AVGIDSWatcher.exe [2009-7-22 571912]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2009-9-26 29208]
R3 AVGIDSDriver;AVGIDSDriver;c:\program files\avg\avg8\identityprotection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-7-22 121352]
R3 AVGIDSFilter;AVGIDSFilter;c:\program files\avg\avg8\identityprotection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-7-22 30216]
R3 AVGIDSShim;AVGIDSShim;c:\program files\avg\avg8\identityprotection\agent\driver\platform_xp\AVGIDSShim.sys [2009-7-22 27232]
R3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2009-9-7 104344]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2009-9-7 69656]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2009-9-26 29208]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
============== File Associations ===============
txtfile=%windir%\NOTEPAD.EXE %1
=============== Created Last 30 ================
2009-09-27 03:10 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-27 03:10 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-27 03:10 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-27 03:07 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-09-27 03:03 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-09-26 23:08 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-09-26 22:46 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-09-26 22:46 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-09-26 22:46 12,552 a------- c:\windows\system32\drivers\avgrkx86.sys
2009-09-26 22:46 335,240 a------- c:\windows\system32\drivers\avgldx86.sys
2009-09-26 22:46 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-09-26 22:45 <DIR> --d----- c:\program files\AVG
2009-09-26 22:40 50,968 a------- c:\windows\system32\avgfwdx.dll
2009-09-26 22:40 29,208 a------- c:\windows\system32\drivers\avgfwdx.sys
2009-09-23 23:51 0 a---h--- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-09-23 23:51 0 a---h--- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-09-23 23:51 26,112 ac------ c:\windows\system32\dllcache\usbser.sys
2009-09-23 23:51 26,112 a------- c:\windows\system32\drivers\usbser.sys
2009-09-23 23:50 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-09-23 23:47 <DIR> --d----- c:\program files\common files\PCSuite
2009-09-23 23:47 <DIR> --d----- c:\program files\common files\Nokia
2009-09-23 23:47 7,808 a------- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-09-23 23:47 1,112,288 a------- c:\windows\system32\wdfcoinstaller01007.dll
2009-09-23 23:47 659,968 a------- c:\windows\system32\nmwcdcocls.dll
2009-09-23 23:47 22,016 a------- c:\windows\system32\drivers\ccdcmbo.sys
2009-09-23 23:47 17,664 a------- c:\windows\system32\drivers\ccdcmb.sys
2009-09-23 23:47 7,808 a------- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-09-23 23:40 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-09-23 23:40 14,640 -------- c:\windows\system32\spmsgXP_2k3.dll
2009-09-23 23:37 18,816 a------- c:\windows\system32\drivers\pccsmcfd.sys
2009-09-23 23:37 <DIR> --d----- c:\program files\PC Connectivity Solution
2009-09-23 22:23 315,392 a------- c:\windows\HideWin.exe
2009-09-23 22:07 571,392 ac------ c:\windows\system32\dllcache\tintlgnt.ime
2009-09-23 22:06 10,096,640 ac------ c:\windows\system32\dllcache\hwxcht.dll
2009-09-23 22:05 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-09-23 22:03 42,577 ac------ c:\windows\system32\dllcache\bckgzm.exe
2009-09-23 21:53 16,535 a----r-- c:\windows\SET47.tmp
2009-09-23 21:53 1,088,840 a----r-- c:\windows\SET3B.tmp
2009-09-23 21:53 1,296,669 a----r-- c:\windows\SET38.tmp
2009-09-23 17:23 361,600 a------- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-09-23 17:23 108,336 a------- c:\windows\system32winsck.ocx
2009-09-18 12:14 <DIR> --d----- c:\program files\NCH Software
2009-09-15 12:02 <DIR> --d----- c:\program files\Call of Duty 1
2009-09-14 12:29 <DIR> --d----- c:\program files\NCH Swift Sound
2009-09-07 14:11 <DIR> --d----- c:\program files\SAGEM
2009-08-29 15:05 <DIR> --d----- c:\program files\KONAMI
==================== Find3M ====================
2009-09-26 22:08 16,512 a------- c:\windows\gdrv.sys
2009-09-26 21:50 721,904 a------- c:\windows\system32\drivers\sptd.sys
2009-09-23 22:03 22,720 a------- c:\windows\system32\emptyregdb.dat
2009-09-12 22:06 5,840 a------- c:\windows\system32\ealregsnapshot1.reg
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-07 14:12 32 a------- c:\windows\system32\drivers\adidsl.cfg
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-29 06:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-12 12:21 233,472 a------- c:\windows\system32\wmpdxm.dll
2009-06-05 20:29 22,328 a------- c:\docume~1\dule\applic~1\PnkBstrK.sys
2008-03-09 08:25 236 a---h--- c:\program files\common files\dx.reg
============= FINISH: 13:43:42,65 ===============
mycity.rs/must-login.png
Stizu i GMER Log-ovi....
Dopuna: 27 Sep 2009 18:48
Format C:....to je bilo jedino resenje
U toku skeniranja GMER-a restart odjednom,nije hteo da podigne sistem...
Hvala na trudu!
|