Poslao: 27 Mar 2007 20:52
|
offline
- garfild24
- Građanin
- Pridružio: 22 Jul 2006
- Poruke: 43
- Gde živiš: Podgorica
|
e izvini molim te sto se ovo iskomplikova taj service mi je stopiram tako kad DTM na njega moze samo Start
|
|
|
|
Poslao: 27 Mar 2007 22:23
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
To znaci da trenutno nije startovan, tako da mozes odmah ono na Properties pa Disable.
|
|
|
|
Poslao: 27 Mar 2007 23:08
|
offline
- garfild24
- Građanin
- Pridružio: 22 Jul 2006
- Poruke: 43
- Gde živiš: Podgorica
|
evo log:
Logfile of HijackThis v1.99.1
Scan saved at 11:03:35 PM, on 3/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\lvhidsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\UTSCSI.EXE
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TrojanHunter 4.6\THGuard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSGTAG\MSGTAG.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\MULTIPRINT\Desktop\PROGRAMS 2007\HijackThis, Ewido Micro, backup, logs\pamet.exe
C:\Program Files\Opera\Opera.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = N3 - Netscape 7: user_pref("browser.search.defaultengine", ""); (C:\Documents and Settings\MULTIPRINT\Application Data\Mozilla\Profiles\default\9mt21tpb.slt\prefs.js)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.6\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSGTAG] "C:\Program Files\MSGTAG\MSGTAG.exe" /startup
O4 - Global Startup: Kaspersky Anti-Hacker.lnk = C:\Program Files\Kaspersky Lab\Kaspersky Anti-Hacker\KAVPF.exe
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ie_banner_deny.htm
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O17 - HKLM\System\CCS\Services\Tcpip\..\{58F7B8B6-D5FF-4801-9168-4BC9138B0071}: NameServer = 195.66.160.1 195.66.160.2
O17 - HKLM\System\CS2\Services\Tcpip\..\{58F7B8B6-D5FF-4801-9168-4BC9138B0071}: NameServer = 195.66.160.1 195.66.160.2
O17 - HKLM\System\CS3\Services\Tcpip\..\{58F7B8B6-D5FF-4801-9168-4BC9138B0071}: NameServer = 195.66.160.1 195.66.160.2
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe" -r (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Remote HID Service (LvHidSvc) - Philips - C:\WINDOWS\system32\lvhidsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: USBest Service Zero (UTSCSI) - USBest - C:\WINDOWS\system32\UTSCSI.EXE
|
|
|
|
Poslao: 27 Mar 2007 23:15
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Meni je ovaj log OK.
Kazi mi sta se to tacno desava, tj. koji su simptomi na koje se zalis? Ja ovde ne vidim nista cudno.
WinPCap se vratio, ali to je drajver za snifovanje mrezne kartice, a koriste ga jako puno programa, sto legitimnih sto malicioznih.
Imas li instaliran WM Recoder ili neki drugi program za snimanje sa webcam-a?
Imas li instaliran Ethereal ili NMap?
|
|
|
|
Poslao: 27 Mar 2007 23:27
|
offline
- garfild24
- Građanin
- Pridružio: 22 Jul 2006
- Poruke: 43
- Gde živiš: Podgorica
|
bobby ::Imas li instaliran Ethereal ili NMap?
Nemam ne znam sta je to? Pa kao prvo ne mogu vise abdejt windowsa da radim instalirao mi se od poslednjeg abdejta ovaj program: Genuine Windows Software koji nikako ne mogu da uklonim ni sa Add/Remove... nema ga ni u Program F. ni na Search a kad se podize sistem pali se on i kad tek kliknem na ok ide mi WElcoME?
Dopuna: 27 Mar 2007 23:27
Imam WM Recoder ali nikad nije uspio da mi proradi uklonicu ga
|
|
|
|
Poslao: 28 Mar 2007 00:02
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Genuine Windows Software sluzi za proveru legalnosti Windowsa, i ukoliko ne mozes vise da radis update to znaci da imas nelegalan Windows, a o tome nema raspravki na MC-u.
|
|
|
|
|