Windows mi ne prepoznaje User-a

2

Windows mi ne prepoznaje User-a

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja. Samo jos ovo Doktore mi objasni.Neznam sta stim?

Dopuna: 07 Jul 2008 23:04

ComboFix 08-07-05.1 - pc 2008-07-07 22:52:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.288 [GMT 2:00]
Running from: C:\Documents and Settings\pc.VARGA\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pc.VARGA\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfweltpen.dll
C:\WINDOWS\mrvtdpqe.exe
C:\WINDOWS\system32\byXQIaYS.dll_old
C:\WINDOWS\system32\cdqjcqge.dll
C:\WINDOWS\system32\RichVideoCodec.dll
C:\WINDOWS\system32\yqflguyl.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\TEMP\Local Settings\Temporary Internet Files\
C:\WINDOWS\axrfgvek.dll
C:\WINDOWS\kgqfweltpen.dll
C:\WINDOWS\mrvtdpqe.exe
C:\WINDOWS\system32\byXQIaYS.dll_old
C:\WINDOWS\system32\cdqjcqge.dll
C:\WINDOWS\system32\RichVideoCodec.dll

.
((((((((((((((((((((((((( Files Created from 2008-06-07 to 2008-07-07 )))))))))))))))))))))))))))))))
.

2008-07-07 22:49 . 2004-08-04 03:07 388,608 --a------ C:\WINDOWS\system32\CF5491.exe
2008-07-07 22:39 . 2008-07-07 22:39 <DIR> d--hs---- C:\found.001
2008-07-07 17:17 . 2008-07-07 17:17 <DIR> d-------- C:\Documents and Settings\TEMP
2008-07-07 17:15 . 2008-07-07 21:47 474 ---hs---- C:\WINDOWS\system32\lyuglfqy.ini
2008-07-07 17:11 . 2008-07-07 17:18 <DIR> d-------- C:\Documents and Settings\pc.VARGA
2008-07-06 23:57 . 2008-07-07 00:00 <DIR> d-------- C:\effbot.exe
2008-07-06 01:25 . 2008-07-06 01:25 244 --ah----- C:\sqmnoopt00.sqm
2008-07-06 01:25 . 2008-07-06 01:25 232 --ah----- C:\sqmdata00.sqm
2008-07-06 00:43 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-07-06 00:28 . 2008-07-06 00:28 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-06 00:24 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-07-05 02:17 . 2008-07-05 02:20 193 --a------ C:\WINDOWS\wininit.ini
2008-07-05 00:03 . 2008-07-04 23:59 691,545 --a------ C:\WINDOWS\unins000.exe
2008-07-05 00:03 . 2008-07-05 00:03 2,537 --a------ C:\WINDOWS\unins000.dat
2008-07-04 23:53 . 2008-07-05 00:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-04 23:53 . 2008-07-05 00:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-04 23:17 . 2008-07-04 23:32 <DIR> d-------- C:\Program Files\Pawn 2
2008-07-04 15:25 . 2008-07-04 15:26 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-29 12:58 . 2004-08-04 03:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-29 01:26 . 2008-06-29 01:26 <DIR> d-------- C:\Program Files\SanDisk
2008-06-28 15:11 . 2008-06-28 15:11 <DIR> d-------- C:\Program Files\Robster Productions
2008-06-26 19:43 . 2008-06-26 19:43 <DIR> d-------- C:\Program Files\Analog Devices
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a--c--- C:\WINDOWS\system32\dllcache\aec.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-26 19:29 . 2001-09-19 14:47 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a--c--- C:\WINDOWS\system32\dllcache\a3d.dll
2008-06-26 19:29 . 2001-09-19 14:47 720,896 --a------ C:\WINDOWS\system32\Audio3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a------ C:\WINDOWS\system32\a3d.dll
2008-06-26 19:21 . 2008-06-26 19:21 <DIR> d-------- C:\Program Files\VIA
2008-06-26 19:21 . 2003-10-31 05:22 77,312 -ra------ C:\WINDOWS\system32\drivers\viasraid.sys
2008-06-26 19:19 . 2003-04-15 10:59 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-06-26 19:19 . 2008-06-26 19:38 2,881 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-06-26 18:11 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-26 18:06 . 2008-06-26 18:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-26 17:44 . 2008-06-26 17:44 <DIR> d--hs---- C:\found.000
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-26 12:11 . 2008-06-26 12:12 <DIR> d-------- C:\Program Files\ScriptCryptor
2008-06-26 00:26 . 2008-07-04 18:21 <DIR> d-------- C:\Program Files\Quick Batch File Compiler
2008-06-26 00:19 . 2008-06-26 00:19 <DIR> d-------- C:\Program Files\SAGEM
2008-06-25 23:46 . 2008-06-25 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-06-25 23:45 . 2008-06-24 20:18 211 --a------ C:\boot.ini.comodofirewall
2008-06-25 23:44 . 2008-06-25 23:44 <DIR> d-------- C:\Program Files\Comodo
2008-06-25 21:31 . 2008-07-07 22:45 53 --a------ C:\biosinfo
2008-06-25 21:29 . 2006-02-15 19:15 176,128 --a------ C:\WINDOWS\autoclk.exe
2008-06-25 21:29 . 2008-06-26 00:19 990 --a------ C:\WINDOWS\adiras.ini
2008-06-25 21:22 . 2008-06-26 15:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-25 21:20 . 2008-06-25 21:20 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-06-25 21:20 . 2003-09-20 00:45 21,248 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-06-25 21:19 . 2008-06-25 21:19 <DIR> d-------- C:\Program Files\ArcSoft
2008-06-25 21:19 . 1995-08-01 13:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\WINDOWS\PixArt
2008-06-25 21:18 . 2008-07-02 15:46 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Trust
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Common Files\PCCamera
2008-06-25 21:18 . 2008-06-26 15:09 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-25 21:16 . 2008-06-25 21:16 0 --a------ C:\WINDOWS\msicpl.ini
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-25 19:17 . 2008-06-25 19:30 <DIR> d-------- C:\WINDOWS\vf_hip
2008-06-25 19:17 . 2008-06-25 19:17 32 --a------ C:\WINDOWS\go
2008-06-25 19:13 . 2008-06-25 19:30 <DIR> d-------- C:\Program Files\Hide IP Platinum
2008-06-25 18:39 . 2003-06-19 02:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-25 18:39 . 2008-07-07 00:02 376 --a------ C:\WINDOWS\ODBC.INI
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-06-25 18:36 . 2008-06-25 18:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-25 18:35 . 2008-06-25 18:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-25 18:29 . 2008-07-06 20:44 <DIR> d-------- C:\Program Files\Windows Live
2008-06-25 18:29 . 2008-06-25 18:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-25 18:28 . 2008-06-25 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-25 18:18 . 2008-06-25 18:31 <DIR> d-------- C:\Documents and Settings\pc\Contacts
2008-06-25 18:18 . 2006-09-25 01:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-06-25 18:18 . 2007-09-05 02:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-06-25 18:18 . 2007-09-21 10:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-06-25 18:18 . 2007-10-04 01:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-06-25 18:17 . 2008-06-25 18:17 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-25 18:17 . 2007-09-29 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-25 18:17 . 2007-07-25 23:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-25 18:17 . 2007-09-29 02:05 739,840 --a------ C:\WINDOWS\system32\divx.dll
2008-06-25 18:17 . 2007-03-10 21:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-25 18:17 . 2004-01-26 02:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-06-25 18:17 . 2007-09-29 02:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-06-25 18:17 . 2007-07-30 01:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-25 18:17 . 2007-07-11 02:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-25 18:16 . 2008-06-25 18:16 <DIR> d-------- C:\Program Files\Winamp
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Ahead
2008-06-25 18:15 . 2001-07-06 23:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-06-25 18:15 . 2001-07-06 21:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-06-25 18:15 . 2001-07-07 03:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-06-25 18:15 . 2001-07-09 20:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-25 18:15 . 2004-03-04 06:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-06-25 18:15 . 2000-06-26 20:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-25 18:15 . 2001-06-26 17:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-06-25 18:15 . 2004-03-04 06:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-06-25 18:14 . 2008-07-04 22:09 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-25 18:13 . 2008-06-29 01:26 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-25 18:13 . 2008-06-25 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-25 18:13 . 2008-06-25 18:13 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-25 18:12 . 2008-06-25 18:13 <DIR> d-------- C:\Program Files\CyberLink
2008-06-25 18:12 . 2008-06-25 18:11 505,392 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-06-25 18:12 . 2008-06-25 18:11 353,840 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-06-25 18:10 . 2008-07-05 16:47 <DIR> d-------- C:\Program Files\Eset
2008-06-25 18:10 . 2008-06-25 18:10 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-06-25 18:10 . 2008-06-25 18:10 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-06-25 18:10 . 2008-06-25 18:10 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-06-25 18:09 . 2008-06-25 18:09 <DIR> d-------- C:\WINDOWS\Cache

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-29 00:14 90,112 ----a-w C:\WINDOWS\DUMP30c4.tmp
2008-06-25 22:19 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-24 18:26 --------- d-----w C:\Program Files\microsoft frontpage
.

((((((((((((((((((((((((((((( snapshot@2008-07-07_17.16.21.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 14:59:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-07 20:44:07 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-25 18:10 949376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 20:50 155648]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 03:15 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 04:37 69632]
"Comodo Firewall"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-06-26 12:41 1115728]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-16 16:51 7569408]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-16 16:51 86016]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2007-10-11 21:06 62760]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-17 04:20 91432]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 07:59 57344 C:\WINDOWS\SOUNDMAN.EXE]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-06-26 00:19:28 1205840]
VIA RAID TOOL.lnk - C:\Program Files\VIA\RAID\raid_tool.exe [2008-06-26 19:21:54 565248]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 20:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 18:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
--a------ 2007-10-22 12:52 75584 C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-05-13 21:08 1271032 E:\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-25 16:10 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-04-16 16:51 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 Inspect;Comodo Network Engine;C:\WINDOWS\system32\DRIVERS\inspect.sys [2008-06-26 12:47]
R0 uagp35;Microsoft AGPv3.5 Filter;C:\WINDOWS\system32\DRIVERS\uagp35.sys [2004-08-04 01:07]
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 05:22]
R1 nod32drv;nod32drv;C:\WINDOWS\system32\drivers\nod32drv.sys [2008-06-25 18:10]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 09:12]
R2 RichVideo;Cyberlink RichVideo Service(CRVS);C:\Program Files\CyberLink\Shared files\RichVideo.exe [2007-10-16 05:46]
R3 aeaudio;aeaudio;C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 08:15]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 22:48]
R3 FETNDIS;VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\fetnd5.sys [2001-08-17 14:13]
R3 smwdm;smwdm;C:\WINDOWS\system32\drivers\smwdm.sys [2003-07-15 16:00]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 22:47]
S2 NVSvc;NVIDIA Display Driver Service;C:\WINDOWS\system32\nvsvc32.exe [2006-04-16 16:51]
S3 ALCXSENS;Service for WDM 3D Audio Driver;C:\WINDOWS\system32\drivers\ALCXSENS.SYS [2003-08-07 16:15]
S3 GMSIPCI;GMSIPCI;G:\INSTALL\GMSIPCI.SYS []
S3 WpdUsb;WpdUsb;C:\WINDOWS\system32\Drivers\wpdusb.sys []

*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-07-07 22:54:55
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-07-07 22:56:40
ComboFix-quarantined-files.txt 2008-07-07 20:56:29
ComboFix2.txt 2008-07-07 15:17:09

Pre-Run: 15,264,952,320 bytes free
Post-Run: 15,253,266,432 bytes free

250 --- E O F --- 2008-06-26 13:49:45
Setio sam se !!!

Dopuna: 07 Jul 2008 23:54

Da li mozes da mi kazes sta da izbacim iz Start Up-a.


Dopuna: 07 Jul 2008 23:59

Ovo sve podize kad upalim Pc.Da li je nesto od toga nepotrebno?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ima dosta toga nepotrebnog. Sve zavisi sta od toga koristis. Bolje nemoj da diras, da deci nesto ne pokvaris. I sacekaj dalja uputstva. Sutra cu ti ih napisati.

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Doco , ja cekam , strpljivo..

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Otvoriti Notepad i iskopirati sledeci tekst:

File::
C:\WINDOWS\system32\lyuglfqy.ini

DirLook::
C:\effbot.exe


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

ComboFix 08-07-08.1 - pc 2008-07-09 14:15:41.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.216 [GMT 2:00]
Running from: C:\Documents and Settings\pc.VARGA\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\pc.VARGA\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\WINDOWS\system32\lyuglfqy.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\lyuglfqy.ini

.
((((((((((((((((((((((((( Files Created from 2008-06-09 to 2008-07-09 )))))))))))))))))))))))))))))))
.

2008-07-09 13:49 . 2008-07-09 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-08 20:24 . 2008-07-08 20:24 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Ahead
2008-07-08 20:18 . 2008-07-08 20:18 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\DivX
2008-07-08 19:15 . 2008-07-08 19:15 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\AdobeUM
2008-07-08 01:47 . 2008-07-08 13:33 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Contacts
2008-07-08 00:40 . 2008-07-08 00:40 <DIR> d-------- C:\Program Files\bfgclient
2008-07-08 00:38 . 2008-07-09 13:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\BigFishGamesCache
2008-07-08 00:24 . 2008-07-08 00:25 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Winamp
2008-07-07 23:30 . 2008-07-07 23:32 <DIR> d-------- C:\Program Files\WebPosition 4
2008-07-07 22:39 . 2008-07-07 22:39 <DIR> d--hs---- C:\found.001
2008-07-07 17:17 . 2008-07-07 17:17 <DIR> d-------- C:\Documents and Settings\TEMP
2008-07-07 17:15 . 2008-07-07 17:15 <DIR> d-------- C:\Documents and Settings\pc.VARGA\Application Data\Comodo
2008-07-07 17:11 . 2008-07-08 01:47 <DIR> d-------- C:\Documents and Settings\pc.VARGA
2008-07-06 23:57 . 2008-07-07 00:00 <DIR> d-------- C:\effbot.exe
2008-07-06 01:25 . 2008-07-06 01:25 244 --ah----- C:\sqmnoopt00.sqm
2008-07-06 01:25 . 2008-07-06 01:25 232 --ah----- C:\sqmdata00.sqm
2008-07-06 00:43 . 2004-08-04 00:56 1,888,992 --a------ C:\WINDOWS\system32\ati3duag.dll
2008-07-06 00:28 . 2008-07-06 00:28 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-07-06 00:24 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\000001_.tmp
2008-07-05 02:17 . 2008-07-05 02:20 193 --a------ C:\WINDOWS\wininit.ini
2008-07-05 00:03 . 2008-07-04 23:59 691,545 --a------ C:\WINDOWS\unins000.exe
2008-07-05 00:03 . 2008-07-05 00:03 2,537 --a------ C:\WINDOWS\unins000.dat
2008-07-04 23:53 . 2008-07-05 00:11 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-04 23:53 . 2008-07-05 00:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-04 23:17 . 2008-07-04 23:32 <DIR> d-------- C:\Program Files\Pawn 2
2008-07-04 15:25 . 2008-07-04 15:26 49 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-29 12:58 . 2004-08-04 03:07 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-06-29 01:26 . 2008-06-29 01:26 <DIR> d-------- C:\Program Files\SanDisk
2008-06-28 15:11 . 2008-06-28 15:11 <DIR> d-------- C:\Program Files\Robster Productions
2008-06-26 19:43 . 2008-06-26 19:43 <DIR> d-------- C:\Program Files\Analog Devices
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2008-06-26 19:31 . 2004-08-03 22:39 142,464 --a--c--- C:\WINDOWS\system32\dllcache\aec.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2008-06-26 19:31 . 2004-08-03 23:15 82,944 --a--c--- C:\WINDOWS\system32\dllcache\wdmaud.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2008-06-26 19:31 . 2001-08-17 14:00 54,272 --a--c--- C:\WINDOWS\system32\dllcache\swmidi.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a------ C:\WINDOWS\system32\drivers\DMusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 52,864 --a--c--- C:\WINDOWS\system32\dllcache\dmusic.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2008-06-26 19:31 . 2004-08-03 23:07 6,400 --a--c--- C:\WINDOWS\system32\dllcache\splitter.sys
2008-06-26 19:29 . 2001-09-19 14:47 765,952 --a------ C:\WINDOWS\system\crlds3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a--c--- C:\WINDOWS\system32\dllcache\a3d.dll
2008-06-26 19:29 . 2001-09-19 14:47 720,896 --a------ C:\WINDOWS\system32\Audio3d.dll
2008-06-26 19:29 . 2001-09-19 14:32 720,896 --a------ C:\WINDOWS\system32\a3d.dll
2008-06-26 19:21 . 2008-06-26 19:21 <DIR> d-------- C:\Program Files\VIA
2008-06-26 19:21 . 2003-10-31 05:22 77,312 -ra------ C:\WINDOWS\system32\drivers\viasraid.sys
2008-06-26 19:19 . 2003-04-15 10:59 5,824 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-06-26 19:19 . 2008-06-26 19:38 2,881 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-06-26 18:11 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-26 18:06 . 2008-06-26 18:06 <DIR> d-------- C:\Program Files\Common Files\Java
2008-06-26 17:44 . 2008-06-26 17:44 <DIR> d--hs---- C:\found.000
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-06-26 15:12 . 2008-06-26 15:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-06-26 12:11 . 2008-06-26 12:12 <DIR> d-------- C:\Program Files\ScriptCryptor
2008-06-26 00:26 . 2008-07-04 18:21 <DIR> d-------- C:\Program Files\Quick Batch File Compiler
2008-06-26 00:19 . 2008-06-26 00:19 <DIR> d-------- C:\Program Files\SAGEM
2008-06-25 23:46 . 2008-06-25 23:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-06-25 23:45 . 2008-06-24 20:18 211 --a------ C:\boot.ini.comodofirewall
2008-06-25 23:44 . 2008-06-25 23:44 <DIR> d-------- C:\Program Files\Comodo
2008-06-25 21:31 . 2008-07-09 12:20 53 --a------ C:\biosinfo
2008-06-25 21:29 . 2006-02-15 19:15 176,128 --a------ C:\WINDOWS\autoclk.exe
2008-06-25 21:29 . 2008-06-26 00:19 990 --a------ C:\WINDOWS\adiras.ini
2008-06-25 21:22 . 2008-06-26 15:11 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-06-25 21:20 . 2008-06-25 21:20 <DIR> d-------- C:\Program Files\Common Files\ArcSoft
2008-06-25 21:20 . 2003-09-20 00:45 21,248 --a------ C:\WINDOWS\system32\drivers\pfc.sys
2008-06-25 21:19 . 2008-06-25 21:19 <DIR> d-------- C:\Program Files\ArcSoft
2008-06-25 21:19 . 1995-08-01 13:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\WINDOWS\PixArt
2008-06-25 21:18 . 2008-07-02 15:46 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Trust
2008-06-25 21:18 . 2008-06-25 21:18 <DIR> d-------- C:\Program Files\Common Files\PCCamera
2008-06-25 21:18 . 2008-06-26 15:09 <DIR> d-------- C:\Program Files\Common Files\InstallShield
2008-06-25 21:16 . 2008-06-25 21:16 0 --a------ C:\WINDOWS\msicpl.ini
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-06-25 21:07 . 2004-08-04 09:56 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-06-25 21:07 . 2004-08-04 07:58 14,848 --a--c--- C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-06-25 21:07 . 2001-08-17 22:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-06-25 21:05 . 2004-08-04 08:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-06-25 21:05 . 2001-08-17 23:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2008-06-25 19:17 . 2008-06-25 19:30 <DIR> d-------- C:\WINDOWS\vf_hip
2008-06-25 19:17 . 2008-06-25 19:17 32 --a------ C:\WINDOWS\go
2008-06-25 19:13 . 2008-06-25 19:30 <DIR> d-------- C:\Program Files\Hide IP Platinum
2008-06-25 18:39 . 2003-06-19 02:31 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2008-06-25 18:39 . 2008-07-07 00:02 376 --a------ C:\WINDOWS\ODBC.INI
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-06-25 18:37 . 2008-06-25 18:37 <DIR> d-------- C:\Program Files\Common Files\L&H
2008-06-25 18:36 . 2008-06-25 18:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-06-25 18:35 . 2008-06-25 18:37 <DIR> d-------- C:\WINDOWS\SHELLNEW
2008-06-25 18:29 . 2008-07-06 20:44 <DIR> d-------- C:\Program Files\Windows Live
2008-06-25 18:29 . 2008-06-25 18:29 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-06-25 18:28 . 2008-06-25 18:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-25 18:18 . 2008-06-25 18:31 <DIR> d-------- C:\Documents and Settings\pc\Contacts
2008-06-25 18:18 . 2006-09-25 01:11 389,120 --a------ C:\WINDOWS\system32\lameACM.acm
2008-06-25 18:18 . 2007-09-05 02:56 164,352 --a------ C:\WINDOWS\system32\unrar.dll
2008-06-25 18:18 . 2007-09-21 10:52 118,784 --a------ C:\WINDOWS\system32\ac3acm.acm
2008-06-25 18:18 . 2007-10-04 01:03 414 --a------ C:\WINDOWS\system32\lame_acm.xml
2008-06-25 18:17 . 2008-06-25 18:17 <DIR> d-------- C:\Program Files\K-Lite Codec Pack
2008-06-25 18:17 . 2007-09-29 02:07 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-06-25 18:17 . 2007-07-25 23:24 1,559,040 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-06-25 18:17 . 2007-09-29 02:05 739,840 --a------ C:\WINDOWS\system32\divx.dll
2008-06-25 18:17 . 2007-03-10 21:51 282,624 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-06-25 18:17 . 2004-01-26 02:18 217,088 --a------ C:\WINDOWS\system32\yv12vfw.dll
2008-06-25 18:17 . 2007-09-29 02:05 81,920 --a------ C:\WINDOWS\system32\dpl100.dll
2008-06-25 18:17 . 2007-07-30 01:51 7,680 --a------ C:\WINDOWS\system32\ff_vfw.dll
2008-06-25 18:17 . 2007-07-11 02:10 547 --a------ C:\WINDOWS\system32\ff_vfw.dll.manifest
2008-06-25 18:16 . 2008-06-25 18:16 <DIR> d-------- C:\Program Files\Winamp
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-06-25 18:15 . 2008-06-25 18:15 <DIR> d-------- C:\Program Files\Ahead
2008-06-25 18:15 . 2001-07-06 23:41 569,344 --a------ C:\WINDOWS\system32\imagr5.dll
2008-06-25 18:15 . 2001-07-06 21:44 544,768 --a------ C:\WINDOWS\system32\imagx5.dll
2008-06-25 18:15 . 2001-07-07 03:24 283,920 --a------ C:\WINDOWS\system32\ImagXpr5.dll
2008-06-25 18:15 . 2001-07-09 20:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-25 18:15 . 2004-03-04 06:30 125,184 --a------ C:\WINDOWS\system32\drivers\imagesrv.sys
2008-06-25 18:15 . 2000-06-26 20:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-25 18:15 . 2001-06-26 17:15 38,912 --a------ C:\WINDOWS\system32\picn20.dll
2008-06-25 18:15 . 2004-03-04 06:30 5,504 --a------ C:\WINDOWS\system32\drivers\imagedrv.sys
2008-06-25 18:14 . 2008-07-04 22:09 <DIR> d-------- C:\Program Files\The KMPlayer
2008-06-25 18:13 . 2008-06-29 01:26 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-06-25 18:13 . 2008-06-25 18:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-06-25 18:13 . 2008-06-25 18:13 664 --a------ C:\WINDOWS\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-07 22:40 0 ----a-w C:\Program Files\temp01
2008-06-29 00:14 90,112 ----a-w C:\WINDOWS\DUMP30c4.tmp
2008-06-25 22:19 32 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-06-24 18:26 --------- d-----w C:\Program Files\microsoft frontpage
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.

---- Directory of C:\effbot.exe ----



((((((((((((((((((((((((((((( snapshot@2008-07-07_17.16.21.70 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 14:59:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-09 10:19:44 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2007-02-22 21:41:12 304,544 ----a-w C:\WINDOWS\Downloaded Program Files\MessengerStatsPAClient.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:07 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-06-25 18:10 949376]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 20:50 155648]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 03:15 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 04:37 69632]
"Comodo Firewall"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-06-26 12:41 1115728]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-16 16:51 7569408]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-16 16:51 86016]
"BDRegion"="C:\Program Files\Cyberlink\Shared Files\brs.exe" [2007-11-17 04:20 91432]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE" [2004-08-04 03:07 158208]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 07:59 57344 C:\WINDOWS\SOUNDMAN.EXE]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2008-06-26 00:19:28 1205840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=C:\WINDOWS\pss\VIA RAID TOOL.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 2007-10-11 21:06 62760 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 20:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 18:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
--a------ 2007-10-22 12:52 75584 C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-05-13 21:08 1271032 E:\Valve\Steam\Steam.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:\Java\jre1.6.0_06\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-25 16:10 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-04-16 16:51 1519616 C:\WINDOWS\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 05:22]
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\000.fcl [2007-11-03 09:12]
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2007-01-04 22:48]
S2 E4LOADER;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2007-01-04 22:47]

.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2008-07-09 14:19:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\000.fcl"
.
Completion time: 2008-07-09 14:21:26
ComboFix-quarantined-files.txt 2008-07-09 12:20:54
ComboFix2.txt 2008-07-07 20:56:42
ComboFix3.txt 2008-07-07 15:17:09

Pre-Run: 15,118,741,504 bytes free
Post-Run: 15,131,906,048 bytes free

238 --- E O F --- 2008-06-26 13:49:45
Evo doktore..

Dopuna: 09 Jul 2008 14:28

Ne rece mi nista za Start Up??

Dopuna: 09 Jul 2008 21:13

Doco sta za Start Up,a?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ne mogu ti tacno reci sta ti treba, a sta ne. To je pitanje za neku drugu temu, u podforumu windows.

Dopuna: 09 Jul 2008 23:02

Imas li jos tih problema sa korisnickim nalozima?

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Ne,hvala ti puno,znaci idem u podforum windows.

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

offline
  • Tomislav Varagic
  • Pridružio: 06 Maj 2008
  • Poruke: 124
  • Gde živiš: Pirot

Hvala ti Helen 1., spasio si me muka a i para.Ovde za gazenje PC-a traze 20Eur.Hvala jos jednom.Pozzz.

Ko je trenutno na forumu
 

Ukupno su 990 korisnika na forumu :: 25 registrovanih, 5 sakrivenih i 960 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Alibaba1981, Ben Roj, Bickoooo, bokisha253, Darko8, DejanCG, Dimitrije Paunovic, Istman, kunktator, m0nstrum_, mikki jons, milenko crazy north, milos.cbr, MilosKop, nemkea71, Parker, Povratak1912, sap, SR-3m, stegonosa, tubular, VJ, voja64, WerWolf14, Wrangler