problem sa zamrzavanjem i restartom

1

problem sa zamrzavanjem i restartom

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

skoro sam odradio reinstalaciju winXP na particiji C, i do jutros je sve bilo u redu.

u poslednjih pet ili šest sati računar se zamrzavao iz čista mira, a par puta je nešto jako brzo ispisao na plavom ekranu i krenuo u restartovanje.

zatim je tražio da se odradi provera particije C , obrisao je jedan .tmp fajl i podigao xp normalno.

posle desetak minuta rada, ponovo se zamrzao, stojao tako nekih 30 sekundi i nastavio sa radom.

evo izveštaja po upustvu ( radjeno DDS-om)


DDS (Ver_09-07-30.01) - NTFSx86
Run by tamara at 17:05:45,14 on pon 21.09.2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.491 [GMT 2:00]

AV: avast! antivirus 4.8.1351 [VPS 090920-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\PROGRA~1\MICROS~2\Office14\GROOVEMN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft Office\Office14\OfficeSAS\officeSASscheduler.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Microsoft Office\Office14\OfficeSAS\OfficeSAS.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\tamara\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uStart Page = hxxp://www.google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Windows Live pomagac za prijavljivanje: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [EasyTuneVPro] c:\program files\gigabyte\et5pro\ETcall.exe
mRun: [Gainward] c:\program files\vdotool\TBPanel.exe /A
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [GrooveMonitor] c:\progra~1\micros~2\office14\GROOVEMN.EXE
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Version Cue CS2] "c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe"
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe"
mRun: [<NO NAME>]
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office14\officesas\officeSASscheduler.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab
TCP: {F496BBB4-C9DA-4E2B-BD43-01782ADDF1CB} = 212.200.190.166 212.200.191.166
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\tamara\applic~1\mozilla\firefox\profiles\r7q9c9jt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-9-12 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-9-12 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-9-12 138680]
R2 osppsvc;Office Software Protection Platform;c:\windows\system32\OSPPSVC.EXE [2009-4-8 4319136]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-9-12 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-9-12 352920]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2009-9-7 24944]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2009-4-25 33480048]

=============== Created Last 30 ================

2009-09-18 09:16 <DIR> --d----- c:\windows\system32\scripting
2009-09-18 09:16 <DIR> --d----- c:\windows\system32\en
2009-09-18 09:16 <DIR> --d----- c:\windows\system32\bits
2009-09-18 09:16 <DIR> --d----- c:\windows\l2schemas
2009-09-18 09:13 <DIR> --d----- c:\windows\network diagnostic
2009-09-15 21:59 <DIR> --d----- c:\windows\Zuma's Revenge!
2009-09-15 21:59 <DIR> --d----- c:\program files\Zuma's Revenge!
2009-09-15 21:15 <DIR> --dsh--- c:\documents and settings\tamara\IECompatCache
2009-09-15 10:13 <DIR> --d----- c:\docume~1\tamara\applic~1\AVS4YOU
2009-09-15 08:33 <DIR> --dsh--- c:\documents and settings\tamara\PrivacIE
2009-09-14 22:18 <DIR> --dsh--- c:\documents and settings\tamara\IETldCache
2009-09-14 21:49 100,352 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-09-14 21:49 <DIR> --d----- c:\windows\ie8updates
2009-09-14 21:48 55,296 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-14 21:48 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-09-14 21:48 11,067,392 -c------ c:\windows\system32\dllcache\ieframe.dll
2009-09-14 21:48 1,985,536 -c------ c:\windows\system32\dllcache\iertutil.dll
2009-09-14 21:48 594,432 -c------ c:\windows\system32\dllcache\msfeeds.dll
2009-09-14 21:48 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-09-14 21:47 <DIR> -cd-h--- c:\windows\ie8
2009-09-14 10:51 <DIR> --d----- c:\program files\IrfanView
2009-09-14 09:57 397,312 -------- c:\windows\system32\mmcex.dll
2009-09-13 16:17 50 a------- c:\windows\cdplayer.ini
2009-09-11 22:26 68,096 a------- c:\windows\ScUnin.exe
2009-09-11 22:26 12,264 a------- c:\windows\scunin.dat
2009-09-11 22:26 967 a------- c:\windows\ScUnin.pif
2009-09-11 22:26 <DIR> --d----- c:\program files\Starcraft
2009-09-11 21:44 <DIR> --d----- c:\docume~1\tamara\applic~1\AIMP
2009-09-11 21:43 <DIR> --d----- c:\program files\AIMP2
2009-09-10 21:58 152 a------- c:\windows\system32\FOLESVR.DLL
2009-09-10 21:46 0 a------- c:\windows\PlayList.Fpl
2009-09-10 21:45 389,120 a------- c:\windows\system32\ACTSKN43.OCX
2009-09-10 21:45 <DIR> --d----- c:\windows\tmp
2009-09-10 21:45 3,286 a------- c:\windows\FantasyDVD.ini
2009-09-10 21:45 2,417 a------- c:\windows\ShortCutInf.ini
2009-09-10 21:45 544,768 a------- c:\windows\system32\CLVSD.ax
2009-09-10 21:45 45,056 a------- c:\windows\system32\ogg.dll
2009-09-10 21:45 <DIR> --d----- c:\windows\system32\FTCodecs
2009-09-10 21:45 <DIR> --d----- c:\program files\Fantasysoft-Studio
2009-09-10 21:35 <DIR> --d----- c:\program files\uTorrent
2009-09-10 21:34 <DIR> --d----- c:\docume~1\tamara\applic~1\uTorrent
2009-09-10 21:09 23 a------- c:\windows\ZDPLUSSEARCH.INI
2009-09-10 21:08 <DIR> --d----- c:\docume~1\tamara\applic~1\Zeon
2009-09-10 21:08 294 a------- c:\windows\dorp.dat
2009-09-10 21:07 <DIR> --d----- c:\program files\Nitro PDF
2009-09-10 21:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Zeon
2009-09-10 16:45 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-09-10 16:44 <DIR> --d----- c:\windows\system32\LogFiles
2009-09-10 16:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-09-10 16:41 <DIR> --d----- c:\program files\common files\AVSMedia
2009-09-10 16:41 221,215 a------- c:\windows\system32\divxdec.ax
2009-09-10 16:41 82,944 a------- c:\windows\system32\vct3216.acm
2009-09-10 16:41 81,920 a------- c:\windows\system32\AC3ACM.acm
2009-09-10 16:41 53,248 a------- c:\windows\system32\xvid.ax
2009-09-10 16:41 38,912 a------- c:\windows\system32\alf2cd.acm
2009-09-10 16:41 13,239 a------- c:\windows\system32\Scg726.acm
2009-09-10 16:40 1,700,352 a------- c:\windows\system32\GdiPlus.dll
2009-09-10 16:40 974,848 a------- c:\windows\system32\mfc70.dll
2009-09-10 16:40 638,976 a------- c:\windows\system32\divx.dll
2009-09-10 16:40 524,288 a------- c:\windows\system32\xvidcore.dll
2009-09-10 16:40 487,424 a------- c:\windows\system32\msvcp70.dll
2009-09-10 16:40 413,760 a------- c:\windows\system32\mpg4c32.dll
2009-09-10 16:40 344,064 a------- c:\windows\system32\msvcr70.dll
2009-09-10 16:40 261,632 a------- c:\windows\system32\mcdvd_32.dll
2009-09-10 16:40 156,910 a------- c:\windows\WMSysPr8.prx
2009-09-10 16:40 139,264 a------- c:\windows\system32\xvidvfw.dll
2009-09-10 16:40 24,576 a------- c:\windows\system32\msxml3a.dll
2009-09-10 16:40 <DIR> --d----- c:\program files\AVS4YOU
2009-09-10 16:28 <DIR> --d----- c:\program files\common files\xing shared
2009-09-10 16:28 <DIR> --d----- c:\program files\common files\Real
2009-09-10 15:32 <DIR> --d----- c:\program files\The KMPlayer
2009-09-10 11:04 2,516 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-09-10 11:02 <DIR> --d----- c:\program files\common files\Corel
2009-09-10 11:00 <DIR> --d----- c:\program files\Corel
2009-09-10 10:05 3,244 a------- c:\windows\system32\wbem\Outlook_01ca31ed68a6c310.mof
2009-09-10 08:47 208,744 a------- c:\windows\system32\muweb.dll
2009-09-10 08:47 268,648 a------- c:\windows\system32\mucltui.dll
2009-09-10 08:47 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-09-09 11:37 <DIR> --d----- c:\windows\Downloaded Installations
2009-09-09 11:33 <DIR> --d----- c:\docume~1\tamara\applic~1\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-09-09 11:33 <DIR> --d----- c:\windows\system32\IOSUBSYS
2009-09-08 23:02 <DIR> --d----- c:\program files\IVT Corporation
2009-09-08 23:02 32 a------- c:\windows\0
2009-09-08 23:02 0 a------- c:\windows\system32\0
2009-09-08 23:01 151,552 a------- c:\windows\system32\irftp.exe
2009-09-08 23:01 28,160 a------- c:\windows\system32\irmon.dll
2009-09-08 23:01 8,192 a------- c:\windows\system32\wshirda.dll
2009-09-08 22:04 <DIR> --d----- c:\documents and settings\tamara\Tracing
2009-09-08 21:31 <DIR> --d----- c:\program files\Microsoft
2009-09-08 21:31 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-09-08 21:18 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-08 21:06 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-09-08 21:05 730,112 -c------ c:\windows\system32\dllcache\lsasrv.dll
2009-09-08 21:05 714,752 -c------ c:\windows\system32\dllcache\ntdll.dll
2009-09-08 21:05 617,472 -c------ c:\windows\system32\dllcache\advapi32.dll
2009-09-08 21:05 473,600 -c------ c:\windows\system32\dllcache\fastprox.dll
2009-09-08 21:05 453,120 -c------ c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-08 21:05 401,408 -c------ c:\windows\system32\dllcache\rpcss.dll
2009-09-08 21:05 284,160 -c------ c:\windows\system32\dllcache\pdh.dll
2009-09-08 21:05 227,840 -c------ c:\windows\system32\dllcache\wmiprvse.exe
2009-09-08 21:05 110,592 -c------ c:\windows\system32\dllcache\services.exe
2009-09-08 21:05 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-08 21:05 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-08 21:05 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-08 21:04 153,088 -c------ c:\windows\system32\dllcache\triedit.dll
2009-09-08 21:00 128,512 -c------ c:\windows\system32\dllcache\dhtmled.ocx
2009-09-08 20:58 203,136 -c------ c:\windows\system32\dllcache\rmcast.sys
2009-09-08 20:58 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-09-08 20:58 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-09-08 20:58 331,776 -c------ c:\windows\system32\dllcache\msadce.dll
2009-09-08 20:58 1,315,328 -c------ c:\windows\system32\dllcache\msoe.dll
2009-09-08 20:57 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-09-08 20:57 2,066,432 -c------ c:\windows\system32\dllcache\mstscax.dll
2009-09-08 20:57 247,326 -c------ c:\windows\system32\dllcache\strmdll.dll
2009-09-08 20:56 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-09-08 20:55 1,203,922 -c------ c:\windows\system32\dllcache\sysmain.sdb
2009-09-08 20:55 215,552 -c------ c:\windows\system32\dllcache\wordpad.exe
2009-09-08 20:55 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-09-07 22:13 16,384 a------- c:\windows\system32\FileOps.exe
2009-09-07 22:13 <DIR> --d----- c:\windows\system32\Adobe
2009-09-07 22:10 <DIR> --d----- c:\program files\common files\Adobe Systems Shared
2009-09-07 21:20 116 a------- c:\windows\NeroDigital.ini
2009-09-07 19:10 <DIR> --d----- c:\windows\system32\AGEIA
2009-09-07 19:10 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-09-07 19:10 201,050 a------- c:\windows\system32\nvapps.nvb
2009-09-07 19:10 <DIR> --d----- C:\NVIDIA
2009-09-07 17:18 <DIR> --d----- c:\documents and settings\all users\Microsoft
2009-09-07 17:16 <DIR> --d----- c:\windows\SHELLNEW
2009-09-07 17:16 <DIR> --d----- c:\program files\Microsoft Analysis Services
2009-09-07 17:14 <DIR> --d----- c:\program files\MSXML 6.0
2009-09-07 17:08 <DIR> --d----- c:\program files\MSXML 4.0
2009-09-07 15:20 <DIR> --d----- c:\program files\CCleaner
2009-09-07 14:39 86,094 a------- c:\windows\system32\ImageDrive.cpl
2009-09-07 12:23 656 a------- c:\windows\WINCMD.INI
2009-09-07 12:19 125,184 -------- c:\windows\system32\drivers\imagesrv.sys
2009-09-07 12:19 5,504 -------- c:\windows\system32\drivers\imagedrv.sys
2009-09-07 12:19 106,496 a------- c:\windows\system32\TwnLib20.dll
2009-09-07 12:19 1,568,768 -------- c:\windows\system32\ImagX7.dll
2009-09-07 12:19 476,320 -------- c:\windows\system32\ImagXpr7.dll
2009-09-07 12:19 471,040 -------- c:\windows\system32\ImagXRA7.dll
2009-09-07 12:19 262,144 -------- c:\windows\system32\ImagXR7.dll
2009-09-07 12:19 155,648 a------- c:\windows\system32\NeroCheck.exe
2009-09-07 11:46 <DIR> --d----- c:\windows\system32\PreInstall
2009-09-07 11:46 <DIR> --d-h--- c:\windows\$hf_mig$
2009-09-07 11:34 193,207 a------- c:\windows\system32\nvapps.xml
2009-09-07 11:34 453,152 a------- c:\windows\system32\nvudisp.exe
2009-09-07 11:34 18,394 a------- c:\windows\system32\nvdisp.nvu
2009-09-07 11:34 <DIR> --d----- c:\windows\nview
2009-09-07 11:25 <DIR> --d----- c:\docume~1\tamara\applic~1\GetRightToGo
2009-09-07 11:12 <DIR> --d----- c:\windows\system32\wbem\AutoRecover
2009-09-07 10:35 <DIR> --d----- c:\windows\ServicePackFiles
2009-09-07 10:34 2,897,920 -------- c:\windows\system32\xpsp2res.dll
2009-09-07 10:34 19,528 a------- c:\windows\002252_.tmp
2009-09-07 10:33 <DIR> --d----- c:\windows\EHome
2009-09-07 10:29 <DIR> --d----- c:\program files\PCPitstop
2009-09-07 10:29 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PCPitstop
2009-09-07 10:16 13,696 a------- c:\windows\system32\wpa.bak
2009-09-07 10:13 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-09-07 08:26 213,528 a------- c:\windows\system32\wuaucpl.cpl
2009-09-07 08:26 183,296 a------- c:\windows\system32\wuaueng1.dll
2009-09-07 08:26 165,888 a------- c:\windows\system32\wuauclt1.exe
2009-09-07 08:25 <DIR> --dsh--- c:\documents and settings\tamara\UserData
2009-09-07 06:43 558 a------- c:\windows\DFC.INI
2009-09-07 06:41 12,256 a------- c:\windows\system32\drivers\TBPanel.sys
2009-09-07 06:41 <DIR> --d----- c:\program files\VDOTool
2009-09-07 06:40 24,944 a------- c:\windows\system32\drivers\GVTDrv.sys
2009-09-07 06:40 4 a------- c:\windows\system32\GVTunner.ref
2009-09-07 06:40 40,136 a------- c:\windows\system32\drivers\ET5Drv.sys
2009-09-07 06:38 327,168 a------- c:\windows\IsUninst.exe
2009-09-07 06:38 <DIR> --d----- c:\program files\Gigabyte
2009-09-07 02:24 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-09-07 02:24 57,600 a------- c:\windows\system32\drivers\redbook.sys
2009-09-07 02:23 <DIR> --d----- c:\program files\common files\ODBC
2009-09-07 02:23 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-09-07 02:22 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-09-07 02:22 390,168 ac------ c:\windows\system32\dllcache\WFC.CAT
2009-09-07 02:21 261 a------- c:\windows\system32\$winnt$.inf
2009-09-07 00:37 <DIR> --d----- c:\program files\Realtek
2009-09-07 00:29 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-09-07 00:28 <DIR> --d----- c:\program files\common files\MSSoap
2009-09-07 00:27 <DIR> --d-h--- c:\program files\WindowsUpdate
2009-09-07 00:27 <DIR> --d----- c:\program files\Online Services
2009-09-07 00:27 <DIR> --d----- c:\program files\Messenger
2009-09-07 00:27 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-09-07 00:26 <DIR> --d----- c:\program files\Windows NT

==================== Find3M ====================

2009-09-18 09:17 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-09-10 16:28 499,712 a------- c:\windows\system32\msvcp71.dll
2009-09-10 16:28 348,160 a------- c:\windows\system32\msvcr71.dll
2009-09-07 06:36 15,600 a------- c:\windows\gdrv.sys
2009-09-07 00:37 315,392 a------- c:\windows\HideWin.exe
2009-09-07 00:29 558,142 a------- c:\windows\java\packages\M2TND7BP.ZIP
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\OBDVB1BZ.DAT
2009-09-07 00:29 155,995 a------- c:\windows\java\packages\AU9JBTVX.ZIP
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\6ZHNTVBP.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\ZZ3VP7RD.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\SJTFFFVH.DAT
2009-09-07 00:29 2,678 a------- c:\windows\java\packages\data\EBV3R579.DAT
2009-09-07 00:27 21,640 a------- c:\windows\system32\emptyregdb.dat
2009-08-05 11:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-29 06:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 06:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-17 21:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-13 23:43 286,208 -------- c:\windows\system32\wmpdxm.dll
2009-07-03 19:09 915,456 a------- c:\windows\system32\wininet.dll
2009-06-25 10:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 10:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 10:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 10:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 10:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 10:25 54,272 a------- c:\windows\system32\wdigest.dll

============= FINISH: 17:05:57,20 ===============

https://www.mycity.rs/must-login.png


zbunjen sam sasvim. ne sećam se da sam uradio ništa loše u poslednjih 24 sata..

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Pozdrav.


Nisi dobro ispratio uputstvo za Gmer.

Pročitaj ponovo uputstvo vezano za Gmer i postavi logove koji se navode u uputstvu.

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

ostao sam dužan ostatak rezultata skeniranja..

evo ih :
https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

nadam se da je sad ok

u medjuvremenu je došlo čak i do toga da računar ne mogu uopšte da ugasim na neki normalan način :-/

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

ok, uradio, prijavio je brisanje 2 fajla, ali nisam stigao da pročitam njihove nazive..

evo izveštaja:

ComboFix 09-09-21.03 - tamara 22.09.2009 16:24.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.421 [GMT 2:00]
Running from: c:\documents and settings\tamara\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090921-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Alcmtr.exe
c:\windows\system32\FOLESVR.DLL

.
((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.

2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\scripting
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\en
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\system32\bits
2009-09-18 07:16 . 2009-09-18 07:16 -------- d-----w- c:\windows\l2schemas
2009-09-15 20:00 . 2009-09-21 11:53 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-15 19:59 . 2009-09-15 19:59 -------- d-----w- c:\windows\Zuma's Revenge!
2009-09-15 19:59 . 2009-09-15 20:08 -------- d-----w- c:\program files\Zuma's Revenge!
2009-09-15 19:15 . 2009-09-15 19:15 -------- d-sh--w- c:\documents and settings\tamara\IECompatCache
2009-09-15 08:13 . 2009-09-15 08:13 -------- d-----w- c:\documents and settings\tamara\Application Data\AVS4YOU
2009-09-15 06:33 . 2009-09-15 06:33 -------- d-sh--w- c:\documents and settings\tamara\PrivacIE
2009-09-14 20:18 . 2009-09-14 20:18 -------- d-sh--w- c:\documents and settings\tamara\IETldCache
2009-09-14 19:49 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-14 19:49 . 2009-09-15 13:42 -------- d-----w- c:\windows\ie8updates
2009-09-14 19:48 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-14 19:48 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-14 19:48 . 2009-07-19 16:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-09-14 19:48 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-14 19:48 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-14 19:48 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-14 19:47 . 2009-09-14 19:48 -------- dc-h--w- c:\windows\ie8
2009-09-14 08:51 . 2009-09-14 08:51 -------- d-----w- c:\program files\IrfanView
2009-09-14 07:57 . 2008-04-14 00:12 33792 ------w- c:\windows\system32\mmcperf.exe
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\program files\QuickTime
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-12 20:12 . 2009-09-12 20:12 -------- d-----w- c:\program files\Common Files\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\program files\Apple Software Update
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-12 20:11 . 2009-09-12 20:11 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Apple Computer
2009-09-11 22:10 . 2009-08-17 16:04 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-09-11 22:10 . 2009-08-17 16:04 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-09-11 22:10 . 2009-08-17 16:03 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-09-11 22:10 . 2009-08-17 16:02 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-09-11 22:10 . 2009-08-17 16:06 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-09-11 22:10 . 2009-08-17 16:06 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-09-11 22:10 . 2009-08-17 16:05 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-09-11 22:10 . 2009-08-17 16:05 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-09-11 22:10 . 2009-08-17 16:10 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-09-11 22:10 . 2009-09-11 22:10 -------- d-----w- c:\program files\Alwil Software
2009-09-11 20:26 . 2009-09-11 20:26 967 ----a-w- c:\windows\ScUnin.pif
2009-09-11 20:26 . 2009-09-11 20:26 68096 ----a-w- c:\windows\ScUnin.exe
2009-09-11 20:26 . 2009-09-11 20:26 12264 ----a-w- c:\windows\scunin.dat
2009-09-11 20:26 . 2009-09-12 07:22 -------- d-----w- c:\program files\Starcraft
2009-09-11 19:44 . 2009-09-18 21:32 -------- d-----w- c:\documents and settings\tamara\Application Data\AIMP
2009-09-11 19:43 . 2009-09-11 19:44 -------- d-----w- c:\program files\AIMP2
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\windows\tmp
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\windows\system32\FTCodecs
2009-09-10 19:45 . 2003-03-25 03:49 45056 ----a-w- c:\windows\system32\ogg.dll
2009-09-10 19:45 . 2009-09-10 19:45 -------- d-----w- c:\program files\Fantasysoft-Studio
2009-09-10 19:35 . 2009-09-10 19:35 -------- d-----w- c:\program files\uTorrent
2009-09-10 19:34 . 2009-09-17 05:50 -------- d-----w- c:\documents and settings\tamara\Application Data\uTorrent
2009-09-10 19:08 . 2009-09-10 19:08 -------- d-----w- c:\documents and settings\tamara\Application Data\Zeon
2009-09-10 19:08 . 2009-09-10 19:08 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Zeon
2009-09-10 19:08 . 2009-09-10 19:14 294 ----a-w- c:\windows\dorp.dat
2009-09-10 19:07 . 2009-09-10 19:07 -------- d-----w- c:\program files\Nitro PDF
2009-09-10 19:07 . 2009-09-10 19:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Zeon
2009-09-10 14:45 . 2009-09-10 14:45 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-10 14:44 . 2009-09-10 14:44 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-09-10 14:44 . 2009-09-10 14:44 -------- d-----w- c:\windows\system32\LogFiles
2009-09-10 14:41 . 2009-09-10 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-09-10 14:41 . 2009-09-10 14:53 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-09-10 14:40 . 2009-09-10 14:53 -------- d-----w- c:\program files\AVS4YOU
2009-09-10 14:40 . 2007-09-27 12:22 638976 ----a-w- c:\windows\system32\divx.dll
2009-09-10 14:40 . 2007-09-27 12:22 524288 ----a-w- c:\windows\system32\xvidcore.dll
2009-09-10 14:40 . 2007-09-27 12:22 413760 ----a-w- c:\windows\system32\mpg4c32.dll
2009-09-10 14:40 . 2007-09-27 12:22 261632 ----a-w- c:\windows\system32\mcdvd_32.dll
2009-09-10 14:40 . 2007-09-27 12:22 139264 ----a-w- c:\windows\system32\xvidvfw.dll
2009-09-10 14:40 . 2003-05-21 21:50 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2009-09-10 14:40 . 2003-05-21 10:50 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-09-10 14:40 . 2002-01-05 13:48 974848 ----a-w- c:\windows\system32\mfc70.dll
2009-09-10 14:40 . 2002-01-05 12:40 487424 ----a-w- c:\windows\system32\msvcp70.dll
2009-09-10 14:40 . 2002-01-05 00:37 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Common Files\xing shared
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Common Files\Real
2009-09-10 14:28 . 2009-09-10 14:28 -------- d-----w- c:\program files\Real
2009-09-10 13:32 . 2009-09-10 13:35 -------- d-----w- c:\program files\The KMPlayer
2009-09-10 12:41 . 2009-09-10 12:41 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\GHISLER
2009-09-10 09:04 . 2009-09-10 09:09 2516 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-09-10 09:04 . 2009-09-10 09:04 -------- d-----w- c:\documents and settings\tamara\Application Data\Corel
2009-09-10 09:02 . 2009-09-10 09:02 -------- d-----w- c:\program files\Common Files\Corel
2009-09-10 09:00 . 2009-09-10 09:02 -------- d-----w- c:\program files\Corel
2009-09-10 06:47 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-09-10 06:47 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-09-09 09:37 . 2009-09-09 09:37 -------- d-----w- c:\windows\Downloaded Installations
2009-09-09 09:33 . 2009-09-09 09:33 -------- d-----w- c:\documents and settings\tamara\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-09-09 09:33 . 2009-09-15 07:53 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Google
2009-09-09 09:33 . 2009-09-09 09:33 -------- d-----w- c:\windows\system32\IOSUBSYS
2009-09-09 09:33 . 2009-09-15 07:53 -------- d-----w- c:\program files\Google
2009-09-09 09:28 . 2009-09-09 09:28 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-09-09 09:24 . 2009-09-11 02:14 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-09-09 09:21 . 2009-09-14 09:12 -------- d-----w- c:\documents and settings\tamara\Local Settings\Application Data\Adobe
2009-09-08 21:03 . 2009-09-08 21:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Bluetooth
2009-09-08 21:02 . 2009-09-08 21:02 -------- d-----w- c:\program files\IVT Corporation
2009-09-08 21:01 . 2008-04-14 00:12 151552 ----a-w- c:\windows\system32\irftp.exe
2009-09-08 21:01 . 2008-04-14 00:12 8192 ----a-w- c:\windows\system32\wshirda.dll
2009-09-08 21:01 . 2008-04-14 00:11 28160 ----a-w- c:\windows\system32\irmon.dll
2009-09-08 20:04 . 2009-09-22 11:25 -------- d-----w- c:\documents and settings\tamara\Tracing
2009-09-08 19:31 . 2009-09-08 19:31 -------- d-----w- c:\program files\Microsoft
2009-09-08 19:31 . 2009-09-08 19:31 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-08 19:18 . 2009-09-08 19:18 -------- d-----w- c:\program files\Common Files\Windows Live
2009-09-08 19:14 . 2009-09-08 19:31 -------- d-----w- c:\program files\Windows Live
2009-09-08 19:06 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-08 19:05 . 2009-06-25 08:25 730112 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-09-08 19:05 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-09-08 19:05 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-09-08 19:05 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-09-08 19:05 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-09-08 19:05 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-09-08 19:05 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-09-08 19:05 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-09-08 19:05 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-09-08 19:05 . 2009-02-06 11:08 2189056 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-08 19:05 . 2009-02-06 11:06 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-08 19:05 . 2009-02-06 10:32 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-08 19:04 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-08 18:58 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-09-08 18:58 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-08 18:58 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-09-08 18:58 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-09-08 18:58 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-09-08 18:57 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-09-08 18:57 . 2009-06-10 07:19 2066432 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-09-08 18:57 . 2008-10-03 10:02 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2009-09-08 18:56 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-09-08 18:55 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 13:25 . 2009-09-22 13:25 -------- d-----w- c:\program files\ESET
2009-09-18 12:21 . 2009-09-18 12:21 -------- d-----w- c:\documents and settings\tamara\Application Data\Media Player Classic
2009-09-10 14:28 . 2003-03-18 18:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-09-10 14:28 . 2003-02-21 02:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-07 19:58 . 2009-09-06 22:37 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-07 04:38 . 2009-09-06 22:37 -------- d-----w- c:\program files\Common Files\InstallShield
2009-09-07 04:36 . 2009-09-06 22:35 15600 ----a-w- c:\windows\gdrv.sys
2009-09-06 22:40 . 2009-09-06 22:37 -------- d-----w- c:\program files\Realtek
2009-09-06 22:39 . 2009-09-06 22:39 -------- d-----w- c:\documents and settings\tamara\Application Data\InstallShield
2009-09-06 22:37 . 2009-09-06 22:37 315392 ----a-w- c:\windows\HideWin.exe
2009-09-06 22:35 . 2009-09-06 22:35 -------- d-----w- c:\program files\Intel
2009-09-06 22:30 . 2009-09-06 22:30 -------- d-----w- c:\program files\microsoft frontpage
2009-09-06 22:27 . 2009-09-06 22:27 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-05 09:01 . 2009-09-07 04:42 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2002-08-29 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2002-08-29 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:01 . 2002-08-29 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2009-09-07 08:36 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2002-08-29 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2002-08-29 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2002-08-29 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2002-08-29 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2002-08-29 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2002-08-29 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2002-08-29 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
2009-04-08 14:05 739688 ----a-w- c:\progra~1\MICROS~2\Office14\URLREDIR.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EasyTuneVPro"="c:\program files\Gigabyte\ET5Pro\ETcall.exe" [2007-07-26 20480]
"Gainward"="c:\program files\VDOTool\TBPanel.exe" [2007-11-01 2165272]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"GrooveMonitor"="c:\progra~1\MICROS~2\Office14\GROOVEMN.EXE" [2009-04-25 875392]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-10 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-07-05 16380416]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-09-17 1657376]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-9-14 25214]
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OfficeSAS.lnk - c:\program files\Microsoft Office\Office14\OfficeSAS\officeSASscheduler.exe [2009-4-8 122264]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\INSTALACIJE\\mirc\\mirc.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [12.9.2009 0:10 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [12.9.2009 0:10 20560]
R2 osppsvc;Office Software Protection Platform;c:\windows\system32\OSPPSVC.EXE [8.4.2009 15:37 4319136]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [25.4.2009 18:18 33480048]
SUnknown GVTDrv;GVTDrv; [x]

--- Other Services/Drivers In Memory ---

*Deregistered* - pxtdapob

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=%s
IE: {{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
TCP: {F496BBB4-C9DA-4E2B-BD43-01782ADDF1CB} = 212.200.191.166 212.200.190.166
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\tamara\Application Data\Mozilla\Firefox\Profiles\r7q9c9jt.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-22 16:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-22 16:31
ComboFix-quarantined-files.txt 2009-09-22 14:31

Pre-Run: 33.754.243.072 bytes free
Post-Run: 33.718.435.840 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

284 --- E O F --- 2009-09-19 05:58

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Pronađi C:\Qoobox\Quarantine

Zapakuj (zip) i izvrši upload preko ovog linka...

http://www.mycity.rs/ambulanta-upload.php


Javi kad odradiš.

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

evo zapakovanog fajla:


https://www.mycity.rs/must-login.png

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Otvoriti Notepad i iskopirati sledeci tekst:


DEQUARANTINE::
C:\Qoobox\Quarantine\C\windows\Alcmtr.exe.vir
QUIT::



Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.



Preuzmi ovaj reg file na desktop i pokreni ga dvoklikom na ikonu.

Kada se pojavi message box klikni Yes pa Ok

https://www.mycity.rs/must-login.png



Javi kakvo je stanje...

offline
  • Pridružio: 07 Maj 2005
  • Poruke: 865
  • Gde živiš: my city, preko puta tri kaputa

Napisano: 23 Sep 2009 9:38

evo fajla...

https://www.mycity.rs/must-login.png

uneo sam i ovaj "regfix", ali se računar restartovao nekih 7, 8 minuta

i pri startu traži da se proveri particija C ( konzistentnost)

meni sve ovo miriše na ponovni reinstal :-(

mozilla mi jako sporo radi..

pretpostavljam da je XP oštećen

čekam dalje uputstvo :-)

Dopuna: 23 Sep 2009 12:55

posle par restarta opet je sve valjda normalno, restartuje se normalno, ne traži više ni proveru particije C

valjda je ok...

offline
  • Pridružio: 04 Jan 2009
  • Poruke: 2168

Što se tiče malware_a, sistem je čist tako da problem nije vezan za infekciju.

Ovo zadnje što si napisao te nisam baš razumeo, da li se i dalje sam restartuje?

Ako se i dalje sam restartuje otvori temu u Windows potforumu i opiši problem pa će neko pomoći.


Isprati još sledeće...


Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

combofix /u

Primeti da postoji razmak između "ComboFix" i "/u".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

Ko je trenutno na forumu
 

Ukupno su 1149 korisnika na forumu :: 54 registrovanih, 14 sakrivenih i 1081 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 8u47, Acivi, airsuba, aleksmajstor, amaterSRB, armor, avijacija, bestguarder, black sabah, Bobrock1, bokisha253, Boris90, ccoogg123, comi_pfc, dankisha, Darko8, Denaya, dragoljub11987, gmlale, kolle.the.kid, kubura91, kunktator, kybonacci, Leonov, mercedesamg, Mercury, Milan A. Nikolic, milenko crazy north, milos.cbr, milutin134, mrvica78, nenad81, Neutral-M, Niko Bitan, Parker, pein, Posmatrac77OKB, Primus17, procesor, Recce, RED4G-304, shlauf, Sirius, skvara, Smajser, ss10, stegonosa, Stoilkovic, TBF1D, vlahale, yrraf, zdrebac, ZetaMan, Žrnov