[ vtl_design @ 09.04.2009. 18:43 ] @
Pozdrav,
Imam skoro nerjesiv problem preciznije nejasan. Na XP-u mi kada otvaram C:\Documents and Settings i jos (i vecinu foldera unutar njega) jaaakoo tesko otvara, zastopa nekoliko sekundi i tek onda ga otvori. Ovo vazi i za neke foldere unutar C:\Documents and Settings kao sto su Aplication Data, Temp i slicno. Desava se samo na C:\Documents and Settings i fakat ne znam sta je problem sve probao. Jako je iritantno kada trebam nesto da pogledam u njemu i slicno. Najvise me muci to sto ne kontam sta je problem ne znam odakle da pocnem rjesavat pa ako neko ima ideju neka kaze.
[ 93 Stefan @ 09.04.2009. 20:20 ] @
To se i meni dešavalo, samo drugi folder. Samo se rešilo, ali mislim tako što se preko one praznine na HDD-u koja je nastala kad sam ko zna kako izbrisao nešto snimilo nešto drugo (koliko se sećam igrica). Ako je to tako, onda možda nešto što će očistiti prazan prostor na HDD-u možda pomogne. Ja sam čak probavao i ovo, sav sadržaj sam iskopirao na drugo mesto, obrisao original, stavio tu kopije i opet je bilo isto. Neka greška je u tom folderu, ne Win-u ili tako nečemu, možda pomogne chkdsk, ne znam da li sam probao sa time nešto da uradim.
[ vtl_design @ 10.04.2009. 14:03 ] @
Aha... Probao sam chkdsk nista. i dalje ne znam kako da rjesim
[ Slobodan Miskovic @ 10.04.2009. 14:13 ] @
Defragmentuj HDD.
[ vtl_design @ 10.04.2009. 16:58 ] @
Probao opet nista :-(
[ calexx @ 10.04.2009. 17:14 ] @
Da li u problematičnim folderima imaš slike, filmove i slične multimedijalne fajlove? Da li se to dešava kada foldere otvaraš explorerom? Šta se dešava kada te foldere otvaraš recimo Total Commanderom, ako ga koristiš?
[ Zoran Rodic @ 11.04.2009. 10:26 ] @
Instaliraj Total commander, uključi opciju da vidiš Hidden files pa pogledaj da li se tamo nalazi i nešto što tamo ne pripada.
Obriši sadržaj Temp direktorijuma svakako, i isprazni recycle bin

CCleaner bi mogao biti rešenje

[ vtl_design @ 11.04.2009. 10:37 ] @
Slike imam u folderu My prictures koji se nalazi u My Documents a on opet u ovom problematicnom folderu. Problem nastaje SAMO KADA PRISTUPAM PREKO EXPLORERA. Ako napravim shortcut na njega, nema problema ulazi odmah. Dakle, nemam nikakve druge multimedijalne sadrzaje, nema nikakvih sumnjivih hidden fajlova, temp davno ispraznjen i ostalo. Problem nastaje cak i ako samo misem jednom kliknem na fodler C:\Documents and Settings (bez double klika) ili recimo ako zelim desni klik na C:Documents and Settings na odem na properties ili slicno. Dakle, cim taknem C:Documents and Settings odmah se javlja problem (isto vazi sa neke foldere unutar njega). Sa ovim CCleanrom sam sve obrisao sto sam i prije radio sa drugim alatima, ali opet nista....
[ Dashkes @ 12.04.2009. 08:03 ] @
Da li biste mogli da napravite log HijackThis-a?
[ vtl_design @ 12.04.2009. 14:17 ] @
HijackThis-a????
[ Dashkes @ 12.04.2009. 14:37 ] @
http://www.elitesecurity.org/t339424-0#2246714

;)
[ vtl_design @ 12.04.2009. 19:02 ] @
Uradio sam. Al ovo nema veze sa tim mislim da je problem nesta drugo u ovom logu nema nista sumnjivo.

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\crypserv.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
d:\Program Files\PaperCut Print Logger\pcpl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\LVComsX.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe
[ Nemanja Živanović @ 12.04.2009. 19:46 ] @
Pozdra vtl_design,
Ovo nije kompletan log, ovo su samo tekuci procesi. Iskopiraj ceo log, da vidimo da li problem nastaje zbog prisustva malware-a.
[ vtl_design @ 12.04.2009. 19:58 ] @
Evo kompletan log. Nema nikakvog malware-a sve je regularno.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:54:02, on 12.4.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\crypserv.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
d:\Program Files\PaperCut Print Logger\pcpl.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\LVComsX.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 196.203.190.226:80
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Firefox] "C:\Program Files\Mozilla Firefox\firefox.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - d:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Append to existing PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://L:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {50F85690-3FB1-4AB4-AB0C-159227CC6BB2} - d:\Program Files\IE AutoFill\ieautofill.dll (file missing)
O9 - Extra 'Tools' menuitem: IE AutoFill - {50F85690-3FB1-4AB4-AB0C-159227CC6BB2} - d:\Program Files\IE AutoFill\ieautofill.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - D:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.co...t/wuweb_site.cab?1192743681468
O23 - Service: Acunetix WVS Scheduler v5 (AcuWVSSchedulerv5) - Unknown owner - d:\Program Files\Acunetix\Web Vulnerability Scanner 5\WVSScheduler.exe (file missing)
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mysql - Unknown owner - d:\AppServ\MySQL\bin\mysqld-nt.exe
O23 - Service: NILM License manager - Macrovision Corporation - D:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: NI Service Locator (niSvcLoc) - National Instruments - C:\windows\system32\niSvcLoc.exe
O23 - Service: PaperCut Print Logger (PCPrintLogger) - PaperCut Software International Pty Ltd - d:\Program Files\PaperCut Print Logger\pcpl.exe
--
End of file - 11383 bytes
[ 93 Stefan @ 12.04.2009. 20:18 ] @
Samo da vam kažem. Imao sam potpuno iste simptome kao on, i znam da mi komp tada nije bio zaražen ni sa čim. To se desio samo neki bag u Win-u. Ja nisam uspeo ovim običnim stvarima koje svi znamo i koje stalno predlažete to da rešim. Napisao sam gore kako mi se rešilo probaj nešto slično da uradiš. Da dodaš neke stvari koje su velike nekoliko giga u to i vidi da li će biti isto, posle ih slobodno vrati. Uzmi nešto što briše free space sa HDD-a, možda pomogne.
[ Dashkes @ 12.04.2009. 20:19 ] @
Fix
O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O9 - Extra button: (no name) - {50F85690-3FB1-4AB4-AB0C-159227CC6BB2} - d:\Program Files\IE AutoFill\ieautofill.dll (file missing)
O9 - Extra 'Tools' menuitem: IE AutoFill - {50F85690-3FB1-4AB4-AB0C-159227CC6BB2} - d:\Program Files\IE AutoFill\ieautofill.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
[ vtl_design @ 12.04.2009. 21:50 ] @
To sam i fixirao cim se past-ovo ovaj log pa sam ga detaljno pregledo. I nista. A ovi bugovi uopce i nisu u mom problematicnom folderu. Slozio bih se sa stefanom da ovo nije neki malware ili slicno ali je jako cudno ili to pokazuje koliki je krs Windows? Ne znam sta da radim.