Log ComboFix za proveru

1

Log ComboFix za proveru

offline
  • Pridružio: 24 Jan 2012
  • Poruke: 25

ComboFix 12-01-23.02 - Smaka 01/24/2012 13:51:15.1.1 - x86
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.895.368 [GMT 1:00]
Running from: c:\users\Smaka\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ji82l
c:\programdata\ji82l\PCGWIN32.LI5
c:\users\Guest\Opera_1160_int_Setup.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-12-24 to 2012-01-24 )))))))))))))))))))))))))))))))
.
.
2012-01-24 12:58 . 2012-01-24 12:58 -------- d-----w- c:\users\Smaka\AppData\Local\temp
2012-01-24 08:13 . 2012-01-24 09:34 -------- d-----w- c:\users\Administrator
2012-01-23 15:16 . 2012-01-23 15:16 -------- d-----w- c:\users\Smaka\AppData\Local\PackageAware
2012-01-23 13:32 . 2012-01-23 13:32 -------- d--h--w- c:\windows\msdownld.tmp
2012-01-23 12:37 . 2012-01-23 12:37 -------- d-----w- c:\users\Smaka\AppData\Roaming\Anvsoft
2012-01-23 12:36 . 2012-01-23 13:19 -------- d-----w- c:\program files\AnvSoft
2012-01-23 01:23 . 2012-01-23 01:23 -------- d-----w- c:\programdata\Sony
2012-01-23 01:23 . 2012-01-23 01:23 -------- d-----w- c:\program files\Sony
2012-01-22 01:45 . 2012-01-22 01:48 -------- d-----w- c:\users\Smaka\AppData\Roaming\GetRightToGo
2012-01-21 07:02 . 2012-01-06 04:19 6557240 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F931354D-6DDE-4EB7-B329-C29DEDA2FAC7}\mpengine.dll
2012-01-14 23:55 . 2012-01-14 23:55 -------- dc-h--w- c:\programdata\{618727BE-40FF-4E42-AB24-60F292ECDF2B}
2012-01-14 23:53 . 2012-01-14 23:53 -------- d-----w- c:\program files\Common Files\Native Instruments
2012-01-14 23:53 . 2012-01-14 23:53 -------- d-----w- c:\programdata\Native Instruments
2012-01-14 23:53 . 2012-01-14 23:53 -------- d-----w- c:\program files\Native Instruments
2012-01-12 00:15 . 2012-01-12 00:15 -------- d-----w- c:\program files\Sonic Foundry Setup
2012-01-11 11:53 . 2011-11-17 05:41 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-11 11:53 . 2011-11-17 05:39 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-11 11:53 . 2011-11-17 05:34 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-11 11:53 . 2011-11-17 05:32 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-11 11:53 . 2011-11-17 05:41 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-11 11:53 . 2011-11-17 05:35 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-11 11:53 . 2011-11-17 05:34 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-11 11:53 . 2011-11-17 05:34 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-11 11:53 . 2011-11-17 05:34 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-11 11:53 . 2011-11-17 05:29 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-11 09:18 . 2011-11-17 05:38 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 09:18 . 2011-11-19 14:01 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 09:18 . 2011-10-26 04:32 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 09:18 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 13:50 . 2009-09-04 16:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2012-01-10 13:50 . 2009-09-04 16:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2012-01-10 13:50 . 2009-09-04 16:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-01-10 13:49 . 2006-11-29 12:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2012-01-10 13:47 . 2012-01-11 13:39 -------- d-----w- c:\users\Smaka\AppData\Local\Windows Live
2012-01-10 13:47 . 2012-01-10 13:47 -------- d-----w- c:\program files\Common Files\Windows Live
2012-01-05 21:17 . 2012-01-05 21:17 -------- d-----w- c:\users\Guest\AppData\Local\Opera
2012-01-05 21:17 . 2012-01-05 21:17 -------- d-----w- c:\users\Guest\AppData\Local\Programs
2012-01-05 21:04 . 2012-01-05 21:05 -------- d-----w- c:\users\Guest\AppData\Local\Microsoft Games
2012-01-05 11:09 . 2012-01-05 11:09 -------- d-----w- c:\program files\ESET
2011-12-28 16:59 . 2011-12-28 17:11 -------- d-----w- c:\users\Smaka\AppData\Local\ElevatedDiagnostics
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-18 14:12 . 2011-12-18 14:12 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-12-18 14:12 . 2011-12-18 14:12 161792 ----a-w- c:\windows\system32\msls31.dll
2011-12-18 14:12 . 2011-12-18 14:12 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-12-18 14:12 . 2011-12-18 14:12 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-12-18 14:12 . 2011-12-18 14:12 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-12-18 14:12 . 2011-12-18 14:12 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-12-18 14:12 . 2011-12-18 14:12 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-12-18 14:12 . 2011-12-18 14:12 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-12-18 14:12 . 2011-12-18 14:12 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-12-18 14:12 . 2011-12-18 14:12 367104 ----a-w- c:\windows\system32\html.iec
2011-12-18 14:12 . 2011-12-18 14:12 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-12-18 14:12 . 2011-12-18 14:12 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-18 14:12 . 2011-12-18 14:12 152064 ----a-w- c:\windows\system32\wextract.exe
2011-12-18 14:12 . 2011-12-18 14:12 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-12-18 14:12 . 2011-12-18 14:12 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-12-18 14:12 . 2011-12-18 14:12 11776 ----a-w- c:\windows\system32\mshta.exe
2011-12-18 14:12 . 2011-12-18 14:12 101888 ----a-w- c:\windows\system32\admparse.dll
2011-12-16 20:12 . 2011-12-16 20:11 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-24 04:25 . 2011-12-17 13:39 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-15 13:29 . 2011-12-17 01:41 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-05 04:35 . 2011-12-17 13:40 981504 ----a-w- c:\windows\system32\wininet.dll_old0
2011-11-05 04:34 . 2011-12-17 13:40 1231360 ----a-w- c:\windows\system32\urlmon.dll_old0
2011-11-05 04:30 . 2011-12-17 13:40 2073600 ----a-w- c:\windows\system32\iertutil.dll_old0
2011-11-05 04:26 . 2011-12-17 13:39 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47 . 2011-12-18 15:18 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40 . 2011-12-18 15:18 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39 . 2011-12-18 15:18 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31 . 2011-12-18 15:18 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-01 20:03 475331 --sh--r- c:\windows\System32\sretah.exe
2011-03-01 20:03 475331 --sh--r- c:\windows\System32\zaeqoo.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-12-23 619352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-03-28 10029672]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-09-22 3080264]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MIDI1"=WGDRVR32.DLL
"WAVE1"=WGDRVR32.DLL
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [2010-11-20 77184]
R3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-20 25600]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-20 112640]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R3 WatAdminSvc;Usluga tehnologije aktivacije operativnog sistema Windows;c:\windows\system32\Wat\WatAdminSvc.exe [2011-12-16 1343400]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2011-08-04 118104]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [2011-12-23 494424]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2011-08-09 163424]
S2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2011-09-22 974944]
S2 epfwwfpr;epfwwfpr;c:\windows\system32\DRIVERS\epfwwfpr.sys [2011-08-04 103112]
.
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-01-24 14:01:53
ComboFix-quarantined-files.txt 2012-01-24 13:01
.
Pre-Run: 7,937,454,080 bytes free
Post-Run: 7,857,725,440 bytes free
.
- - End Of File - - 7A862BA1900D5F5B153E3E557B15A550

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Pozdrav i dobrodosao na forum.




Koji ti problem imas sa sistemom?
Da li si mozda video ovu temu? Ako nisi obavezno je detaljno procitaj: http://www.mycity.rs/Ambulanta/Kako-otvoriti-temu-u-Ambulanti.html


-------------------------

ComboFix nije dijagnosticki alat kao ovi iz uputstva. To je jako mocan alat, koji nepravilnim rukovanjem, moze unistiti operativni sistem ili pak obrisati sve padatke sa hard diska. Pokrece se iskljucivo uz predlog, nadleznost i detaljno uputstvo helpera koji je expert u toj oblasti i zna sta radi.

Za ubuduce, ne pokreci ComboFix na svoju ruku!!!

-------------------------







goran9888 (AMF Tim)

offline
  • Pridružio: 24 Jan 2012
  • Poruke: 25

Imam win7 ultimate,ne mogu na kontrolnoj tabli da pokrenem funkciju dodaj ili ukloni korisnicke naloge,ne mogu da pristupim UAC funkciji,sistem pretrage ne funkcionise,za sada sam to primetio pa ako moze pomoc,hvala

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Dragan Smakic ::Imam win7 ultimate,ne mogu na kontrolnoj tabli da pokrenem funkciju dodaj ili ukloni korisnicke naloge,ne mogu da pristupim UAC funkciji,sistem pretrage ne funkcionise,za sada sam to primetio pa ako moze pomoc,hvala

Procitaj Uputstvo koje sam ti link-ovao i uradi sta tamo pise.

offline
  • Pridružio: 24 Jan 2012
  • Poruke: 25

Napisano: 24 Jan 2012 15:37

.Atach fajl nemam na desktopu

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer:
Run by Smaka at 15:18:21 on 2012-01-24
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.895.211 [GMT 1:00]
.
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\DllHost.exe
F:\Programi\Opera\operausb1152 - Smaka\opera.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /Manual
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{B8EBC282-1BC1-4B2A-8464-DADADA084535} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{B8EBC282-1BC1-4B2A-8464-DADADA084535}\A6564735075656460294144402230282053545E492 : DhcpNameServer = 192.168.1.1
.
============= SERVICES / DRIVERS ===============
.
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2011-12-23 494424]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2011-8-9 163424]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-9-22 974944]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2011-8-4 103112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 WatAdminSvc;Usluga tehnologije aktivacije operativnog sistema Windows;c:\windows\system32\wat\WatAdminSvc.exe [2011-12-16 1343400]
.
=============== Created Last 30 ================
.
2012-01-24 13:27:49 -------- d-----w- c:\programdata\Malwarebytes
2012-01-24 13:27:48 -------- d-----w- c:\users\smaka\appdata\roaming\Malwarebytes
2012-01-24 13:01:59 -------- d-sh--w- C:\$RECYCLE.BIN
2012-01-24 13:01:55 -------- d-----w- c:\users\smaka\appdata\local\temp
2012-01-23 23:53:26 -------- d-----w- c:\windows\pss
2012-01-23 15:16:13 -------- d-----w- c:\users\smaka\appdata\local\PackageAware
2012-01-23 13:32:19 -------- d--h--w- c:\windows\msdownld.tmp
2012-01-23 12:37:06 -------- d-----w- c:\users\smaka\appdata\roaming\Anvsoft
2012-01-23 12:36:32 -------- d-----w- c:\program files\AnvSoft
2012-01-23 01:23:18 -------- d-----w- c:\program files\Sony
2012-01-22 01:45:56 -------- d-----w- c:\users\smaka\appdata\roaming\GetRightToGo
2012-01-21 07:02:36 6557240 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f931354d-6dde-4eb7-b329-c29deda2fac7}\mpengine.dll
2012-01-14 23:55:26 -------- dc-h--w- c:\programdata\{618727BE-40FF-4E42-AB24-60F292ECDF2B}
2012-01-14 23:53:53 -------- d-----w- c:\program files\common files\Native Instruments
2012-01-14 23:53:51 -------- d-----w- c:\programdata\Native Instruments
2012-01-14 23:53:51 -------- d-----w- c:\program files\Native Instruments
2012-01-12 00:15:22 -------- d-----w- c:\program files\Sonic Foundry Setup
2012-01-11 11:53:06 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-11 11:53:06 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-11 11:53:06 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-11 11:53:06 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-11 11:53:05 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-11 11:53:04 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-11 11:53:04 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-11 11:53:04 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-11 11:53:04 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-11 11:53:04 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-11 09:45:37 -------- d-----w- c:\users\smaka\appdata\local\{8B6348E5-04E4-401D-9F47-0C3324423583}
2012-01-11 09:45:25 -------- d-----w- c:\users\smaka\appdata\local\{B886F567-0EF7-4BB9-863E-9F0D169962C2}
2012-01-11 09:18:07 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 09:18:06 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 09:18:03 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 09:18:03 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 17:30:14 -------- d-----w- c:\users\smaka\appdata\local\{EEC742CE-7565-42AE-BF10-2CBD84AC4F57}
2012-01-10 17:29:49 -------- d-----w- c:\users\smaka\appdata\local\{AED756AE-5150-42F1-AC98-C82D312D16DB}
2012-01-10 13:50:21 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2012-01-10 13:50:21 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2012-01-10 13:50:20 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-01-10 13:49:58 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2012-01-10 13:49:47 94040 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\DSETUP.dll
2012-01-10 13:49:47 525656 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\DXSETUP.exe
2012-01-10 13:49:47 1691480 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\dsetup32.dll
2012-01-10 13:49:34 94040 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\DSETUP.dll
2012-01-10 13:49:34 525656 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\DXSETUP.exe
2012-01-10 13:49:34 1691480 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\dsetup32.dll
2012-01-10 13:47:54 -------- d-----w- c:\users\smaka\appdata\local\Windows Live
2012-01-10 13:47:52 -------- d-----w- c:\program files\common files\Windows Live
2012-01-05 11:09:39 -------- d-----w- c:\program files\ESET
2011-12-28 16:59:39 -------- d-----w- c:\users\smaka\appdata\local\ElevatedDiagnostics
.
==================== Find3M ====================
.
2011-12-16 20:12:06 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-16 19:48:40 0 ----a-w- c:\windows\ativpsrm.bin
2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-15 13:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-05 04:35:00 981504 ----a-w- c:\windows\system32\wininet.dll_old0
2011-11-05 04:34:46 1231360 ----a-w- c:\windows\system32\urlmon.dll_old0
2011-11-05 04:30:30 2073600 ----a-w- c:\windows\system32\iertutil.dll_old0
2011-11-05 04:26:03 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-01 20:03:34 475331 --sh--r- c:\windows\system32\sretah.exe
2011-03-01 20:03:34 475331 --sh--r- c:\windows\system32\zaeqoo.exe
.
============= FINISH: 15:18:45.94 ===============

Dopuna: 24 Jan 2012 15:50

Dragan Smakic ::.
Evo atach

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer:
Run by Smaka at 15:18:21 on 2012-01-24
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.895.211 [GMT 1:00]
.
AV: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET NOD32 Antivirus 5.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\DllHost.exe
F:\Programi\Opera\operausb1152 - Smaka\opera.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /Manual
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{B8EBC282-1BC1-4B2A-8464-DADADA084535} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{B8EBC282-1BC1-4B2A-8464-DADADA084535}\A6564735075656460294144402230282053545E492 : DhcpNameServer = 192.168.1.1
.
============= SERVICES / DRIVERS ===============
.
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2011-12-23 494424]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2011-8-9 163424]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-9-22 974944]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2011-8-4 103112]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 WatAdminSvc;Usluga tehnologije aktivacije operativnog sistema Windows;c:\windows\system32\wat\WatAdminSvc.exe [2011-12-16 1343400]
.
=============== Created Last 30 ================
.
2012-01-24 13:27:49 -------- d-----w- c:\programdata\Malwarebytes
2012-01-24 13:27:48 -------- d-----w- c:\users\smaka\appdata\roaming\Malwarebytes
2012-01-24 13:01:59 -------- d-sh--w- C:\$RECYCLE.BIN
2012-01-24 13:01:55 -------- d-----w- c:\users\smaka\appdata\local\temp
2012-01-23 23:53:26 -------- d-----w- c:\windows\pss
2012-01-23 15:16:13 -------- d-----w- c:\users\smaka\appdata\local\PackageAware
2012-01-23 13:32:19 -------- d--h--w- c:\windows\msdownld.tmp
2012-01-23 12:37:06 -------- d-----w- c:\users\smaka\appdata\roaming\Anvsoft
2012-01-23 12:36:32 -------- d-----w- c:\program files\AnvSoft
2012-01-23 01:23:18 -------- d-----w- c:\program files\Sony
2012-01-22 01:45:56 -------- d-----w- c:\users\smaka\appdata\roaming\GetRightToGo
2012-01-21 07:02:36 6557240 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{f931354d-6dde-4eb7-b329-c29deda2fac7}\mpengine.dll
2012-01-14 23:55:26 -------- dc-h--w- c:\programdata\{618727BE-40FF-4E42-AB24-60F292ECDF2B}
2012-01-14 23:53:53 -------- d-----w- c:\program files\common files\Native Instruments
2012-01-14 23:53:51 -------- d-----w- c:\programdata\Native Instruments
2012-01-14 23:53:51 -------- d-----w- c:\program files\Native Instruments
2012-01-12 00:15:22 -------- d-----w- c:\program files\Sonic Foundry Setup
2012-01-11 11:53:06 369352 ----a-w- c:\windows\system32\drivers\cng.sys
2012-01-11 11:53:06 224768 ----a-w- c:\windows\system32\schannel.dll
2012-01-11 11:53:06 134000 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-01-11 11:53:06 1038848 ----a-w- c:\windows\system32\lsasrv.dll
2012-01-11 11:53:05 67440 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-01-11 11:53:04 314880 ----a-w- c:\windows\system32\webio.dll
2012-01-11 11:53:04 22528 ----a-w- c:\windows\system32\lsass.exe
2012-01-11 11:53:04 22016 ----a-w- c:\windows\system32\secur32.dll
2012-01-11 11:53:04 15872 ----a-w- c:\windows\system32\sspisrv.dll
2012-01-11 11:53:04 100352 ----a-w- c:\windows\system32\sspicli.dll
2012-01-11 09:45:37 -------- d-----w- c:\users\smaka\appdata\local\{8B6348E5-04E4-401D-9F47-0C3324423583}
2012-01-11 09:45:25 -------- d-----w- c:\users\smaka\appdata\local\{B886F567-0EF7-4BB9-863E-9F0D169962C2}
2012-01-11 09:18:07 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 09:18:06 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 09:18:03 514560 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 09:18:03 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-10 17:30:14 -------- d-----w- c:\users\smaka\appdata\local\{EEC742CE-7565-42AE-BF10-2CBD84AC4F57}
2012-01-10 17:29:49 -------- d-----w- c:\users\smaka\appdata\local\{AED756AE-5150-42F1-AC98-C82D312D16DB}
2012-01-10 13:50:21 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2012-01-10 13:50:21 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2012-01-10 13:50:20 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2012-01-10 13:49:58 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2012-01-10 13:49:47 94040 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\DSETUP.dll
2012-01-10 13:49:47 525656 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\DXSETUP.exe
2012-01-10 13:49:47 1691480 ----a-w- c:\program files\common files\windows live\.cache\b70d6e6a1cccf9e03\dsetup32.dll
2012-01-10 13:49:34 94040 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\DSETUP.dll
2012-01-10 13:49:34 525656 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\DXSETUP.exe
2012-01-10 13:49:34 1691480 ----a-w- c:\program files\common files\windows live\.cache\af122f201cccf9e02\dsetup32.dll
2012-01-10 13:47:54 -------- d-----w- c:\users\smaka\appdata\local\Windows Live
2012-01-10 13:47:52 -------- d-----w- c:\program files\common files\Windows Live
2012-01-05 11:09:39 -------- d-----w- c:\program files\ESET
2011-12-28 16:59:39 -------- d-----w- c:\users\smaka\appdata\local\ElevatedDiagnostics
.
==================== Find3M ====================
.
2011-12-16 20:12:06 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-16 19:48:40 0 ----a-w- c:\windows\ativpsrm.bin
2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys
2011-11-15 13:29:56 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-11-05 04:35:00 981504 ----a-w- c:\windows\system32\wininet.dll_old0
2011-11-05 04:34:46 1231360 ----a-w- c:\windows\system32\urlmon.dll_old0
2011-11-05 04:30:30 2073600 ----a-w- c:\windows\system32\iertutil.dll_old0
2011-11-05 04:26:03 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-03 22:47:42 1798144 ----a-w- c:\windows\system32\jscript9.dll
2011-11-03 22:40:21 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-03 22:39:47 1127424 ----a-w- c:\windows\system32\wininet.dll
2011-11-03 22:31:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-03-01 20:03:34 475331 --sh--r- c:\windows\system32\sretah.exe
2011-03-01 20:03:34 475331 --sh--r- c:\windows\system32\zaeqoo.exe
.
============= FINISH: 15:18:45.94 ===============

mycity.rs/must-login.png

Dopuna: 24 Jan 2012 16:17

Evo i gmer logovi

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Arrow Preuzmi program CatchMe.

Dvoklikom pokreni catchme.exe i klikni na tab Script.
U (beli) prozor programa iskopiraj sledeći tekst:

files:
c:\windows\system32\sretah.exe
c:\windows\system32\zaeqoo.exe
 


Klikni na dugme Run.

Kada se pojavi poruka sa obaveštenjem, klikni na dugme OK.

Po završetku procesa, na Desktopu će se nalaziti datoteka catchme.zip.
Tu datoteku je neophodno postaviti (uploadovati) na forum preko sledeće forme:
http://www.mycity.rs/ambulanta-upload.php

offline
  • Pridružio: 24 Jan 2012
  • Poruke: 25

Preuzeo sam program,iskopirao u beli prozor,nejasno mi koje dugme Run? Moze pomoc,hvala!

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Dragan Smakic ::Preuzeo sam program,iskopirao u beli prozor,nejasno mi koje dugme Run? Moze pomoc,hvala!




Ako nemas dugme Run, izadji iz programa, desni klik na njega pa Run As Administrator -> Yes.

offline
  • Pridružio: 24 Jan 2012
  • Poruke: 25

Kad pokrenem program meni sa pojavi ovo
mycity.rs/must-login.png

offline
  • Pridružio: 02 Feb 2008
  • Poruke: 14018
  • Gde živiš: Nish

Izgleda da catchme 0.3 ne radi na Windows 7 operativnom sistemu. Sad


Nista, idemo "pesaka" ...

Potrebno je da prvo ukljucis prikaz svih skrivenih fajlova/foldera. Detaljno objasnjenje imas na ovom linku: http://www.mycity.rs/MyCity-Laboratorija/Kako-videti-skrivene-fajlove.html


Putem ovog linka: http://www.mycity.rs/ambulanta-upload.php posalji mi sledece fajlove:
c:\windows\system32\sretah.exe
c:\windows\system32\zaeqoo.exe

Ko je trenutno na forumu
 

Ukupno su 1350 korisnika na forumu :: 26 registrovanih, 2 sakrivenih i 1322 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: aleksandarbl, Bane san, Boris BM, Dorcolac, draganca, FileFinder, ILGromovnik, Istman, Ivica1102, jackreacher011011, janbo, Joja2, kovinacc, kraJo, Krusarac, Mi lao shu, raketaš, S2M, Srky Boy, suton, taz1cl, vasa.93, Vlada1389, vladulns, wolf1, zlatkoa987