|
|
|
Poslao: 10 Jul 2012 09:43
|
rip
- argus

- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
Imas tri linka za DDS, probaj sa nekog drugog.
Ako nece, preuzmi OTL pokreni ga po uputstvu i dostavi nam logove.
|
|
|
|
|
|
|
Poslao: 10 Jul 2012 11:27
|
offline
- Pridružio: 02 Maj 2012
- Poruke: 368
|
Napisano: 10 Jul 2012 11:10
Evo dds fajlova:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.5.1
Run by HP at 11:05:40 on 2012-07-10
Microsoft Windows 7 Ultimate 6.1.7601.1.1250.381.1033.18.3036.2148 [GMT 2:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\AEADISRV.EXE
C:\ProgramData\bProtector\bProtect.exe
C:\Windows\system32\schtasks.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel RMS License Manager\WinNT\lservnt.exe
C:\ProgramData\bProtector\bProtect.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Skype\Updater\Updater.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
C:\Program Files\MCShield\MCShieldRTM.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\HP\Desktop\CoreTemp32\Core Temp.exe
C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Users\HP\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = [Link mogu videti samo ulogovani korisnici]
uSearch Bar =
uLocal Page = c:\program files\hewlett-packard\hp quick launch buttons\Blank.htm
mStart Page = about:blank
mLocal Page = c:\program files\hewlett-packard\hp quick launch buttons\Blank.htm
mSearchAssistant =
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
TB: {98889811-442D-49dd-99D7-DC866BE87DBC} - No File
TB: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
TB: {FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - No File
TB: {51A86BB3-6602-4C85-92A5-130EE4864F13} - No File
TB: {EEE6C35B-6118-11DC-9C72-001320C79847} - No File
TB: {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
TB: {37483B40-C254-4A72-BDA4-22EE90182C1E} - No File
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
mRun: [QlbCtrl.exe] c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe /Start
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\users\hp\appdata\roaming\micros~1\windows\startm~1\programs\startup\autoru~1\onenot~1.lnk - c:\program files\microsoft office\office14\ONENOTEM.EXE
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [Link mogu videti samo ulogovani korisnici]
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [Link mogu videti samo ulogovani korisnici]
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7C9E8127-5B92-4917-A9A6-045D27AA6378} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7C9E8127-5B92-4917-A9A6-045D27AA6378}\47F60736F6D6 : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{A2E8EFA6-650B-4E83-9B75-133736F99A10} : DhcpNameServer = 79.143.101.225 79.143.101.229
TCP: Interfaces\{BF806B5C-9B4E-4C88-AABB-0B35D0BAF4FC} : NameServer = 195.66.189.137,195.66.189.138
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: protector.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2012-5-9 15672]
R1 MpKsldd5f1939;MpKsldd5f1939;c:\programdata\microsoft\microsoft antimalware\definition updates\{b7f3d7f8-2334-439d-8482-853cdaeff59b}\MpKsldd5f1939.sys [2012-7-10 29904]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-8-18 176128]
R2 bProtector;bProtector;c:\programdata\bprotector\bProtect.exe [2012-3-14 773624]
R2 hpsrv;HP Service;c:\windows\system32\hpservice.exe [2011-4-21 26168]
R2 Sentinel RMS License Manager;Sentinel RMS License Manager;c:\program files\common files\safenet sentinel\sentinel rms license manager\winnt\lservnt.exe [2006-8-1 774144]
R2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-5 160944]
R3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2011-5-17 227896]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-7-14 311296]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-12-29 136176]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-7-10 654408]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-13 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-12-29 136176]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-7-10 22344]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-22 30963576]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-10 4640000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-9-24 1343400]
S4 IObitUnlocker;IObitUnlocker;c:\program files\iobit\iobit unlocker\IObitUnlocker.sys [2012-5-9 28016]
.
=============== File Associations ===============
.
.scr=AutoCADScriptFile
.
=============== Created Last 30 ================
.
2012-07-10 09:04:06 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b7f3d7f8-2334-439d-8482-853cdaeff59b}\MpKsldd5f1939.sys
2012-07-10 06:22:44 6762896 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{b7f3d7f8-2334-439d-8482-853cdaeff59b}\mpengine.dll
2012-07-10 06:02:38 -------- d-----w- c:\users\hp\appdata\roaming\Malwarebytes
2012-07-10 06:02:23 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-10 06:02:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-07 12:52:24 6762896 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-07-04 16:01:56 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{088b0372-4f20-4e68-a8e1-591c2da2e9f3}\gapaengine.dll
2012-07-03 22:02:28 293376 ----a-w- c:\windows\system32\browserchoice.exe
2012-06-30 12:03:40 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-06-30 12:03:25 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-06-30 12:03:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-06-30 12:03:12 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-18 10:04:37 -------- d-----w- c:\program files\Oracle
2012-06-13 12:23:44 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2012-06-11 19:41:30 -------- d-----w- c:\programdata\RFA
2012-06-11 19:40:39 -------- d-----w- c:\programdata\Registry First Aid
2012-06-11 19:40:38 -------- d-----w- c:\program files\RFA 8
2012-06-11 19:29:09 -------- d-----w- c:\program files\GomPlayer
2012-06-11 19:24:09 -------- d-----w- c:\users\hp\appdata\roaming\AIMP3
2012-06-11 19:24:02 -------- d-----w- c:\program files\AIMP3
.
==================== Find3M ====================
.
2012-07-10 09:04:00 95 ----a-w- c:\windows\system32\prsrvk.dll
2012-07-10 09:04:00 72 ----a-w- c:\windows\system32\nsprs.dll
2012-06-30 12:30:57 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-30 12:30:57 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-16 04:55:54 204 ----a-w- c:\windows\system32\lsprst7.dll
2012-05-15 03:03:54 981504 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 01:05:38 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-05-09 21:38:04 63423 ----a-w- c:\programdata\1336598070.2236.bin
2012-05-09 21:37:58 2991 ----a-w- c:\programdata\1336598070.4520.bin
2012-05-09 21:37:58 225435 ----a-w- c:\programdata\1336598070.1960.bin
2012-05-09 21:33:12 36082 ----a-w- c:\programdata\1336598070.2688.bin
2012-05-09 21:33:08 591 ----a-w- c:\programdata\1336598070.4024.bin
2012-05-09 21:32:40 21001 ----a-w- c:\programdata\1336598070.3324.bin
2012-05-09 21:18:46 7029 ----a-w- c:\programdata\1336598070.368.bin
2012-05-09 21:18:46 1403 ----a-w- c:\programdata\1336598070.380.bin
2012-05-09 21:14:54 4512 ----a-w- c:\programdata\1336598070.5008.bin
2012-05-09 21:14:40 1404 ----a-w- c:\programdata\1336598070.4832.bin
2012-05-09 21:14:40 10226 ----a-w- c:\programdata\1336598070.4768.bin
2012-05-08 14:22:26 100 ----a-w- c:\windows\system32\prsgrc.dll
2012-05-08 11:59:18 2048 ----a-w- c:\windows\system32\sysprs7.dll
2012-05-08 11:59:14 1024 ----a-w- c:\windows\system32\serauth2.dll
2012-05-08 11:59:14 1024 ----a-w- c:\windows\system32\serauth1.dll
2012-05-08 11:59:14 1024 ----a-w- c:\windows\system32\rvkauth2.dll
2012-05-08 11:59:14 1024 ----a-w- c:\windows\system32\rvkauth1.dll
2012-05-08 11:19:03 1024 ----a-w- c:\windows\system32\s97c53x.dll
2012-05-08 11:19:01 72 ----a-w- c:\windows\system32\ssprs.dll
2012-05-08 11:19:01 1024 ----a-w- c:\windows\system32\grcauth2.dll
2012-05-08 11:19:01 1024 ----a-w- c:\windows\system32\grcauth1.dll
2012-05-08 11:19:01 1024 ----a-w- c:\windows\system32\clauth2.dll
2012-05-08 11:19:01 1024 ----a-w- c:\windows\system32\clauth1.dll
2012-05-04 17:29:22 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-05-04 17:29:16 687504 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-01 04:44:12 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-04-28 04:41:44 919040 ----a-w- c:\windows\system32\rdpcorets.dll
2012-04-28 03:17:07 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-26 04:45:55 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-04-26 04:45:54 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-04-26 04:41:16 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-04-24 04:36:42 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-24 04:36:42 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-04-24 04:36:42 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-20 03:16:44 1638912 ----a-w- c:\windows\system32\mshtml.tlb
.
============= FINISH: 11:06:56,28 ===============
[Link mogu videti samo ulogovani korisnici]
Jedno pitanje: da li MBAM PRO verzija moze da zamijeni MSE AV?
Dopuna: 10 Jul 2012 11:27
Ovaj fajl bProtector sto ga MBAM detektuje kao virus sam skenirao online - [Link mogu videti samo ulogovani korisnici]
|
|
|
|
|
|
|
Poslao: 10 Jul 2012 11:48
|
rip
- argus

- Anti Malware Fighter
Rank 2
- Pridružio: 27 Apr 2008
- Poruke: 9160
- Gde živiš: Prokuplje
|
MBAM ne moze da zameni antivirus.
Tvoj problem nije uzrokovan malware-om.
C:\Windows\System32\mrvcl32.exe > Ovaj fajl nije maliciozan mbam prijavljuje fp.
C:\Windows\System32\mrvcl32.exe > Vezan za Warcraft igricu
Na tebi je da odlucis hoces li ga brisati.
|
|
|
|
|
|
|
Poslao: 10 Jul 2012 13:49
|
offline
- Pridružio: 02 Maj 2012
- Poruke: 368
|
Ako sam dobro shvatio, nista od ovog sto je MBAM detektovao nije opasno po kompjuter?
|
|
|
|
|
|