Problem

Problem

offline
  • Dario
  • Pridružio: 01 Dec 2012
  • Poruke: 26
  • Gde živiš: Banja Luka

Ovako.
Do prije par dana je sve bilo ok dok se računar odjednom nije počeo naglo gasiti.
Najprije sam mislio da je do pregrijavanja neke komponente.
Otvorio sam kućište, detaljno pročistio sve kulere tako da nije ostalo ni trunke prašine.
Pratio sam temperature i ništa neobično nisam primijetio,sve je u nekim granicama normale.
U početku je to bilo samo dok sam igrao igrice ali više nije.
Sad se zna ugasiti i kad radim nešto na netu i sl...
Sumnjam na neki malware ali opet se vi bolje razumijete u ovo pa molim da pomognete.
Avast je počeo da detektuje neki Sality na svaku .exe datoteku (automatsski ju obriše/nestane).

DDS

[*] DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16455 BrowserJavaVersion: 10.9.2
Run by Dario at 10:39:16 on 2012-12-02
Microsoft Windows 7 Home Premium 6.1.7600.0.1250.381.1033.18.1023.255 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\NLSSRV32.EXE
D:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
D:\Program Files\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
C:\ProgramData\Boxtools\Toolbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Windows\system32\Macromed\Flash\FlashPlayerPlugin_11_5_502_110.exe
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Dario\Desktop\Aplikacije\Core Temp.exe
D:\Program Files\GPU Temp\GPUTemp.exe
d:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
d:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
d:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.searchnu.com/410
BHO: HP Print Enhancer: {0347C33E-8762-4905-BF09-768834316C61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Adobe Acrobat Create PDF Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\common files\adobe\acrobat\wcieactivex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - c:\program files\common files\adobe\acrobat\wcieactivex\AcroIEFavClient.dll
BHO: HP Smart BHO Class: {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\common files\adobe\acrobat\wcieactivex\AcroIEFavClient.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
EB: HP Smart Web Printing: {555D4D79-4BD2-4094-A395-CFC534424A05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [Boxoft Tools] "c:\programdata\boxtools\Boxofttoolbox.exe" -autorun
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [AdobeAAMUpdater-1.0] "c:\program files\common files\adobe\oobe\pdapp\uwa\UpdaterStartupUtility.exe"
mRun: [Acrobat Assistant 8.0] "d:\program files\adobe\acrobat 11.0\acrobat\Acrotray.exe"
mRunOnce: [Malwarebytes Anti-Malware] d:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent
mRunOnce: [Malwarebytes Anti-Malware (cleanup)] rundll32.exe "c:\programdata\malwarebytes\malwarebytes' anti-malware\cleanup.dll",ProcessCleanupScript
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\program files\microsoft office\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TCP: NameServer = 217.23.192.9 217.23.192.14
TCP: Interfaces\{9B2B51D9-9B91-4D12-8F5D-F04BE1FB4A9E} : DHCPNameServer = 217.23.192.9 217.23.192.14
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - d:\program files\microsoft office\office12\GrooveShellExtensions.dll
Hosts: 210.249.144.166 we9stun.winning-eleven.net
Hosts: 31.193.132.42 pes6gate-ec.winning-eleven.net
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\Dario\appdata\roaming\mozilla\firefox\profiles\y4jqbkez.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.rs/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&gct=ds&appid=20&systemid=410&apn_dtid=BND410&apn_ptnrs=AGA&apn_uid=2131321092844856&o=APN10649&q=
FF - plugin: c:\program files\adobe\reader 11.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\adobe\oobe\pdapp\ccm\utilities\npAdobeAAMDetect32.dll
FF - plugin: c:\program files\common files\adobe\oobe\pdapp\ccm\utilities\npAdobeAAMDetect64.dll
FF - plugin: c:\program files\google\update\1.3.21.123\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1167637.dll
FF - plugin: c:\windows\system32\adobe\director\np32dsw_1168638.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_5_502_110.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
FF - plugin: d:\program files\adobe\acrobat 11.0\acrobat\air\nppdf32.dll
FF - ExtSQL: 2012-10-18 17:27; wrc@avast.com; c:\program files\avast software\avast\webrep\FF
FF - ExtSQL: 2012-11-01 20:53; fmconverter@gmail.com; c:\program files\freemake\freemake video converter\browserplugin\Firefox
FF - ExtSQL: 2012-11-04 12:43; smartwebprinting@hp.com; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3
FF - ExtSQL: 2012-11-09 15:57; {37E4D8EA-8BDA-4831-8EA1-89053939A250}; c:\users\Dario\appdata\roaming\mozilla\firefox\profiles\y4jqbkez.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF - ExtSQL: 2012-11-10 18:32; 509e9227767e8@509e922776821.com; c:\users\Dario\appdata\roaming\mozilla\firefox\profiles\y4jqbkez.default\extensions\509e9227767e8@509e922776821.com.xpi
FF - ExtSQL: 2012-11-29 14:06; web2pdfextension@web2pdf.adobedotcom; d:\program files\adobe\acrobat 11.0\acrobat\browser\WCFirefoxExtn
FF - ExtSQL: !HIDDEN! 2012-11-04 12:43; smartwebprinting@hp.com; c:\program files\hp\digital imaging\smart web printing\MozillaAddOn3
.
============= SERVICES / DRIVERS ===============
.
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2012-11-12 20624]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-10-18 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-10-18 361032]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-10-18 242240]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-10-18 21256]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-10-18 58680]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-11-8 44808]
R2 MBAMScheduler;MBAMScheduler;d:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-12-2 399432]
R2 MBAMService;MBAMService;d:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-12-2 676936]
R2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\system32\NLSSRV32.EXE [2012-10-30 69640]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2012-10-2 382824]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-12-2 22856]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-10-19 1343400]
.
=============== Created Last 30 ================
.
2012-12-02 09:30:27 54016 ----a-w- c:\windows\system32\drivers\rmbcsuiu.sys
2012-12-02 09:17:13 -------- d-----w- c:\users\Dario\appdata\roaming\Malwarebytes
2012-12-02 09:17:00 -------- d-----w- c:\programdata\Malwarebytes
2012-12-02 09:16:58 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-12-01 15:25:14 -------- d-----w- c:\windows\pss
2012-12-01 10:40:16 -------- d-----w- c:\users\Dario\appdata\local\DOSBox
2012-12-01 09:17:25 60872 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{d311206b-d758-4821-bd07-6483e1fccf13}\offreg.dll
2012-12-01 08:21:47 6812136 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{d311206b-d758-4821-bd07-6483e1fccf13}\mpengine.dll
2012-11-30 12:49:22 -------- d-----w- c:\windows\system32\wbem\framework\root\OpenHardwareMonitor
2012-11-30 12:49:22 -------- d-----w- c:\windows\system32\wbem\framework\root
2012-11-30 12:49:22 -------- d-----w- c:\windows\system32\wbem\Framework
2012-11-29 13:08:48 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2012-11-28 18:54:38 -------- d-----w- c:\users\Dario\appdata\roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-11-28 18:52:55 -------- d-----w- c:\users\Dario\appdata\local\Adobe
2012-11-24 17:33:51 -------- d-----w- c:\users\Dario\appdata\roaming\ts3overlay
2012-11-19 15:05:34 -------- d-----w- c:\users\Dario\appdata\roaming\Ashampoo
2012-11-19 15:04:41 -------- d-----w- c:\users\Dario\appdata\local\ashampoo
2012-11-19 15:02:37 -------- d-----w- c:\programdata\Ashampoo
2012-11-19 15:01:57 -------- d-----w- c:\users\Dario\appdata\local\Programs
2012-11-17 17:21:01 409088 ----a-w- c:\windows\system32\systemcpl.dll
2012-11-17 07:49:38 -------- d-----w- c:\users\Dario\appdata\roaming\Softland
2012-11-17 06:29:14 -------- d--h--w- C:\$WINDOWS.~BT
2012-11-16 06:00:13 78336 ----a-w- c:\windows\system32\synceng.dll
2012-11-16 06:00:09 2344960 ----a-w- c:\windows\system32\win32k.sys
2012-11-13 12:07:17 -------- d-----w- c:\windows\system32\RTCOM
2012-11-13 12:05:58 359768 ----a-w- c:\windows\system32\RTEEP32A.dll
2012-11-13 12:04:36 204800 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iuser.dll
2012-11-13 12:04:35 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\ctor.dll
2012-11-13 12:04:35 274432 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iscript.dll
2012-11-13 12:04:33 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\DotNetInstaller.exe
2012-11-13 12:04:30 757760 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iKernel.dll
2012-11-13 12:04:25 200836 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\iGdi.dll
2012-11-13 12:04:12 331908 ----a-w- c:\program files\common files\installshield\professional\runtime\11\50\intel32\setup.dll
2012-11-12 13:27:02 20624 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2012-11-10 16:11:03 -------- d-----w- c:\users\Dario\appdata\roaming\TS3Client
2012-11-07 12:50:19 -------- d-----w- c:\users\Dario\appdata\local\HiSuite
2012-11-07 12:49:42 581192 ----a-w- c:\windows\system32\drivers\WinUSBCoInstaller.dll
2012-11-07 12:49:42 245376 ----a-w- c:\windows\system32\drivers\hw_quusbnet.sys
2012-11-07 12:49:42 195200 ----a-w- c:\windows\system32\drivers\hw_quusbmdm.sys
2012-11-07 12:49:42 1302600 ----a-w- c:\windows\system32\drivers\WUDFUpdate_01007.dll
2012-11-07 12:49:42 102272 ----a-w- c:\windows\system32\drivers\hw_usbdev.sys
2012-11-07 12:36:10 2560 ----a-w- c:\windows\system32\SHCDMACoInstaller.dll
2012-11-07 12:24:08 -------- d-----w- c:\users\Dario\appdata\local\Research In Motion
2012-11-07 12:22:12 35328 ----a-w- c:\windows\system32\drivers\RimSerial.sys
2012-11-07 12:20:44 -------- d-----w- c:\program files\common files\XCPCSync.OEM
2012-11-07 11:46:38 -------- d-----w- c:\users\Dario\appdata\roaming\smc
2012-11-07 11:10:12 -------- d-----w- c:\users\Dario\appdata\local\HP
2012-11-07 06:09:50 -------- d-----w- c:\users\Dario\appdata\roaming\DVDVideoSoft
2012-11-04 19:10:44 -------- d-----w- c:\users\Dario\appdata\local\Torch
2012-11-04 19:06:01 -------- d-----w- c:\programdata\Boxtools
2012-11-04 19:05:52 756736 ----a-w- c:\windows\system32\LameACM.acm
2012-11-04 19:05:16 -------- d-----w- c:\programdata\boost_interprocess
2012-11-04 11:45:28 -------- d-----w- c:\programdata\WEBREG
2012-11-04 11:38:50 -------- d-----w- c:\program files\common files\HP
2012-11-04 11:38:39 -------- d-----w- c:\program files\common files\Hewlett-Packard
2012-11-04 11:37:05 -------- d-----w- c:\program files\HP
2012-11-04 11:35:28 452408 ----a-w- c:\windows\system32\hpzids01.dll
2012-11-04 11:35:27 729088 ----a-w- c:\windows\system32\hpowiax7.dll
2012-11-04 11:35:27 372736 ----a-w- c:\windows\system32\hppldcoi.dll
2012-11-04 11:35:26 303104 ----a-w- c:\windows\system32\hpovst15.dll
2012-11-04 11:35:25 581632 ----a-w- c:\windows\system32\hpotscl6.dll
2012-11-04 11:15:23 280064 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\hpzppw71.dll
2012-11-02 16:31:14 -------- d-----w- c:\users\Dario\appdata\roaming\Nitro
2012-11-02 16:31:14 -------- d-----w- c:\users\Dario\appdata\roaming\FileOpen
2012-11-02 16:31:14 -------- d-----w- c:\programdata\FileOpen
2012-11-02 16:28:52 -------- d-----w- c:\programdata\Nitro
2012-11-02 16:25:04 -------- d-----w- c:\users\Dario\appdata\roaming\Downloaded Installations
.
==================== Find3M ====================
.
2012-11-17 17:21:01 13824 ----a-w- c:\windows\system32\slwga.dll
2012-11-09 05:51:13 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-09 05:51:13 697272 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-30 22:51:58 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2012-10-30 22:51:57 58680 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-10-30 22:51:07 41224 ----a-w- c:\windows\avastSS.scr
2012-10-30 10:30:30 69640 ----a-w- c:\windows\system32\NLSSRV32.EXE
2012-10-20 13:13:27 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-10-20 13:12:50 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-10-20 13:12:49 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-10-19 05:40:46 801792 ----a-w- c:\windows\system32\FntCache.dll
2012-10-19 05:40:46 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2012-10-19 05:40:46 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2012-10-19 05:40:46 3181568 ----a-w- c:\windows\system32\mf.dll
2012-10-19 05:40:46 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2012-10-19 05:40:46 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2012-10-19 05:40:46 196608 ----a-w- c:\windows\system32\mfreadwrite.dll
2012-10-19 05:40:46 1619456 ----a-w- c:\windows\system32\WMVDECOD.DLL
2012-10-19 05:40:46 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2012-10-19 05:40:46 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2012-10-19 05:40:46 107520 ----a-w- c:\windows\system32\cdd.dll
2012-10-18 16:04:38 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-10-18 15:50:02 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-10-15 16:59:28 44784 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2012-10-15 08:08:30 12672 ----a-w- c:\windows\system32\drivers\vjoy.sys
2012-10-08 07:56:24 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-10-08 07:48:03 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-10-08 07:47:44 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-10-08 07:44:05 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-10-08 07:43:21 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-10-08 07:40:56 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-10-02 19:29:42 645992 ----a-w- c:\windows\system32\nvvsvc.exe
2012-10-02 19:29:41 62312 ----a-w- c:\windows\system32\nvshext.dll
2012-10-02 19:29:41 108392 ----a-w- c:\windows\system32\nvmctray.dll
2012-10-02 19:29:22 2853224 ----a-w- c:\windows\system32\nvsvc.dll
2012-10-02 19:28:53 3965288 ----a-w- c:\windows\system32\nvcpl.dll
2012-10-02 12:15:52 430952 ----a-w- c:\windows\system32\nvStreaming.exe
2012-09-14 18:30:38 2048 ----a-w- c:\windows\system32\tzres.dll
.
============= FINISH: 10:40:21,93 ===============



mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Preuzmi program SystemLook sa ovog ili ovog linka na Desktop;

Dvoklikom pokreni SystemLook;


- U beli okvir prozora iskopirati sledeći tekst:

:file
C:\Windows\system32\services.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\Explorer.EXE


Klikni taster Look;


Po završetku rada programa priloži uz poruku file SystemLook.txt koji će se nalaziti na Desktop-u korišćenjem opcije Prikači Fajl.

offline
  • Dario
  • Pridružio: 01 Dec 2012
  • Poruke: 26
  • Gde živiš: Banja Luka

mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Okaci mi zadnja 2-3 loga Malwarebytes-a

Start -> Run -> %AppData%\Malwarebytes\Malwarebytes' Anti-Malware\Logs -> Enter


Ko je trenutno na forumu
 

Ukupno su 1011 korisnika na forumu :: 51 registrovanih, 9 sakrivenih i 951 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., aramis s, babaroga, Ben Roj, Bubimir, CikaKURE, Dannyboy, Denaya, Dimitrise93, djboj, draganca, dragoljub11987, FileFinder, Georgius, goxin, hatman, HrcAk47, ILGromovnik, Karla, kolle.the.kid, kybonacci, Luka Blažević, mercedesamg, mile23, milenko crazy north, Mlav, Oscar, Parker, pein, Petar35, raptorsi, RJ, ruma, slonic_tonic, SR-3m, Srle993, stegonosa, Stoilkovic, theNedjeljko, tmanda323, Trpe Grozni, trundle, tubular, Tvrtko I, vaso1, vathra, Vatreni Zmaj, Vlada1389, Webb, YU-UKI, zillbg