Provera sistema

Provera sistema

offline
  • Pridružio: 09 Okt 2010
  • Poruke: 679
  • Gde živiš: Kragujevac

Pozdrav. Racunar mi je uzasno usporio. I Chrome mi cesto otvara tek iz drugog ili treceg puta, a ako ga malo duze koristim, znatno sporije, ili nikako, ne otvara stranice. Verovatno je jedan od razloga sto sam skidao sve i svja (sto za sebe, sto za druge), pa sam sada prenatrpan, no mozda i imam neki virus ili tako nesto. Inace ja se u ovo jedva razumem ali valjda cu uspeti da ispratim upustva.
Iskljucio sam AVG firevall (nisam mogao kopletanAVG) i COMODO firevall.
Internet konekcija je wireless, a brzina 54 Mbps.



DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 9.0.8112.16457 BrowserJavaVersion: 10.7.2
Run by Zoran at 17:54:22 on 2013-01-22
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2815.1079 [GMT 1:00]
.
AV: AVG Internet Security *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Enabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
FW: COMODO Firewall *Enabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
FW: AVG Firewall *Disabled* {621CC794-9486-F902-D092-0484E8EA828B}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Program Files\Common Files\Comodo\launcher_service.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Comodo\Dragon\dragon_updater.exe
C:\Program Files\Process Lasso\processgovernor.exe
C:\Program Files\Process Lasso\processlasso.exe
C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe
C:\Program Files\IB Updater\ExtensionUpdaterService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Comodo\GeekBuddyRSP.exe
C:\Program Files\AVG\AVG9\avgtray.exe
C:\Program Files\ManicTime\ManicTime.exe
C:\Program Files\MCShield\MCShieldRTM.exe
C:\Program Files\Comodo\GeekBuddy\unit_manager.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Comodo\GeekBuddy\unit.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://us.yahoo.com?fr=fp-comodo
uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60747
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: {124d001a-bdcb-472f-aa59-bbe7e4bc3204} - <orphaned>
dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - <orphaned>
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealNetworks Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\programdata\realnetworks\realdownloader\browserplugins\ie\rndlbrowserrecordplugin.dll
BHO: IB Updater: {336D0C35-8A85-403a-B9D2-65C292C39087} - c:\program files\ib updater\Extension32.dll
BHO: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office14\GROOVEEX.DLL
BHO: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - c:\program files\utorrentcontrol_v2\prxtbuTor.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - c:\program files\microsoft office\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: uTorrentControl_v2 Toolbar: {7473B6BD-4691-4744-A82B-7854EB3D70B6} - c:\program files\utorrentcontrol_v2\prxtbuTor.dll
TB: uTorrentControl_v2 Toolbar: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - c:\program files\utorrentcontrol_v2\prxtbuTor.dll
TB: AVG Security Toolbar: {95B7759C-8C7F-4BF1-B163-73684A933233} - c:\program files\avg secure search\11.1.0.12\AVG Secure Search_toolbar.dll
uRun: [avgui.exe] c:\program files\avg\avg9\avgui.exe
uRun: [avgtray.exe] c:\program files\avg\avg9\avgtray.exe
uRun: [ManicTime] c:\program files\manictime\ManicTime.exe /minimized /name:
uRun: [Advanced SystemCare 5] "c:\program files\iobit\advanced systemcare 5\ASCTray.exe" /AutoStart
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [gbrspcontrol] "c:\program files\common files\comodo\GeekBuddyRSP.exe" -controlservice -slave
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedb.....er=9.0.914
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\startg~1.lnk - c:\program files\comodo\geekbuddy\launcher.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:221
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
LSP: c:\program files\speedbit video accelerator\SBLSP.dll
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: NameServer = 192.168.1.20
TCP: Interfaces\{D07EEE4E-3BF7-455E-AA43-01FE4669AF6C} : NameServer = 8.26.56.26,156.154.70.22
TCP: Interfaces\{D07EEE4E-3BF7-455E-AA43-01FE4669AF6C} : DHCPNameServer = 192.168.1.20
TCP: Interfaces\{D07EEE4E-3BF7-455E-AA43-01FE4669AF6C}\14E64627F696461405 : DHCPNameServer = 192.168.43.1
TCP: Interfaces\{D07EEE4E-3BF7-455E-AA43-01FE4669AF6C}\8474533303 : DHCPNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\common files\avg secure search\viprotocolinstaller\11.2.0\ViProtocol.dll
AppInit_DLLs= c:\windows\system32\guard32.dll
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office14\GROOVEEX.DLL
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\24.0.1312.52\installer\setup.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSErHrw7x;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSwx.sys [2012-9-9 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2012-9-9 52872]
R0 EUBAKUP;EUBAKUP;c:\windows\system32\drivers\eubakup.sys [2012-9-10 50312]
R0 EUBKMON;EUBKMON;c:\windows\system32\drivers\EUBKMON.sys [2012-9-10 44680]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwd6x.sys [2012-9-9 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2012-9-9 226016]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2012-9-9 29712]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2012-9-9 243152]
R1 CFRMD;CFRMD;c:\windows\system32\drivers\CFRMD.sys [2012-12-4 35064]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2012-11-7 494416]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2012-11-7 36072]
R1 EUDSKACS;EUDSKACS;c:\windows\system32\drivers\eudskacs.sys [2012-9-10 17032]
R1 EUFDDISK;EUFDDISK;c:\windows\system32\drivers\EuFdDisk.sys [2012-9-10 187016]
R1 networx;networx;c:\windows\system32\drivers\networx.sys [2012-12-22 52728]
R1 sp_rsdrv2;Spyware Terminator 2012 Realtime Shield Driver;c:\windows\system32\drivers\sp_rsdrv2.sys [2012-9-12 32768]
R1 VD_FileDisk;VD_FileDisk;c:\windows\system32\drivers\vd_filedisk.sys [2006-1-13 15872]
R2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2012-9-9 921952]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2012-9-9 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2012-9-9 2331544]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2012-9-9 5897808]
R2 CLPSLauncher;COMODO LPS Launcher;c:\program files\common files\comodo\launcher_service.exe [2012-12-19 70352]
R2 DragonUpdater;COMODO Dragon Update Service;c:\program files\comodo\dragon\dragon_updater.exe [2013-1-16 1868432]
R2 GeekBuddyRSP;GeekBuddyRSP Service;c:\program files\common files\comodo\GeekBuddyRSP.exe [2012-11-26 1851088]
R2 IB Updater;IB Updater;c:\program files\ib updater\ExtensionUpdaterService.exe [2012-12-14 188760]
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-1-16 398184]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-1-16 682344]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\realnetworks\realdownloader\rndlresolversvc.exe [2012-11-29 38608]
R3 athrusb;TP-LINK Wireless LAN USB device driver;c:\windows\system32\drivers\athrusb.sys [2007-8-17 891392]
R3 AVGIDSDriverw7x;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSDriver.sys [2012-9-9 122448]
R3 AVGIDSFilterw7x;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSFilter.sys [2012-9-9 30288]
R3 AVGIDSShimw7x;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_win7\AVGIDSShim.sys [2012-9-9 20560]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-1-16 21104]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\iobit\advanced systemcare 5\ASCService.exe [2012-9-12 913792]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2012-9-9 167264]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 EaseUS Agent;EaseUS Agent;c:\program files\easeus\todo backup\bin\Agent.exe [2012-9-12 61064]
S3 Freemake Improver;Freemake Improver;c:\programdata\freemake\freemakeutilsservice\FreemakeUtilsService.exe [2012-9-16 100864]
S3 Guard Agent;Guard Agent;c:\program files\easeus\todo backup\bin\GuardAgent.exe [2012-9-12 23176]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2011-12-16 15544]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2012-9-10 15576]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2012-9-10 10200]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2012-9-9 327784]
S3 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2012-9-24 1328736]
S3 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2012-9-24 656480]
S3 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files\spyware terminator\st_rsser.exe [2012-9-12 587472]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 VideoAcceleratorService;VideoAcceleratorService; [x]
S3 vToolbarUpdater11.2.0;vToolbarUpdater11.2.0;c:\program files\common files\avg secure search\vtoolbarupdater\11.2.0\ToolbarUpdater.exe [2012-9-11 935008]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-9-9 1343400]
S3 WiseBootAssistant;Wise Boot Assistant;c:\program files\wise\wise care 365\BootTime.exe [2013-1-2 580648]
.
=============== Created Last 30 ================
.
2013-01-21 20:02:02 626688 ----a-w- c:\windows\system32\usp10.dll
2013-01-21 20:02:01 2345984 ----a-w- c:\windows\system32\win32k.sys
2013-01-21 20:02:00 492032 ----a-w- c:\windows\system32\win32spl.dll
2013-01-21 20:00:21 46592 ----a-w- c:\windows\system32\fpb.rs
2013-01-21 19:59:54 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-01-21 18:29:13 -------- d-----w- c:\users\zoran\appdata\roaming\EQATEC Analytics
2013-01-21 18:28:31 -------- d-----w- c:\programdata\SpeedBit
2013-01-21 18:28:28 -------- d-----w- c:\program files\DAP
2013-01-19 17:47:17 -------- d-----w- c:\users\zoran\appdata\local\WinZip
2013-01-17 18:06:44 -------- d-----w- c:\programdata\ProcessLasso
2013-01-17 16:08:12 -------- d-----w- c:\users\zoran\appdata\local\SKIDROW
2013-01-16 22:17:48 -------- d-----w- c:\users\zoran\appdata\local\FUJIFILM
2013-01-16 22:08:59 -------- d-----w- c:\program files\common files\Comodo
2013-01-16 21:54:28 -------- d-----w- c:\programdata\Comodo
2013-01-16 21:54:16 -------- d-----w- c:\users\zoran\appdata\local\Comodo
2013-01-16 21:54:12 47368 ----a-w- c:\windows\system32\certsentry.dll
2013-01-16 21:54:06 -------- d-----w- c:\program files\Comodo
2013-01-16 21:54:02 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2013-01-16 21:54:02 1060864 ----a-w- c:\windows\system32\mfc71.dll
2013-01-16 21:40:11 -------- d-----w- c:\users\zoran\appdata\roaming\Malwarebytes
2013-01-16 21:39:59 -------- d-----w- c:\programdata\Malwarebytes
2013-01-16 21:39:58 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-01-16 21:39:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-01-16 21:32:18 -------- d-----w- c:\programdata\MCShield
2013-01-16 21:32:17 -------- d-----w- c:\program files\MCShield
2013-01-14 17:40:00 208896 ----a-w- c:\windows\system32\FFRafShellEx.dll
2013-01-14 17:39:54 233472 ----a-w- c:\windows\system32\RFCLauncher.exe
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2013-01-14 17:38:27 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2013-01-10 10:37:34 -------- d-sh--w- C:\$RECYCLE.BIN
2013-01-09 21:26:37 -------- d-s---w- C:\ComboFix
2013-01-09 18:26:24 -------- d-----w- c:\program files\common files\xing shared
2013-01-09 18:26:01 499712 ----a-w- c:\windows\system32\msvcp71.dll
2013-01-09 18:26:01 348160 ----a-w- c:\windows\system32\msvcr71.dll
2013-01-06 19:39:22 -------- d-----w- c:\users\zoran\appdata\roaming\RealNetworks
2013-01-06 19:39:00 -------- d-----w- c:\program files\RealNetworks
2013-01-06 19:38:58 -------- d-----w- c:\programdata\RealNetworks
2013-01-06 00:27:32 -------- d-----w- c:\users\zoran\appdata\roaming\Wise Game Booster
2013-01-05 10:41:07 -------- d-----w- c:\users\zoran\appdata\roaming\WinPatrol
2013-01-05 10:40:59 -------- d-----w- c:\program files\BillP Studios
2013-01-05 10:40:58 -------- d-----w- c:\programdata\InstallMate
2013-01-04 15:40:50 -------- d-----w- c:\users\zoran\appdata\local\Finkit
2013-01-04 15:40:42 -------- d-----w- c:\program files\ManicTime
2013-01-04 15:39:40 -------- d-----w- c:\program files\Process Lasso
2013-01-02 18:48:02 -------- d-----w- c:\programdata\VSO
2013-01-02 18:48:02 -------- d-----w- c:\program files\VSO
2013-01-02 18:36:31 -------- d-----w- c:\users\zoran\appdata\local\Chromium
2013-01-02 18:21:21 -------- d-----w- c:\users\zoran\appdata\roaming\Sports Interactive
2013-01-02 18:21:21 -------- d-----w- c:\users\zoran\appdata\local\Sports Interactive
2013-01-02 00:20:02 -------- d-----w- c:\users\zoran\appdata\roaming\Wise Care 365
2013-01-02 00:19:00 -------- d-----w- C:\install
2012-12-30 18:44:01 -------- d-----w- c:\programdata\BlueStacksSetup
2012-12-30 18:17:21 -------- d-----w- c:\users\zoran\appdata\roaming\AC3Filter
2012-12-29 23:02:01 -------- d-----w- c:\program files\Pale Moon
2012-12-29 19:24:00 -------- d-----w- c:\program files\Mafia
2012-12-26 22:44:47 -------- d-----w- c:\users\zoran\appdata\roaming\Wise Registry Cleaner
.
==================== Find3M ====================
.
2013-01-16 11:03:11 226016 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2013-01-10 14:35:01 697864 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-01-10 14:35:00 74248 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-01-10 14:34:58 16369160 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2013-01-01 04:06:17 452032 ----a-w- c:\users\zoran\appdata\roaming\ProcessLassopl_rsrc_temp.dll
2012-12-21 18:34:05 138056 ----a-w- c:\users\zoran\appdata\roaming\PnkBstrK.sys
2012-12-21 18:33:49 189248 ----a-w- c:\windows\system32\PnkBstrB.ex0
2012-12-16 14:13:28 295424 ----a-w- c:\windows\system32\atmfd.dll
2012-12-16 14:13:20 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-12-07 12:26:17 308736 ----a-w- c:\windows\system32\Wpc.dll
2012-12-07 12:20:43 2576384 ----a-w- c:\windows\system32\gameux.dll
2012-12-04 08:41:28 35064 ----a-w- c:\windows\system32\drivers\CFRMD.sys
2012-12-04 08:41:28 35064 ----a-w- c:\windows\inf\cfrmd\cfrmd.sys
2012-11-30 04:53:34 169984 ----a-w- c:\windows\system32\winsrv.dll
2012-11-30 04:47:45 293376 ----a-w- c:\windows\system32\KernelBase.dll
2012-11-30 02:55:25 271360 ----a-w- c:\windows\system32\conhost.exe
2012-11-30 02:38:59 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2012-11-30 02:38:59 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2012-11-30 02:38:59 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2012-11-30 02:38:59 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-11-26 15:34:28 52728 ----a-w- c:\windows\system32\drivers\networx.sys
2012-11-20 04:51:09 220160 ----a-w- c:\windows\system32\ncrypt.dll
2012-11-14 02:09:22 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-11-14 01:58:15 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-11-14 01:57:37 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-11-14 01:49:25 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-11-14 01:48:27 420864 ----a-w- c:\windows\system32\vbscript.dll
2012-11-14 01:44:42 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-11-09 04:42:49 2048 ----a-w- c:\windows\system32\tzres.dll
2012-11-07 22:37:56 494416 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2012-11-07 22:37:56 36072 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2012-11-07 22:37:54 19632 ----a-w- c:\windows\system32\drivers\cmderd.sys
2012-11-07 22:37:36 34024 ----a-w- c:\windows\system32\cmdcsr.dll
2012-11-07 22:37:36 301264 ----a-w- c:\windows\system32\guard32.dll
2012-11-02 05:11:31 376832 ----a-w- c:\windows\system32\dpnet.dll
2012-11-01 17:52:22 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2012-11-01 04:47:54 1389568 ----a-w- c:\windows\system32\msxml6.dll
.
============= FINISH: 17:55:26.26 ===============


https://www.mycity.rs/must-login.png


https://www.mycity.rs/must-login.png


https://www.mycity.rs/must-login.png

Ovaj treci korak mi nije uspeo. Tacnije, prilikom pritiska na taster scan nista se nije desavalo.
To, valjda znaci da trebam probati RootRepeal.

Nece. Skinuo sam na desktop kao "Compressed (zipped) folders" ali kada sam kliknuo da raspakujem izbacilo mi prozor na kome je pisalo: "Root Repeal error/Attempt to write to address: 0x0179a000"

Izgleda da je ozbiljniji problem.

offline
  • Més que un club
  • Glavni vokal @ Harpun
  • Pridružio: 27 Feb 2009
  • Poruke: 3898
  • Gde živiš: Novi Sad,Klisa

Pozdrav zoranzota



Arrow
Na računaru su ti aktivna dva Firewall-a. Comodo firewall i AVG-ov firewall. Savetovao bih ti da obrišeš Comodo-ov firewall, pošto je vrlo moguće da ti to pravi problem




Arrow

Vidim iz logova da si pokretao Combofix....

ComboFix nije dijagnosticki alat kao ovi iz uputstva. To je jako mocan alat, koji nepravilnim rukovanjem, moze unistiti operativni sistem ili pak obrisati sve padatke sa hard diska. Pokrece se iskljucivo uz predlog, nadleznost i detaljno uputstvo helpera koji je expert u toj oblasti i zna sta radi.

Za ubuduce, ne pokreci ComboFix na svoju ruku!!!




Arrow

Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop
Dvoklikom pokreni program i klikni na dugme [Search] .
Kada program zavrsi analizu otvorice notepad sa izvestajem. Zatvori taj notepad.

Klikni na dugme [Delete] i pricekaj da program zavrsi.
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok

Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt

offline
  • Pridružio: 09 Okt 2010
  • Poruke: 679
  • Gde živiš: Kragujevac

Prvo da zahvalim na vremenu koje ti oduzimam. Ziveli

Ja vec dugo koristim AVG antivirus, koji, pored ostalog, ima i firewall. Mada sam cuo da AVG nije bas najbolji jer moze da uspori racunar. Za Comodo sam video da ga dosta osoba sa ovog foruma koristi, pa rekoh da probam. (Videla zaba da se konji potkivaju...) Vec sam cuo da ne valja dva antivirusa ali mislio sam da moze firewall. U svakom slucaju, uspeo sam nekako da ga uklonim. Za ComboFix stvarno nisam pametan (no to nije tema Wink ) Nema ga u instaliranim programima, mada je moguce da sam ga obrisao prilikom oporavka sistema. Uglavnom, savet je prihvacen.



https://www.mycity.rs/must-login.png

offline
  • Més que un club
  • Glavni vokal @ Harpun
  • Pridružio: 27 Feb 2009
  • Poruke: 3898
  • Gde živiš: Novi Sad,Klisa

Kakvo je sada stanje sistema?

offline
  • Pridružio: 09 Okt 2010
  • Poruke: 679
  • Gde živiš: Kragujevac

Napisano: 23 Jan 2013 18:08

Mislim da je brzi. Mada, prilikom podizanja je i dalje spor. Bolje nego sto je bilo, ali imao je i lepsih trenutaka. Tako nekako.

Dopuna: 23 Jan 2013 18:39

Sada sam primetio da me i dalje zeza Chrome. Ako ga duze koristim slabo otvara stranice, bas slabo. A kada ga iskljucim tek iz drugog ili treceg puta otvori.

offline
  • Més que un club
  • Glavni vokal @ Harpun
  • Pridružio: 27 Feb 2009
  • Poruke: 3898
  • Gde živiš: Novi Sad,Klisa

Ok. Ti si čist što se malicioznih programa tiče.



Arrow

Otvori novu temu u potforumu Windows, i tamo iznesi svoj problem, pošto se u Amublanti isključivo bavimo rešavanjem problema vezanih za maliciozne programe.



Idea Takođe, poseti ovu temu da vidiš da li ti je pretraživač ranjiv i instaliraš ažurirane komponente
http://www.mycity.rs/Propusti-i-azuriranja/Testira.....anjiv.html



offline
  • Pridružio: 09 Okt 2010
  • Poruke: 679
  • Gde živiš: Kragujevac

Aham. Znaci AVG radi svoj posao. Wink Hvala na pomoci i na savetima pa se "vidimo" u nekoj drugoj temi. Ziveli

Ko je trenutno na forumu
 

Ukupno su 1040 korisnika na forumu :: 51 registrovanih, 5 sakrivenih i 984 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., arton, babaroga, Boris90, brundo65, cavatina, comi_pfc, dankisha, darkangel, dekan.m, Denaya, DonRumataEstorski, doom83, DragoslavS, dule10savic, FileFinder, galijot, ILGromovnik, Japidson, JOntra, Još malo pa deda, Karla, Klecaviks, krkalon, Kubovac, kunktator, kybonacci, laki_bb, Lieutenant, macak44, magna86, mercedesamg, mileJNA, milenko crazy north, milimoj, miodrag, mrav pesadinac, NoOneEver Dreams, nuke92, oldtimer, panonski mornar, panzerwaffe, raptorsi, saputnik plavetnila, slonic_tonic, stalja, Vlad000, ZetaMan, Zimbabwe, |_MeD_|, 1107