Poslao: 22 Jun 2012 16:32
|
offline
- Pridružio: 20 Apr 2012
- Poruke: 1645
|
Pozdrav.
Ovako,moj drug ima puno virusa na kompjuteru.
Sigurno je pokupio viruse sa interneta,sporo mu se otvaraju programi. I sve je usporeno.
Njegov kompjuter je Windows enterprise 32-bit.
Evo izvještaja DDS
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Mashine at 15:26:37 on 2012-06-22
Microsoft Windows 7 Enterprise 6.1.7601.1.1250.381.1033.18.1014.210 [GMT 2:00]
.
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\PixArt\Pac7302\Monitor.exe
C:\Program Files\MCShield\MCShieldRTM.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = www.google.com
uURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTo0.dll
mURLSearchHooks: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTo0.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\bh\BabylonToolbar.dll
BHO: Web Assistant: {336d0c35-8a85-403a-b9d2-65c292c39087} - c:\program files\web assistant\Extension32.dll
BHO: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTo0.dll
BHO: Incredibar.com Helper Object: {6e13dde1-2b6e-46ce-8b66-dc8bf36f6b99} - c:\program files\incredibar.com\incredibar\1.5.11.14\bh\incredibar.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~1\office14\GROOVEEX.DLL
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~1\office14\URLREDIR.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: Incredibar Toolbar: {f9639e4a-801b-4843-aee3-03d9da199e77} - c:\program files\incredibar.com\incredibar\1.5.11.14\incredibarTlbr.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - c:\program files\babylontoolbar\babylontoolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB: uTorrentControl2 Toolbar: {687578b9-7132-4a7a-80e4-30ee31099e03} - c:\program files\utorrentcontrol2\prxtbuTo0.dll
uRun: [MCShield Monitor] c:\program files\mcshield\mcshieldrtm.exe
uRun: [uTorrent] "d:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~1\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{1CCE19EE-3444-49C9-A56C-8C47509B19CF} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{87E8940D-889F-4135-B27F-EEB0DF9D5505} : DhcpNameServer = 192.168.39.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~1\office14\GROOVEEX.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-5-11 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-5-11 337880]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [2012-5-23 242240]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-14 48128]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-5-11 20696]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2012-5-11 57688]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-5-11 44768]
R2 Web Assistant Updater;Web Assistant Updater;c:\program files\web assistant\ExtensionUpdaterService.exe [2012-5-21 185856]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-3-1 139776]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-5-11 136176]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-21 62464]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-5-11 136176]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 netr73;RT73 USB Extensible Wireless LAN Card Driver;c:\windows\system32\drivers\netr73.sys [2011-10-5 564800]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2010-11-21 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2010-11-21 25600]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2010-11-20 52224]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2010-11-21 112640]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2012-5-10 1343400]
.
=============== Created Last 30 ================
.
2012-06-15 12:02:07 -------- d-----w- c:\programdata\MCShield
2012-06-15 12:02:07 -------- d-----w- c:\program files\MCShield
2012-06-15 10:50:56 -------- d-----w- c:\windows\system32\appmgmt
2012-06-15 10:14:09 -------- d-----w- c:\program files\Touchdown Entertainment
2012-06-15 10:13:53 77824 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\ctor.dll
2012-06-15 10:13:53 32768 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\objectps.dll
2012-06-15 10:13:53 225280 ----a-w- c:\program files\common files\installshield\iscript\iscript.dll
2012-06-15 10:13:53 176128 ----a-w- c:\program files\common files\installshield\engine\6\intel 32\iuser.dll
2012-06-14 20:27:39 -------- d-----w- c:\users\mashine\appdata\local\Facebook
2012-06-14 05:58:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-14 05:58:02 194560 ----a-w- c:\program files\internet explorer\ieproxy.dll
2012-06-14 05:58:02 140920 ----a-w- c:\program files\internet explorer\sqmapi.dll
2012-06-14 05:58:01 194048 ----a-w- c:\program files\internet explorer\IEShims.dll
2012-06-14 05:58:00 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-14 05:58:00 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-14 05:57:58 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-06-14 05:57:57 748664 ----a-w- c:\program files\internet explorer\iexplore.exe
2012-06-14 05:57:57 387584 ----a-w- c:\program files\internet explorer\jsdbgui.dll
2012-06-14 05:57:56 678912 ----a-w- c:\program files\internet explorer\iedvtool.dll
2012-06-14 05:57:55 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-13 07:07:18 919040 ----a-w- c:\windows\system32\rdpcorets.dll
2012-06-13 07:07:18 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-06-13 07:07:15 2342400 ----a-w- c:\windows\system32\msi.dll
2012-06-13 07:07:13 2343936 ----a-w- c:\windows\system32\win32k.sys
2012-06-13 07:07:11 58880 ----a-w- c:\windows\system32\rdpwsx.dll
2012-06-13 07:07:11 129536 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-06-13 07:07:10 8192 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-06-13 07:07:05 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2012-06-13 07:07:05 1158656 ----a-w- c:\windows\system32\crypt32.dll
2012-06-13 07:07:05 103936 ----a-w- c:\windows\system32\cryptnet.dll
2012-06-13 07:06:43 164352 ----a-w- c:\windows\system32\profsvc.dll
2012-05-31 16:14:57 1060864 ----a-w- c:\windows\system32\mfc71.dll
2012-05-31 16:14:56 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-05-31 16:14:54 503808 ----a-w- c:\windows\system32\msvcp71.dll
2012-05-31 16:14:50 -------- d-----w- c:\windows\Album
2012-05-31 16:14:46 -------- d-----w- c:\program files\KYE
2012-05-31 16:12:49 6656 ----a-w- c:\windows\system32\CoInst_070614.dll
2012-05-31 16:12:49 457856 ----a-w- c:\windows\system32\drivers\PAC7302.SYS
2012-05-31 16:12:49 -------- d-----w- c:\program files\common files\Eye 312
2012-05-31 16:12:42 129024 ----a-w- c:\windows\system32\SP7302.ax
2012-05-31 16:12:41 14336 ----a-w- c:\windows\system32\P7302USD.dll
2012-05-31 16:12:40 -------- d-----w- c:\windows\PixArt
2012-05-31 16:12:40 -------- d-----w- c:\program files\common files\Pac7302
2012-05-26 15:53:47 -------- d-----w- c:\users\mashine\appdata\roaming\OpenCandy
2012-05-26 15:53:12 -------- d-----w- c:\program files\Veetle
2012-05-23 13:43:47 -------- d-----w- c:\windows\pss
.
==================== Find3M ====================
.
2012-05-23 12:14:31 242240 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2012-05-11 11:09:33 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-05-10 11:51:16 13824 ----a-w- c:\windows\system32\slwga.dll
2012-05-10 11:51:15 811520 ----a-w- c:\windows\system32\user32.dll
2012-05-10 11:51:15 409088 ----a-w- c:\windows\system32\systemcpl.dll
2012-03-31 04:39:37 3968368 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 10:23:11 1291632 ----a-w- c:\windows\system32\drivers\tcpip.sys
.
============= FINISH: 15:27:16,29 ===============
https://www.mycity.rs/must-login.png
Evo izvještaja GMER
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
Izvještaj OTL
https://www.mycity.rs/must-login.png
https://www.mycity.rs/must-login.png
Pozdrav
|
|
|
|
|
|
|
|
|
Poslao: 22 Jun 2012 21:58
|
offline
- Pridružio: 20 Apr 2012
- Poruke: 1645
|
Ok hvala ti puno TwinHeadedEagle,nego on je imao avast 7.0 ja koliko znam on je najnovi,i nema das dobar racunar,ram mu je 1GB,Graficka 250mb,Procesor 2,0GHZ,i komp mu je bio usporen,viste mu pomogli puno sad je ociscen instaliro sam mu Malwarebytes Anti-Malware,McShield,ali kad sam mu obrisao avast komp mu se ubrzo,da li avast usporava komp i koji bi vi djemu predlozili da instalira antivirusni program,sjutra cu da mu provjer kakvo mu je stanje sa internetom,u svakom slucaju vi ste svoje uradili,i on vam je veoma zahvalam,pozzz
|
|
|
|
|
Poslao: 22 Jun 2012 22:05
|
offline
- Pridružio: 20 Apr 2012
- Poruke: 1645
|
Ok hvala ti,vidje cu sjutra,pa ako bude problema otvoricu temu
|
|
|
|