Poslao: 10 Jul 2012 16:15
|
offline
- TeoDos
- Građanin
- Pridružio: 23 Jan 2008
- Poruke: 65
- Gde živiš: Beograd
|
Log ComboFix-a:
ComboFix 12-07-10.01 - mix 10.07.2012 16:00:49.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1250.381.1033.18.894.403 [GMT 2:00]
Running from: c:\users\mix\Desktop\ComboFix.exe
Command switches used :: c:\users\mix\Desktop\CFScript.txt
.
FILE ::
"c:\windows\system32\drivers\9a95ba92f4f69065.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\drivers\9a95ba92f4f69065.sys
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Created from 2012-06-10 to 2012-07-10 )))))))))))))))))))))))))))))))
.
.
2012-07-10 14:08 . 2012-07-10 14:08 -------- d-----w- c:\users\mix\AppData\Local\temp
2012-07-10 14:08 . 2012-07-10 14:08 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-07-10 09:46 . 2012-07-10 09:46 -------- d-----w- c:\program files\Windows Resource Kits
2012-07-10 08:20 . 2012-07-10 07:47 47560 ----a-w- c:\windows\system32\SPReview.exe
2012-07-10 08:20 . 2012-07-10 07:47 152576 ----a-w- c:\windows\system32\SPWizUI.dll
2012-07-10 06:55 . 2012-07-10 06:55 -------- d-----w- c:\windows\system32\EventProviders
2012-07-09 13:29 . 2006-11-02 12:33 2565432 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87AFEFA8-7594-4667-A487-E835D2DF7C58}\mpengine.dll
2012-07-09 10:21 . 2012-07-09 10:27 -------- d-----w- c:\users\mix\AppData\Roaming\GlarySoft
2012-07-09 10:21 . 2012-07-09 23:28 -------- d-----w- c:\program files\Glary Utilities
2012-07-06 12:44 . 2012-07-06 12:44 -------- d-----w- c:\program files\Launch Manager
2012-07-06 12:44 . 2003-04-28 09:27 9867 ----a-w- c:\windows\system32\drivers\HOTKEY.sys
2012-07-06 12:43 . 2012-07-06 12:43 -------- d-----w- c:\users\mix\AppData\Roaming\InstallShield
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-29 4317184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"LaunchAp"="c:\program files\Launch Manager\LaunchAp.exe" [2005-07-25 32768]
"HotkeyApp"="c:\program files\Launch Manager\HotkeyApp.exe" [2006-12-14 192512]
"LMgrVolOSD"="c:\program files\Launch Manager\OSD.exe" [2006-12-26 180224]
"LMgrOSD"="c:\program files\Launch Manager\OSDCtrl.exe" [2006-08-29 241664]
"Wbutton"="c:\program files\Launch Manager\Wbutton.exe" [2006-11-09 86016]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-10 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2012-07-09 20:16]
.
2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 06:58]
.
2012-07-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-02 06:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.0.2 188.93.120.2 188.93.120.3
TCP: Interfaces\{527DEBCC-910F-4768-80CC-620BF2D0CBEE}: NameServer = 188.93.120.2,188.93.120.3,192.168.0.11
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, gmer.net
Rootkit scan 2012-07-10 16:08
Windows 6.0.6000 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-10 16:11:30
ComboFix-quarantined-files.txt 2012-07-10 14:11
ComboFix2.txt 2012-07-10 12:44
.
Pre-Run: 87.492.591.616 bytes free
Post-Run: 87.462.072.320 bytes free
.
- - End Of File - - 0F291B70F38CA9023EA9E510DEF85912
|
|
|
|
|
|
Poslao: 10 Jul 2012 17:27
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Napisano: 10 Jul 2012 17:08
Sada je potrebno da preuzmeš Service Pack 2 za Vistu sa sljedećeg linka:
Windows Vista SP2 x86
Kada ga preuzmeš, pokreni instalaciju. Nakon što se instalacija završi, pokušaj opet da pokreneš Windows Update i da instaliraš ponuđene zakrpe.
Javi kada to završiš i ako sve prođe kako treba dobićeš uputstvo za obavljanje jednog koraka koji je potrebno obaviti prije instalacije AV programa.
Dopuna: 10 Jul 2012 17:27
Izvini što ti nisam napomenuo da Service Pack 2 za Vistu zahijeva instaliran Service Pack 1. Njega možeš preuzeti sa sljedećeg linka.
http://download.microsoft.com/download/2/1/9/21916.....-wave1.exe
Nakon što instaliraš SP1 pa SP2, pokušaj da pokreneš Windows Update.
|
|
|
|
Poslao: 11 Jul 2012 10:44
|
offline
- TeoDos
- Građanin
- Pridružio: 23 Jan 2008
- Poruke: 65
- Gde živiš: Beograd
|
Evo da se javim da sam instalirao SP1 i SP2 i odradio ceo update bez prijavljene i jedne greske.
Sad je ostao jos AV. Cekam dalja uputstva.
|
|
|
|
|
Poslao: 11 Jul 2012 14:03
|
offline
- TeoDos
- Građanin
- Pridružio: 23 Jan 2008
- Poruke: 65
- Gde živiš: Beograd
|
Evo odradjeno sve po uputstvu:
DDS:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19272
Run by mix at 11:57:05 on 2012-07-11
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1250.381.1033.18.894.275 [GMT 2:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TeamViewer3\TeamViewer_Host.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Launch Manager\LaunchAp.exe
C:\Program Files\Launch Manager\HotkeyApp.exe
C:\Program Files\Launch Manager\OSD.exe
C:\Program Files\Launch Manager\OSDCtrl.exe
C:\Program Files\Launch Manager\WButton.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Launch Manager\WisLMSvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\wsqmcons.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\rundll32.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [LaunchAp] c:\program files\launch manager\LaunchAp.exe
mRun: [HotkeyApp] c:\program files\launch manager\HotkeyApp.exe
mRun: [LMgrVolOSD] c:\program files\launch manager\OSD.exe
mRun: [LMgrOSD] c:\program files\launch manager\OSDCtrl.exe
mRun: [Wbutton] "c:\program files\launch manager\Wbutton.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
TCP: DhcpNameServer = 192.168.0.2 188.93.120.2 188.93.120.3
TCP: Interfaces\{09CF84D8-FB30-4BA3-9133-1EE7448ABA0A} : DhcpNameServer = 192.168.0.2 188.93.120.2 188.93.120.3
TCP: Interfaces\{527DEBCC-910F-4768-80CC-620BF2D0CBEE} : NameServer = 188.93.120.2,188.93.120.3,192.168.0.11
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R1 MpKsleffa6dc6;MpKsleffa6dc6;c:\programdata\microsoft\microsoft antimalware\definition updates\{fedc3a07-0c12-4dd9-a2cc-48d2daba7eb4}\MpKsleffa6dc6.sys [2012-7-11 29904]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2012-7-10 21504]
R2 TeamViewer;TeamViewer 3;c:\program files\teamviewer3\TeamViewer_Host.exe [2008-3-12 181544]
R3 WisLMSvc;WisLMSvc;c:\program files\launch manager\WisLMSvc.exe [2012-7-6 118784]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [2007-2-27 218112]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== File Associations ===============
.
vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*
jsefile\shell\open2\command=c:\windows\system32\CScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-07-11 09:37:53 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{fedc3a07-0c12-4dd9-a2cc-48d2daba7eb4}\offreg.dll
2012-07-11 09:37:53 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{fedc3a07-0c12-4dd9-a2cc-48d2daba7eb4}\MpKsleffa6dc6.sys
2012-07-11 09:28:31 713784 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{fad68055-513f-4b78-8655-3161d9bf8988}\gapaengine.dll
2012-07-11 09:27:15 6762896 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{fedc3a07-0c12-4dd9-a2cc-48d2daba7eb4}\mpengine.dll
2012-07-11 09:10:36 -------- d-----w- c:\program files\Microsoft Security Client
2012-07-11 06:35:43 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2012-07-11 06:35:41 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-07-11 06:35:41 1069056 ----a-w- c:\windows\system32\DWrite.dll
2012-07-11 06:35:40 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-07-11 06:35:40 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-07-11 06:35:40 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-07-11 05:28:31 -------- d-----w- c:\program files\Windows Portable Devices
2012-07-10 21:51:18 2047488 ----a-w- c:\windows\system32\win32k.sys
2012-07-10 21:48:20 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2012-07-10 21:48:17 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2012-07-10 21:48:16 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2012-07-10 21:45:45 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2012-07-10 21:45:37 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2012-07-10 21:45:37 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2012-07-10 21:45:37 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2012-07-10 21:45:36 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2012-07-10 21:45:36 252928 ----a-w- c:\windows\system32\dxdiag.exe
2012-07-10 21:45:33 519680 ----a-w- c:\windows\system32\d3d11.dll
2012-07-10 21:29:30 5120 ----a-w- c:\windows\system32\wmi.dll
2012-07-10 21:29:30 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-07-10 21:29:30 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-07-10 21:29:30 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-07-10 21:05:17 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2012-07-10 20:51:46 6762896 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{9c8cbac7-56a6-4202-950b-1f1a385256b6}\mpengine.dll
2012-07-10 20:46:41 6762896 ------w- c:\programdata\microsoft\windows defender\definition updates\updates\mpengine.dll
2012-07-10 20:30:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2012-07-10 20:30:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2012-07-10 20:30:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2012-07-10 20:30:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2012-07-10 20:30:46 1130824 ----a-w- c:\windows\system32\dfshim.dll
2012-07-10 20:05:17 59904 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\PPhp2600.DLL
2012-07-10 20:01:31 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2012-07-10 20:01:02 40448 ----a-w- c:\windows\system32\winrs.exe
2012-07-10 20:01:02 20480 ----a-w- c:\windows\system32\winrshost.exe
2012-07-10 20:01:02 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2012-07-10 20:01:00 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2012-07-10 20:01:00 10240 ----a-w- c:\windows\system32\winrssrv.dll
2012-07-10 19:57:34 2067968 ----a-w- c:\windows\system32\mstscax.dll
2012-07-10 19:54:44 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2012-07-10 19:54:42 23552 ----a-w- c:\windows\system32\mciseq.dll
2012-07-10 19:54:42 189952 ----a-w- c:\windows\system32\winmm.dll
2012-07-10 19:54:27 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2012-07-10 19:54:27 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2012-07-10 19:54:27 238080 ----a-w- c:\windows\system32\oleacc.dll
2012-07-10 19:54:26 563712 ----a-w- c:\windows\system32\oleaut32.dll
2012-07-10 19:53:43 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
2012-07-10 19:53:41 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2012-07-10 19:53:16 601600 ----a-w- c:\windows\system32\schedsvc.dll
2012-07-10 19:53:16 352768 ----a-w- c:\windows\system32\taskschd.dll
2012-07-10 19:53:16 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2012-07-10 19:53:15 270336 ----a-w- c:\windows\system32\taskcomp.dll
2012-07-10 19:53:15 171520 ----a-w- c:\windows\system32\taskeng.exe
2012-07-10 19:53:02 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2012-07-10 19:53:01 1136640 ----a-w- c:\windows\system32\mfc42.dll
2012-07-10 19:51:54 708608 ----a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-10 19:50:59 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-07-10 19:49:59 72704 ----a-w- c:\windows\system32\fontsub.dll
2012-07-10 19:49:59 292864 ----a-w- c:\windows\system32\atmfd.dll
2012-07-10 19:49:58 34304 ----a-w- c:\windows\system32\atmlib.dll
2012-07-10 19:49:54 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2012-07-10 19:49:50 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2012-07-10 19:49:48 36864 ----a-w- c:\windows\system32\rtutils.dll
2012-07-10 19:49:45 6144 ----a-w- c:\program files\internet explorer\iecompat.dll
2012-07-10 19:49:44 758784 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2012-07-10 19:49:11 1401856 ----a-w- c:\windows\system32\msxml6.dll
2012-07-10 19:49:11 1248768 ----a-w- c:\windows\system32\msxml3.dll
2012-07-10 19:48:34 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-10 19:48:28 440704 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-10 19:48:28 278528 ----a-w- c:\windows\system32\schannel.dll
2012-07-10 19:48:28 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2012-07-10 19:48:27 9728 ----a-w- c:\windows\system32\lsass.exe
2012-07-10 19:48:27 72704 ----a-w- c:\windows\system32\secur32.dll
2012-07-10 19:48:27 204288 ----a-w- c:\windows\system32\ncrypt.dll
2012-07-10 19:48:20 531968 ----a-w- c:\windows\system32\comctl32.dll
2012-07-10 19:48:08 231424 ----a-w- c:\windows\system32\msshsq.dll
2012-07-10 18:46:06 2422272 ----a-w- c:\windows\system32\wucltux.dll
2012-07-10 18:45:39 88576 ----a-w- c:\windows\system32\wudriver.dll
2012-07-10 18:45:28 33792 ----a-w- c:\windows\system32\wuapp.exe
2012-07-10 18:45:28 171904 ----a-w- c:\windows\system32\wuwebv.dll
2012-07-10 18:23:59 -------- d-----w- c:\windows\system32\eu-ES
2012-07-10 18:23:59 -------- d-----w- c:\windows\system32\ca-ES
2012-07-10 18:23:58 -------- d-----w- c:\windows\system32\vi-VN
2012-07-10 18:13:32 -------- d-----w- c:\windows\system32\SPReview
2012-07-10 17:52:26 928768 ----a-w- c:\windows\system32\scavenge.dll
2012-07-10 17:52:06 57856 ----a-w- c:\windows\system32\compcln.exe
2012-07-10 17:40:59 614376 ----a-w- c:\windows\system32\ci.dll
2012-07-10 17:39:58 83456 ----a-w- c:\windows\system32\SMBHelperClass.dll
2012-07-10 17:07:27 -------- d-----w- C:\PerfLogs
2012-07-10 15:42:59 -------- d-----w- C:\cceb474fca4aa657d47b2a22c2
2012-07-10 14:11:38 -------- d-sh--w- C:\$RECYCLE.BIN
2012-07-10 14:11:31 -------- d-----w- c:\users\mix\appdata\local\temp
2012-07-10 09:46:16 -------- d-----w- c:\program files\Windows Resource Kits
2012-07-10 07:55:35 193024 ----a-w- c:\windows\system32\recdisc.exe
2012-07-10 07:55:34 6656 ----a-w- c:\windows\system32\sdspres.dll
2012-07-10 07:53:59 93184 ----a-w- c:\windows\system32\ncsi.dll
2012-07-10 07:52:59 70144 ----a-w- c:\windows\system32\amstream.dll
2012-07-10 06:55:56 -------- d-----w- c:\windows\system32\EventProviders
2012-07-09 10:21:28 -------- d-----w- c:\users\mix\appdata\roaming\GlarySoft
2012-07-09 10:21:27 -------- d-----w- c:\program files\Glary Utilities
2012-07-06 12:44:23 9867 ----a-w- c:\windows\system32\drivers\HOTKEY.sys
2012-07-06 12:44:23 -------- d-----w- c:\program files\Launch Manager
.
==================== Find3M ====================
.
2012-07-10 16:45:43 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2012-07-10 16:45:29 82432 ----a-w- c:\windows\system32\axaltocm.dll
2012-05-15 06:37:49 916992 ----a-w- c:\windows\system32\wininet.dll
2012-05-15 06:32:25 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-05-15 06:32:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-15 06:31:44 109056 ----a-w- c:\windows\system32\iesysprep.dll
2012-05-15 06:31:43 71680 ----a-w- c:\windows\system32\iesetup.dll
2012-05-15 05:01:56 385024 ----a-w- c:\windows\system32\html.iec
2012-05-15 03:26:05 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-15 03:23:41 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-04-23 16:00:53 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-04-23 16:00:53 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-23 16:00:53 133120 ----a-w- c:\windows\system32\cryptsvc.dll
.
============= FINISH: 11:58:18,58 ===============
mycity.rs/must-login.png
GMER:
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
|
|
|
|
Poslao: 11 Jul 2012 14:09
|
offline
- Sass Drake
- Anti Malware Fighter
Rank 2
- Pridružio: 26 Avg 2010
- Poruke: 10622
- Gde živiš: Hypnos Control Room, Tokyo Metropolitan Government Building
|
Kakvo je sad stanje sistema?
|
|
|
|
Poslao: 11 Jul 2012 14:14
|
offline
- TeoDos
- Građanin
- Pridružio: 23 Jan 2008
- Poruke: 65
- Gde živiš: Beograd
|
Za sada sve deluje da je o.k.
Sva azuriranja su prosla bez ikakvih problema i instalacija AV je prosla bez zastoja.
Hvala na odvojenom vremenu i pomoci.
|
|
|
|
|