uvijek iskoci neki eror code
rkill
Rkill 2.6.5 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2014 BleepingComputer.com
More Information about Rkill can be found at this link:
http://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 04/12/2014 04:20:29 PM in x86 mode.
Windows Version: Windows 7 Ultimate Service Pack 1
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* No malware processes found to kill.
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* No issues found.
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* No issues found.
Program finished at: 04/12/2014 04:21:25 PM
Execution time: 0 hours(s), 0 minute(s), and 56 seconds(s)
nista sada cu da vidim ovaj drugi
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16660
Run by RADE at 14:20:42 on 2014-04-13
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2039.1077 [GMT 2:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Settings Manager\systemk\SystemkService.exe
C:\Program Files\Settings Manager\systemk\SystemkService.exe
C:\Program Files\Settings Manager\systemk\systemku.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.default-search.net?sid=476&aid=106&itype=n&ver=12302&tm=312&src=hmp
uProxyServer = proxy.uns.ac.rs:8080
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB80D62C-F03C-4D9B-B4A2-36DE0B73CB06} : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB80D62C-F03C-4D9B-B4A2-36DE0B73CB06}\0564D234944514F4E4943414 : DHCPNameServer = 8.8.4.4 8.8.8.8
TCP: Interfaces\{DB80D62C-F03C-4D9B-B4A2-36DE0B73CB06}\4505D2C494E4B4F5547363647363 : DHCPNameServer = 192.168.0.1
TCP: Interfaces\{DB80D62C-F03C-4D9B-B4A2-36DE0B73CB06}\4756C656B6F6D6E63713 : DHCPNameServer = 192.168.1.1
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\program files\common files\skype\Skype4COM.dll
AppInit_DLLs=
SSODL: WebCheck - <orphaned>
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\34.0.1847.116\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
IFEO: bitguard.exe - tasklist.exe
IFEO: bprotect.exe - tasklist.exe
IFEO: bpsvc.exe - tasklist.exe
IFEO: browserdefender.exe - tasklist.exe
IFEO: browserprotect.exe - tasklist.exe
.
Note: multiple IFEO entries found. Please refer to Attach.txt
.
============= SERVICES / DRIVERS ===============
.
R1 F06DEFF2-5B9C-490D-910F-35D3A9119622;F06DEFF2-5B9C-490D-910F-35D3A9119622;c:\program files\settings manager\systemk\systemkmgrc1.cfg [2014-4-9 31120]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2013-10-9 3275136]
R2 SystemkService;Systemk Service;c:\program files\settings manager\systemk\SystemkService.exe [2014-4-9 3543056]
R3 NETwLv32; Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETwLv32.sys [2013-3-14 6639616]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2013-3-14 552080]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2013-10-23 172192]
S3 asmthub3;ASMedia USB3 Hub Service;c:\windows\system32\drivers\asmthub3.sys [2013-4-12 110920]
S3 asmtxhci;ASMEDIA XHCI Service;c:\windows\system32\drivers\asmtxhci.sys [2013-4-12 333128]
S3 b06diag;Broadcom NetXtreme II Diag Driver;c:\windows\system32\drivers\bxdiagx.sys [2013-3-14 75816]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 BFN7x86;Bigfoot Networks Killer Gaming Service;c:\windows\system32\drivers\Xeno7x86.sys [2013-3-14 130152]
S3 bxfcoe;bxfcoe;c:\windows\system32\drivers\bxfcoe.sys [2013-3-14 150568]
S3 bxois;bxois;c:\windows\system32\drivers\bxois.sys [2013-3-14 435240]
S3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2011-4-12 62464]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\drivers\EtronHub3.sys [2013-2-27 65152]
S3 EtronSTOR;Etron Enhance USB BOT/UASP Mass Storage Driver;c:\windows\system32\drivers\EtronSTOR.sys [2013-2-27 32512]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\drivers\EtronXHCI.sys [2013-2-27 88832]
S3 iusb3hub;Intel(R) USB 3.0 Hub Driver;c:\windows\system32\drivers\iusb3hub.sys [2013-4-12 359560]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible Host Controller Driver;c:\windows\system32\drivers\iusb3xhc.sys [2013-4-12 792712]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\drivers\nusb3hub.sys [2013-2-27 73984]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\drivers\nusb3xhc.sys [2013-2-27 165120]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2013-8-16 14848]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2014-4-12 27192]
S3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\Synth3dVsc.sys [2011-4-12 77184]
S3 terminpt;Microsoft Remote Desktop Input Driver;c:\windows\system32\drivers\terminpt.sys [2013-8-16 24064]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-8-16 49664]
S3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2013-8-16 27136]
S3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [2011-4-12 112640]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-8-16 1343400]
S3 wuexfuea;wuexfuea;c:\windows\system32\drivers\wuexfuea.sys [2014-4-12 411552]
.
=============== Created Last 30 ================
.
2014-04-13 11:17:57 -------- d-----w- C:\1150afdbd3f1e726a5bd
2014-04-12 14:54:42 -------- d-----w- c:\program files\HitmanPro
2014-04-12 14:52:12 -------- d-----w- c:\program files\ASM104xUSB3
2014-04-12 14:28:43 12872 ----a-w- c:\windows\system32\bootdelete.exe
2014-04-12 14:22:56 -------- d-----w- c:\programdata\HitmanPro
2014-04-12 09:30:17 411552 ----a-w- c:\windows\system32\drivers\wuexfuea.sys
2014-04-12 08:19:04 -------- d--h--w- c:\programdata\Common Files
2014-04-12 08:19:03 -------- d-----w- c:\users\rade\appdata\local\MFAData
2014-04-12 08:19:03 -------- d-----w- c:\programdata\MFAData
2014-04-12 08:09:12 -------- d-----w- C:\WINSSLog
2014-04-12 06:56:38 -------- d-----w- c:\program files\Perfect Uninstaller
2014-04-12 06:44:02 27192 ----a-w- c:\windows\system32\drivers\revoflt.sys
2014-04-12 06:43:56 -------- d-----w- c:\program files\VS Revo Group
2014-04-12 06:34:59 -------- d-----w- c:\windows\Downloaded Installations
2014-04-09 20:10:17 1500160 ----a-w- c:\windows\system32\drivers\athur.sys
2014-04-09 20:10:09 1500160 ----a-r- c:\windows\system32\athur.sys
2014-04-09 20:10:09 -------- d-----w- c:\windows\Options
2014-04-09 20:08:21 -------- d-----w- c:\windows\system32\appmgmt
2014-04-09 19:53:26 -------- d-----w- c:\programdata\TP-LINK
2014-04-09 15:19:06 -------- d-----w- c:\users\rade\appdata\roaming\Carambis
2014-04-09 15:18:28 -------- d-----w- c:\users\rade\appdata\local\TempDIR
2014-04-09 12:18:03 -------- d-----w- c:\program files\Settings Manager
2014-04-09 12:17:57 -------- d-----w- c:\programdata\systemk
2014-04-02 15:55:35 -------- d-----w- c:\users\rade\appdata\local\VS Revo Group
2014-04-02 15:55:16 -------- d-----w- c:\programdata\VS Revo Group
2014-04-02 15:53:59 -------- d-----w- c:\users\rade\appdata\local\WinZip
2014-04-02 15:45:40 -------- d-----w- c:\program files\The KMPlayer
2014-04-02 15:40:37 -------- d-----w- c:\users\rade\appdata\roaming\uTorrent
2014-04-02 13:25:06 -------- d-----w- c:\windows\system32\RTCOM
2014-04-02 13:19:19 -------- d-----w- c:\users\rade\appdata\roaming\RealNetworks
2014-04-02 13:17:40 -------- d-----w- c:\programdata\RealNetworks
2014-04-02 13:12:36 -------- d-----w- c:\users\rade\appdata\roaming\DRPSu
2014-04-02 13:04:12 -------- d-----w- c:\program files\Realtek
2014-04-02 13:04:09 -------- d--h--w- c:\program files\Temp
2014-04-02 13:02:28 -------- d-----w- C:\SWTOOLS
2014-04-02 12:22:47 -------- d-----w- c:\users\rade\appdata\local\DriverToolkit
2014-04-02 12:22:41 -------- d-----w- c:\program files\DriverToolkit
2014-04-02 12:22:01 -------- d-----w- c:\users\rade\appdata\local\Programs
2014-04-02 12:10:24 7969936 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{df9bd84e-1ac9-4878-819d-5e9e0814613f}\mpengine.dll
2014-04-02 12:10:21 231584 ------w- c:\windows\system32\MpSigStub.exe
2014-04-02 11:58:46 -------- d-----w- c:\users\rade\appdata\local\Skype
2014-04-02 11:58:15 -------- d-----r- c:\program files\Skype
2014-03-25 23:12:58 -------- d-----w- c:\windows\Panther
2014-03-25 17:27:10 -------- d-----w- c:\programdata\mts mobilni internet
2014-03-25 17:26:53 1112288 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01007.dll
2014-03-25 17:25:15 -------- d-----w- c:\programdata\DatacardService
2014-03-25 17:23:35 -------- d-----w- c:\users\rade\appdata\local\Microsoft Games
2014-03-25 15:17:36 -------- d-----w- c:\programdata\AVAST Software
2014-03-25 14:55:41 33104 ----a-w- c:\windows\system32\spool\prtprocs\w32x86\msonpppr.dll
2014-03-25 14:55:41 32592 ----a-w- c:\windows\system32\msonpmon.dll
2014-03-25 14:52:31 -------- d-----w- c:\windows\PCHEALTH
2014-03-25 14:50:34 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2014-03-25 14:49:56 -------- d-----w- c:\users\rade\appdata\local\Microsoft Help
2014-03-25 14:49:51 -------- d-sh--w- c:\windows\Installer
2014-03-25 14:30:55 -------- d-----w- c:\users\rade\appdata\local\Google
2014-03-25 14:30:43 -------- d-----w- c:\users\rade\appdata\local\Deployment
2014-03-25 14:30:43 -------- d-----w- c:\users\rade\appdata\local\Apps
2014-03-25 14:22:22 123904 ----a-w- c:\windows\system32\poqexec.exe
2014-03-25 14:21:43 -------- d-sh--w- C:\Recovery
.
==================== Find3M ====================
.
2014-03-25 17:25:49 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2014-01-24 23:19:42 231960 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
============= FINISH: 14:21:53.86 ===============
Si probao da formatiras ceo disk i na svez win instaliras neki anti-virus?
Imao sam slican problem kao i ti. Sredjaivao sam drugaru komp, formatirao samo jednu particiju i nakon instalacije win-a nije bilo teorije da instaliram niti jedan anti-virus, na bilo koji nacin. Ne znam kako sam skontao, uglavnom problem je bio u nekom virusu koji je "skakao" sa particije na particiju i zarazio exe fajlove. Zaboravio sam ime, da li je ime virusa bilo hijack, ili sam ga eliminisao sa hijack this, ne secam se bas najbolje.
+1Neke od mogucnosti..
Mozda postoji neki av (security) program koji nisi pravilno deinstalirao i pravi conflikt prilikom instalacije ?
Ili je aktiviran "Access Protection rule" u nekom softweru ?
Mozda da probas apdejt/reinstal NET Framework ??
Nisam mogao da odolim..:smoke:nisam to ali me ovo ubija ne znam sta da radim najvjerovatnije da iako je novi sistem da cu ga ponovo morati nositi da mi ga dignu:d:d
Follow along with the video below to see how to install our site as a web app on your home screen.
Napomena: this_feature_currently_requires_accessing_site_using_safari