Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Kocenje...pomozite....

[es] :: Zaštita :: Kocenje...pomozite....

Strane: 1 2

[ Pregleda: 6042 | Odgovora: 24 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Kocenje...pomozite....25.12.2008. u 01:59 - pre 186 meseci
Kupila laptop skoro, tako da se bas i ne razumem u sve te probleme....

Prikljucila net, gledala neke real arcade screen saver-e, instalirala neki bezvezni i od tada mi se laptop stalno koci. Ukoci se apsolutno sve i moram ga restartovati. To se dogadjalo bas cesto. Imala antivirus. Rekli mi da reinstaliram sistem, da je neki gadan virus tu bio.... Renstalirala sistem, proslo nekoliko dana i opet se ukocio nekoliko puta....Desava se da to bude 10 puta zaredom, a nekad nema da koci duzi period.
Rekli mi da je mozda do ovog kabla za net, posto imam bezicni net...ne znam....
Onda se neko javio i rekao mi da uradim sledece: ubaci instalacioni cd service packa kojeg imas i pokreni Command Promt(start+run+cmd)i ukucaj sfc /scannow (obavezno pazi na razmak)
ja nemam cd instaliranog windows-a.....

Zaista ne znam u cemu je problem i sta da radim....
Posto se ja apsolutno ne razumem u sve to, molila bih da mi pomogne neko ko zna.....

Unapred zahvalna.....
 
Odgovor na temu

Boris

Član broj: 82
Poruke: 450

ICQ: 100801505


+2 Profil

icon Re: Kocenje...pomozite....25.12.2008. u 02:39 - pre 186 meseci
Prvo nemoj da posljas na ubijanje :D, znam da se shalish ali polako.

Moguce da ti je neki trojanac, virus, i sl. upao u sistem.

nabavi neki AntiVirus, snadji se, moze neki free, AVG, Avira ili Avast...

Skini http://www.malwarebytes.org/mbam.php
udji u safemod i skeniraj sa tim programom sto skines kompjuter i ocisti ga.

u safemode ulazis tako sto pre nego sto ti se podigne Windows stiskash dugme f8 dok ti se ne pojave opcije, ti izaberes opciju safe mode i posle skeniraj.

I da treba ti neko(komsija, komsinica, brat, tetka, zet, kolega) ko se razume malo u kompjutere da ti objasni neke osnovne stvarchice, da se en bi nervirala i u buduce :))).
[::b0ris::]
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....25.12.2008. u 02:47 - pre 186 meseci
Hvala ti Borise, imala avast tada....a imam i sada....

ok probacu, ali ja se plasila da nije nesto do laptopa.....

hvala ti puno....
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....25.12.2008. u 03:40 - pre 186 meseci
E, uradila i to....skenirala u safe modu....

Jednom u safe modu ukoci....pa morala opet....skenirala i objects infected: 0

dva puta ukocio, treci put podigla sistem ponovo normalno....joooj...boze.....

I sta sad.....
 
Odgovor na temu

Miroslav Cvejić
Technical Lead
Revel Systems UAB
Vilnius, Lithuania

Član broj: 802
Poruke: 6610
91.148.113.*



+536 Profil

icon Re: Kocenje...pomozite....25.12.2008. u 04:28 - pre 186 meseci
Da li si možda obrisala dotične screen savere?
 
Odgovor na temu

Rumpletstilskin

Član broj: 42454
Poruke: 297
195.229.237.*



+13 Profil

icon Re: Kocenje...pomozite....25.12.2008. u 08:04 - pre 186 meseci
A da odneses laptop u servis? Kazes da je skoro kupljen, pretpostavljam da je pod garancijom, pa nek oni to rese.

I koji je lap u pitanju?
If there's ever a time when I've matured to the point that I don't want to look at camera-phone-titties, go ahead and bury me in a shallow grave by the railroad tracks.
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Kocenje...pomozite....25.12.2008. u 13:06 - pre 186 meseci
@M a k a
postavi HJT log

http://www.majorgeeks.com/download5554.html
Stavi ga u zaseban Folder na Desktop
nazovi taj Folder i HJT program u Systav.exe
pokreni ga...
do a system scan and save the logfile
postavi log koji se na kraju pojavi
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....27.12.2008. u 00:33 - pre 186 meseci
Miroslave, da obrisala sam....


Rumpletstilskin ja sam razmisljala o tome, jednom sam ga nosila i rekli mi da mora da se reinstalira....ja sam to uradila i nista....pod garancijom je, radi se o MSI laptopu....

Magna86, ok....
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....05.01.2009. u 00:43 - pre 186 meseci
Jel iko ima pojma?
 
Odgovor na temu

magna86
Anti Malware Fighter

Član broj: 189287
Poruke: 557

Sajt: www.mycity.rs/Ambulanta


+16 Profil

icon Re: Kocenje...pomozite....05.01.2009. u 04:58 - pre 186 meseci
Citat:
M a k a: Jel iko ima pojma?

pa postavi HjT log...
mozda neki softwer ili ostatak programa pravi problem
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....12.01.2009. u 02:38 - pre 186 meseci
Citat:
magna86: @M a k a
postavi HJT log

http://www.majorgeeks.com/download5554.html
Stavi ga u zaseban Folder na Desktop
nazovi taj Folder i HJT program u Systav.exe
pokreni ga...
do a system scan and save the logfile
postavi log koji se na kraju pojavi



magna, skinula sam to sa linka koji je ostavljen....nisam bas skapirala....buduci da se ne razumem bas u sve to...HJT je neka skracenica ili sta? ako hoces ostavi mi malo detaljnije sta da uradim....jer ovo sto sam skinula trebam instalirati.... ali nisam razumela ovo "i HJT program u Systav.exe".....
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....12.01.2009. u 02:58 - pre 186 meseci
valjda sam se snasla :)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:56:48, on 12/1/2552
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe -H
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Styler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{D5218969-286C-4DC3-AA6A-210D98C6F6EA}: NameServer = 10.10.8.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Oz128 Driver\o2flash.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - Unknown owner - hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,6b,00,20,00,57,00,75,00,64,00,66,00,53,00,65,00,72,00,76,00,69,00,63,00,65,00,47,00,72,00,6f,00,75,00,70,00,00,00 (file missing)

--
End of file - 7783 bytes
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
82.208.201.*

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Kocenje...pomozite....12.01.2009. u 09:26 - pre 186 meseci
@Maka da te pitam, da li koristis originalni Windows ili piratsku modifikaciju poznatiju kao LastXP?
 
Odgovor na temu

zexoni
Beograd

Član broj: 114933
Poruke: 67
*.vektor.net.



Profil

icon Re: Kocenje...pomozite....12.01.2009. u 12:11 - pre 186 meseci
Jeste da je moderator savetovao da otvorim novu temu vezano za moj problem,ali mislim da je ova sasvim odgovarajuca.I meni se u zadnjih 5-6 dana prilicno usporio komp.Kao sto sam vec napisao u jednom odgovoru,Bitdefender,ad-aware,spybot i malware bites antimalware ne nalaze nista.A nisam u skorije vreme nista ni inst.Pa ko se bolje razume neka pogleda,evo hijack this i combo fix loga
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:05:52 PM, on 1/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\Zeljko Jovanovic\My Documents\RAZNI PROGRAMI\USDownloader-Lite_O14V39B0\USDownloader-Lite O14V39B0\USDownloader.exe
C:\Documents and Settings\Zeljko Jovanovic\My Documents\RAZNI PROGRAMI\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.vektor.net:8080
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /install
O4 - HKLM\..\Run: [NvMediaCenter] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.co...t/wuweb_site.cab?1205084409921
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia....ockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 7138 bytes

ComboFix 09-01-09.03 - Zeljko Jovanovic 2009-01-12 8:42:28.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.270 [GMT 1:00]
Running from: c:\documents and settings\Zeljko Jovanovic\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: ActiveArmor Firewall *disabled*
FW: Bitdefender Firewall *enabled*
* Created a new restore point

[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF
-------\Service_NPF


((((((((((((((((((((((((( Files Created from 2008-12-12 to 2009-01-12 )))))))))))))))))))))))))))))))
.

2009-01-02 17:35 . 2009-01-02 17:35 1,572,918 --a------ c:\windows\ACD Wallpaper.bmp
2009-01-02 14:01 . 2009-01-02 14:01 <DIR> d-------- c:\program files\Common Files\Apple
2009-01-02 14:00 . 2009-01-02 14:00 <DIR> d-------- c:\program files\Apple Software Update
2009-01-02 14:00 . 2009-01-02 14:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Apple
2008-12-23 12:19 . 2008-12-23 12:21 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-23 11:02 . 2008-12-23 11:02 603,904 --a------ c:\windows\system32\TUProgSt.exe
2008-12-23 11:02 . 2008-12-23 11:02 360,192 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-12-23 11:02 . 2008-12-11 13:31 27,904 --a------ c:\windows\system32\uxtuneup.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-11 00:22 --------- d-----w c:\documents and settings\Zeljko Jovanovic\Application Data\mIRC
2009-01-10 18:14 --------- d-----w c:\program files\mIRC
2009-01-09 22:16 --------- d-----w c:\documents and settings\Zeljko Jovanovic\Application Data\Skype
2009-01-09 22:04 --------- d-----w c:\documents and settings\Zeljko Jovanovic\Application Data\skypePM
2009-01-08 10:21 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-04 17:38 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-04 17:38 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-02 13:01 --------- d-----w c:\program files\QuickTime
2009-01-02 13:00 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-12-23 10:02 --------- d-----w c:\program files\TuneUp Utilities 2009
2008-12-20 18:24 --------- d-----w c:\program files\Opera
2008-12-20 18:17 --------- d-----w c:\program files\Common Files\Adobe
2008-12-09 10:43 --------- d-----w c:\documents and settings\Zeljko Jovanovic\Application Data\Malwarebytes
2008-12-09 10:43 --------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-09 10:21 --------- d-----w c:\documents and settings\All Users\Application Data\TuneUp Software
2008-12-09 10:20 --------- d-sh--w c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2008-12-09 09:41 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-09 09:36 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-27 13:06 --------- d-----w c:\program files\AviSynth 2.5
2008-11-27 13:05 --------- d-----w c:\program files\eRightSoft
2008-11-21 15:28 --------- d-----w c:\program files\Backspin Billiards
2008-11-11 19:34 164 ----a-w C:\install.dat
2005-03-16 13:26 1,765,376 ----a-w c:\program files\Skin.exe
2003-08-01 09:34 798,794 ----a-w c:\program files\JpegCompressDll.dll
2003-07-30 15:59 221,260 ----a-w c:\program files\MJPEGCompressDll.dll
2002-10-31 08:22 340,054 ----a-w c:\program files\Mpeg1Dll.dll
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 --sh--r c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-07-20 847872]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-14 7323648]
"nwiz"="c:\windows\system32\nwiz.exe" [2005-12-14 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-14 86016]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-15 368640]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.HFYU"= huffyuv.dll
"VIDC.VP31"= vp31vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_10\bin\jusched.exe"
"ehTray"=c:\windows\ehome\ehtray.exe
"PCSuiteTrayApplication"=c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup
"RemoteControl"=c:\windows\system32\rmctrl.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11989:TCP"= 11989:TCP:BitComet 11989 TCP
"11989:UDP"= 11989:UDP:BitComet 11989 UDP

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-01-25 86792]
R3 PAC207;VideoCAM GE111;c:\windows\system32\drivers\PFC027.sys [2005-04-08 162176]
R4 TuneUp.ProgramStatisticsSvc;TuneUp Program Statistics Service;c:\windows\system32\TUProgSt.exe [2008-12-23 603904]
S3 ZD1201U(TwinMOS);TwinMOS Netkey(B241) Wireless LAN Driver (USB)(TwinMOS);c:\windows\system32\drivers\ZD1201U.sys [2008-08-22 55040]
S3 ZDNDIS5;ZDNDIS5 NDIS Protocol Driver;c:\windows\system32\ZDNDIS5.sys [2008-08-22 15872]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-01-12 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-12-11 21:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyServer = proxy.vektor.net:8080
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-12 08:47:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\ATKKBService.exe
c:\windows\ehome\ehSched.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PAStiSvc.exe
c:\program files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
c:\program files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe
c:\program files\BitDefender\BitDefender 2008\vsserv.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-12 8:49:48 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-12 07:49:37

Pre-Run: 52,816,678,912 bytes free
Post-Run: 52,976,955,392 bytes free

158
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
82.208.201.*

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Kocenje...pomozite....12.01.2009. u 18:02 - pre 186 meseci
Postavi HijackThis log po ovom uputstvu.


Skini HiJackThis program:


Stavi ga u zaseban Folder na Desktop
Promeni naziv Foldera u ES2 i Programa u ES2.exe

* Pokreni HijackThis
* Izaberi opciju "Do a system scan and save the logfile"
* Na kraju skeniranja program ce izbaciti tekstualni log.
* taj log kopiraj ovde ( opcije copy / paste)
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....12.01.2009. u 22:18 - pre 186 meseci
Citat:
kristi1: @Maka da te pitam, da li koristis originalni Windows ili piratsku modifikaciju poznatiju kao LastXP?


kristi1- nije originalni windows, bio je kad sam ga kupila ali su mi savetovali da ga zbog virusa reinstaliram, drug mi je reinstalirao i ovo je modifikacija, oprosti ali se ne razumem u to, jedino sto znam je da podseca na vistu :)
 
Odgovor na temu

kristi1

Član broj: 151211
Poruke: 2012
82.208.201.*

Sajt: www.mycity.rs/Ambulanta


+88 Profil

icon Re: Kocenje...pomozite....12.01.2009. u 22:40 - pre 186 meseci
U tvom logu nema malware-a, predlazem ti da instaliras Windows sp2 Profesional, verovatni uzrok tvog problema je ta verzija modifikovanog Windowsa. Desava se da na nekim racunarima radi, a na drugim pravi probleme.
 
Odgovor na temu

mt2807

Član broj: 86041
Poruke: 134
91.148.78.*



+1 Profil

icon Re: Kocenje...pomozite....12.01.2009. u 22:49 - pre 186 meseci
Meni se cini da je ona rekla da joj je i sa prvim windowsom bilo slicnih problema, tako da win mislim da nije Maka moguce da ti problem pravi neki eksterni uredjaj koji si prikacila na laptop ili je problem do laptopa posto je vrlo mala verovatno da ti se na dva windowsa javlja isti problem a da je rec do softwera znaci jedino je moguce da su od softvera problem drajveri koje se negde ne slazu ili je problem do laptopa zato ako nemas nikog ko se bolje razume u kompjutere odnesi ti njega u servis i reci ocu moje pare ili ga popravite :))))))
Vlada
 
Odgovor na temu

M a k a

Član broj: 206154
Poruke: 11
*.ptt.rs.



Profil

icon Re: Kocenje...pomozite....12.01.2009. u 23:03 - pre 186 meseci
Citat:
kristi1: U tvom logu nema malware-a, predlazem ti da instaliras Windows sp2 Profesional, verovatni uzrok tvog problema je ta verzija modifikovanog Windowsa. Desava se da na nekim racunarima radi, a na drugim pravi probleme.


bio je instaliran vec...

Citat:
mt2807: Meni se cini da je ona rekla da joj je i sa prvim windowsom bilo slicnih problema, tako da win mislim da nije Maka moguce da ti problem pravi neki eksterni uredjaj koji si prikacila na laptop ili je problem do laptopa posto je vrlo mala verovatno da ti se na dva windowsa javlja isti problem a da je rec do softwera znaci jedino je moguce da su od softvera problem drajveri koje se negde ne slazu ili je problem do laptopa zato ako nemas nikog ko se bolje razume u kompjutere odnesi ti njega u servis i reci ocu moje pare ili ga popravite :))))))


tako je bio je instaliran, i opet isto....primetila sam obavezno kada izvadim kabl od neta, obavezno se ukoci...ali nekad ne mogu ni sistem da pokrenem, ukoci se pri pokretanju....drug je takodje rekao da je do tih drajvera...ipak hvala vam....
 
Odgovor na temu

mt2807

Član broj: 86041
Poruke: 134
91.148.78.*



+1 Profil

icon Re: Kocenje...pomozite....12.01.2009. u 23:09 - pre 186 meseci
Evo ti mali savet cisto da budes kolko tolko sigurna dal je do tog modema kad uspes da dignes sistem ti idi na uninstal tog modema i drajvera i probaj da ga koristis malo pa vidi dal radi normalno ako radi onda probaj sa neta da skines nove drajvere za taj modem pa probaj ponovo ako i onda imas problema onda menjaj modem ili ako si kod nekog provajdera ne znam koji net koristis trazi da ti daju neki drugi modem ili jos bolje ruter pozz
Vlada
 
Odgovor na temu

[es] :: Zaštita :: Kocenje...pomozite....

Strane: 1 2

[ Pregleda: 6042 | Odgovora: 24 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.