Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

pomoc oko virusa ?

[es] :: Zaštita :: pomoc oko virusa ?

[ Pregleda: 2496 | Odgovora: 18 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.231.*

Sajt: www.partizan.net


+10 Profil

icon pomoc oko virusa ?29.04.2009. u 18:25 - pre 182 meseci
pozz. pre nekoliko dana sam otvorio temu oko problema sa ADSL -om koji mi se se blokira svakih 2-3 min al to je dr. stvar mada iz tehnicke sluzbe kazu da je do windowsa da trebam instalirati sp3 ili da trebam instalirati neku zakrpu koju nemam pojma koja i gde je naci. Ono sto me sad muci i stavlja u dilemu je to da mi je limit za ovog meseca ispunjen t.e limit mi je 25GB a ja imam potroseno 26GB iako vec mesec dana se mucim sa ADSL-om pa mi je sumljivo to kako sam uspeo potrositi 26GB kad i kad mi je bio ADSL u redu svega sam trosio najvise 15gb dali mozda to neki virus radi ili stavrno sam uspeo da potrosim 26GB u sta sumnjam . komp sam skenirao sa NOD32 ,ZONE ALARM koji od virusa nisu nista pronasli. takodje sam skenitao i sa Spybot-SD koji nije nista pronasao dok ad-awarwe je pronasao 4 cookies i 1 Win 32 Trojan Agent t.e Malware koji je najverojatno bio smesten u C:\System Volume Inf\_\}\RP350\A0254905.exe .sta sledece uraditi?
cepac
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.231.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?29.04.2009. u 18:54 - pre 182 meseci
greskom sam otvorio temu oko hijack this evo ovde

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:47:06, on 29.04.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\blabla.exe\blabla.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\3.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\3.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FC2458DB-B263-48C5-A106-0651B05DF38C} - (no file)
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E5EEA-26DE-40CA-A7C3-58C48134D062}: NameServer = 62.162.32.5 62.162.32.9
O18 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 8601 bytes
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?29.04.2009. u 19:40 - pre 182 meseci
Stiklirajte sledece objekte i kliknite “Fix checked”
R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\3.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\3.bin\A5SRCHAS.DLL (file missing)
O2 - BHO: (no name) - {FC2458DB-B263-48C5-A106-0651B05DF38C} - (no file)
O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL (file missing)
O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\3.bin\ASKTBAR.DLL (file missing)
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O18 - Protocol: KuGoo - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx
O18 - Protocol: KuGoo3 - {6AC4FBC7-AA38-45EC-9634-D6D20B679EFC} - C:\WINDOWS\system32\KuGoo3DownXControl.ocx

Ako ovo nisu vasa podesavanja, obrisite i njih
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E5EEA-26DE-40CA-A7C3-58C48134D062}: NameServer = 62.162.32.5 62.162.32.9

Posle toga restartujte kompjuter i napravite novi log.

Dalje
• Preuzmite i instalirajte program Malwarebytes` Anti-Malware - http://www.malwarebytes.org/mbam-download.php
• Pokrenite ga i izvrsite update (Update > Check for Updates) i po zavrsetku potvrdite sa OK
• Posle update-a odaberi Scanner, oznaci Perform full scan i pritisni Scan
• Kada se skeniranje zavrsi pritisnite OK, pa Show Results da vidite izvestaj.
• Proverite da li su svi pronadjeni fajlovi stiklirani (ako nisu selektujte ih), pritisnite Remove Selected i potvrdite sa OK
• Program ce vas upitati da restartujes racunar i vi to potvrdite
• Takodje posle ukljanjanje malware-a sa racunara dobicete log fajl (izvestaj) koji cete iskopirati ovde

P.S. Ako imate legalan Windows XP onda skinite i instalirajte SP3 - http://www.softwarepatch.com/w...windows-xp-service-pack-3.html
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.233.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 01:30 - pre 182 meseci
Ako ovo nisu vasa podesavanja, obrisite i njih
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E5EEA-26DE-40CA-A7C3-58C48134D062}: NameServer = 62.162.32.5 62.162.32.9 Ovo n
isam obrisao posto se nerazumem u komp a kamoli da nesto podesavam ako je potrebno obrisacu i njega


evo novi log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:28:51, on 30.04.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\VDOTool\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\blabla.exe\blabla.exe.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Gainward] C:\Program Files\VDOTool\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{930E5EEA-26DE-40CA-A7C3-58C48134D062}: NameServer = 62.162.32.5 62.162.32.9
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Google Desktop Manager 5.1.709.19590 (GoogleDesktopManager-091907-194040) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 7427 bytes
cepac
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.237.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 03:49 - pre 182 meseci
evo loga iz malwarebytes nadam se da je to to:)


Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 221890
Time elapsed: 31 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{48d78be5-cfb9-4b66-9ac4-96d4cf21de06} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{74d46bba-5638-473a-83b6-97e7804a7411} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\AppID\orgnavi.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\orgnavi.Video (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


kad sam restartovao komp. izasla mi je poruka iz Security Center ne znam sta je tacno pisalo nesto u vezi computer is risk gde je Automatic Updated bilo na off pa sam ga stavio na "on" isto tako u Security Centetr Firewale je bio na "on" i Virus Protection na "on" pa sad pitam dali je to sto mi je stajalo da mi je Firewal "on" to sto imam instalirano ZONE ALARM i Virus Protection "on" sto imam NOD 32 posto u control panelu stoji da je windows firewal off sto bi bilo logicno jel kolko znam zone alarm ga isklucuje kada se instalira


cepac
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.237.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 04:39 - pre 182 meseci
pozz.da napomenem da mi je dole kod sata izasla zuta ikona nesto u vezi Automatic updates pokrenuo sam update i dosad je download updates stigao na 12% i nije se pomklo pola sata to je izgleda sto mi je sporo radi inernet jel iz telekoma su mi smanjili brzinu jel sam nadmasio limit od 25GB za sta sam i otvorio temu . ono sto bih hteo da pitam je to dali da ostavim Automatik Update ukljucen ili ne posto ovu zutu ikonu prvi put gledam. i dali ukoliko izvrsim update a windows xp sp2 mi nije legalan dali mi moze oboriti sistem posto nesto sam gledao na netu neka pitanja u vezi toga , posto zaista nemam poim dali mi je windows xp legalan ili ne ?
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 14:58 - pre 182 meseci
Ako je legalan XP, necete imati problema. Ako nije, ne bih vam preporucio da se update-ujete.
Log izgleda cisto. Da li jos uvek imate problema?
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.224.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 16:51 - pre 182 meseci
pozz. oko problema to cu da vidim sutra kada mi vrate limit na 0 i zgoleme brzinu tada cu proverti dali mi nesto trosi GB posto sad radim sa namalenom brzinom. posto sada imam na komp.NOD32 ,ZONE ALARAM ,spybot-sd, ad-aware,hijack this,malwarebytes, hteo bi da znam sta od ovo da zadrzim a sta da obrisem da ne bi doslo do medzusebnog sudira ili pak mogu sve da zadrzim?
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?30.04.2009. u 17:44 - pre 182 meseci
HijackThis mozete da izbrisete. Recite mi malo detaljnije o NOD32(samo antivirus?) i ZoneAlarm(bespaltna verzija?).
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.231.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?01.05.2009. u 04:22 - pre 182 meseci
NOD32 imam stariju verziju v2.5 a zone alarm security suite v.7 . nod 32 koristim kao real time zastitu dok zone alarm koristim kao firewal, gde mi je samo spyware uklucen dok antivirus kod zone alarm mi je isklucen t.e off
cepac
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.234.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?01.05.2009. u 06:17 - pre 182 meseci
pokusao sam da obrisem Hijack This iz control panela Add or remove ali mi je izasla sledeca poruka:

Uninstaler Error:

An error occurred while trying to remove Hijack This 2.0.2 It may have already been uninstalled

Would you like to remove Hijack This 2.0.2 the Add or Remove programs list

YES NO

kada pritsnem YES onda program nestane iz control panela u add or remove ali stoji na desktopu gde je i bio znaci nije se obrisao e kad se ponovo vratim u control panel u add or remove opet je tu . sta je ova poruka i kako deinstalirati Hijack This
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?01.05.2009. u 08:43 - pre 182 meseci
1. HijackThis mozete rucno obrisati sa Desktop-a
2. U Add or Remove Programs-u ako se javi greska pritisnite YES(za brisanje)

Ako ne osecate nikakvu usporenost kompjutera, onda mozete da ostavite tako NOD32 i ZoneAlarm zajedno.
Mada bih vam preporucio da predjete na novije verzije.
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.225.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?01.05.2009. u 16:35 - pre 182 meseci
samo da te pozdravim Dashkes i da ti se zahvalim za sav trud koji si ulozio oko resavanja problema :

samo da pitam oko Hijack This dali rucno brisenje ovog programa sa desktopa se podrazumeva ono uobicajeno brisanje dugmetom Delete t.e dali da obelezim folder gde je Hijack This pa pritisnem Delete

pozz jos jednom i hvala
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?01.05.2009. u 16:41 - pre 182 meseci
Nema na cemu, ja sam uvek tu da pomognem ako znam i umem. :)
Da, izaberite folder/fajl i pritisnite Delete.
 
Odgovor na temu

danijell
Banjaluka

Član broj: 85584
Poruke: 29
*.teol.net.



+1 Profil

icon Re: pomoc oko virusa ?05.05.2009. u 19:08 - pre 181 meseci
da li je i dalje aktivan proces
C:\Documents and Settings\User\Desktop\blabla.exe\blabla.exe.exe
to mi je nešto sumnjivo
http://virscan.org/report/192631675770ab1f44ffdb5f6f62220d.html
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?05.05.2009. u 20:36 - pre 181 meseci
Citat:
danijell: da li je i dalje aktivan proces
C:\Documents and Settings\User\Desktop\blabla.exe\blabla.exe.exe
to mi je nešto sumnjivo
http://virscan.org/report/192631675770ab1f44ffdb5f6f62220d.html


Ako se ne varam, to je preimenovani HijackThis.
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.231.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?05.05.2009. u 20:42 - pre 181 meseci
pozz. ovo blabla.exe. je preimenovan hijack this a dali je aktivan proces to ne znam, kako da proverim . inace hijack this sam izbrisao iz desktopa dumetom delete i iz control panela add or remuve . a sta ti je sumlivo sta treba da uradim da vidim dali je aktivan proces
cepac
 
Odgovor na temu

inspektor69
stojko stojkoski
radnik
oh

Član broj: 171524
Poruke: 148
77.29.234.*

Sajt: www.partizan.net


+10 Profil

icon Re: pomoc oko virusa ?05.05.2009. u 20:51 - pre 181 meseci
pozz. ovo blabla.exe. je preimenovan hijack this a dali je aktivan proces to ne znam, kako da proverim . inace hijack this sam izbrisao iz desktopa dumetom delete i iz control panela add or remuve . a sta ti je sumlivo sta treba da uradim da vidim dali je aktivan proces. i posto imam strasnih problema sa ADSL-om zadnjih mecec dana blokira mi se konekcija svakih 1-2min. dali mozda je to zbog nekog aktivnog procesa ili je zbog nedovolnog napajanja el.enrgije kako kazu iz tehnicke poddrske posto samo to znaju da kazu ili je struja ili je virus:)
cepac
 
Odgovor na temu

Dashkes

Član broj: 90973
Poruke: 845



+27 Profil

icon Re: pomoc oko virusa ?05.05.2009. u 21:45 - pre 181 meseci
Pa on i treba da bude aktivan dok pravi log, sada vise nije.

Ako mislite da imate viruse, onda preuzmite program Dr.Web CureIt!.

• Posle preuzimanja restartujte racunar u Safe Mode(dok se pali racunar pritiskaj F8 pa kada se pojavi meni odaberi Safe Mode - prva stavka).
• Kada se ucita Safe Mode pokreni Dr.Web CureIt! pokretanjem fajla launch.exe.
• Kad se upali odaberi Start. On ce automatski poceti da skenira racunar. Pustiti da skenira(to je brzo skeniranje).
• Kada zavrsi sa skeniranjem odaberi kompletno skeniranje - Complete scan i sa desne strane pritisnu dugme Start Scanning(izgleda kao Play dugme).

Moram da te upozorim da kompletno skeniranje moze da potraje nekoliko sati!

[Ovu poruku je menjao Dashkes dana 06.05.2009. u 10:15 GMT+1]
 
Odgovor na temu

[es] :: Zaštita :: pomoc oko virusa ?

[ Pregleda: 2496 | Odgovora: 18 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.