Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Proces u memoriji - j?vaw.exe

[es] :: Zaštita :: Proces u memoriji - j?vaw.exe

[ Pregleda: 2338 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

Alex DeLarge
Bgd

Član broj: 45918
Poruke: 22
*.f.bg.ac.yu.

Sajt: www.alexdelarge.net


Profil

icon Proces u memoriji - j?vaw.exe17.04.2005. u 21:34 - pre 231 meseci
Ne detektuje ga Kasperski ni Adaware. Ali mi zato iskace u AdWatch-u svaki put kad hocu da otvorim novu stranu na internetu. Javlja mi sledece:

Harmful process identified
Object:j?vaw.exe
Path:C:/WINDOWS/system32
Category: Malware
Vendor: ClickSpring
Comment: This object was found active in memory


Kako da se ovoga oslobodim? Pokusala sam da ga nadjem u system 32 ali ga tamo naravno nema. Ni jedan antivirus ga ne detektuje (ni Anti Trojan dok skenira memoriju). Heeelp!

Out of sight, still in mind, but never mind.
 
Odgovor na temu

VRKY

Član broj: 21087
Poruke: 4690
*.adsl.net.t-com.hr.



+8 Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 21:56 - pre 231 meseci
1.) Provaj s HijackThis
2.) Pogledaj startup fajlove (Start>Run>msconfig)
3.) Vidi je li aktivan u procesim ako da ubijaj gamad
4.) Potraži je li gdje na računalu iskopiran (Start>Search)
...
Prikačeni fajlovi
 
Odgovor na temu

Alex DeLarge
Bgd

Član broj: 45918
Poruke: 22
*.bg.ac.yu
Via: [es] mailing liste

Sajt: www.alexdelarge.net


Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 22:29 - pre 231 meseci
>
>
HijackThis nece da obrise nista dok ne ubacim br. registracije, a to
mora da se plati :(
U procesima nije aktiviran.
Gledala sam vec da li postoji u kompu ali nisam mogla da ga nadjem.
Kad aktiviram "msconfig", sta da radim?
Out of sight, still in mind, but never mind.
 
Odgovor na temu

VRKY

Član broj: 21087
Poruke: 4690
*.adsl.net.t-com.hr.



+8 Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 22:34 - pre 231 meseci
Otiđi na jezičak Startup i pogledaj nalazi li se na listi taj fajl...AKo da ukloni ga.
 
Odgovor na temu

Alex DeLarge
Bgd

Član broj: 45918
Poruke: 22
*.bg.ac.yu
Via: [es] mailing liste

Sajt: www.alexdelarge.net


Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 22:51 - pre 231 meseci
>
>
Nalazi se neki javaw, ali to nije j?vaw, otkud znam. Nemam pojma da li
je to isti fajl
Out of sight, still in mind, but never mind.
 
Odgovor na temu

wex-alpha
Sarajevo

Član broj: 7580
Poruke: 845
*.dlp185.bih.net.ba.



+13 Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 22:59 - pre 231 meseci
Pogledaj u registriju sljedecu vrijednost:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

I jednostavno izbrisi sumnjive unose.
 
Odgovor na temu

Alex DeLarge
Bgd

Član broj: 45918
Poruke: 22
*.bg.ac.yu
Via: [es] mailing liste

Sajt: www.alexdelarge.net


Profil

icon Re: Proces u memoriji - j?vaw.exe17.04.2005. u 23:13 - pre 231 meseci
>
>

Reci mi molim te kako to da uradim. Kako da pogledam registry.
Out of sight, still in mind, but never mind.
 
Odgovor na temu

VRKY

Član broj: 21087
Poruke: 4690
*.adsl.net.t-com.hr.



+8 Profil

icon Re: Proces u memoriji - j?vaw.exe19.04.2005. u 19:09 - pre 231 meseci
Marko je upravu što se tiče imena fajla, ma provaj. Dobit ćeš ovaku poruku:




I provaj s ovim HijackThis-om, mislim da za njega nije potrebna registracija

http://www.elitesecurity.org/poruka/fajluzporuku/717945


[Ovu poruku je menjao VRKY dana 19.04.2005. u 20:20 GMT+1]
Prikačeni fajlovi
 
Odgovor na temu

mulaz
Ljubljana

Član broj: 47602
Poruke: 2239
*.dsl.siol.net.

Jabber: mulaz@elitesecurity.org
Sajt: www.mulaz.org


+184 Profil

icon Re: Proces u memoriji - j?vaw.exe19.04.2005. u 19:12 - pre 231 meseci
mozda je neki simbol koji nije podrzan u locel charsetu, mozda i neki znak iz cirilice kojeg windows napise kao '?'
Bolje ispasti glup nego iz aviona
http://www.mulaz.org/
 
Odgovor na temu

Alex DeLarge
Bgd

Član broj: 45918
Poruke: 22
*.f.bg.ac.yu.

Sajt: www.alexdelarge.net


Profil

icon Re: Proces u memoriji - j?vaw.exe19.04.2005. u 20:23 - pre 231 meseci
Ok, evo ga HijackThis log. Sta da brisem!

Logfile of HijackThis v1.97.7
Scan saved at 21:09:05, on 19.4.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\Program Files\Protector Plus\PPAVMon.exe
C:\Program Files\Protector Plus\PPServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\Program Files\EzButton\CPLDBL10.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\TrojanShield\AntiTroj.exe
C:\Program Files\TrojanShield\st.exe
C:\Program Files\ICQLite\ICQLite.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://webmail.f.bg.ac.yu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.f.bg.ac.yu:8080
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - C:\WINDOWS\mslagent\4b_1,0,1,2_mslagent.dll (file missing)
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {A1051613-AAF7-DD05-D16F-8E1D84614095} - C:\WINDOWS\system32\vnnxgjud.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CPLDBL10] C:\Program Files\EzButton\CPLDBL10.EXE
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.1\THGuard.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: TrojanShield.lnk = C:\Program Files\TrojanShield\Init.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxmk133YYUS
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Download...bridge-c361.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe...etup1.0.0.8.cab
O16 - DPF: {26D73573-F1B3-48C9-A989-E6CE071957A1} - http://akamai.downloadv3.com/binaries/EGDA...ESS_1057_XP.cab
O16 - DPF: {2AEEAC34-FD74-4142-B891-4B05C0C03C87} - http://akamai.downloadv3.com/binaries/Dial...054_pack_XP.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binaries/IA/nethv32_EN_XP.cab
O16 - DPF: {50AD557E-3426-41FD-AFDD-2AF39BB1C387} - http://akamai.downloadv3.com/binaries/Live...ice_5_EN_XP.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.com/CAB/...B?38053.0184375
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {D7B59209-0ED9-4986-BD4A-527BE836C6B2} - http://akamai.downloadv3.com/binaries/Dial...ICE_1049_XP.cab
O16 - DPF: {E3943A24-2F83-4505-9AE5-F705E81B50CB} - http://akamai.downloadv3.com/binaries/EGDA...ESS_1055_XP.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.companion....ebio5_1_6_0.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} - http://akamai.downloadv3.com/binaries/IA/netslv32_EN_XP.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{93B7956E-F778-43D0-96B4-1E287F9C367A}: NameServer = 147.91.75.1 147.91.1.5
Out of sight, still in mind, but never mind.
 
Odgovor na temu

[es] :: Zaštita :: Proces u memoriji - j?vaw.exe

[ Pregleda: 2338 | Odgovora: 12 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.