![]() |
| |||||||
| Registracija | Mapa Spy | Member List | Donacije | Pretraživanje | Today's Posts | Označi Sve Forume Kao Pročitane | Forum Rules |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Pozdrav svima Moj računalo je naglo usporila, i treperi stranicama držati up telling me moj sistem mogao biti zaražene i pretplatiti na protu-virus raznim lokacijama, kao što su PC čišći, ultimate branitelj, skeniranje spywarea, sustav upozorenja itd. svaki put kad otvorite novi ekran 4 ili 5 od iste one će pop up. Ja sam trčanje McAfee, adaware protuvirusne i čišći cc nisu gore navedene će ukloniti ovaj. bilo koja savjetuje mnogo poštovati, jer je to driving me nuts Thanks in advance |
|
#2
| |||
| |||
| Hi Shaune. Omogućuje vidjeti što možemo učiniti kako bi vam očistiti gore. Prvo: Ukoliko nemate Spybot Search & Destroy molimo za download.Ovdje Spybot.exe * Kliknite na ikonu za pokretanje instalacije. * Slijedite upute koristite zadane postavke i jednostavno kliknite svoj put kroz Installer koristeći Dalje gumb. * Nakon što je instalacija završi, vidjet ćete Spybot - Search & Destroy gumb na vašem desktopu i start u svom izborniku. Kliknite na nju kako bi pokrenuli Spybot-S & D po prvi put. * Prvi put ste pokrenuli Spybot-S & D, to će prikazati Wizard. + Vrlo je važno da zadržite up-to-date. Budite sigurni da ste provjerili ažuriranja za sada, i koristiti značajku cijepiti. + I predlažemo koristeći Resident SDHelper. + Ja ne aktivirate TeaTimer koji pružaju zaštitu u realnom vremenu, ali je problematično. * Nakon što je završio tutorial, naći ćete se na Postavke ili Ažurirati stranici. + Lijevoj strani program ima navigation bar da vas može dovesti na sve funkcije programa. * Kliknite etiketom Spybot-S & D i ovaj vodi Vas na glavnu stranicu. * Prvi gumb u ovoj alatnoj traci se zove Provjerite postoje li problemi. To je vas pritisnite gumb da biste pokrenuli skeniranju. Zasjesti i gledati skeniranje napredak. + Nakon što je završeno skeniranje možete razlikovati se crvenih stavki, Koji predstavljaju spyware prijetnji i slično, kao i zelena unose, Koji su upotreba pjesme. + Svi problemi prikazan u crveno se smatrati stvarne prijetnje a trebalo bi se bavila. Za zelen Zapisi uklanjanje nije kritično, ali ovisi o vašoj osobnoj sklonosti. * Sada je vrijeme za korištenje Popravi odabrane probleme dugme. Ovo će ukloniti sve prijetnje pronađeno. * Nakon što je učinio za čišćenje Spybot izlaz. Napomena: Neki oblici zlonamjernih programa ne može se ukloniti Spybot na prvi pokušaj. Ako je to slučaj Spybot će vas pitati za uklanjanje stavke prilikom ponovnog pokretanja računala. Nakon ponovnog pokretanja računala pokrenuti Spybot ponovno. Ako se problem i dalje je tu smo da će se baviti uklanjanjem s posebnim alatima. Onemogući TeaTimer Spybot-a tako da se miješati s ispravci HijackThis, 1) Pokreni Spybot-S & D 2) Idi na način izbornika, a pobrinite se "Advanced Mode" je odabrana 3) se nalazi na lijevoj strani odaberite Tools -> Resident 4) Isključite "Resident TeaTimer" i OK bilo koje potiču Možete ponovno omogućite TeaTimer još jednom sustava je čist. ===================== Next: Download HijackThis Ovdje Spremi HJTsetup.exe na Vašu radnu površinu. Dvaput kliknite na HJTsetup.exe ikonu na radnoj površini. Po zadanom će se instalirati C: \ Program Files \ HijackThis. Neke nove verzije spremiti u C: \ Program Files \ Trend Micro \ HijackThis Nastavi da kliknete na Next setup dijalog kutije, sve dok ne dođete do Odaberite Zbrajanje Zadaci dijaloga. Put ček po Kreiraj ikonu Desktopa zatim kliknite Next ponovno. Nastavite slijediti ostatak se potiču od tamo. Na završnoj dijaloški okvir i kliknite Završi da će lansirati Hijack This. Ne stavljajte HijackThis.exe na desktopu ili u Temp folder. To je važno jer će se stvoriti sigurnosne kopije i oni su jednostavno nestati ako nije ispravno instaliran. Važno * * Hijackthis.exe Preimenujte datoteku Analyze.exe. To je važno zbog nekih novih oblika zlonamjernih programa može sakriti od HijackThis.exe. Desnom tipkom miša kliknite na datoteku u HijackThis.exe C: \ Program Files \ HijackThis i izaberite preimenovati. Upišite Analyze.exe i pritisnite tipku Enter. Desni klik na datoteku i poslati Analyze.exe na radnoj površini stvorili prečac. Sljedeći kliknite na "Da li je sustav skenirati i spremanje log datoteku Gumb ". Ona će scan a zatim i prijava će se otvoriti u Notepad. Desni klik na notepad i kliknite "Odaberi sve" Desno klikni opet i odaberite "copy" Lijepljenje se prijaviti u vaš sljedeći odgovor. Nemate Hijack To škripac išta još. Većina onoga što će se pronađe bezopasni ili čak obavezna. ==================== Ako Spybot nađe ništa ne može ukloniti onda molim javite mi. Jednom sam pogled na HijackThis (HJT) log ćemo znati gdje otići odande. |
|
#3
| |||
| |||
| hi opet i puno hvala za pomoć za sve do sada, sam učinio ono što je rekao i to naći razne prijetnje, ali oni su i dalje pojavljuju. log spealed ga je naveden dolje, ako vam mogu biti od bilo kakve daljnje pomoći bi bilo mnogo poštovati, Logfile of Trend Micro HijackThis v2.0.2 Scan spremljena u 18:43:31, dana 25/09/2007 Platforma: Windows XP SP1 (Winnt 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Pokretanje procesa: F: \ WINDOWS \ System32 \ smss.exe F: \ WINDOWS \ system32 \ Winlogon.exe F: \ WINDOWS \ system32 \ services.exe F: \ WINDOWS \ system32 \ lsass.exe F: \ WINDOWS \ system32 \ Svchost.exe F: \ WINDOWS \ System32 \ Svchost.exe F: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe F: \ WINDOWS \ system32 \ spoolsv.exe F: \ WINDOWS \ explorer.exe F: \ Program Files \ QuickTime \ qttask.exe F: \ WINDOWS \ Mixer.exe F: \ Program Files \ Lexmark 6300 Series \ lxcdmon.exe F: \ Program Files \ Lexmark 6300 Series \ ezprint.exe F: \ Program Files \ Musicmatch \ Musicmatch džu-boks \ mm_tray.exe F: \ Program Files \ Musicmatch \ Musicmatch džu-boks \ mmtask.exe F: \ Program Files \ Sony Ericsson \ Mobile2 \ Application Launcher \ Application Launcher.exe C: \ Program Files \ Adobe \ Photoshop Album Starter Edition \ 3,0 \ Apps \ apdproxy.exe F: \ programa ~ 1 \ BTYAHO ~ 1 \ Pomoć \ SMARTB ~ 1 \ MotiveSB.exe F: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ AAWTray.exe F: \ Program Files \ McAfee \ MSK \ MskAgent.exe F: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.exe F: \ Program Files \ Messenger \ msmsgs.exe F: \ Program Files \ BT Yahoo! \ Pomoć \ bin \ mpbtn.exe F: \ Program Files \ Common Files \ Teleca Shared \ Generic.exe F: \ Program Files \ Common Files \ McAfee \ HackerWatch \ HWAPI.exe F: \ programa ~ 1 \ McAfee \ MSC \ mcmscsvc.exe f: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ mna \ mcnasvc.exe F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcods.exe F: \ Program Files \ Sony Ericsson \ Mobile2 \ Mobile Phone Monitor \ epmworker.exe F: \ programa ~ 1 \ McAfee \ MSC \ mcpromgr.exe f: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ mcproxy \ mcproxy.exe f: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ redirsvc \ redirsvc.exe F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcshield.exe F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcsysmon.exe F: \ Program Files \ McAfee \ MPF \ MPFSrv.exe F: \ programa ~ 1 \ McAfee \ MJS \ mps.exe f: \ programa ~ 1 \ mcafee.com \ agent \ mcagent.exe F: \ Program Files \ McAfee \ MSK \ MskSrver.exe F: \ Program Files \ SiteAdvisor \ 6172 \ SAService.exe F: \ WINDOWS \ System32 \ Svchost.exe F: \ Program Files \ McAfee \ MJS \ mpsevh.exe F: \ Program Files \ Yahoo! \ Preglednik \ ybrowser.exe F: \ WINDOWS \ System32 \ lxcdcoms.exe F: \ WINDOWS \ System32 \ wuauclt.exe F: \ programa ~ 1 \ Yahoo! \ Preglednik \ ycommon.exe F: \ Program Files \ Yahoo! \ Preglednik \ ybrwicon.exe F: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ lxcdPSW X. exe F: \ Program Files \ Trend Micro \ analyze.exe \ analyzeexe.exe R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/ R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://home.bt.yahoo.com R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://uk.red.clientapps.yahoo.com/c...o/bt_side.html R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/ R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://home.bt.yahoo.com R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://uk.red.clientapps.yahoo.com/c...rch.yahoo.com/ R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Postavke, ProxyOverride = 127.0.0.1 R3 - URLSearchHook: BT Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - F: \ Program Files \ Yahoo! \ Companion \ Instalira \ cpn \ ycomp5_3_17_0. dll O2 - BHO: Yahoo! Companion BHO - (02478D38-C3F9-4efb-9B51-7695ECA05670) - F: \ Program Files \ Yahoo! \ Companion \ Instalira \ cpn \ ycomp5_3_17_0. dll O2 - BHO: Adobe PDF Reader Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - F: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll O2 - BHO: (no name) - (089FD14D-132B-48FC-8861-0048AE113215) - F: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.dll O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - F: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O2 - BHO: scriptproxy - (7DB2D5A0-7241-4E79-B68D-6309F01C5231) - F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ scriptcl.dll O2 - BHO: McAfee Popup Blocker - C68AE9C0 (-0909-4DDC-B661-C1AFB9F5AE53) - F: \ programa ~ 1 \ McAfee \ MPS \ mcpopup.dll O3 - Toolbar: & Radio - (8E718888-423F-11D2-876E-00A0C9082467) - F: \ WINDOWS \ System32 \ msdxm.ocx O3 - Toolbar: BT Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - F: \ Program Files \ Yahoo! \ Companion \ Instalira \ cpn \ ycomp5_3_17_0. dll O3 - Toolbar: McAfee SiteAdvisor - (0BF43445-2F28-4351-9252-17FE6E806AA0) - F: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.dll O4 - HKLM \ .. \ Run: [QuickTime Task] "F: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [C-Media mixer] Mixer.exe / pokretanja O4 - HKLM \ .. \ Run: [lxcdmon.exe] "F: \ Program Files \ Lexmark 6300 Series \ lxcdmon.exe" O4 - HKLM \ .. \ Run: [EzPrint] "F: \ Program Files \ Lexmark 6300 Series \ ezprint.exe" O4 - HKLM \ .. \ Run: [FaxCenterServer] "F: \ Program Files \ Lexmark Faks Rješenja \ fm3032.exe" / s O4 - HKLM \ .. \ Run: [MMTray] "F: \ Program Files \ Musicmatch \ Musicmatch džu-boks \ mm_tray.exe" O4 - HKLM \ .. \ Run: [mmtask] "F: \ Program Files \ Musicmatch \ Musicmatch džu-boks \ mmtask.exe" O4 - HKLM \ .. \ Run: [Sony Ericsson PC Suite] "F: \ Program Files \ Sony Ericsson \ Mobile2 \ Application Launcher \ Application Launcher.exe" / startoptions O4 - HKLM \ .. \ Run: [Adobe Photo Downloader] "C: \ Program Files \ Adobe \ Photoshop Album Starter Edition \ 3,0 \ Apps \ apdproxy.exe" O4 - HKLM \ .. \ Run: [pokretačkoj SmartBridge] F: \ programa ~ 1 \ BTYAHO ~ 1 \ Pomoć \ SMARTB ~ 1 \ MotiveSB.exe O4 - HKLM \ .. \ Run: [AAWTray] F: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ AAWTray.exe O4 - HKLM \ .. \ Run: [MskAgentexe] F: \ Program Files \ McAfee \ MSK \ MskAgent.exe O4 - HKLM \ .. \ Run: [SiteAdvisor] F: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.exe O4 - HKLM \ .. \ Run: [LXCDCATS] rundll32 F: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ LXCDtim e.dll, _RunDLLEntry @ 16 O4 - HKLM \ .. \ Run: [MBkLogOnHook] F: \ Program Files \ McAfee \ MBK \ LogOnHook.exe O4 - HKCU \ .. \ Run: [Yahoo! Pager] F: \ Program Files \ Yahoo! \ Messenger \ ypager.exe-tišina O4 - HKCU \ .. \ Run: [MSMSGS] "F: \ Program Files \ Messenger \ msmsgs.exe" / background O4 - HKCU \ .. \ Run: [AdobeUpdater] F: \ Program Files \ Common Files \ Adobe \ Updater5 \ AdobeUpdater.exe O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] F: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] F: \ WINDOWS \ System32 \ Ctfmon.exe (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] F: \ WINDOWS \ System32 \ Ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] F: \ WINDOWS \ System32 \ Ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] F: \ WINDOWS \ System32 \ Ctfmon.exe (User 'Default user') O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Reader \ reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C: \ Reader \ AdobeCollabSync.exe O4 - Global Startup: BT Yahoo! Help.lnk = f: \ Program Files \ BT Yahoo! \ Pomoć \ bin \ matcli.exe O4 - Global Startup: Microsoft Office.lnk = f: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE O8 - Extra kontekst meni stavka: E & zvezi u Microsoft Excel - res: / / F: \ programa ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000 O9 - Extra button: BT Yahoo! Sidebar - (51085E3D-A958-42A2-A6BE-A6A9B0BAF276) - F: \ Program Files \ Yahoo! \ Preglednik \ ysidebarIE.dll O9 - Extra 'Tools' MENUITEM: BT & Yahoo! Sidebar - (51085E3D-A958-42A2-A6BE-A6A9B0BAF276) - F: \ Program Files \ Yahoo! \ Preglednik \ ysidebarIE.dll O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - F: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' MENUITEM: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - F: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - F: \ Program Files \ Messenger \ MSMSGS.EXE O9 - Extra 'Tools' MENUITEM: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - F: \ Program Files \ Messenger \ MSMSGS.EXE O21 - SSODL: msmdev - (B71E88D1-41DA-3158-877B-AD1C15040A30) - F: \ WINDOWS \ msmdev.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - F: \ Program Files \ Lavasoft \ Ad-Aware 2007 \ aawservice.exe O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc - F: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ EmProxy \ emproxy.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F: \ Program Files \ Common Files \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe O23 - Service: lxcd_device - Unknown vlasnika - F: \ WINDOWS \ System32 \ lxcdcoms.exe O23 - Service: MBackMonitor - McAfee - F: \ Program Files \ McAfee \ MBK \ MBackMonitor.exe O23 - Service: McAfee HackerWatch Service - McAfee, Inc - F: \ Program Files \ Common Files \ McAfee \ HackerWatch \ HWAPI.exe O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ MSC \ mcupdmgr.exe O23 - Service: McAfee Usluge (mcmscsvc) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ MSC \ mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc - F: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ mna \ mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcods.exe O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ MSC \ mcpromgr.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - F: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ mcproxy \ mcproxy.exe O23 - Service: McAfee preusmjerivač Service (McRedirector) - McAfee, Inc - F: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ McAfee \ redirsvc \ redirsvc.exe O23 - Service: McAfee stvarnom vremenu Scanner (McShield) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc - F: \ Program Files \ McAfee \ MPF \ MPFSrv.exe O23 - Service: McAfee privatnosti Service (MPS9) - McAfee, Inc - F: \ programa ~ 1 \ McAfee \ MJS \ mps.exe O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc - F: \ Program Files \ McAfee \ MSK \ MskSrver.exe O23 - Service: SiteAdvisor Service - Unknown vlasnika - F: \ Program Files \ SiteAdvisor \ 6172 \ SAService.exe O23 - Service: YPCService - Yahoo! Inc - F: \ WINDOWS \ system32 \ YPCSER ~ 1.EXE -- End of file - 10590 bytes |
|
#4
| |||
| |||
| Bok. Prvo idite u Spybot i isključivanje Tea Timer, tako da ne blokira bilo kojeg ispravke. Možete ga natrag poslije smo učinili. Napravite HijackThis skeniranja i mjesto ček pored ovih predmeta: R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2 O21 - SSODL: msmdev - (B71E88D1-41DA-3158-877B-AD1C15040A30) - F: \ WINDOWS \ msmdev.dll Sada, zatvorite sve slučajeve Internet Explorer i sve druge prozore koje ste otvorili osim HiJackThis, Kliknite na "Fix checked". ========================= 1. Preuzmi ovu datoteku combofix.exe 2. Dvaput kliknite combofix.exe i slijedite upute. 3. Kada završite, on će proizvesti prijava za vas. Pošta da se prijavite u vaš sljedeći odgovor. Napomena: Ne mouseclick combofix's prozor dok je pokrenut. Svibanj uzrokovati da ga zatajiti. U sljedećem post molim dodati. Prijavite Combofix Svježa HijackThis Log Također javite mi kako stvari stoje sada. |