![]() |
| |||||||
| Registracija | Mapa Spy | Member List | Donacije | Pretraživanje | Today's Posts | Označi Sve Forume Kao Pročitane | Forum Rules |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Hi, moj računalo izgleda da ima neke štetne sadržaje koje sam otkrio kad moj stric povezani njegov USB ključ. Avast skeniranja nađe neke stvari, ali nije mogla čisto / uklonite. Defender skenirat će zamrznuti nakon oko 7 minuta. A MBAM punim scan smrznuti i nakon 5 minuta, ali se brzo skeniranje je ok. Evo logs: Avast: 18/06/2009 11:07:37 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "D: \ čistač \ S-1-5-21-1214440339-602162358-839522115-1003 \ Dd16 \ Outlook.pst \ osobnih mapa \ Vrh osobnih mapa \ Inbox \ UPS praćenje Broj 7124353990 \ UPS_INVOICE_978172.zip \ UPS_INVOICE_9781 72.exe "file. 18/06/2009 11:06:59 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "D: \ čistač \ S-1-5-21-1214440339-602162358-839522115-1003 \ Dd16 \ Outlook.pst \ osobnih mapa \ Vrh osobnih mapa \ izbrisane stavke \ UPS praćenje Broj 7124353990 \ UPS_INVOICE_978172.zip \ UPS_INVOICE_9781 72.exe "file. 18/06/2009 11:06:59 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "D: \ čistač \ S-1-5-21-1214440339-602162358-839522115-1003 \ Dd16 \ Outlook.pst \ osobnih mapa \ Vrh osobnih mapa \ izbrisane stavke \ UPS praćenje Broj 0762005263 \ invoice_8712.zip \ INVOICE_8712.exe "file. 18/06/2009 11:06:58 AM 3652 korisnika znak "Win32: Agent-AAPS [Trj]" je pronađen u "D: \ čistač \ S-1-5-21-1214440339-602162358-839522115-1003 \ Dd16 \ Outlook.pst \ osobnih mapa \ Vrh osobnih mapa \ izbrisane stavke \ UPS praćenje Broj 3508422599 \ ups_invoice.zip \ ups_invoice.exe "file. 18/06/2009 10:42:55 AM 3652 korisnika znak "Win32: Trojan-gen Ostala ()" je pronađen u "C: \ Documents and Settings \ korisnik \ Local Settings \ Application Data \ Microsoft \ Outlook \ Outlookinfo @ fcagroup.com (IMAP)-00000005.pst \ info@fcagroup.com \ Vrh osobnih mapa \ [Gmail] \ All Mail \ Stvarno cool photos \ pussy.zip \ pussy.exe "file. 18/06/2009 10:42:41 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "C: \ Documents and Settings \ korisnik \ Local Settings \ Application Data \ Microsoft \ Outlook \ Outlookinfo @ fcagroup . com (IMAP)-00000005.pst \ info@fcagroup.com \ Vrh osobnih mapa \ [Gmail] \ All Mail \ UPS: Vaša praćenje # 358010698330 \ PDF76512.zip \ PDF76512.exe "file. 18/06/2009 10:42:41 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "C: \ Documents and Settings \ korisnik \ Local Settings \ Application Data \ Microsoft \ Outlook \ Outlookinfo @ fcagroup . com (IMAP)-00000005.pst \ info@fcagroup.com \ Vrh osobnih mapa \ [Gmail] \ All Mail \ UPS: Vaša praćenje # 145132932471 \ PDF76512.zip \ PDF76512.exe "file. 18/06/2009 10:42:23 AM 3652 korisnika znak "Win32: Ups [Cryp]" je pronađen u "C: \ Documents and Settings \ korisnik \ Local Settings \ Application Data \ Microsoft \ Outlook \ Outlookinfo @ fcagroup . com (IMAP)-00000005.pst \ info@fcagroup.com \ Vrh osobnih mapa \ [Gmail] \ All Mail \ UPS: Vaša praćenje # 239293259082 \ EXL6512721.zip \ EXL6512721.exe "file. 17/06/2009 5:36:18 PM SYSTEM 1328 Sign of "BV: autorun-T [Wrm]" je pronađen u "F: \ Autorun.inf" file. SUPERAntiSpyware Scan Prijava http://www.superantispyware.com Generirano 06/19/2009 at 10:43 Application Version: 4/26/1004 Core Pravila Database Version: 3947 Trace Pravila Database Version: 1889 Scan type: Cijela Scan Ukupno Scan Vrijeme: 00:36:36 Memorija predmeta skenirane: 631 Memorija prijetnje otkrivena: 0 Registry stavke skenirane: 6110 Matični prijetnje otkrivena: 0 File skenirane podatke: 46796 File prijetnje otkrivena: 9 Adware.Tracking Cookie C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ xiti [1]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ revsci [2]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ tribalfusion [2]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ RealMedia [2]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ user@microsoftwindows.112.2o 7 [1]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ user@pandasoftware.112.2o7 [1]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ user@adopt.euroclick [2]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ specificclick [2]. Txt C: \ Documents and Settings \ korisnik \ Cookies \ korisničko @ 247realmedia [1]. Txt Malwarebytes' Anti-zaštita od zlonamjernih programa 1,38 Database Version: 2308 5/1/2600 Windows Service Pack 3 19/06/2009 11:01:44 AM mbam-log-2009-06-19 (11-01-44). txt Scan type: Quick Scan Objekti skenirane: 87063 Proteklo vrijeme: 2 minute (s), 24 Drugi (a / e) Memory Processes zaraženih: 0 Memorijske module zaraženih: 0 Ključevi registra zaraženih: 0 Registry Values zaraženih: 0 Registry Data Items zaraženih: 0 Mape zaraženih: 0 Zaraženih datoteka: 0 Memory Processes zaraženih: (Nema stavki otkrivenih zlonamjernih) Memorijske module zaraženih: (Nema stavki otkrivenih zlonamjernih) Ključevi registra zaraženih: (Nema stavki otkrivenih zlonamjernih) Registry Values zaraženih: (Nema stavki otkrivenih zlonamjernih) Registry Data Items zaraženih: (Nema stavki otkrivenih zlonamjernih) Mape zaraženih: (Nema stavki otkrivenih zlonamjernih) Zaražene datoteke: (Nema stavki otkrivenih zlonamjernih) Logfile of Trend Micro HijackThis v2.0.2 Scan spremljena u 11:04:24, dana 19/06/2009 Platforma: Windows XP SP3 (Winnt 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Pokretanje procesa: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ Winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ Program Files \ Windows Defender \ MsMpEng.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ WINDOWS \ system32 \ ZoneLabs \ vsmon.exe C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ WINDOWS \ system32 \ cisvc.exe C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe C: \ Program Files \ Hamachi \ hamachi.exe C: \ WINDOWS \ system32 \ cidaemon.exe C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe C: \ Program Files \ Common Files \ Microsoft Shared \ VS7DEBUG \ MDM.EXE C: \ WINDOWS \ system32 \ nvsvc32.exe C: \ WINDOWS \ explorer.exe C: \ Program Files \ prožima Software \ PSQL \ bin \ w3dbsmgr.exe C: \ WINDOWS \ system32 \ Svchost.exe C: \ WINDOWS \ system32 \ SearchIndexer.exe C: \ WINDOWS \ system32 \ fxssvc.exe C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe C: \ WINDOWS \ RTHDCPL.EXE C: \ programa ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe C: \ Program Files \ Zone Labs \ ZoneAlarm \ zlclient.exe C: \ WINDOWS \ Samsung \ PanelMgr \ SSMMgr.exe C: \ WINDOWS \ Twain_32 \ Samsung \ SCX4x28 \ Scan2pc.exe C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe C: \ WINDOWS \ system32 \ Ctfmon.exe C: \ WINDOWS \ System32 \ Svchost.exe C: \ Program Files \ Skype \ Phone \ Skype.exe C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe C: \ Program Files \ Hamachi \ hamachi.exe C: \ Program Files \ 2BrightSparks \ SyncBack \ SyncBack.exe C: \ Program Files \ Skype \ Plugin Manager \ skypePM.exe C: \ WINDOWS \ system32 \ taskmgr.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ WINDOWS \ system32 \ NOTEPAD.EXE C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ WINDOWS \ system32 \ SearchProtocolHost.exe C: \ Program Files \ Trend Micro \ HijackThis \ sniper.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.dhl.ca/ca/wfHomeLoggedIn.aspx F2 - REG: SYSTEM.INI: UserInit = C: \ WINDOWS \ system32 \ userinit.exe, userinit. Exe O1 - Hosts: 66.98.148.65 auto.search.msn.com O1 - Hosts: 66.98.148.65 auto.search.msn.es O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O2 - BHO: Java (tm) Plug-in 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ rasporediti \ jqs \ ie \ jqs_plugin.dll O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM \ .. \ Run: [Alcmtr] ALCMTR.EXE O4 - HKLM \ .. \ Run: [DiskeeperSystray] "C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkIcon.exe" O4 - HKLM \ .. \ Run: [avast!] C: \ programa ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp.exe O4 - HKLM \ .. \ Run: [Windows Defender] "C: \ Program Files \ Windows Defender \ MSASCui.exe"-hide O4 - HKLM \ .. \ Run: [ZoneAlarm Client] "C: \ Program Files \ Zone Labs \ ZoneAlarm \ zlclient.exe" O4 - HKLM \ .. \ Run: [Samsung PanelMgr] C: \ WINDOWS \ Samsung \ PanelMgr \ SSMMgr.exe / autorun O4 - HKLM \ .. \ Run: [4x28 Scan2PC] "C: \ WINDOWS \ Twain_32 \ Samsung \ SCX4x28 \ Scan2pc.e Xe" O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe" O4 - HKLM \ .. \ RunOnce: [Malwarebytes' Anti-zaštita od zlonamjernih programa] C: \ Program Files \ Malwarebytes' Anti-zaštita od zlonamjernih programa \ mbamgui.exe / install / tihe O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe O4 - HKCU \ .. \ Run: [Skype] "C: \ Program Files \ Skype \ Phone \ Skype.exe" / nosplash / minimizirane O4 - HKUS \ S-1-5-19 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (User 'Default user') O4 - Startup: hamachi.lnk = C: \ Program Files \ Hamachi \ hamachi.exe O4 - Startup: Shortcut to Drive.lnk Karta = C: \ Documents and Settings \ korisnik \ Desktop \ Drive.bat Karta O4 - Startup: SyncBack.lnk = C: \ Program Files \ 2BrightSparks \ SyncBack \ SyncBack.exe O4 - Global Startup: Windows Search.lnk = C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe O8 - Extra kontekst meni stavka: E & zvezi u Microsoft Excel - res: / / C: \ programa ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000 O8 - Extra kontekst meni stavka: Web bilježenja - C: \ Program Files \ SmarThru Office \ WebCapture.dll O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ programa ~ 1 \ MICROS ~ 2 \ OFFICE11 \ REFIEBAR.DLL O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' MENUITEM: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/wind...?1203273577140 O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ Skype \ SKYPE4 ~ 1.DLL O20 - Winlogon Obavijesti:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Adobe LM Service - Unknown vlasnika - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe O23 - Service: Diskeeper - Diskeeper Corporation - C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe O23 - Service: Hamachi Service (HamachiService) - LogMeIn Inc - C: \ Program Files \ Hamachi \ hamachi.exe O23 - Service: Quick Početničko Java (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: prožima PSQL Workgroup Engine (psqlWGE) - prožima Software Inc - C: \ Program Files \ prožima Software \ PSQL \ bin \ w3dbsmgr.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C: \ WINDOWS \ system32 \ ZoneLabs \ vsmon.exe -- End of file - 7353 bytes |
|
#2
| ||||||||||||
| ||||||||||||
| Zdravo i welcome to postoji Računalna soka I'm Steve i ja ću vam pomoći da se thoughout ovo popraviti. Prije početka popraviti, pročitajte ovaj post u potpunosti. Ako postoji nešto što ne razumijete, ljubazno molimo vaša pitanja prije nastavka. Važno je da ne propustite jedan korak. Molimo obaviti sve što je u ispravan poredak / sequence. Mi ćemo početi sa ComboFix.exe. Molimo, posjetite ovu web stranicu za download linkovi i upute za pokretanje alata: http://www.bleepingcomputer.com/comb...o-use-combofix Bili sigurni da imate onemogućene sve protu-virus i anti štetnih sadržaja programa, tako da ne ometati vođenje ComboFix. Molimo uključite C: \ ComboFix.txt u sljedećoj odgovor na daljnje razmatranje.
__________________
__________________
Ponosni član ASAP & Unite My System: Steves katarka
|
|
#3
| |||
| |||
| Hej, hvala za pomoć. Ovdje se prijavite: ComboFix 09-06-21.01 - korisnik 22/06/2009 10:29.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1511 [GMT -4:00] Running from: C: \ Documents and Settings \ korisnik \ Desktop \ ComboFix.exe AV: avast! protuvirusne 4/8/1335 [VPS 090621-0] * On-onemogućen pristup skeniranju * (Ažurirano) 7591DB91 (-48A3-41F0-B128-1A293FD8233D) FW: ZoneAlarm Firewall * * onemogućen (829BDA32-94B3-44F4-8446-F8FCFF809F8B) . Ostali ((((((((((((((((((((((((((((((((((((((( brisanja ))))))))) )))))))))))))))))))))))))))))))))))))))) . c: \ windows \ system32 \ winsusrm.dll . ((((((((((((((((((((((((( Files Created from 2009/05/22 da 2009/06/22 ))))))))))) )))))))))))))))))))) . 2009-06-19 15:34. 2009-06-19 15:34 -------- d ----- w-C: \ Program Files \ Microsoft ActiveSync 2009-06-19 14:07. 2009-06-19 14:07 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ Malwarebytes 2009-06-19 14:07. 2009-06-17 15:27 38160 ---- AW-c: \ windows \ system32 \ drivers \ mbamswissarmy.sys 2009-06-19 14:07. 2009-06-19 14:07 -------- d ----- w-C: \ Program Files \ Malwarebytes' Anti-zaštita od zlonamjernih programa 2009-06-19 14:07. 2009-06-19 14:07 -------- d ----- w-c: \ Documents and Settings \ All Users \ Application Data \ Malwarebytes 2009-06-19 14:07. 2009-06-17 15:27 19096 ---- AW-c: \ windows \ system32 \ drivers \ mbam.sys 2009-06-19 13:58. 2009-06-19 13:58 117760 ---- AW-c: \ Documents and Settings \ korisnik \ Application Data \ SUPERAntiSpyware.com \ SUPERAntiSpyware \ SDDLLS \ UIREPAIR.DLL 2009-06-19 13:57. 2009-06-19 13:57 -------- d ----- w-c: \ Documents and Settings \ All Users \ Application Data \ SUPERAntiSpyware.com 2009-06-19 13:57. 2009-06-19 13:57 -------- d ----- w-C: \ Program Files \ SUPERAntiSpyware 2009-06-19 13:57. 2009-06-19 13:57 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ SUPERAntiSpyware.com 2009-06-19 13:57. 2009-06-19 13:57 -------- d ----- w-C: \ Program Files \ Common Files \ Wise Installation Wizard 2009-06-10 17:39. 2009-06-10 17:39 152576 ---- AW-c: \ Documents and Settings \ korisnik \ Application Data \ nedjelja \ Java \ jre1.6.0_14 \ lzma.dll 2009-06-10 00:53. 2009-06-10 00:53 -------- d ----- w-c: \ Documents and Settings \ All Users \ Application Data \ NCH Software 2009-05-29 11:46. 2008-04-14 09:42 26624 ---- AW-c: \ Documents and Settings \ LocalService \ Application Data \ Microsoft \ UPnP Device Host \ upnphost \ udhisapi.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2009-06-22 14:22. 2009-04-28 15:03 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ Skype 2009-06-22 13:56. 2008-02-17 21:01 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ Hamachi 2009-06-22 12:02. 2009-04-28 15:18 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ skypePM 2009-06-19 13:35. 2008-02-17 22:39 -------- d ----- w-c: \ Documents and Settings \ All Users \ Application Data \ Spybot - Search & Destroy 2009-06-18 19:10. 2008-06-19 15:20 31703397 ---- AW-c: \ windows \ Internet Evidencije \ tvDebug.zip 2009-06-12 07:08. 2008-12-03 14:46 -------- d ----- w-C: \ Program Files \ Windows Desktop Search 2009-06-10 17:39. 2009-03-26 15:12 -------- d ----- w-C: \ Program Files \ Java 2009-06-10 16:58. 2008-12-30 17:22 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ filezilla 2009-05-30 21:05. 2008-08-28 17:15 -------- d ----- w-c: \ program files \ MK PowerTools 2009-05-25 04:24. 2008-05-27 03:18 350208 ---- AW-c: \ windows \ system32 \ mssph.dll 2009-05-21 15:33. 2008-12-06 16:44 410984 ---- AW-c: \ windows \ system32 \ deploytk.dll 2009-05-12 19:12. 2008-02-17 18:05 26144 ---- AW-c: \ windows \ system32 \ spupdsvc.exe 2009-05-07 15:32. 2004-08-03 16:56 345600 ---- AW-c: \ windows \ system32 \ Localspl.dll 2009-05-01 16:37. 2009-02-07 19:53 -------- d ----- w-c: \ Documents and Settings \ korisnik \ Application Data \ Unyte 2009-04-29 04:46. 2004-08-03 16:56 666624 ---- AW-c: \ windows \ system32 \ Wininet.dll 2009-04-29 04:46. 2004-08-03 16:56 81920 ---- AW-c: \ windows \ system32 \ ieencode.dll 2009-04-28 15:18. 2009-04-28 15:18 56 --- ha-w-c: \ windows \ system32 \ ezsidmv.dat 2009-04-28 15:02. 2009-04-28 15:02 -------- d ----- w-C: \ Program Files \ Common Files \ Skype 2009-04-28 15:02. 2009-04-28 15:02 -------- d ----- R-C: \ Program Files \ Skype 2009-04-28 15:02. 2009-04-28 15:02 -------- d ----- w-c: \ Documents and Settings \ All Users \ Application Data \ Skype 2009-04-17 12:26. 2004-08-03 15:17 1847168 ---- AW-c: \ windows \ system32 \ Win32k.sys 2009-04-15 14:51. 2004-08-03 16:56 585216 ---- AW-c: \ windows \ system32 \ rpcrt4.dll 2009-04-09 02:09. 2009-04-09 02:04 664 ---- AW-c: \ windows \ system32 \ d3d9caps.dat 2009-04-01 21:57. 2008-02-17 22:30 4212 --- ha-w-c: \ windows \ system32 \ zllictbl.dat 2009-04-01 21:21. 2009-04-01 21:21 152576 ---- AW-c: \ Documents and Settings \ korisnik \ Application Data \ nedjelja \ Java \ jre1.6.0_13 \ lzma.dll 2009-03-31 21:41. 2009-03-31 21:41 0 ---- AW-c: \ windows \ system32 \ WSSPOOL.TMP 2009-03-26 15:11. 2009-03-26 15:11 152576 ---- AW-c: \ Documents and Settings \ korisnik \ Application Data \ nedjelja \ Java \ jre1.6.0_12 \ lzma.dll 2008-06-23 22:36. 2008-06-23 22:36 0 ---- AW-c: \ program files \ gditst 2008-05-22 20:04. 2008-05-22 20:04 190 AW----- C: \ Program Files \ Common Files \ psasetup.log . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & čitljiv default unose se ne prikazuju REGEDIT4 [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Run] "Ctfmon.exe" = "c: \ windows \ system32 \ Ctfmon.exe" [2008-04-14 15360] "Skype" = "C: \ Program Files \ Skype \ Phone \ Skype.exe" [2009-04-21 24264488] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "NvCplDaemon" = "c: \ windows \ system32 \ NvCpl.dll" [2007-09-17 8491008] "DiskeeperSystray" = "C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkIcon.exe" [2006-10-04 163840] "avast!" = "c: \ programa ~ 1 \ ALWILS ~ 1 \ Avast4 \ ashDisp. exe" [2009-02-05 81000] "ZoneAlarm Client" = "C: \ Program Files \ Zone Labs \ ZoneAlarm \ zlclient.exe" [2009-02-16 981384] "Samsung PanelMgr" = "C: \ Windows \ Samsung \ PanelMgr \ SSMMgr.exe" [2008-07-31 536576] "4x28 Scan2PC" = "C: \ Windows \ Twain_32 \ Samsung \ SCX4x28 \ Scan 2pc.exe" [2008-09-29 495616] "SunJavaUpdateSched" = "C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe" [2009-05-21 148888] "RTHDCPL" = "RTHDCPL.EXE" - c: \ windows \ RTHDCPL.exe [2007-04-26 16132608] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "Ctfmon.exe" = "c: \ windows \ system32 \ Ctfmon.exe" [2008-04-14 15360] C: \ Documents and Settings \ korisnik \ Start Menu \ Programs \ Startup \ hamachi.lnk - C: \ Program Files \ Hamachi \ hamachi.exe [2008-2-17 625952] Shortcut to Karta Drive.lnk - C: \ Documents and Settings \ korisnik \ Desktop \ Karta Drive.bat [2008/7/30 42] SyncBack.lnk - C: \ Program Files \ 2BrightSparks \ SyncBack \ SyncBack.exe [2008-11-15 2936064] C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Windows Search.lnk - C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe [2008-5-26 123904] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entversion \ Explorer \ ShellExecuteHooks] "(56F9679E-7826-4C84-81F3-532071A8BCC5)" = "C: \ Program Files \ Windows Desktop Search \ MSNLNamespaceMgr.dll" [2009-05-25 304128] "(5AE067D3-9AFB-48E0-853A-EBB7F4A000DA)" = "C: \ Program Files \ SUPERAntiSpyware \ SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ winlogon \ obavijestiti \! SASWinLogon] 2008-12-22 16:05 356352 ---- AW-C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ Contro l \ SafeBoot \ Minimal \ WinDefend] @ = "Usluga" [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ sigurnosni centar \ Praćenje \ ZoneLabsFirewall] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "c: \ \ WINDOWS \ \ system32 \ \ fxsclnt.exe" = "c: \ \ Program Files \ \ prožima Software \ \ PSQL \ \ bin \ \ w3dbsmgr.exe" = "c: \ \ WINDOWS \ \ twain_32 \ \ Samsung \ \ ScanMgr.exe" = "c: \ \ WINDOWS \ \ twain_32 \ \ Samsung \ \ SCX4x28 \ \ Scan2Pc. exe" = "c: \ \ WINDOWS \ \ twain_32 \ \ Samsung \ \ SCX4x28 \ \ Sscan2io. exe" = "c: \ \ Program Files \ \ Skype \ \ Phone \ \ Skype.exe" = [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ GloballyOpenPorts \ List] "3389: TCP" = 3389: TCP: @ xpsp2res.dll, -22009 R1 aswSP; avast! Self Protection; c: \ windows \ system32 \ drivers \ aswSP.sys [07/04/2008 10:44 114768] R1 SASDIFSV; SASDIFSV; C: \ Program Files \ SUPERAntiSpyware \ sasdifsv.sys [26/05/2009 10:05 AM 9968] R1 SASKUTIL; SASKUTIL; C: \ Program Files \ SUPERAntiSpyware \ SASKUTIL.SYS [26/05/2009 10:05 AM 72944] R2 aswFsBlk; aswFsBlk; c: \ windows \ system32 \ drivers \ aswF sBlk.sys [07/04/2008 10:44 20560] R2 HamachiService; Hamachi Service; c: \ program files \ Hamachi \ hamachi.exe [17/02/2008 5:01 PM 625952] R2 psqlWGE; prožima PSQL Workgroup Engine; c: \ program files \ prožima Software \ PSQL \ bin \ w3dbsmgr.exe [06/06/2008 1:03 PM 435488] R2 WinDefend; Windows Defender, c: \ Program Files \ Windows Defender \ MsMpEng.exe [03/11/2006 8:19 PM 13592] R3 SASENUM; SASENUM; C: \ Program Files \ SUPERAntiSpyware \ SASENUM.SYS [26/05/2009 10:05 AM 7408] S1 KPSYSDRV; KPSYSDRV; c: \ windows \ system32 \ drivers \ Kpsy sdrv.sys [23/06/2008 6:36 PM 17016] S2 BulkUsb; Genesys Logic Controller USB NT 5,0; c: \ windows \ system32 \ drivers \ usbprn.sys [23/06/2008 6:27 PM 7552] S2 SSPORT; SSPORT; \? \ C: \ Windows \ System32 \ Drivers \ SSPO RT.sys -> c: \ Windows \ System32 \ Drivers \ SSPORT.sys [?] S3 Moarer; Moarer; [x] --- Other Services / Vozači u spomen --- NewlyCreated * * - SASDIFSV NewlyCreated * * - SASENUM NewlyCreated * * - SASKUTIL . Sadržaj je 'Scheduled Tasks' folder 2009/06/22 C: \ Windows \ Tasks \ MP Planirano Scan.job - C: \ Program Files \ Windows Defender \ MpCmdRun.exe [2006-11-04 00:20] 2009/06/22 C: \ Windows \ Tasks \ SyncBack Outlook.job - C: \ Program Files \ 2BrightSparks \ SyncBack \ SyncBack.exe [2008-11-15 16:19] . . ------- Supplementary Scan ------- . Page uStart = hxxp: / / www.dhl.ca / ca / wfHomeLoggedIn.aspx IE: E & zvezi u Microsoft Excel - C: \ programa ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000 IE: Web bilježenja - c: \ program files \ SmarThru Office \ WebCapture.dll FF - ProfilePath -- . ************************************************** ************************ catchme 0.3.1398 W2K/XP/Vista - rootkit / potaja detector by Gmer zlonamjernih programa, http://www.gmer.net Rootkit scan 2009-06-22 10:31 5/1/2600 Windows Service Pack 3 NTFS skeniranja skrivenih procesa ... skeniranja skrivenih autostart entries ... skeniranja skrivenih datoteka ... scan uspješno završena skrivenih datoteka: 0 ************************************************** ************************ . --------------------- --------------------- Zaključana registarske ključeve [HKEY_LOCAL_MACHINE \ SOFTWARE \ prožima Software \ PSQL] @ Odbijen:) (svi) @ = "" . Completion time: 2009-06-22 10:32 ComboFix-u karanteni-files.txt 2009-06-22 14:32 Pre-Run: 32245211136 bytes free Post-Run: 32239325184 bytes free WindowsXP-KB310994-SP2-Pro-Bootdisk-enu.exe [boot loader] timeout = 2 default = multi (0) disk (0) rdisk (0) partition (1) \ WINDOW S [operating systems] c: \ cmdcons \ BOOTSECT.DAT = "Microsoft Windows Recovery Console" / cmdcons multi (0) disk (0) rdisk (0) partition (1) \ WINDOWS = "Micro soft Windows XP Professional" / noexecute = OptIn / fastdetect 164 --- EOF --- 2009-06-18 19:28 |
|
#4
| |||
| |||
| Zdravo postoji U ovom sljedeći post želim pokrenuti online virus scan, najprije omogućava uklonite neke neželjene džunka .... Molimo download ATF čistiju by Atribune. Ovaj program je za XP i Windows 2000, samo Dvokliknite ATF-Cleaner.exe za pokretanje programa. Pod Glavni odaberite: Odaberi Sve Kliknite Prazan Izdvojeno gumb. Ako koristite Firefox preglednik Kliknite Firefox na vrhu i odaberite: Odaberi Sve Kliknite Prazan Izdvojeno gumb. NAPOMENA: Ako želite zadržati svoje spremljene lozinke, molimo Vas kliknite Ne na redak. Ako koristite Opera browser Kliknite Opera na vrhu i odaberite: Odaberi Sve Kliknite Prazan Izdvojeno gumb. NAPOMENA: Ako želite zadržati svoje spremljene lozinke, molimo Vas kliknite Ne na redak. Kliknite Izlaz na glavnom izborniku za zatvaranje programa. Za Tehnička podrška, Dvokliknite e-mail adresa se nalazi na dnu svake izbornika. Uspostaviti internetsku vezu i obavite online scan sa Internet Explorer na Kaspersky Online Scanner. ** Vista korisnici - kliknite desnom tipkom IE / Firefox Ikona i trčanje kao upravnik Kliknite Prihvati, Kada su upitani za preuzimanje i instaliranje programskih datoteka i baza podataka zlonamjernih programa definicije.
Ova animacija vodit će vas kroz proces: ![]() Napomena ** ** Da biste optimizirali skeniranje i proizvesti više osjetljiv izvješće za pregled: Zatvori bilo koji otvoreni programi Isključite realnom vremenu za sve postojeće skener antivirusni program tijekom vršenja online scan. Vi svibanj isključiti s interneta nakon što počnete skeniranje. Napomena za Internet Explorer 7 korisnicima: Ako u bilo koje vrijeme ste imali problema s pregledom prihvatiti dugme za licencu, kliknite na Zoom tool se nalazi na dnu desnom dijelu IE prozora i postavite zoom na 75%. Nakon što je prihvatio licencu, vratiti na 100%. Post natrag s rezultatima iz Kasperksy, također ažurirati mi o tome kako se stvari prikazuju
__________________ Ponosni član ASAP & Unite |
|
#5
| |||
| |||
| http://www.dhl.ca/ca/wfHomeLoggedIn.aspx R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 http://www.eset.eu/buxus/docs/OnlineScanner.cab O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://www.update.microsoft.com/wind...?1203273577140 O18 - Protocol: skype4com - (FFC8B962-9B40-4DFF-9458-1830C7DD7F5D) - C: \ programa ~ 1 \ UOBIČAJENA ~ 1 \ Skype \ SKYPE4 ~ 1.DLL O20 - Winlogon Obavijesti:! SASWinLogon - C: \ Program Files \ SUPERAntiSpyware \ SASWINLO.dll O23 - Service: Adobe LM Service - Unknown vlasnika - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C: \ Program Files \ Alwil Software \ Avast4 \ ashWebSv.exe O23 - Service: Diskeeper - Diskeeper Corporation - C: \ Program Files \ Diskeeper Corporation \ Diskeeper \ DkService.exe O23 - Service: Hamachi Service ( HamachiService) - LogMeIn Inc - C: \ Program Files \ Hamachi \ hamachi.exe O23 - Service: Quick Početničko Java (JavaQuickStarterService) - Sun Microsystems, Inc - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe O23 - Service: prožima PSQL Workgroup Engine (psqlWGE) - prožima Software Inc - C: \ Program Files \ Software prožima \ PSQL \ bin \ w3dbsmgr.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C: \ WINDOWS \ system32 \ ZoneLabs \ vsmon.exe - End of file - 7090 bytes |
|
#6
| |||
| |||
| Hi there Mi stvarno potreba to trčanje potpuni sustav skeniranja na disku biti sigurni da ništa nije ostatak. Neki predmet JA dont primjetiti je da je on-line skener podići na phishing muljaža e-pošte. To ne nam točno koje je to reći, ali čini nam se da je u Vašu pristiglu poštu. Phishing prevare pokušati namamiti u koju stavljate svoje podatke u web stranicama, tako da kriminalci mogu dobiti informacije i koristiti ga za vlastitu korist. Za više informacija o phishing pročitali ovaj članak ovdje. Adresa e-pošte u pitanju svibanj izgledaju kao da je došao iz vlastite banke ili druge financijske institucije, te će čak i nose grbove ukraden iz originalne lokacije. Nikada se prijavite u bankarstvu bilo koje stranice ili bilo koje druge stranice s linkovima iz e-pošte. Uvijek idi na početnu stranicu i prijavite se sa svojih. Ja bih vam savjetovati da prazna obrisane stavke mape pored bilo koje druge sumnjive e-mail adresa. Omogućava potpunu pokušajte skenirati koristeći drugu skener. Obavi online scan sa Panda ActiveScan
* Isključite realnom vremenu za sve postojeće skener antivirusni program tijekom vršenja online scan. Avast korisnici napomena: Molimo da nastavi s online scan at Panda ako primiti obavijest. To je lažno pozitivnih od Avast Panda Antivirus jer ne šifriramo njegovih virus database. Iz nekog razloga, prijavite HJT ste poslali je nečitak, umjesto želim da post različite vrste prijava Molimo download DDS i spremite ju na radnu površinu.
Pošta i logove nazad u svoj sljedeći odgovor Također uključuju panda scan rezultati i držati mene ažurirana na vašem sustavu status
__________________ Ponosni član ASAP & Unite |
![]() |
|
| Bookmarks |
Slične teme | ||||
| Nit | Temu Započeo | Forum | Odgovori | Zadnji Post |
| Panda i USB Autorun Vakcine 1.0.0.19 Beta | evilfantasy | Virus, Spyware i sigurnost | 0 | 7. ožujak 2009 12:47 |
| Autorun CD | severntales | Drives & Izmjenjivi mediji | 2 | 13. prosinac 2008 00:28 |
| Vozač autorun cd nece da ga vodi me kroz postavljanje | P5200 | Općenito Software Chat | 8 | 4. Sep 2008 08:30 |
| Autorun Problem | Zephiron | Virus, Spyware i sigurnost | 10 | 17. veljača 2008 14:28 |
| CD-a neće autorun / autostart | rigisme | Drives & Izmjenjivi mediji | 11 | 18. prosinac 2007 14:37 |
| Thread Tools | |
| |