manji kapital -

Magazine
Go Back   Computer soka > Computer Software > Virus, Spyware i sigurnost

Register


 Default 

Desktop nestale, više rješenja i nije suđeno




Reply
 
Thread Tools
  #1  
Old 23. prosinca 2007, 22:58
Novi član grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Moj radna površina i traka sa zadacima su nestali i ja licemjerje 'činiti se držati sve prozore otvorene za to dugo (Upravljačka ploča, Moje računalo). Moja druga aplikacija posao pravedan prekid kad sam ih otvoriti sa zadaća voditelj.


Na taj način Im 'trčanje registrirani i pravna verzijom sustava Windows XP, nemam cd ili na bilo koji uvođenje u službu stvari tako da mi neće biti u mogućnosti to reinstalirati Windows na moj računalo to škripac moj problem.

Ive suđen stvaranje siguran taj JA nije 'imati explorer.exe na trčanje aplikacija, onda trčanje istraživač, ali da se ne radi ni.

Ive 'pokušao trčanje Spybot S & D, Runreg, Symantics i SpySweeper, i izbrisati loše stvari (nakon nje googling i stvaranje siguran to je bio loš), ali problem i dalje pojavljuje.

Našto JA trčanje istraživač, traci dolazi u i izvan ...

Krivovjerje moj ovaj Hijack zapisnika:

http://security.symantec.com/sscv6/h...SIVFWMFKPXKBQW
  #2  
Old 26. prosinca 2007, 09:21
Donatorska Grupa
 
Default Desktop nestale, više rješenja i nije suđeno

ovo se dogodilo da me prije i to zvuči kao da je trajno oštećenje učinjeno mimo virus. svoj najbolji to reinstalirati Windows ili naći utočište disk iz drug ili interneta.
  #3  
Old 26. prosinca 2007, 17:53
Moderator / ica grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Molimo pogledajte ovaj post i predali dnevnike započeti postupak uklanjanja.
__________________

  #4  
Old 3 siječnja 2008, 11:16
Novi član grupe
 
Default Desktop nestale, više rješenja i nije suđeno

U redu, tako da sam učinio sve one korake na moje računalo i Internet zavrtač vanjska strana moj računalo je nered i osvoji ga puno stvari od njih, ali moj glavni problem i dalje pojavljuje.

Moj desktop navika pokazivanje dok sam istraživač na trčanje zadaća voditelj, a čak i tada se pojavi za nekoliko sekundi i nestaje. Ne mogu pristupiti bilo koji od moj savijač jer su se zatvoriti u roku od nekoliko sekundi, ali sam saznao da mogu izvoditi druge programe pravedan prekid.

Krivovjerje moj novi HJT varalica.

Logfile of Trend Micro HijackThis v2.0.2
Skenirajte spremljena u 11:13:13, dana 1/3/2008
Platforma: Windows XP SP2 (Winnt 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Pokretanje procesa:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ Winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ Svchost.exe
C: \ WINDOWS \ System32 \ Svchost.exe
C: \ Program Files \ TGTSoft \ StyleXP \ StyleXPService.exe
C: \ WINDOWS \ system32 \ Svchost.exe
C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe
C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe
C: \ Program Files \ Common Files \ Symantec Shared \ ccProxy.exe
C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe
C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe
C: \ WINDOWS \ system32 \ bmwebcfg.exe
C: \ Program Files \ Toshiba \ ConfigFree \ CFSvcs.exe
C: \ WINDOWS \ system32 \ DVDRAMSV.exe
C: \ WINDOWS \ eHome \ ehRecvr.exe
C: \ WINDOWS \ eHome \ ehSched.exe
C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe
C: \ Program Files \ Norton Internet Security \ Norton AntiVirus \ navapsvc.exe
C: \ WINDOWS \ System32 \ Svchost.exe
C: \ Program Files \ Novatel Wireless \ Sprint \ Sprint PCS Connection Manager \ OSCMUtilityService.exe
C: \ Program Files \ Sprint \ Pantech \ Sprint Mobile Broadband (Pantech) \ PWIUtilityService.exe
C: \ WINDOWS \ System32 \ Svchost.exe
C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe
C: \ WINDOWS \ system32 \ Svchost.exe
c: \ Toshiba \ IVP \ swupdate \ swupdtmr.exe
C: \ Program Files \ Toshiba \ Toshiba applet \ TAPPSRV.exe
C: \ WINDOWS \ system32 \ dllhost.exe
C: \ Program Files \ Toshiba \ Toshiba Kontrole \ TFncKy.exe
C: \ WINDOWS \ system32 \ TDispVol.exe
C: \ WINDOWS \ AGRSMMSG.exe
C: \ WINDOWS \ system32 \ TPSBattM.exe
C: \ Program Files \ Sprint \ Pantech \ Sprint Mobile Broadband (Pantech) \ CMPWI.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ Adobe \ Acrobat 7,0 \ Reader \ AcroRd32.exe
C: \ WINDOWS \ system32 \ taskmgr.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
C: \ WINDOWS \ explorer.exe

R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar = http://www.toshiba.com/search
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.toshibadirect.com/dpdstart
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
O3 - Toolbar: Norton Internet Security 2006 - (0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7) - C: \ Program Files \ Common Files \ Symantec Shared \ AdBlocking \ NISShExt.dll
O3 - Toolbar: Norton AntiVirus - (C4069E3A-68F1-403E-B40E-20066696354B) - C: \ Program Files \ Norton Internet Security \ Norton AntiVirus \ NavShExt.dll
O4 - HKLM \ .. \ Run: [TPSMain] TPSMain.exe
O4 - HKLM \ .. \ Run: [THotkey] "C: \ Program Files \ Toshiba \ Toshiba Applet \ thotkey.exe"
O4 - HKLM \ .. \ Run: [TFncKy] TFncKy.exe
O4 - HKLM \ .. \ Run: [TDispVol] TDispVol.exe
O4 - HKLM \ .. \ Run: [SynTPLpr] "C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe"
O4 - HKLM \ .. \ Run: [SpySweeper] C: \ Program Files \ Webroot \ Spy Sweeper \ SpySweeperUI.exe / startintray
O4 - HKLM \ .. \ Run: [SmoothView] "C: \ Program Files \ TOSHIBA \ TOSHIBA Zumiranje Utility \ SmoothView.exe"
O4 - HKLM \ .. \ Run: [RegRun WinBait] C: \ WINDOWS \ xxxwinbait.exe
O4 - HKLM \ .. \ Run: [PadTouch] C: \ Program Files \ Toshiba \ Touch i pokrenite \ PadExe.exe
O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe"
O4 - HKLM \ .. \ Run: [IntelWireless] "C: \ Program Files \ Intel \ Wireless \ Bin \ ifrmewrk.exe" / TF Intel PROSet / Bežični
O4 - HKLM \ .. \ Run: [igfxtray] C: \ WINDOWS \ system32 \ igfxtray.exe
O4 - HKLM \ .. \ Run: [igfxpers] C: \ WINDOWS \ system32 \ igfxpers.exe
O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ DLACTRLW.exe
O4 - HKLM \ .. \ Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM \ .. \ Run: [@ RegRunOnSecure] C: \ Program ~ 1 \ Greatis \ REGRUN ~ 1 \ xxxOnSecure.exe
O4 - HKLM \ .. \ Run: [Registra] "C: \ Program Files \ Greatis \ RegRunSuite \ lsoon.exe" -1 30 "C: \ Program Files \ Greatis \ RegRunSuite \ rescue.exe" / "c: \ backreg \ rstore.ini "
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe
O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe
O4 - HKLM \ .. \ Run: [TOSCDSPD] "C: \ Program Files \ TOSHIBA \ TOSCDSPD \ toscdspd.exe"
O4 - HKLM \ .. \ Run: [STYLEXP] "C: \ Program Files \ TGTSoft \ StyleXP \ StyleXP.exe"-Hide
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
O4 - HKLM \ .. \ Run: [Regrun2] C: \ Program ~ 1 \ Greatis \ REGRUN ~ 1 \ WatchDog.exe
O4 - HKCU \ .. \ Run: [msnmsgr] "C: \ Program Files \ MSN Messenger \ MsnMsgr.Exe" / background
O4 - HKCU \ .. \ Run: [Aim6] "C: \ Program Files \ AIM6 \ aim6.exe" / locale d = en-US EE: / / AOL / imApp
O4 - Global Startup: hpoddt01.exe.lnk =?
O4 - Global Startup: RAMASST.lnk = C: \ WINDOWS \ system32 \ RAMASST.exe
O8 - Extra kontekst meni stavka: & Windows Live Search - res: / / C: \ Program Files \ Windows Live Toolbar \ msntb.dll / search.htm
O8 - Extra kontekst meni stavka: E & zvezi u Microsoft Excel - res: / / C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O9 - Extra button: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_04 \ bin \ npjpi150_04.dll
O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_04 \ bin \ npjpi150_04.dll
O9 - Extra button: Send to OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra 'Tools' MENUITEM: S & kraj OneNote - (2670000A-7350-4f3c-8081-5663EE0C6C49) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ ONBttnIE.dll
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: Real.com - (CD67F990-D8E9-11D2-98FE-00C0F0318AFE) - C: \ WINDOWS \ system32 \ Shdocvw.dll
O9 - Extra button: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O9 - Extra 'Tools' MENUITEM: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ programa ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O9 - Extra button: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O14 - IERESET.INF: START_PAGE_URL = http://www.toshibadirect.com/dpdstart
O16 - DPF: (14B87622-4EA8-7E19-93B3-97215F77A6BC) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: (2BC66F54-93A8-11D3-BEB6-00105AA9B6AE) (Symantec AntiVirus skener) -- http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) (OnlineScanner Control) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: (5F8469B4-B055-49DD-83F7-62B522420ECC) (Facebook Foto Uploader Control) -- http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: (644E432F-49D3-41A1-8DD5-E099162EEEC5) (Symantec RuFSI Utility Class) -- http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: (8E0D4DE5-3180-4024-A327-4DFAD1796A8D) (MessengerStatsClient Class) -- http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: (A7A61125-0EAA-11D1-B22F-0000C08C00C4) (SSDBGrid Control 3.1 -) -- https: / / www.ext.ch2m.com/ETS/controls/sheridan3_13.cab
O16 - DPF: (F5131C24-E56D-11cf-B78A-444553540000) (Ikonić Menu Control) -- https: / / www.ext.ch2m.com/cgi-bin/controls/ikcntrls.cab
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (75405C70-8319-41CB-8288-402151999888): NameServer = 68.28.50.91 68.28.58.92
O18 - Protocol: grooveLocalGWS - (88FED34C-F0CA-4636-A375-3CB6248B04CD) - C: \ programa ~ 1 \ MICROS ~ 2 \ Office12 \ GR99D3 ~ 1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C: \ Program Files \ Common Files \ Adobe Systems Shared \ Service \ Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown vlasnika - C: \ WINDOWS \ Microsoft.NET \ Framework \ v2.0.50727 \ aspn et_state.exe (file missing)
O23 - Service: Automatic LiveUpdate Planer - Symantec Corporation - C: \ Program Files \ Symantec \ LiveUpdate \ ALUSchedulerSvc.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc - C: \ WINDOWS \ system32 \ bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe
O23 - Service: Symantec Password Validation Internet Security (ccISPwdSvc) - Symantec Corporation - C: \ Program Files \ Norton Internet Security \ ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - Toshiba CORPORATION - C: \ Program Files \ Toshiba \ ConfigFree \ CFSvcs.exe
O23 - Service: COM Domaćin (comHost) - Symantec Corporation - C: \ Program Files \ Norton Internet Security \ comHost.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co, Ltd - C: \ WINDOWS \ system32 \ DVDRAMSV.exe
O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 1050 \ Intel 32 \ IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C: \ programa ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C: \ Program Files \ Norton Internet Security \ Norton AntiVirus \ navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ Security konzole \ NSCSRVCE.EXE
O23 - Service: OSCM Komunalne usluge - Sprint Spectrum, LLC - C: \ Program Files \ Novatel Wireless \ Sprint \ Sprint PCS Connection Manager \ OSCMUtilityService.exe
O23 - Service: Pantech Komunalne usluge - Sprint Spectrum, LLC - C: \ Program Files \ Sprint \ Pantech \ Sprint Mobile Broadband (Pantech) \ PWIUtilityService.exe
O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe
O23 - Service: Intel (R) PROSet / wirelessom (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C: \ Program Files \ Norton Internet Security \ Norton AntiVirus \ SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ SPBBCSvc.exe
O23 - Service: StyleXPService - Unknown owner - C: \ Program Files \ TGTSoft \ StyleXP \ StyleXPService.exe
O23 - Service: Swupdtmr - Unknown vlasnika - C: \ Toshiba \ IVP \ swupdate \ swupdtmr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
O23 - Service: Toshiba Application Service (TAPPSRV) - Toshiba Corp - C: \ Program Files \ Toshiba \ Toshiba applet \ TAPPSRV.exe

--
End of file - 12.024 bajtova
  #5  
Old 3. siječanj 2008, 13:48
Moderator / ica grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Mogu li postavljati druge logove?

Otvori SUPERAntiSpyware > Preferences> Statistika / Trupci kartica> isticanja zapisnika> Pogledaj Prijava ..

ESET > Idi na C: \ Program Files \ EsetOnlineScanner \ log.txt

--------------------

Molimo download ATF čistiju by Atribune. ATF Cleaner.exe

Ne ga koristiti još, mi ćemo kasnije.

--------------------

Mi moramo onemogućiti neke zaštitne programe tako da ne ometaju popravaka smo pokušaj.



Onemogući Spybot-a TeaTimer

Dok TeaTimer je odličan alat za sprečavanje spywarea, to ponekad može spriječi naše alate iz pričvršćivanje određene stvari.
Molimo vas onemogućiti TeaTimer za sada dok ne budete čisti. TeaTimer mogu biti ponovno aktiviran nakon vaše logove su čista.

Prvo:
  • Desnom tipkom miša kliknite Spybot u programskoj traci (izgleda kao s kalendarom katanac symbol)
  • Izabrati Zatvorite Spybot S & D Resident
Drugo:
  • Otvori Spybot S & D
  • Kliknite ModaProvjeriti Advanced Mode
  • Idi na lijevo Panel, kliknite Alati, A zatim i na lijevoj strani panela, kliknite Resident
  • Ako vaš vatrozid postavlja pitanje, reci U redu
  • Isključite potvrdni okvir pod nazivom Resident Tea-Timer i bilo koji potiču redu.
  • Koristiti Datoteka, Izlaz raskida Spybot
  • Reboot vaš stroj za promjene stupiti na snagu.
Treći:

S obje Tea timer i download Spybot zatvoreno ResetTeaTimer.zip
  • Otvoriti rajsfešlus datoteku.
  • Dvaput kliknite na ResetTeaTimer.bat Da biste uklonili sve stavke koje postavlja Spybot's TeaTimer.
  • Nakon što ga je vodio, možete izbrisati ga. To neće biti potrebno ponovno.
Napomena: Ako TeaTimer vam daje upozorenje nakon što su neke promjene, omogućuju blokiranje ovog umjesto njega.

--------------------

Onemogući SpySweeper

Možete ponovno omogućiti da nakon što budete čisti.

Da biste onemogućili SpySweeper:


Otvoriti Spysweeper klik> Opcije na to onda lijevo> Program Options > Isključi "opterećenje pri pokretanju Windowsa"

Preko na lijevoj strani kliknite na "štit" i Isključi sve tamo.

Isključi "home page štit"

Isključi "automatski vratiti propust bez obavijesti"

--------------------

Ja sam ne siguran ako Watch Dog Program štiti registra iz promjena, pa ako se onda ne onemogućite ga.

-------------------

Enable Prikazivanje skrivenih sistemskih datoteka i mapa

Idi na My Computer-> Tools-> Folder Options-> View Kartica:
  • Pod Skrivene datoteke i mape zaglavlje:
  • Odaberi Prikaži skrivene datoteke i mape.
  • Isključi Sakrij zaštićen operativni sistem kartoteka (preporučeno) opciju.
  • Također, provjerite postoji ne kvačica pored Sakrij nastavke za poznate vrste datoteka.
  • Kliknite U redu.
--------------------

Otvoriti Task Manager i odaberite Procesi tab.

Ubiti procesi za:

xxxwinbait.exe
xxxOnSecure.exe


--------------------

Otvori HijackThis i odaberite Da li je sustav skenirati samo zatim staviti kvačica pored:

O4 - HKLM \ .. \ Run: [RegRun WinBait] C: \ WINDOWS \ xxxwinbait.exe <<-Mislim da je ovaj program ili je otet ili je nije zakonit RegRun preuzimanje. To bi trebao biti winbait.exe ali se pokazuje kao xxxwinbait.exe
O4 - HKLM \ .. \ Run: [@ RegRunOnSecure] C: \ Program ~ 1 \ Greatis \ REGRUN ~ 1 \ xxxOnSecure.exe <<-Mislim da je ovaj program ili je otet ili je nije zakonit RegRun preuzimanje. To bi trebao biti OnSecure.exe ali se pokazuje kao xxxOnSecure.exe
O4 - Global Startup: hpoddt01.exe.lnk =?


Zatvori sve prozore osim HijackThis i kliknite Fix checked

--------------------

Otvoriti My Computer smjestiti i tada izbrisati ovi Datoteke i Mape.

C: \ Windows \xxxwinbait.exe
C: \ Program ~ 1 \Greatis \ REGRUN ~ 1\xxxOnSecure.exe

--------------------

Pokrenuti ATF-čistiju

Uvjerite se da sve su zatvorene prozore preglednika.
  • Dvokliknite ATF-Cleaner.exe za pokretanje programa.
  • Pod Glavna odaberite: Odaberi Sve i Isključi Cookies.
  • Kliknite Prazan Izdvojeno gumb.
Ako koristite Firefox preglednik
  • Kliknite Firefox na vrhu i odaberite: Odaberi Sve i Isključi Cookies.
  • Kliknite Prazno Odabrana gumb.
    NAPOMENA: Ako želite zadržati svoje spremljene lozinke, molimo Vas kliknite Ne na redak.
Ako koristite Opera preglednik
  • Kliknite Opera na vrhu i odaberite: Odaberi Sve i Isključi Cookies.
  • Kliknite Prazan Izdvojeno gumb.
    NAPOMENA: Ako želite zadržati svoje spremljene lozinke, molimo Vas kliknite Ne na redak.
Kliknite Izlaz na glavnom izborniku ATF čistiju zatvoriti program.

--------------------

Next post molimo dodaj
Novi HijackThis log
SUPERAntiSpyware log <<- Od maknuti naredbe
ESET log
<<- Od maknuti naredbe
__________________

  #6  
Old 5 siječnja 2008, 03:31
Novi član grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Ja licemjerje pristup moj radna površina ili moj fascikl ipak.

Ima li taj put okolo? JA pokušao pristup moj kartoteka preko moj preglednik, ali Internet se funkcionirati
  #7  
Old 5 siječnja 2008, 03:33
Novi član grupe
 
Default Desktop nestale, više rješenja i nije suđeno

# Version = 4
# OnlineScanner.ocx = 1.0.0.56
# OnlineScannerDLLA.dll = 1, 0, 0, 51
# OnlineScannerDLLW.dll = 1, 0, 0, 51
# OnlineScannerUninstaller.exe = 1, 0, 0, 49
# Vers_standard_module = 2762 (20080102)
# Vers_arch_module = 1,060 (20071228)
# Vers_adv_heur_module = 1,064 (20070717)
# EOSSerial = 6051a39d0346bc4b8901f101faab2805
# End = završio
# Remove_checked = true
# Unwanted_checked = true
# Utc_time = 2008-01-03 08:02:05
# Local_time = 2008-01-03 01:02:05 (-0700, SAD Mountain Standard Time)
# Zemlje = "United States"
# Osver = 5/1/2600 NT Service Pack 2
# Skenirane = 601.050
# Pronađeno = 48
# Scan_time = 6.894
C: \ Documents and Settings \ administrator \ Local Settings \ Temp \ TMP22.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ obitelji \ Local Settings \ Temp \ RCX3.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ obitelji \ Local Settings \ Temp \ TMP28.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ D1B9.tmp Win32/TrojanDownloader.PurityScan.EG Trojan (izbrisan) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ D1B9.tmp »NSIS» Yazzle1552OinAdmin.exe Win32/TrojanDownloader.PurityScan.EG trojanski (greška dok čišćenje - rad nedostupna za ovu vrstu objekta - greška, dok brisanje - rad nedostupna za ovaj tip objekta - bio je dio briše objekt) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ RCX10.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ RCX29D2.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP10.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP12.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP13.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP19.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP20C.tmp Win32/TrojanDownloader.Agent.BLS izdržljiv čovjek (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP223.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP241.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP288C.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP29D0.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP30.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP36.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP3D.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP65.tmp Win32/TrojanDownloader.Agent.BLS izdržljiv čovjek (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP72.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP7766.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP8.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMP9D.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMPD.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Documents and Settings \ Mikael \ Local Settings \ Temp \ TMPD0.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ AIM6 \ aim6.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Common Files \ Symantec Shared \ ccApp.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Greatis \ RegRunSuite \ lsoon.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Greatis \ RegRunSuite \ OnSecure.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Hewlett-Packard \ HP Software Update \ HPWuSchd2.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Intel \ Wireless \ bin \ ZCfgSvc.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Microsoft Office \ Office12 \ GrooveMonitor.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ QuickTime \ qttask. Exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ QuickTime \ qttask.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ TOSHIBA \ TOSCDSPD \ toscdspd.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ Program Files \ TOSHIBA \ TVs \ TvsTray.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ mrofinu72.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ mrofinu72.exe.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ winbait.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ pchealth \ helpctr \ dvostruki \ msconfig.exe. tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ ctfmon.exe.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ hkcmd.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ mllji.exe Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ PMNKIIF.DLL.del Win32/Adware.Virtumonde aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ RCX416.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
C: \ WINDOWS \ system32 \ RCX8.tmp Win32/Adware.Virtumonde.CLI aplikacija (nesposoban za čišćenje - izbrisati) 00000000000000000000000000000000
  #8  
Old 5 siječnja 2008, 05:01
Zabranjen Group
 
Default Desktop nestale, više rješenja i nije suđeno

kako o sigurnom načinu rada?

kad udovice započeti pritiskom na F8 bottum repeadetly prozori će biti apear koristiti siguran način kako pokrenuti

<EDIT> softver je najbolji za sigurnost sustava
  #9  
Old 5. siječanj 2008, 10:16
Moderator / ica grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Quote:
Originally Posted by Kolubive View Post
kako o sigurnom načinu rada?

kad udovice započeti pritiskom na F8 bottum repeadetly prozori će biti apear koristiti siguran način kako pokrenuti

<EDIT> softver je najbolji za sigurnost sustava
Sam te upozorio na razgovor o piratstvu na ovim forumima.
__________________

  #10  
Old 5. siječanj 2008, 10:22
Moderator / ica grupe
 
Default Desktop nestale, više rješenja i nije suđeno

Pokušati dobiti SUPERAntiSpyware zapisnik i novi HijackThis log.
__________________

Reply

Register

Bookmarks

Slične teme
Nit Temu Započeo Forum Odgovori Zadnji Post
IE Hladan UP - Multiple strojevi - više operacijskih sustava ehsankhan Web Browsers & FTP Klijenti 1 9. lipnja 2009 12:42
Vaš Backup Rješenja platti Drives & Izmjenjivi mediji 10 4. svibanj 2009 10:30
Hotmail račun hijacked - rješenja? JodyM Email, VoIP & IM Razgovor 6 1. srpnja 2008 23:48
Volume Control icon nestalo iz Desktop! TheDellMan Općenito Software Chat 1 4. studeni 2007 16:20
Backup rješenja - savjete molim Ola Drives & Izmjenjivi mediji 1 7. lipnja 2007 22:45
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer soka.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO by vBSEO © 2009, Crawlability, Inc