![]() |
| |||||||
| Registracija | Mapa Spy | Member List | Donacije | Pretraživanje | Today's Posts | Označi Sve Forume Kao Pročitane | Forum Rules |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Ive 'bio okužen sa neke vrste Spyware / Adware, ja sam nakon nekoliko teme pošta ovdje koji je imao sličnu stvar, ali to nijedan pomoći. Adware: Changed moj radna površina to zabrljati kazivanje "Spyware prijetnja je otkriti, kliknite ovdje za trčanje pun skandirati što", a također se drži na iskakanje settle s mjehurić u kutu znakovit mene iste stvari. Ive 'pokušao preuzeti i pokrenuti hrpa programa: SmitFraudFix Combofix ATF-čistiju CCleaner SpyBotSearch & Destroy Ali nitko od njih ne čini se da su fiksne ništa ... molim pomoć! ![]() Ja sam privržen hrpa od najnovijih logove. Zelen |
|
#2
| |||
| |||
| Welcome to CJ žutokljunac ![]() Izbriši ove datoteke / mape, kako slijedi: 1. Idi na Početak > Pokrenuti > Tip Notepad.exe i kliknite U redu otvoriti Notepad. To morati biti Notepad, WordPad ne.
Code: KillAll:: Mapa:: C: \ WINDOWS \ FLEOK File:: C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ system32 \ wmsdkns.exe 4. Zatim kliknite na Datoteka > Spremiti 5. Ime datoteke CFScript.txt - Spremi datoteku na svoj Desktop 6. Zatim povucite CFScript (držite lijevu tipku miša dok povučete datoteku), a pad je (otpustite lijevu tipku miša) u ComboFix.exe kao što vidite na sliki ispod. Važno: Obavi ovo uputstvo pažljivo! ![]() ComboFix će se početi izvršavati, samo slijedite upute. Nakon što ponovno podizanje sustava (u slučaju da ga zatraži ponovno podizanje sustava), on će proizvesti prijava za vas. Pošta koja log (Combofix.txt) u sljedeći odgovor. Napomena: Ne mouseclick combofix's prozor dok je pokrenut. To svibanj nanijeti tvoj sistem za zamrzavanje ---------- Hijackthis Otvori, a zatim odaberite Da li je sustav skenirati samo. Stavite oznaku uz sljedeće stavke: (ako postoji)
Izlaz Hijackthis. ---------- Preuzmite ATF čistiju by Atribune. ATF Cleaner.exe Uvjerite se da sve su zatvorene prozore preglednika.
---------- Važno: De-instalirati HijackThis verziju imate. to je stara Beta verzije i moramo imati na novu verziju, kao i preimenovati Internet to snajper. Prvo ići OVDJE i učiniti korake u red. Korak tri -- Malwarebytes' Anti-zaštita od zlonamjernih programa (MBAM) Korak Four -- Ažuriraju Java Korak Šestorice -- HijackThis Sada pokrenite novu HijackThis skeniranja i pošta prijavite zajedno s drugima. ---------- Next post molimo dodaj Combofix log MBAM log NOVO Hijackthis log |
|
#3
| |||
| |||
Hej, hvala na srdačnoj dobrodošlici i brzom odgovoru, i čast da vas za savjet!JA slijeđen tvoj naredbe svi poput tebe, rekao je, nakon dodavanja original to comofix virus činilo da nestane, ali ja slijeđen ostatak ionako koraka do makesure. Ja sam ja HijackThis! skeniranje, ali datoteke koje me je zamolio da izbrisati tako da više nisu tu, Ja sam guessing combofix od mora je dobio osloboditi od njih. JA ran Malware bytes kao i, i postaviti neke datoteke koje sam ga izbrisati. Čini se kao da je sve dobro sad, nema više Pozadina oglasa ili mjehurić popups, sam privržen trupaca po želji. Morao stisnuti 2 od njih jer su bili iznad filesize limit, komprimiran sa Winrar koja je kasnije preimenovana. Zip, nada da je u redu. Hvala opet Evilfantasy. ComboFix 08-04-08.7 - Ashton 2008-04-09 18:21:02.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.682 [GMT 1:00] Running from: C: \ Documents and Settings \ Ashton \ Desktop \ ComboFix.exe Command sklopke koriste:: C: \ Documents and Settings \ Ashton \ Desktop \ CFScript.txt * Created novu točku vraćanja * Resident AV je aktivna UPOZORENJE-ovaj stroj nema Recovery Console Installed! SLIKA: C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ system32 \ wmsdkns.exe . Ostali ((((((((((((((((((((((((((((((((((((((( brisanja ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ Program Files \ 180search asistent C: \ Program Files \ 180search asistent \ 180sa.exe C: \ Program Files \ 180search asistent \ sau.exe C: \ Program Files \ 180searchassistant C: \ Program Files \ 180searchassistant \ saap.exe C: \ Program Files \ 180searchassistant \ sac.exe C: \ Program Files \ 180solutions C: \ Program Files \ 180solutions \ sais.exe C: \ Program Files \ seekmo C: \ Program Files \ seekmo \ seekmohook.dll C: \ Program Files \ STC C: \ Program Files \ STC \ csv5p070.exe C: \ Program Files \ Sysmnt C: \ Program Files \ Sysmnt \ Ssmgr.exe C: \ Program Files \ zango C: \ Program Files \ Zango \ zango.exe C: \ WINDOWS \ 180ax.exe C: \ WINDOWS \ 2020search.dll C: \ WINDOWS \ 2020search2.dll C: \ WINDOWS \ bjam.dll C: \ WINDOWS \ bokja.exe C: \ WINDOWS \ cdsm32.dll C: \ WINDOWS \ default.htm C: \ WINDOWS \ didduid.ini C: \ WINDOWS \ FLEOK C: \ WINDOWS \ FLEOK \ 180ax.exe C: \ WINDOWS \ mspphe.dll C: \ WINDOWS \ mssvr.exe C: \ WINDOWS \ saiemod.dll C: \ WINDOWS \ salm.exe C: \ WINDOWS \ stcloader.exe C: \ WINDOWS \ swin32.dll C: \ WINDOWS \ system32 \ msixu.dll C: \ WINDOWS \ system32 \ wer8274.dll C: \ WINDOWS \ system32 \ wmsdkns.exe C: \ WINDOWS \ TEMP \ salm.exe C: \ WINDOWS \ updatetc.exe C: \ WINDOWS \ voiceip.dll . ((((((((((((((((((((((((( Files Created from 2008/03/09 da 2008/04/09 ))))))))))) )))))))))))))))))))) . 2008-04-09 08:52. 2008-04-09 08:52 <DIR> d -------- C: \ Program Files \ Ned 2008-04-09 08:36. 2008-04-09 08:36 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Program Files \ Malwarebytes 'Anti-Malware 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ Malwarebytes 2008-04-09 08:35. 2008-04-09 08:35 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Malwarebytes 2008-04-09 08:31. 2008-04-09 08:31 <DIR> d -------- C: \ Program Files \ Common Files \ Authentium 2008-04-09 08:31. 2008-04-09 18:11 53.192 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_skt32.sys 2008-04-09 08:31. 2007-04-19 11:36 48.384 - a ------ C: \ WINDOWS \ system32 \ drivers \ rp_pkt32.sys 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Program Files \ Raxco 2008-04-09 08:30. 2008-04-09 18:07 <DIR> d -------- C: \ Program Files \ Common Files \ Scanner 2008-04-09 08:30. 2008-04-09 08:30 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Raxco 2008-04-09 08:28. 2008-04-09 08:28 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ InstallShield 2008-04-09 08:25. 2008-04-09 08:30 <DIR> d -------- C: \ Program Files \ Virgin Broadband 2008-04-09 01:42. 2008-04-09 01:42 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Yahoo! Companion 2008-04-09 01:14. 2008-04-09 01:14 <DIR> d -------- C: \ Program Files \ Yahoo! 2008-04-09 01:13. 2008-04-09 01:15 <DIR> d -------- C: \ Program Files \ CCleaner 2008-04-09 00:43. 2008-04-09 01:52 3.314 - a ------ C: \ WINDOWS \ system32 \ tmp.reg 2008-04-09 00:42. 2007-09-06 00:22 289.144 - a ------ C: \ WINDOWS \ system32 \ VCCLSID.exe 2008-04-09 00:42. 2006-04-27 17:49 288.417 - a ------ C: \ WINDOWS \ system32 \ SrchSTS.exe 2008-04-09 00:42. 2008-03-29 00:19 86.528 - a ------ C: \ WINDOWS \ system32 \ VACFix.exe 2008-04-09 00:42. 2008-04-08 22:44 82.432 - a ------ C: \ WINDOWS \ system32 \ IEDFix.exe 2008-04-09 00:42. 2003-06-05 21:13 53.248 - a ------ C: \ WINDOWS \ system32 \ Process.exe 2008-04-09 00:42. 2004-07-31 18:50 51.200 - a ------ C: \ WINDOWS \ system32 \ dumphive.exe 2008-04-09 00:42. 2007-10-04 00:36 25.600 - a ------ C: \ WINDOWS \ system32 \ WS2Fix.exe 2008-04-09 00:01. 2008-04-09 00:01 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ FLEXnet 2008-04-08 23:57. 2008-04-08 23:57 <DIR> d -------- C: \ Program Files \ Spybot - Search & Destroy 2008-04-08 23:57. 2008-04-09 00:46 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Spybot - Search & Destroy 2008-04-08 23:50. 2008-04-08 23:50 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ ALM 2008-04-08 23:47. 2008-04-08 23:47 <DIR> d -------- C: \ Program Files \ Bonjour 2008-04-08 23:29. 2008-04-08 23:29 <DIR> d -------- C: \ Program Files \ Common Files \ Macrovision Shared 2008-04-08 22:42. 2008-04-08 22:42 <DIR> d -------- C: \ Program Files \ Power PC 2008-04-07 01:56. 2008-04-07 01:56 1.110 - a ------ C: \ WINDOWS \ mozver.dat 2008-04-01 22:42. 2008-04-01 22:42 <DIR> d - h ----- C: \ Documents and Settings \ All Users \ Application Data \ (0E8E33D8-193A-414A-A909-0F101A142D26) 2008-04-01 22:38. 2008-04-01 22:38 <DIR> d -------- C: \ Program Files \ Stardock Igre 2008-03-28 18:39. 2008-03-28 18:39 <DIR> d -------- C: \ Documents and Settings \ Ashton \ Application Data \ dvdcss 2008-03-14 07:04. 2008-03-14 07:04 46.652 - a ------ C: \ WINDOWS \ system32 \ drivers \ scdemu.sys 2008-03-13 23:07. 2008-03-13 23:07 <DIR> d -------- C: \ Program Files \ Common Files \ NSV . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-04-09 07:54 --------- d ----- w C: \ Program Files \ Java 2008-04-09 07:30 --------- d ----- w C: \ Program Files \ CA 2008-04-09 07:29 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Virgin Broadband 2008-04-09 07:28 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2008-04-09 01:58 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ Virgin Broadband 2008-04-08 22:47 --------- d ----- w C: \ Program Files \ Common Files \ Adobe 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ ATI 2008-02-26 20:59 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ ATI 2008-02-26 20:50 --------- d ----- w C: \ Program Files \ ATI Technologies 2008-02-26 01:30 --------- d ----- w C: \ Program Files \ Games-Masters.com 2008-02-25 09:39 --------- d ----- w C: \ Program Files \ Common Files \ Shared INCA 2008-02-25 09:19 --------- d ----- w C: \ Program Files \ GameTribe 2008-02-24 03:18 --------- d ----- w C: \ Program Files \ Temp.p 2008-02-23 22:31 --------- d ----- w C: \ Program Files \ Common Files \ DirectX 2008-02-23 22:26 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Kontiki 2008-02-23 21:42 --------- d ----- w C: \ Program Files \ OGPlanet 2008-02-22 19:06 --------- d ----- w C: \ Documents and Settings \ Ashton \ Application Data \ AdobeUM 2008-02-21 19:33 --------- d ----- w C: \ Program Files \ Three Rings Dizajn 2008-02-20 22:40 --------- d ----- w C: \ Documents and Settings \ All Users \ Application Data \ Channel4 2008-02-15 19:17 --------- d ----- w C: \ Program Files \ Winamp 2008-02-15 18:00 --------- d ----- w C: \ Program Files \ Hidden City Igre 2008-02-15 16:55 --------- d ----- w C: \ Program Files \ SealOnlineUSA 2008-02-13 21:44 --------- d ----- w C: \ Program Files \ Funcom 2007-12-23 19:41 32 ---- ar C: \ Documents and Settings \ All Users \ hash.dat 2004-02-02 10:31 236.510-c - aw C: \ Documents and Settings \ Ashton \ DIAG.EXE 2004-01-30 18:21 62.480-c - aw C: \ Documents and Settings \ Ashton \ FETODI.COM 2004-01-09 14:28 51.356-c - aw C: \ Documents and Settings \ Ashton \ FETND3.sys 2004-01-09 14:27 53.136-c - aw C: \ Documents and Settings \ Ashton \ FETND4.sys 2004-01-09 14:24 40.960-c - aw C: \ Documents and Settings \ Ashton \ FETND5A.sys 2004-01-09 14:23 42.496-c - aw C: \ Documents and Settings \ Ashton \ FETND5B.sys 2003-11-27 15:01 57.344-c - aw C: \ Documents and Settings \ Ashton \ winsetup.exe 2002-10-09 16:29 147.456-c - aw C: \ Documents and Settings \ Ashton \ NTUTIL.DLL 2002-02-20 11:04 15.552-c - aw C: \ Documents and Settings \ Ashton \ WINNDI.DLL . ((((((((((((((((((((((((((((( Snimak @ 2008-04-09_ 1.41.00.14 ))))))))))) )))))))))))))))))))))))))))))) . - 2008-04-08 22:11:46 29.696 ---- aw C: \ WINDOWS \ apphelp32.dll + 2008-04-09 17:08:03 9.472 ---- aw C: \ WINDOWS \ apphelp32.dll - 2008-04-08 22:11:46 14.592 ---- aw C: \ WINDOWS \ asferror32.dll + 2008-04-09 17:08:03 8.448 ---- aw C: \ WINDOWS \ asferror32.dll - 2008-04-08 22:11:46 29.952 ---- aw C: \ WINDOWS \ asycfilt32.dll + 2008-04-09 17:08:03 12.800 ---- aw C: \ WINDOWS \ asycfilt32.dll - 2008-04-08 22:11:46 20.480 ---- aw C: \ WINDOWS \ athprxy32.dll + 2008-04-09 17:08:03 18.432 ---- aw C: \ WINDOWS \ athprxy32.dll - 2008-04-08 22:11:46 17.408 ---- aw C: \ WINDOWS \ ati2dvaa32.dll + 2008-04-09 17:08:03 16.896 ---- aw C: \ WINDOWS \ ati2dvaa32.dll - 2008-04-08 22:11:46 10.752 ---- aw C: \ WINDOWS \ ati2dvag32.dll + 2008-04-09 17:08:03 20.480 ---- aw C: \ WINDOWS \ ati2dvag32.dll - 2008-04-08 22:11:46 22.016 ---- aw C: \ WINDOWS \ audiosrv32.dll + 2008-04-09 17:08:03 10.496 ---- aw C: \ WINDOWS \ audiosrv32.dll - 2008-04-08 22:11:47 22.272 ---- aw C: \ WINDOWS \ autodisc32.dll + 2008-04-09 17:08:03 30.464 ---- aw C: \ WINDOWS \ autodisc32.dll - 2008-04-08 22:11:47 12.288 ---- aw C: \ WINDOWS \ avifile32.dll + 2008-04-09 17:08:04 25.856 ---- aw C: \ WINDOWS \ avifile32.dll - 2008-04-08 22:11:47 27.392 ---- aw C: \ WINDOWS \ avisynthex32.dll + 2008-04-09 17:08:04 23.296 ---- aw C: \ WINDOWS \ avisynthex32.dll - 2008-04-08 22:11:47 23.808 ---- aw C: \ WINDOWS \ aviwrap32.dll + 2008-04-09 17:08:04 11.776 ---- aw C: \ WINDOWS \ aviwrap32.dll - 2008-04-08 22:11:47 17.920 ---- aw C: \ WINDOWS \ browserad.dll + 2008-04-09 17:08:04 18.944 ---- aw C: \ WINDOWS \ browserad.dll - 2008-04-08 22:11:45 31.488 ---- aw C: \ WINDOWS \ changeurl_30.dll + 2008-04-09 17:08:03 29.696 ---- aw C: \ WINDOWS \ changeurl_30.dll - 2007-10-10 15:36:22 10.134 ar ---- C: \ Windows \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:00 10.134 ar ---- C: \ Windows \ Installer \ (05BCCF27-DC23-4ED9-87A2-F8D5B244B4C4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:18 26.582 ar ---- C: \ Windows \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe + 2008-04-09 07:30:56 26.582 ar ---- C: \ Windows \ Installer \ (212F5777-1190-4DEF-8E4D-6B2F313B45E7) \ PerfectDisk.exe - 2007-10-10 15:36:46 10.134 ar ---- C: \ Windows \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:31 10.134 ar ---- C: \ Windows \ Installer \ (324D4909-7A7B-45CD-B199-E975DC108249) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 10.134 ar ---- C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:45 10.134 ar ---- C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:53 25.214 ar ---- C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe + 2008-04-09 07:31:45 25.214 ar ---- C: \ Windows \ Installer \ (3A836186-46F8-4388-9830-820E35C02992) \ Sm_En_DiagD_7C6BED816D7E4AD1AEAF5A1A DB6C8676.exe - 2007-10-10 15:36:52 10.134 ar ---- C: \ Windows \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:43 10.134 ar ---- C: \ Windows \ Installer \ (3AFF4279-A590-4010-8C8A-3B096A220CFC) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:59 10.134 ---- C ar: \ Windows \ Installer \ (3C441434-737C-4D54-8EAB, B409BE54E734) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:50 10.134 ar ---- C: \ Windows \ Installer \ (3C441434-737C-4D54-8EAB-B409BE54E734) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:00 10.134 ar ---- C: \ Windows \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:52 10.134 ar ---- C: \ Windows \ Installer \ (53C32728-D434-4143-9C9D-D73D68D00893) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:02 10.134 ar ---- C: \ Windows \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:55 10.134 ar ---- C: \ Windows \ Installer \ (5E7EBB6D-F44B-4D8B-9C52-F0F9173FD166) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:48 10.134 ar ---- C: \ Windows \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:36 10.134 ar ---- C: \ Windows \ Installer \ (6EA0ABC4-172B-48D4-AF26-93322D7FDE72) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:50 10.134 ar ---- C: \ Windows \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:42 10.134 ar ---- C: \ Windows \ Installer \ (A542D695-16D3-4F89-A6F1-091F009B8ABA) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 10.134 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:07 10.134 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ ARPPRODUCTICON.exe - 2007-10-10 15:35:46 25.214 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe + 2008-04-09 07:30:07 25.214 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Desktop_En_Rps_A64EE928C7A645A784CE5 9FBDBDD9D1B.exe - 2007-10-10 15:35:46 25.214 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe + 2008-04-09 07:30:07 25.214 ar ---- C: \ Windows \ Installer \ (AFE0D559-DAC2-4DF0-B432-4CBA15769AA9) \ Sm_En_Rps_A64EE928C7A645A784CE59FBDB DD9D1B.exe - 2007-10-10 15:36:49 10.134 ar ---- C: \ Windows \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:41 10.134 ar ---- C: \ Windows \ Installer \ (B5C0FD16-3A5D-40D5-8B59-4B43279BB5D0) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:57 10.134 ar ---- C: \ Windows \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:47 10.134 ar ---- C: \ Windows \ Installer \ (C831972C-3834-4D9D-A095-8350B324AC3C) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:07 10.134 ar ---- C: \ Windows \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:29 10.134 ar ---- C: \ Windows \ Installer \ (D8AEA1D1-78FE-4CE1-9405-D7E55E797C4D) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:11 10.134 ar ---- C: \ Windows \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:50 10.134 ar ---- C: \ Windows \ Installer \ (DD1C392B-226D-42C9-B8E6-2A9BEF7583B4) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:32 10.134 ar ---- C: \ Windows \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:10 10.134 ar ---- C: \ Windows \ Installer \ (ECBDDBD7-43CC-417C-B87A-943AFED8EB57) \ ARPPRODUCTICON.exe - 2007-10-10 15:36:09 10.134 ar ---- C: \ Windows \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe + 2008-04-09 07:30:32 10.134 ar ---- C: \ Windows \ Installer \ (EE1D5780-AF29-4DC4-A107-3FD5F79AC63A) \ ARPPRODUCTICON.exe - 2007-10-10 15:37:01 10.134 ar ---- C: \ Windows \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe + 2008-04-09 07:31:53 10.134 ar ---- C: \ Windows \ Installer \ (FD2EC356-DB5E-40AE-907A-9A1D38F9396D) \ ARPPRODUCTICON.exe - 1998-10-29 16:45:06 306.688 ---- aw C: \ WINDOWS \ IsUninst.exe + 1998-10-29 15:45:06 306.688 ---- aw C: \ WINDOWS \ IsUninst.exe - 2008-04-08 22:11:49 14.080 ---- aw C: \ WINDOWS \ msa64chk.dll + 2008-04-09 17:08:06 11.776 ---- aw C: \ WINDOWS \ msa64chk.dll - 2008-04-08 22:11:49 26.368 ---- aw C: \ WINDOWS \ msapasrc.dll + 2008-04-09 17:08:06 26.624 ---- aw C: \ WINDOWS \ msapasrc.dll - 2008-04-08 22:11:48 25.344 ---- aw C: \ WINDOWS \ ntnut.exe + 2008-04-09 17:08:05 8.960 ---- aw C: \ WINDOWS \ ntnut.exe - 2008-04-08 22:11:47 18.432 ---- aw C: \ WINDOWS \ shdocpe.dll + 2008-04-09 17:08:05 32.000 ---- aw C: \ WINDOWS \ shdocpe.dll - 2008-04-08 22:11:48 21.504 ---- aw C: \ WINDOWS \ shdocpl.dll + 2008-04-09 17:08:05 27.904 ---- aw C: \ WINDOWS \ shdocpl.dll - 2007-09-24 22:30:28 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe + 2008-02-22 00:23:35 135.168 ---- aw C: \ WINDOWS \ system32 \ java.exe - 2007-09-24 22:30:30 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe + 2008-02-22 00:23:39 135.168 ---- aw C: \ WINDOWS \ system32 \ javaw.exe - 2007-09-24 23:31:42 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe + 2008-02-22 01:33:32 139.264 ---- aw C: \ WINDOWS \ system32 \ javaws.exe - 2008-04-08 22:11:50 9.984 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll + 2008-04-09 17:08:07 14.336 ---- aw C: \ WINDOWS \ system32 \ MSNSA32.dll - 2008-04-08 22:11:48 31.488 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe + 2008-04-09 17:08:05 28.928 ---- aw C: \ WINDOWS \ system32 \ ntnut32.exe - 2008-04-08 22:11:48 21.760 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll + 2008-04-09 17:08:05 26.880 ---- aw C: \ WINDOWS \ system32 \ shdocpe.dll - 2008-04-08 22:11:48 19.712 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll + 2008-04-09 17:08:06 30.720 ---- aw C: \ WINDOWS \ system32 \ SIPSPI32.dll - 2008-04-08 22:11:47 12.800 ---- aw C: \ WINDOWS \ winsb.dll + 2008-04-09 17:08:04 18.432 ---- aw C: \ WINDOWS \ winsb.dll - 2007-10-10 15:35:42 1.233.920 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ Msxml4.dll + 2008-04-09 07:30:03 1.233.920 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2_6bd6b9abf34 5378f_4.20.9818.0_x-ww_8ff50c5d \ Msxml4.dll - 2007-10-10 15:35:42 82.432 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll + 2008-04-09 07:30:03 82.432 ---- aw C: \ WINDOWS \ WinSxS \ x86_Microsoft.MSXML2R_6bd6b9abf3 45378f_4.1.0.0_x-ww_29c3ad6a \ Msxml4r.dll . - Kratki pregled resetirati na trenutni datum -- . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & čitljiv default unose se ne prikazuju REGEDIT4 [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ Run] "MsnMsgr" = "C: \ Program Files \ MSN Messenger \ MsnMsgr.exe" [2007-01-19 12:54 5674352] "SB Audigy 2 Početak Meni" = "/ L: ENG" [] "Ctfmon.exe" = "C: \ WINDOWS \ system32 \ Ctfmon.exe" [2004-08-04 08:56 15360] [HKEY_CURRENT_USER \ Software \ Microsoft \ Windows \ Curre ntVersion \ RunOnce] "IndexCleaner" = "C: \ Program Files \ Djevičanski Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2004-03-15 01:04 122933] "UpdateManager" = "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" [2003-08-19 01:01 110592] "CTSysVol" = "C: \ Program Files \ Creative \ SBAudigy2 \ Surround Mixer \ CTSysVol.exe" [2002-10-29 09:18 49152] "CTDVDDet" = "C: \ Program Files \ Creative \ SBAudigy2 \ DVDAudio \ CTDVDDet.EXE" [2002-09-30 01:00 45056] "CTHelper" = "CTHELPER.EXE" [2003-02-20 23:45 28672 C: \ WINDOWS \ system32 \ CTHELPER.EXE] "AsioReg" = "Regsvr32.exe" [2004-08-04 08:56 11776 C: \ WINDOWS \ system32 \ regsvr32.exe] "UpdReg" = "C: \ WINDOWS \ UpdReg.EXE" [2000-05-11 01:00 90112] "ATIPTA" = "C: \ Program Files \ ATI Technologies \ ATI Control Panel \ atiptaxx.exe" [2004-05-25 22:35 335872] "BJCFD" = "C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe" [2003-01-27 17:16 376912] "WinampAgent" = "C: \ Program Files \ Winamp \ winampa.exe" [2008-01-15 23:54 37376] "StartCCC" = "C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statični \ CLIStart.exe" [2006-11-10 13:35 90112] "PWRISOVM.EXE" = "C: \ Program Files \ Power PC \ PWRISOVM.EXE" [2008-03-15 00:50 233472] "workflow" = "D: \ instalira \ workflow.exe" [] "Broadbandadvisor.exe" = "C: \ Program Files \ Djevičanski Broadband \ savjetnik \ Broadbandadvisor.exe" [2007-08-07 18:49 2061552] "PCguard" = "C: \ Program Files \ Djevičanski Broadband \ PCguard \ Rps.exe" [2007-09-05 14:10 310000] "-FreedomNeedsReboot" = "C: \ Program Files \ Djevičanski Broadband \ PCguard \ ZkRunOnceR.exe" [2007-09-05 14:10 13552] "SunJavaUpdateSched" = "C: \ Program Files \ Java \ jre1.6.0_05 \ bin \ jusched.exe" [2008-02-22 04:25 144784] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ RunOnce] "IndexCleaner" = "C: \ Program Files \ Djevičanski Broadband \ PCguard \ IdxClnR.exe" [2007-09-05 14:09 61168] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "CTFMON.EXE" = "C: \ WINDOWS \ System32 \ CTFMON.EXE" [2004-08-04 08:56 15360] C: \ Documents and Settings \ All Users \ Start Menu \ Programs \ Startup \ Adobe Reader Speed Launch.lnk - C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe [2004-12-14 05:44:06 29696] Microsoft Office.lnk - C: \ Program Files \ Microsoft Office \ Office \ OSA9.EXE [2000-01-21 09:15:54 65588] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ drivers32] "VIDC.X264" = x264vfw.dll "msacm.ac3acm" = AC3ACM.acm "msacm.scg726" = scg726.acm "msacm.alf2cd" = alf2cd.acm "vidc.dvsd" = mcdvd_32.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ shared tools \ msconfig \ startupreg \ demon Alati] - a ------ 2007-08-29 16:09 171464 C: \ Program Files \ DAEMON Tools \ daemon.exe [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile] "EnableFirewall" = 0 (0x0) [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ \ Program Files \ \ Messenger \ \ msmsgs.exe" = "% windir% \ \ Network Diagnostic \ \ xpnetdiag.exe" = "C: \ \ Program Files \ \ Skype \ \ Phone \ \ Skype.exe" = "C: \ \ Program Files \ \ Messenger \ \ msnmsgr.exe" = "C: \ \ Program Files \ \ Messenger \ \ livecall.exe" = "C: \ Program Files \ Stardock Games \ \ Sins of Solar Empire \ \ Sins of Solar Empire.exe" = "C: \ \ Program Files \ \ Bonjour \ \ mDNSResponder.exe" = [HKLM \ ~ \ Services \ sharedaccess \ Parameters \ firewallpo licy \ standardprofile \ GloballyOpenPorts \ List] "15808: TCP" = 15808: TCP: BitComet 15.808 TCP "15808: UDP" = 15.808: UDP: 15808 UDP BitComet "3724: TCP" = 3724: TCP: Mećava Downloader: 3724 S3 iadusb; GlobespanVirata USB IAD modema LAN, C: \ WINDOWS \ system32 \ drivers \ glauiad.sys [2004-07-02 09:20] S3 Radialpoint Security Services; Djevičanski Broadband PCguard; C: \ WINDOWS \ system32 \ dllhost.exe [2004-08-04 08:56] S3 XDva037; XDva037, C: \ WINDOWS \ system32 \ XDva037.sys [] . Sadržaj je 'Scheduled Tasks' folder "2008-04-03 19:15:02 C: \ WINDOWS \ Tasks \ AppleSoftwareUpdate.job" - C: \ Program Files \ Apple Software Update \ SoftwareUpdate.exe . ************************************************** ************************ catchme 0.3.1351 W2K/XP/Vista - rootkit / potaja detector by Gmer zlonamjernih programa, http://www.gmer.net Rootkit scan 2008-04-09 18:26:36 5/1/2600 Windows Service Pack 2 NTFS skeniranja skrivenih procesa ... skeniranja skrivenih autostart entries ... skeniranja skrivenih datoteka ... scan uspješno završena skrivenih datoteka: 0 ************************************************** ************************ . ------------------------ Other Running Processes ----------------------- -- . C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Program Files \ Virgin Širokopojasni \ PCguard \ Fws.exe C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ Program Files \ Bonjour \ mDNSResponder.exe C: \ WINDOWS \ System32 \ CTsvcCDA.exe C: \ Program Files \ Common Files \ Authentium \ AntiVirus \ dvpapi.exe C: \ Program Files \ CA \ PPRT \ bin \ ITMRTSVC.exe C: \ Program Files \ Raxco \ PerfectDisk \ PDAgent.exe C: \ WINDOWS \ system32 \ PnkBstrA.exe C: \ Program Files \ Analog Devices \ SoundMAX \ spkrmon.exe C: \ WINDOWS \ system32 \ wdfmgr.exe C: \ WINDOWS \ System32 \ MsPMSPSv.exe C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statični \ MOM.EXE C: \ Program Files \ Raxco \ PerfectDisk \ PDEngine.exe C: \ Program Files \ Djevičanski Broadband \ savjetnik \ BroadbandadvisorComHandler.exe C: \ Program Files \ Djevičanski Broadband \ PCguard \ rpsupdaterR.exe C: \ Program Files \ ATI Technologies \ ATI.ACE \ Core-Statični \ ccc.exe C: \ Program Files \ MSN Messenger \ usnsvc.exe . ************************************************** ************************ . Completion time: 2008-04-09 18:31:56 - stroj digne ComboFix-u karanteni-files.txt 2008-04-09 17:31:47 ComboFix2.txt 2008-04-09 00:59:01 ComboFix3.txt 2008-04-09 00:41:25 Pre-Run: 12340674560 bytes free Post-Run: 12324302848 bytes free . 2008-03-22 04:20:29 --- EOF --- |
|
#4
| |||
| |||
| Izgleda dobro. Sada pokrenite ATF Čistač opet da biste dobili osloboditi od zloban kartoteka u temp mape. Stavio sam Combofix se prijaviti na post. Siguran sam da možete vidjeti ovo: UPOZORENJE-ovaj stroj nema Recovery Console Installed! To je uobičajeno i možete instalirati recovery konzolu ako odaberete slijedeći upute OVDJE Vrijeme je za napraviti neki čišćenje i siguran posao koje ste učinili.
![]() Gore navedeni postupak će:
1. Dvaput kliknite na OTMoveIt2.exe pokrenuti ga. Vista korisnike kliknite desnom tipkom i odaberite Pokreni kao administrator 2. Kliknite na Cleanup! gumb. 3. OTMoveIt2 će preuzeti s Interneta lista, ako je vaš vatrozid ili drugi obrambeni programi upozorenja vas, dopustiti pristup. 4. Kliknite DA Na sljedećem retku (popis preuzetih, Želite li početi čišćenje postupak?)
Postavljanje novu točku vraćanja NAKON čišćenja sustava omogućit će računalo roll-back na čisto radno države ako je potrebno.
Zastario softver sigurnosnih propusta ima zlonamjernih programa koji mogu iskoristiti.
Također pogledajte Computer Sporo? To ne može biti zaštita od zlonamjernih programa besplatno za čišćenje / održavanje alata za pomoć držati tvoj računalo trčanje glatka. Pustiti mene znati ako ništa drugo dolazi gore. |