manji kapital -

Magazine
Go Back   Computer soka > Computer Software > Virus, Spyware i sigurnost

Register


 Default 

Niste sigurni, ako je to virus ili BOSD




Reply
 
Thread Tools
  #1  
Old 15 svi 2009, 21:29
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

Bio je na liniji writting email jednom imao taj dogoditi. Dobio sam izgledao kao što mala napomena karticu koja ide od ugla do ugla s malo plave trgu u gornjem lijevom kutu i ruci plavom linijom izvodi kroz njih. Sve je nestala ikona, tipkovnice i miša neće funkcionirati. Jedini način JA mogao ukloniti je za isključivanje napajanja.
Kad sam kući s posla i tokareno računalo natrag na svim sam je crni ekran.
Zato sam pokušao sve sljedeće.
Prva uklonjena kabela na monitor i dobili probnu svjetlo na monitor. ček Internet sa starim PC i to radi dobro. Tada je morao ukloniti CPU ventilatora (jedan na ovom računalu je kao trubač više od ventilatora.) Sam uobičajen vidjeti ako JA mogao čuti navijač procesor radi. Ona radi u redu. Tada sam bio idući u pokušati jedan memtest, ali nije mogao dobiti bilo što na moniter pa ne znam da je pokrenut ili ne.
Uklonili sva vlast na pc i bateriju za ovo bi se zvučni signal. je dobio nijedan bip kad vlast upecan back up. I ja sam također primijetio da kada su svi kabeli upecan i vlast je uključen tipkovnice i miša ne rade ..
Jednom sam dobio virus softver skinuti u starom pc ću provjeriti da li je hard disk i dalje radi.
Kao za hijacks file sam išla samo jednom prije nego što se to događalo, ali to je bio sa WinPatrol i to je bio spremljen u datoteku. Ako ne mogu dobiti hard disk da radi u tom starom računalu ću to post.
  #2  
Old 16 svi 2009, 14:38
Moderator / ica grupe
 
Default Niste sigurni, ako je to virus ili BOSD

Bez logove ne možemo napraviti ako je određivanje štetnih sadržaja ili ne.
__________________

  #3  
Old 17 svi 2009, 14:29
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

Će raditi na dobivanju log datoteku. Hard disk doza funkcionirati u starom računalu.
  #4  
Old 17 svi 2009, 15:05
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

Ovdje je zapisnik koji je vodio samo pred sudar.

Prijavite created by WinPatrol PLUS verzija 16.0.2009.2:16.0.2009.2
Scan spremljena u 11:57:58, dana 5/13/2009
Platforma: Windows XP SP3 Service Pack 3 (Build 2600)
MSIE: Internet Explorer (8.00.6001.18372)
Boot mode: Normal
Pokretanje procesa:
C: \ Windows \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ Winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ Svchost.exe
C: \ Program Files \ COMODO \ COMODO Internet Security \ cmdagent.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ UOBIČAJENA Files \ AOL \ ACS \ AOLacsd.exe
C: \ Program Files \ UOBIČAJENA Files \ AOL \ TopSpeed \ 2,0 \ aoltsmon.exe
C: \ WINDOWS \ ARSERVICE.EXE
C: \ WINDOWS \ explorer.exe
C: \ WINDOWS \ system32 \ bgsvcgen.exe
C: \ WINDOWS \ ehome \ ehrecvr.exe
C: \ WINDOWS \ ehome \ ehSched.exe
C: \ Program Files \ SPOTMAU WINCARES 2007 \ FOLDERPROTECTSERVICE.EXE
C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe
C: \ Program Files \ MALWAREBYTES 'PROTUPJEŠAČKIH štetnih sadržaja \ MBAMSERVICE.EXE
C: \ WINDOWS \ system32 \ nvsvc32.exe
C: \ Program Files \ UOBIČAJENA Files \ boundary NOVO \ PrismXL \ PRISMXL.SYS
C: \ WINDOWS \ system32 \ atwtusb.exe
C: \ WINDOWS \ ehome \ ehtray.exe
C: \ Program Files \ DIGITAL MEDIA READER \ READERICON45G.EXE
C: \ WINDOWS \ RTHDCPL.exe
C: \ WINDOWS \ arpwrmsg.exe
C: \ Program Files \ LEXMARK 5200 SERIES \ lxbtbmgr.exe
C: \ WINDOWS \ ehome \ ehmsas.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ Program Files \ LEXMARK 5200 SERIES \ lxbtbmon.exe
C: \ Program Files \ UOBIČAJENA Files \ AOL \ 1229613011 \ EE \ AOLSOFTWARE.EXE
C: \ Program Files \ COMODO \ SafeSurf \ cssurf.exe
C: \ Program Files \ COMODO \ COMODO Internet Security \ cfp.exe
C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
C: \ WINDOWS \ system32 \ WTMKM.exe
C: \ Program Files \ UOBIČAJENA Files \ ULEAD SYSTEMS \ AUTODETECTOR \ Monitor.exe
C: \ Program Files \ BILLP Studios \ WINPATROL \ WINPATROL.EXE
C: \ Program Files \ Messenger \ msmsgs.exe
C: \ WINDOWS \ system32 \ Ctfmon.exe
C: \ WINDOWS \ system32 \ SEARCHINDEXER.EXE
C: \ Program Files \ FILEHIPPO.COM \ UPDATECHECKER.EXE
C: \ Program Files \ FINEPIXVIEWER \ QUICKDCF2.EXE
C: \ Program Files \ Windows Desktop Search \ WINDOWSSEARCH.EXE
C: \ WINDOWS \ system32 \ dllhost.exe
C: \ Program Files \ AMERICA ONLINE 9,0 \ waol.exe
C: \ Program Files \ AMERICA ONLINE 9,0 \ shellmon.exe
C: \ Program Files \ BILLP Studios \ WINPATROL \ WINPATROLEX.EXE
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.comodo.com/search/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Link Helper - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Program Files \ Common Files \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: VIPTToolbarManager Class - (1A2641AE-2C42-4C51-A05F-8ECEC3FDC94D) - C: \ Program Files \ Visual IP Trace 2008 \ VisualIPTraceIE.dll
O2 - BHO: AskBar BHO - (201f27d4-3704-41d6-89c1-aa35e39143ed) - C: \ Program Files \ AskBarDis \ bar \ bin \ askBar.dll
O2 - BHO: EntDownloadHelper Class - (2956DD50-4F3E-4C20-81D1-FF36435FF288) - C: \ Program Files \ Enterra \ Download Manager \ edm.dll
O2 - BHO: AOL Toolbar Loader - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Program Files \ AOL Toolbar \ aoltb.dll
O2 - BHO: URLHooker2 Class - (93935F7F-9C88-42F8-8445-95251D27FABC) - C: \ Program Files \ Flash Video Downloader \ URLHooker.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Program Files \ Google \ googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Program Files \ Google \ GoogleToolbarNotifier \ 2.1.1119.1736 \ s wg.dll
O2 - BHO: CBrowserHelperObject Object - (CA6319C0-31B7-401E-A518-A07C3DB8F777) - c: \ windows \ system32 \ BAE.dll
O2 - BHO: Java (tm) Plug-in 2 SSV Helper - (DBC80044-A445-435b-BC74-9C25C1C588A9) - C: \ Program Files \ Java \ jre6 \ bin \ jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl Class - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Program Files \ Java \ jre6 \ lib \ rasporediti \ jqs \ ie \ jqs_plugin.dll
O3 - Toolbar: & Google - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Program Files \ Google \ googletoolbar2.dll
O3 - Toolbar: Enterra Download Manager - (B5147546-9359-4D9B-8B36-F54C54555799) - C: \ Program Files \ Enterra \ Download Manager \ edm.dll
O3 - Toolbar: Visual IP Trace - (E70C26AE-DFF1-40A8-8D37-19180F56F0AA) - C: \ Program Files \ Visual IP Trace 2008 \ VisualIPTraceIE.dll
O3 - Toolbar: AOL Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Program Files \ AOL Toolbar \ aoltb.dll
O3 - Toolbar: Ask Toolbar - (3041d03e-fd4b-44e0-b742-2d9b88305f98) - C: \ Program Files \ AskBarDis \ bar \ bin \ askBar.dll
O4 - HKLM \ .. \ Run: [ehTray] C: \ WINDOWS \ ehome \ ehtray.exe
O4 - HKLM \ .. \ Run: [readericon] C: \ Program Files \ Digital Media Reader \ readericon45G.exe
O4 - HKLM \ .. \ Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM \ .. \ Run: [NvCplDaemon] C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [AlwaysReady Power Poruka APP] ARPWRMSG.EXE
O4 - HKLM \ .. \ Run: [Lexmark 5200 series] C: \ Program Files \ Lexmark 5200 serija \ lxbtbmgr.exe
O4 - HKLM \ .. \ Run: [LXBTCATS] rundll32 C: \ WINDOWS \ System32 \ spool \ drivers \ W32X86 \ 3 \ LXBTtim e.dll, _RunDLLEntry @ 16
O4 - HKLM \ .. \ Run: [QuickTime Task] C: \ Program Files \ QuickTime \ qttask.exe-atboottime
O4 - HKLM \ .. \ Run: [NvMediaCenter] C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [HostManager] C: \ Program Files \ Common Files \ AOL \ 1229613011 \ EE \ AOLSoftware.exe
O4 - HKLM \ .. \ Run: [AOLDialer] C: \ Program Files \ Common Files \ AOL \ ACS \ AOLDial.exe
O4 - HKLM \ .. \ Run: [Pure Networks Port Magija] C: \ programa ~ 1 \ PURENE ~ 1 \ PORTMA ~ 1 \ PortAOL.exe-Run
O4 - HKLM \ .. \ Run: [REGSHAVE] C: \ Program Files \ REGSHAVE \ REGSHAVE.EXE / Autorun
O4 - HKLM \ .. \ Run: [KernelFaultCheck]% systemroot% \ system32 \ dumprep 0-k
O4 - HKLM \ .. \ Run: [Windows Defender] C: \ Program Files \ Windows Defender \ MSASCui.exe-hide
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] C: \ Program Files \ Adobe \ Reader 9,0 \ Reader \ Reader_sl.exe
O4 - HKLM \ .. \ Run: [Malwarebytes' Anti-zaštita od zlonamjernih programa] C: \ Program Files \ Malwarebytes' Anti-zaštita od zlonamjernih programa \ mbamgui.exe / starttray
O4 - HKLM \ .. \ Run: [COMODO SafeSurf] C: \ Program Files \ COMODO \ SafeSurf \ cssurf.exe-s
O4 - HKLM \ .. \ Run: [COMODO Internet Security] C: \ Program Files \ COMODO \ COMODO Internet Security \ cfp.exe-h
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] C: \ Program Files \ Java \ jre6 \ bin \ jusched.exe
O4 - HKLM \ .. \ Run: [MacrokeyManager] WTMKM.exe
O4 - HKLM \ .. \ Run: [Ulead AutoDetector v2] C: \ Program Files \ Common Files \ Ulead Systems \ AutoDetector \ Monitor.exe
O4 - HKLM \ .. \ Run: [WinPatrol PLUS] C: \ Program Files \ BillP Studios \ WinPatrol \ winpatrol.exe-expressboot
O4 - HKLM \ .. \ RunOnce: [NSSInstallation] C: \ WINDOWS \ system32 \ Adobe \ Shockwave 11 \ nssstub.exe / RunOnce
O4 - HKCU \ .. \ Run: [MSMSGS] C: \ Program Files \ Messenger \ msmsgs.exe / background
O4 - HKCU \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe
O4 - HKCU \ .. \ Run: [filehippo.com] C: \ Program Files \ filehippo.com \ UpdateChecker.exe / background
O4 - Global Startup: ExifLauncher2.lnk = C: \ Program Files \ FinePixViewer \ QuickDCF2.exe
O4 - Global Startup: Windows Search.lnk = C: \ Program Files \ Windows Desktop Search \ WindowsSearch.exe
O8 - Extra kontekst meni stavka: & AOL Toolbar Search - C: \ Documents and Settings \ All Users \ Application Data \ AOL \ ieToolbar \ resurse \ en-us \ Local \ search.html
O8 - Extra kontekst meni stavka: & Download by Enterra Download Manager - res: / / C: \ Program Files \ Enterra \ Download Manager \ edm.dll/3000
O9 - Extra button: Enterra Download Manager - (1AB6CC97-17C1-4207-BC51-5C9D435A338E) - res: / / C: \ Program Files \ Enterra \ Download Manager \ edm.dll/3002
O9 - Extra button: (no name) - (85d1f590-48f4-11d9-9669-0800200c9a66) -% windir% \ bdoscandel.exe
O9 - Extra 'Tools' MENUITEM: Deinstalacija BitDefender Online Scanner V8 - (85d1f590-48f4-11d9-9669-0800200c9a66) -% windir% \ bdoscandel.exe
O9 - Extra button: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra button: FWI Prijevara štit - (44E50755-EAC0-49ea-B52D-37372157D100) - C: \ Program Files \ FWI \ FraudShield \ FWIFraudShield.exe (HKCU)
O9 - Extra button: Flash Video Downloader - (df7831dd-a048-4336-8cc8-266a03f00d63) - C: \ Program Files \ Flash Video Downloader \ FlashRunner.exe (HKCU)
O11 - Options group: [Java (ned)] Java (ned) - C: \ Program Files \ Java \ jre6 \ bin
O11 - Options group: [] --
O14 - IERESET.INF: START_PAGE_URL = http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
O14 - IERESET.INF: SEARCH_PAGE_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
O14 - IERESET.INF: HKCU, Start Page =%% START_PAGE_URL
O14 - IERESET.INF: HKLM, Default_Page_URL =% START_PAGE_URL%
O14 - IERESET.INF: HKLM, Default_Search_URL =% SEARCH_PAGE_URL%
O14 - IERESET.INF: HKLM, Search Page =%% SEARCH_PAGE_URL
O14 - IERESET.INF: HKCU, Search Page =%% SEARCH_PAGE_URL
O15 - Trusted Zone: aol.com
O16 - DPF: (5ED80217-570B-4DA9-BF44-BE107C0EC166) (Windows Live Safety Center Base Module) -- http://cdn.scan.onecare.live.com/res...scbase5036.cab
O16 - DPF: (8AD9C840-044E-11D1-B3E9-00805F499D93) (Java Plug-in 1.6.0_13) -- http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
O16 - DPF: (A90A5822-F108-45AD-8482-9BC8B12DD539) (presudno cpcScan) -- http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: (B1E2B96C-12FE-45E2-BEF1-44A219113CDD) (SABScanProcesses Class) -- http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: (BB21F850-63F4-4EC9-BF9D-565BD30C9AE9) (A-kvadratna Scanner) -- http://ax.emsisoft.com/asquared.cab
O16 - DPF: (CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA) (Java Plug-in 1.5.0_02) -- http://java.sun.com/update/1.5.0/jin...ndows-i586.cab
O16 - DPF: (CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA) (Java Plug-in 1.6.0_05) -- http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
O16 - DPF: (CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA) (Java Plug-in 1.6.0_07) -- http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
O16 - DPF: (CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA) (Java Plug-in 1.6.0_13) -- http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
O16 - DPF: (CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA) (Java Plug-in 1.6.0_13) -- http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
O16 - DPF: (E8F628B5-259A-4734-97EE-BA914D7BE941) (Driver Agent ActiveX Control) -- http://plugin.driveragent.com/files/driveragent.cab
O21 - WPDShServiceObj - WPDShServiceObj Class - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj.dll
O23 - Service: AOL Povezivanje Service - AOL LLC - C: \ Program Files \ Common Files \ AOL \ ACS \ AOLacsd.exe
O23 - Service: AOL TopSpeed Monitor - America Online, Inc - C: \ Program Files \ Common Files \ AOL \ TopSpeed \ 2,0 \ aoltsmon.exe
O23 - Service: B's Snimač GOLD Library General Service - BHA Corporation - C: \ WINDOWS \ system32 \ bgsvcgen.exe
O23 - Service: COMODO Internet Security Helper Service - - C: \ Program Files \ COMODO \ COMODO Internet Security \ cmdagent.exe
O23 - Service: FolderProtectService - - C: \ Program Files \ Spotmau WinCares 2007 \ FolderProtectService.exe
O23 - Service: Google Updater Service - Google - C: \ Program Files \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: Java Quick Početničko - - C: \ Program Files \ Java \ jre6 \ bin \ jqs.exe-service-config C: \ Program Files \ Java \ jre6 \ lib \ rasporediti \ jqs \ jqs.conf
O23 - Service: lxbt_device - - C: \ WINDOWS \ system32 \ lxbtcoms.exe-service
O23 - Service: MBAMService - Malwarebytes Corporation - C: \ Program Files \ Malwarebytes' Anti-zaštita od zlonamjernih programa \ mbamservice.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32.exe
O23 - Service: WTService - - C: \ WINDOWS \ system32 \ atwtusb.exe-a
Additional Info WinPatrol --- ---
Default Browser: Windows ® Internet Explorer - Internet Explorer verzija 8.00.6001.18372
MSIE: Internet Explorer (8.00.6001.18372)
25 IE Cookies u mapu: C: \ Documents and Settings \ Owner.YOUR-DC0C6E8137 \ Cookies \
WP00 - HKLM \ CS1: BootExecute = autocheck autochk *
WP00 - HKLM \ CCS: BootExecute = autocheck autochk *
WP00 - HKLM \ CS2: BootExecute = autocheck autochk *
WP00 - HKLM \ CS3: BootExecute = autocheck autochk *
WP02 - HKLM \ CCS: Command = C: \ WINDOWS \ system32 \ cmd.exe
WP03 - Automatic Windows Update = 4: automatsko preuzimanje ažuriranja za preporučio moj računalo i instalirati ih.

WP08 - HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ URL \ DefaultPrefix: Default = http://
WP08 - HKLM \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ URL \ prefiksima: www = http://
WP31 - Scheduled Tasks: [Uniblue SpeedUpMyPC.job] C: \ Program Files \ Uniblue \ SpeedUpMyPC 3 \ SpeedUpMyPC.exe Nikada
WP31 - Scheduled Tasks: [Uniblue SpeedUpMyPC Nag.job] C: \ Program Files \ Uniblue \ SpeedUpMyPC 3 \ SpeedUpMyPC.exe Nikada
WP31 - Scheduled Tasks: [NSSstub.job] C: \ WINDOWS \ system32 \ Adobe \ Shockwave 11 \ nssstub.exe 05/13/2009 11:30 PM
WP31 - Scheduled Tasks: [Driver Robot.job] C: \ Program Files \ Driver Robot \ DriverRobot.exe Nikada
WP31 - Scheduled Tasks: [Basic čistih up.job] C: \ Program Files \ Panda Security \ Panda Global Protection 2009 \ PlaTasks.exe Nikada
WP31 - Scheduled Tasks: [User_Feed_Synchronization-FD03A801 (-5427-4516-93CD-BC74874B5889). Job] C: \ WINDOWS \ system32 \ msfeedssync.exe 05/13/2009 11:42 PM
WP16 - ActiveX: (00EF2092-6AC5-47C0-BD25-CF2D5D657FEB) [Script Object Google] C: \ Program Files \ Google \ GOOGLETOOLBAR2.DLL 4, 0, 1601, 4978
WP16 - ActiveX: (17492023-C23A-453E-A040-C7C580BBF700) [Windows Genuine Advantage Validation Tool] C: \ WINDOWS \ system32 \ LEGITCHECKCONTROL.DLL 1.7.0069.2
WP16 - ActiveX: (19916E01-B44E-94A4-4E31-4696DF46157B) [InformationCardSigninHelper Klasa] C: \ WINDOWS \ system32 \ icardie.dll 8.00.6001.18372
WP16 - ActiveX: (25336920-03F9-11CF-8FD0-00AA00686F13) [HTML Document] C: \ WINDOWS \ system32 \ Mshtml.dll 8.00.6001.18372
WP16 - ActiveX: (2933BF90-7B36-11D2-B20E-00C04F983E60) [XML DOM Document] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (2D360201-FFF5-11D1-8D03-00A0C959BC0A) [DHTML Uređivanje Kontrola sigurno za skriptiranje za IE5] C: \ Program Files \ UOBIČAJENA Files \ Microsoft Shared \ Triedit \ dhtmled.ocx 6.01.9234
WP16 - ActiveX: (48123BC4-99D9-11D1-A6B3-00C04FD91555) [XML dokument] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (4E430174-1673-4FF3-BF28-A3B37F6573E7) [Windows Desktop Search Combo Control] C: \ Program Files \ Windows Desktop Search \ wdsShell.dll 7.0.6001.16503
WP16 - ActiveX: (4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2) [Microsoft Terminal Services Client Control (redist)] C: \ WINDOWS \ system32 \ mstscax.dll 6.0.6001.18000
WP16 - ActiveX: (4EDCB26C-D24C-4e72-AF07-B576699AC0DE) [Microsoft Terminal Services Client Control (redist)] C: \ WINDOWS \ system32 \ mstscax.dll 6.0.6001.18000
WP16 - ActiveX: (63610B21-6B0D-46C5-909D-3BD000B9A5A9) [ToolbarParams Klasa] C: \ Program Files \ AOL TOOLBAR \ aoltb.dll 5.13.4.1
WP16 - ActiveX: (6414512B-B978-451D-A0D8-FCFDF33E833C) [WUWebControl Klasa] C: \ WINDOWS \ system32 \ wuweb.dll 7.2.6001.788
WP16 - ActiveX: (6BF52A52-394A-11D3-B153-00C04F79FAA6) [Windows Media Player] C: \ WINDOWS \ system32 \ wmp.dll 11.0.5721.5260
WP16 - ActiveX: (6E32070A-766D-4EE6-879C-DC1FA91D2FC3) [MUWebControl Klasa] C: \ WINDOWS \ system32 \ muweb.dll 7.2.6001.788
WP16 - ActiveX: (72267F6A-A6F9-11D0-BC94-00C04FB67863) [Active Desktop selilac] C: \ WINDOWS \ system32 \ shell32.dll 6.00.2900.5622
WP16 - ActiveX: (7390f3d8-0439-4c05-91e3-cf5cb290c3d0) [Microsoft Terminal Services Client Control (redist)] C: \ WINDOWS \ system32 \ mstscax.dll 6.0.6001.18000
WP16 - ActiveX: (75565ED2-1560-4F15-B841-20358DE6A0D1) [ImageControl Klasa] C: \ WINDOWS \ system32 \ mfimgvwr.ocx 2.0.0.1
WP16 - ActiveX: (7584c670-2274-4efb-b00b-d6aaba6d3850) [Microsoft Terminal Services Client Control (redist)] C: \ WINDOWS \ system32 \ mstscax.dll 6.0.6001.18000
WP16 - ActiveX: (8856F961-340A-11D0-A96B-00C04FD705A2) [Microsoftova web preglednika] C: \ WINDOWS \ system32 \ ieframe.dll 8.00.6001.18372
WP16 - ActiveX: (88D969C0-F192-11D4-A65F-0040963251E5) [XML DOM Document 4,0] C: \ WINDOWS \ system32 \ msxml4.dll 4.20.9870.0
WP16 - ActiveX: (88D969C5-F192-11D4-A65F-0040963251E5) [XML HTTP 4,0] C: \ WINDOWS \ system32 \ msxml4.dll 4.20.9870.0
WP16 - ActiveX: (88D969EA-F192-11D4-A65F-0040963251E5) [XML HTTP 5,0] C: \ Program Files \ UOBIČAJENA Files \ Microsoft Shared \ OFFICE11 \ msxml5.dll 5.20.1087.0
WP16 - ActiveX: (8AD9C840-044E-11D1-B3E9-00805F499D93) [Java Plug-in 1.6.0_13] C: \ Program Files \ Java \ jre6 \ bin \ jp2iexp.dll
WP16 - ActiveX: (9059f30f-4eb1-4bd2-9fdc-36f43a218f4a) [Microsoft Terminal Services Client Control (redist)] C: \ WINDOWS \ system32 \ mstscax.dll 6.0.6001.18000
WP16 - ActiveX: (B1E2B96C-12FE-45E2-BEF1-44A219113CDD) [SABScanProcesses Klasa] C: \ WINDOWS \ Downloaded Program Files \ sabspx.dll 1.0.0.1
WP16 - ActiveX: (BB21F850-63F4-4EC9-BF9D-565BD30C9AE9) [A-kvadratna Scanner] C: \ WINDOWS \ Downloaded Program Files \ asquared.ocx 4.0.0.0
WP16 - ActiveX: (CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA) [Java Plug-in 1.6.0_05] C: \ Program Files \ Java \ jre6 \ bin \ jp2iexp.dll
WP16 - ActiveX: (CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA) [Java Plug-in 1.6.0_07] C: \ Program Files \ Java \ jre6 \ bin \ jp2iexp.dll
WP16 - ActiveX: CFBFAE00 (-17A6-11D0-99CB-00C04FD64497) [Microsoft Url Ključna zakačaljka] C: \ WINDOWS \ system32 \ ieframe.dll 8.00.6001.18372
WP16 - ActiveX: (D27CDB6E-AE6D-11CF-96B8-444553540000) [Shockwave Flash Object] C: \ WINDOWS \ system32 \ Macromed \ flash \ Flash10b.ocx 10,0,22,87
WP16 - ActiveX: (DFEAF541-F3E1-4C24-ACAC-99C30715084A) [Microsoft Silverlight] C: \ Program Files \ Microsoft SILVERLIGHT \ 2.0.40115.0 \ npctrl.dll 2.0.40115.0
WP16 - ActiveX: (E8F628B5-259A-4734-97EE-BA914D7BE941) [Driver Agent ActiveX Control] C: \ WINDOWS \ Downloaded Program Files \ DRIVERAGENT.OCX 1.0.0.0
WP16 - ActiveX: (EA756889-2338-43DB-8F07-D1CA6FB9C90D) [IAOLTBSearch Klasa] C: \ Program Files \ AOL TOOLBAR \ aoltb.dll 5.13.4.1
WP16 - ActiveX: (ED8C108E-4349-11D2-91A4-00C04F7969E8) [XML HTTP Request] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (F5078F32-C551-11D3-89B9-0000F81FE221) [XML DOM Document 3,0] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (F6D90F11-9C73-11D3-B32E-00C04F990BB4) [XML DOM Document] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (F6D90F16-9C73-11D3-B32E-00C04F990BB4) [XML HTTP] C: \ WINDOWS \ system32 \ msxml3.dll 8.100.1048.0
WP16 - ActiveX: (DFEAF541-F3E1-4c24-ACAC-99C30715084A) [Microsoft Silverlight] C: \ Program Files \ Microsoft SILVERLIGHT \ 2.0.40115.0 \ npctrl.dll 2.0.40115.0
WP16 - ActiveX: DFEAF541-F3E1-4c24-ACAC-99C30715084A [Microsoft Silverlight] C: \ Program Files \ Microsoft SILVERLIGHT \ 2.0.40115.0 \ npctrl.dll 2.0.40115.0
WP16 - ActiveX: (05589fa1-c356-11ce-bf01-00aa0055595a) [ActiveMovieControl Objekt] C: \ WINDOWS \ system32 \ wmpdxm.dll 11.0.5721.5145
WP16 - ActiveX: (0713E8A2-850A-101B-AFC0-4210102A8DA7) [Microsoft TreeView Control, verzije 5.0 (SP2)] C: \ WINDOWS \ system32 \ COMCTL32.OCX 5.01.4319
WP16 - ActiveX: (0713E8D2-850A-101B-AFC0-4210102A8DA7) [Microsoft ProgressBar Control, verzije 5.0 (SP2)] C: \ WINDOWS \ system32 \ COMCTL32.OCX 5.01.4319
WP16 - ActiveX: (233C1507-6A77-46A4-9443-F871F945D258) [Shockwave ActiveX Control] C: \ WINDOWS \ system32 \ Adobe \ direktor \ SwDir.dll 11,5
WP16 - ActiveX: (17492023-C23A-453E-A040-C7C580BBF700) [Windows Genuine Advantage Validation Tool] C: \ WINDOWS \ system32 \ LEGITCHECKCONTROL.DLL 1.7.0069.2
WP16 - ActiveX: (1D2B4F40-1F10-11D1-9E88-00C04FDCAB92) [ThumbCtl Klasa] C: \ WINDOWS \ system32 \ webvw.dll 6.00.2900.5512
WP16 - ActiveX: (DFEAF541-F3E1-4c24-ACAC-99C30715084A) [Microsoft Silverlight] C: \ Program Files \ Microsoft SILVERLIGHT \ 2.0.40115.0 \ npctrl.dll 2.0.40115.0
WP16 - ActiveX: (52A2AAAE-085D-4187-97EA-8C30DB990436) [HHCtrl Objekt] C: \ WINDOWS \ system32 \ hhctrl.ocx 5.2.3790.4110
WP16 - ActiveX: (58DA8D8A-9D6A-101B-AFC0-4210102A8DA7) [Microsoft ListView kontroli, verzija 5.0 (SP2)] C: \ WINDOWS \ system32 \ COMCTL32.OCX 5.01.4319
WP16 - ActiveX: (58DA8D8F-9D6A-101B-AFC0-4210102A8DA7) [Microsoft Imagelist Control, verzije 5.0 (SP2)] C: \ WINDOWS \ system32 \ COMCTL32.OCX 5.01.4319
WP16 - ActiveX: (6B7E638F-850A-101B-AFC0-4210102A8DA7) [Microsoft StatusBar Control, verzije 5.0 (SP2)] C: \ WINDOWS \ system32 \ COMCTL32.OCX 5.01.4319
WP16 - ActiveX: (8856F961-340A-11D0-A96B-00C04FD705A2) [Microsoftova web preglednika] C: \ WINDOWS \ system32 \ ieframe.dll 8.00.6001.18372
WP16 - ActiveX: (8BD21D50-EC42-11CE-9E0D-00AA006002F3) [Microsoft Forms 2,0 OptionButton] C: \ WINDOWS \ system32 \ FM20.DLL 11.0.6550
WP16 - ActiveX: (AE24FDAE-03C6-11D1-8B76-0080C744F389) [Microsoft Scriptlet Komponenta] C: \ WINDOWS \ system32 \ Mshtml.dll 8.00.6001.18372
WP16 - ActiveX: (CA8A9780-280D-11CF-A24D-444553540000) [Adobe PDF Reader] C: \ Program Files \ UOBIČAJENA Files \ Adobe \ Acrobat \ ActiveX \ AcroPDF.dll
WP16 - ActiveX: (CFCDAA03-8BE4-11cf-B84B-0020AFBBCCFA) [RealPlayer G2 Control] C: \ WINDOWS \ system32 \ rmoc3260.dll 6.0.8.1266
WP16 - ActiveX: (D27CDB6E-AE6D-11CF-96B8-444553540000) [Shockwave Flash Object] C: \ WINDOWS \ system32 \ Macromed \ flash \ Flash10b.ocx 10,0,22,87
WP16 - ActiveX: (E5DF9D10-3B52-11D1-83E8-00A0C90DC849) [WebViewFolderIcon Klasa] C: \ WINDOWS \ system32 \ webvw.dll 6.00.2900.5512
WP32 - Hidden File: C: \ boot.ini
WP32 - Hidden File: C: \ IO.SYS
WP32 - Hidden File: C: \ msdos.sys
WP32 - Hidden File: C: \ NTDETECT.COM
WP32 - Hidden File: C: \ NTLDR
WP32 - Hidden File: C: \ pagefile.sys
WP32 - Hidden File: C: \ USER
WP32 - Hidden File: C: \ WINDOWS \ WindowsShell.Manifest
WP32 - Hidden File: C: \ WINDOWS \ winnt.bmp
WP32 - Hidden File: C: \ WINDOWS \ winnt256.bmp
WP32 - Hidden File: C: \ WINDOWS \ system32 \ cdplayer.exe.manifest
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ default.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ default.tmp.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ SAM.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ SAM.tmp.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ SECURITY.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ SECURITY.tmp.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ software.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ software.tmp.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ system.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ system.tmp.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ TempKey.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Config \ userdiff.LOG
WP32 - Hidden File: C: \ Windows \ System32 \ Drivers \ hosts
WP32 - Hidden File: C: \ WINDOWS \ system32 \ logonui.exe.manifest
WP32 - Hidden File: C: \ WINDOWS \ system32 \ ncpa.cpl.manifest
WP32 - Hidden File: C: \ WINDOWS \ system32 \ nwc.cpl.manifest
WP32 - Hidden File: C: \ WINDOWS \ system32 \ restore \ filelist.xml
WP32 - Hidden File: C: \ WINDOWS \ system32 \ sapi.cpl.manifest
WP32 - Hidden File: C: \ WINDOWS \ system32 \ WindowsLogon.manifest
WP32 - Hidden File: C: \ WINDOWS \ system32 \ wuaucpl.cpl.manifest
WP32 - Hidden File: C: \ Program Files \ Common Files \ Services \ Thumbs.db
WP32 - Hidden File: C: \ boot.ini
WP32 - Hidden File: C: \ IO.SYS
WP32 - Hidden File: C: \ msdos.sys
WP32 - Hidden File: C: \ NTDETECT.COM
WP32 - Hidden File: C: \ NTLDR
WP32 - Hidden File: C: \ pagefile.sys
WP32 - Hidden File: C: \ USER
WP33 - File Type. CAT: [Security Katalog] rundll32.exe cryptext.dll, CryptExtOpenCAT% 1
WP33 - File Type. CHM: [kompilirane HTML Help file] C: \ WINDOWS \ hh.exe% 1
WP33 - File Type. COM: [MS-DOS Application]% 1% *
WP33 - File Type. Cmd: [Windows NT Command Script]% 1% *
WP33 - File Type. EML: [Internet E-mail poruku] C: \ Program Files \ Outlook Express \ msimn.exe / eml:% 1
WP33 - File Type. Exe: [Aplikacija]% 1% *
WP33 - File Type. INF: [Setup Information] C: \ WINDOWS \ System32 \ NOTEPAD.EXE% 1
WP33 - File Type. JS: [Script JScript File] C: \ WINDOWS \ System32 \ WScript.exe% 1% *
WP33 - File Type. LOG: [tekst dokument] C: \ WINDOWS \ system32 \ NOTEPAD.EXE% 1
WP33 - File Type. MSI: [Windows Installer Package] C: \ WINDOWS \ System32 \ Msiexec.exe / i% 1% *
WP33 - File Type. MID: [MIDI sekvencu] C: \ Program Files \ Windows Media Player \ wmplayer.exe / Open% L
WP33 - File Type. MP3: [MP3 Format Sound] C: \ Program Files \ Windows Media Player \ wmplayer.exe / prefekt: 6 / Open% L
WP33 - File Type. PIF: [Shortcut to MS-DOS Program]% 1% *
WP33 - File Type. RAM: [RealPlayer File] C: \ Program Files \ Real \ RealPlayer \ RealPlay.exe / m audio / x-pn-RealAudio% 1
WP33 - File Type. REG: [Registration Entries] regedit.exe% 1
WP33 - File Type. RTF: [Rich Text Document] C: \ Program Files \ Windows NT \ Accessories \ WORDPAD.EXE% 1
WP33 - File Type. SCR: [Screen Saver]% 1 / S
WP33 - File Type. TXT: [tekst dokument] C: \ WINDOWS \ system32 \ NOTEPAD.EXE% 1
WP33 - File Type. URL: [Internet Shortcut] rundll32.exe ieframe.dll, OpenURL% l
WP33 - File Type. VBS: [Script File VBSCRIPT] C: \ WINDOWS \ System32 \ WScript.exe% 1% *
WP33 - File Type. VBE: [VBSCRIPT šifrovan Script datoteka] C: \ WINDOWS \ System32 \ WScript.exe% 1% *
WP33 - File Type. WSF: [Windows Script datoteka] C: \ WINDOWS \ System32 \ WScript.exe% 1% *
WP33 - File Type. WSH: [Windows Script Host Settings File] C: \ WINDOWS \ System32 \ WScript.exe% 1% *
Memorija u uporabi trenutačno: 18%
Fizička memorija Free: 2097151 KB
Free stranične datoteke: 4194303 KB
Virtualna memorija Free: 2048264 KB

--
Kraj datoteke
  #5  
Old 17 svi 2009, 15:21
Moderator / ica grupe
 
Default Niste sigurni, ako je to virus ili BOSD

Ja ne vidim ništa što bi se uzrok problema imate. Jeste li sigurni da se pogon ne ide loše?
__________________

  #6  
Old 17 svi 2009, 16:26
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

U ovom trenutku sve što je moguće.
Kada reći voziti to misliš HD za to je u redu prikazivati na starom kompjuteru?
  #7  
Old 17 svi 2009, 16:39
Moderator / ica grupe
 
Default Niste sigurni, ako je to virus ili BOSD

Da HD. Možete li napraviti kompletan virus skandirati što na njemu? To bi bilo pouzdanije zatim HJT scan.
__________________

  #8  
Old 27 svi 2009, 08:53
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

Žao nam je bilo tako dugo da se vratim EF. Imali problema sa starim računalom. Što želite od mene da se pokreću u ovom trenutku ja ću probati, ali ništa comboFix.
  #9  
Old 27 svi 2009, 09:18
Moderator / ica grupe
 
Default Niste sigurni, ako je to virus ili BOSD

Preuzimanje DrWeb CureIt & Spremili na radnu površinu. Skeniraj sa DrWeb-CureIt kako slijedi:

  • Dvaput kliknite na drweb-cureit.exe a zatim Početak
  • An obavijesti pojavit će se informacije, kliknite na U redu.
  • Ovaj kratki počinje skandirati što će skandirati što datoteke trenutno izvodi u memoriji.
  • Ako dobijete upit za kupiti punu verziju samo izlaz kroz prozor. Skener i dalje će raditi bez kupovine punu verziju
  • Ako ili kada nešto nije pronađena, kliknite na Da gumb kad ga pita želite li izliječiti ga.


  • Nakon što je kratko scan završite, kliknite Settings> Change Settings
  • Pod Skeniranje tab Isključi Heurističan analiza i kliknite U redu
  • Natrag na glavnom prozoru, odaberite Cijela scan gumb, a zatim kliknite na Green Arrow Start Scanning gumb na desnoj strani, a počet će skenirati.
  • Kliknite Da za sve ako se pita ako želite liječiti / pomaknuti bilo koju datoteku (e).
  • Kada se vrši skeniranje.
  • U Dr.Web CureIt lijevom izborniku na vrhu, kliknite na Datoteka te odabrati Spremi izvješće lista.
  • Spremite DrWeb.csv Izvještaj na svoj Desktop.
  • Izlaz Dr.Web Cureit.
  • Važno! Ponovno pokrenuti računalo, jer bi to moglo biti moguće da se datoteka u upotrebi će biti premještena / obrisane tijekom rada računala.


* Nakon što ponovno podizanje sustava, Desnom tipkom miša kliknite Dr.Web se prijavite na radnu površinu i izabrati Otvori S> Notepad
* Kopirajte i zalijepite da se prijavite u sljedećem odgovoru
__________________

  #10  
Old 27 svi 2009, 20:00
Member Group
 
Default Niste sigurni, ako je to virus ili BOSD

Će učiniti. nisu sigurni koliko će se za mene da biste dobili leđa to vam izvještaj. Stari kompjuter mi se ne dozvoljava da vidimo froum. nešto u redu s IE7 ali će raditi oko koje za sada.
Reply

Register
Thread Tools




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Computer soka.

Powered by vBulletin ® Copyright © 2000 - 2009 Jelsoft Enterprises Ltd SEO by vBSEO © 2009, Crawlability, Inc