Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
Trenutno vreme je: 24. Apr 2024, 18:42:55
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 1 gost pregledaju ovu temu.

 Napomena: Za sva pitanja u vezi kupovine novog hardware-a ili procene vrednosti i preporuke koristite - ovu temu

Spyware,sta je,kako radi,kako se zastititi? :: Kako rade mreze :: Burek Anti-virus software review :: Index tema koje ne treba propustiti

Idi dole
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: Brisanje NOD-a  (Pročitano 3507 puta)
29. Avg 2012, 20:55:07
Clan u razvoju

Zodijak
Pol
Poruke 26
Browser
Mozilla Firefox 14.0.1
Pozdrav ljudi,imam ogroman problem,ne zamerite sto nisam pretrazio forum,mozda tema slicno postoji,al nemam vremena da pretrazujem jer mi je komp izlozen napadima trojanaca i usporen je do bola.

Nakko mi je hakovan,ili sta vec komp,Nod koji je bio u funkciji vise ne radi(nema nikakve zastite),ne mogu da ga ni izbrisem,samim tim ni da instaliram novi.Problem je nastao na video catu,kad je NOD prestao da daje znake zivota,ne moze se updejtovati,ne moze da se izbrise,cak ga vise ne mogu ni videti u ad or remove.Takodjer sam probao i sa cc cleanerom,ne vidi ga cleaner.

Instalirao sam Antimalwere i superAntyspywere i posle ciscenja svih tih trojanaca,sve isto,ne mogu ukloniti nod ni iz program Files,stalnose pojavljuje ova poruka

"Cannot delite callmsi.exe:Access is denied
Make sure the disk is not full or write protected and that the file is not curently in use."
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 14.0.1
mob
HTC 
Preuzmi program DDS na desktop   http://download.bleepingcomputer.com/sUBs/dds.scr
Dvoklikom pokreni DDS
Sacekaj malo, izbacice ti dva loga
Kopiraj mi log DDS.txt na http://pastebin.com/

Klikni Submit pa kopiraj link sa izvestajem u poruci
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Clan u razvoju

Zodijak
Pol
Poruke 26
OS
Windows XP
Browser
Mozilla Firefox 14.0.1
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 14.0.1
mob
HTC 
Da ne idem na ekstremniju varijantu odradi ovako:


Preuzmi OTL na desktop http://oldtimer.geekstogo.com/OTL.exe

Dvoklikom pokreni OTL;

klikni Run Scan;

Po završetku skeniranja, izveštaj ce se otvoriti u Notepad-u.

Kopiraj mi log.
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Clan u razvoju

Zodijak
Pol
Poruke 26
OS
Windows XP
Browser
Mozilla Firefox 14.0.1
izbacilo mi dva fajla ne znam koji te zanima,pa cu oba staviti
http://pastebin.com/UZPXxNi0

http://pastebin.com/dNKBbkpF
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 14.0.1
mob
HTC 
Preuzmi ovaj Uninstaller
http://kb.eset.com/esetkb/index?page=content&id=SOLN2289&actp=search&viewlocale=en_US&searchid=1254657447620

Restartuj i klikci F8, Izaberi Safe Mode. Iz Safe Mode pokreni Uninstaller za Eset. Restartuj




Preuzmi ComboFix sa sledece adrese na Desktop:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe



Pokreni Combofix iskljucivo sa desktopa (I Agree)
Na svaki popup prozor klikci Yes \ Ok

Kad zavrsi skeniranje izbacice ti log na desktop

Kopiraj mi log
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Clan u razvoju

Zodijak
Pol
Poruke 26
OS
Windows XP
Browser
Mozilla Firefox 14.0.1
Ovo bas i nisam odradio kako treba Smile Smile
Cekaj udjem u safe mode i ulogujem se na sempron komp i tu pokrecem eset unstaler ,jel.....sve mi nekako velike ikone  bile.....

Jel ima neki laksi nacin,ja se bas nesto i ne kontam oko ulaska u safe mode i sl
Al,ako nema  drugi nacin,pojasni ovo malo bolje
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Clan u razvoju

Zodijak
Pol
Poruke 26
OS
Windows XP
Browser
Mozilla Firefox 14.0.1
Evo uspio sam,odradio sam sve kako si reako,samo  moram ovako prilepiti log,jer ne mogu uci na "pastebin".

Citat
ComboFix 12-08-29.03 - SEMPRON 3000 30.08.2012   1:00.1.1 - x86
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.511.126 [GMT 2:00]
Running from: c:\documents and settings\SEMPRON 3000\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\SEMPRON 3000\WINDOWS
c:\program files\ViOrb
c:\program files\ViOrb\resources\flag.png
c:\program files\ViOrb\StartHook.dll
c:\program files\ViOrb\ViOrb.exe
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\system32\scrnrdr.exe
c:\windows\system32\SET4021.tmp
c:\windows\system32\SET4022.tmp
c:\windows\system32\SET4023.tmp
c:\windows\system32\SET4027.tmp
c:\windows\system32\SET4028.tmp
c:\windows\system32\SET4029.tmp
c:\windows\system32\SET402B.tmp
c:\windows\system32\SET402D.tmp
c:\windows\system32\SET402F.tmp
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\fusion.dll
c:\windows\system32\URTTemp\mscoree.dll
c:\windows\system32\URTTemp\mscoree.dll.local
c:\windows\system32\URTTemp\mscorsn.dll
c:\windows\system32\URTTemp\mscorwks.dll
c:\windows\system32\URTTemp\msvcr71.dll
c:\windows\system32\URTTemp\regtlib.exe
c:\windows\system32\VIRepair
c:\windows\system32\VIRepair\vi.sif
.
.
(((((((((((((((((((((((((   Files Created from 2012-07-28 to 2012-08-29  )))))))))))))))))))))))))))))))
.
.
2012-08-28 23:07 . 2012-08-28 23:07   --------   d-----w-   c:\documents and settings\SEMPRON 3000\Application Data\SUPERAntiSpyware.com
2012-08-28 23:06 . 2012-08-28 23:07   --------   d-----w-   c:\program files\SUPERAntiSpyware
2012-08-28 23:06 . 2012-08-28 23:06   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-28 19:15 . 2012-08-28 19:15   --------   d-----w-   c:\documents and settings\SEMPRON 3000\Application Data\Malwarebytes
2012-08-28 19:15 . 2012-08-28 19:15   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-28 19:15 . 2012-07-03 11:46   22344   ----a-w-   c:\windows\system32\drivers\mbam.sys
2012-08-28 19:15 . 2012-08-28 19:15   --------   d-----w-   c:\program files\Malwarebytes' Anti-Malware
2012-08-28 18:50 . 2012-08-28 18:50   --------   d-----w-   c:\program files\CCleaner
2012-08-21 15:56 . 2012-08-21 15:57   --------   d-----w-   c:\program files\Mozilla Maintenance Service
2012-08-08 21:19 . 2012-08-08 21:20   --------   d-----w-   c:\windows\VMUVC
2012-08-08 21:19 . 2011-03-16 12:44   252928   ----a-w-   c:\windows\system32\drivers\VMUVC.sys
2012-08-08 21:19 . 2009-04-29 14:01   516096   ----a-w-   c:\windows\system32\VMUVC.ax
2012-08-08 21:19 . 2008-09-02 15:47   94208   ----a-w-   c:\windows\system32\VvFtCtrl.dll
2012-08-08 21:19 . 2008-07-01 09:16   188416   ----a-w-   c:\windows\system32\vvftUVC.ax
2012-08-08 21:19 . 2007-04-12 20:59   73728   ----a-w-   c:\windows\system32\exvmuvc.ax
2012-08-08 21:19 . 2011-05-27 07:55   399360   ----a-w-   c:\windows\system32\drivers\vvftUVC.sys
2012-08-08 21:19 . 2008-09-18 14:28   98304   ----a-w-   c:\windows\system32\VMCtrl.ax
2012-08-08 21:19 . 2008-02-29 08:11   11776   ----a-w-   c:\windows\system32\VMUVC.dll
2012-08-08 21:19 . 2007-01-24 10:26   319456   ----a-w-   c:\windows\system32\DIFxAPI.dll
2012-08-08 21:19 . 2012-08-08 21:19   --------   d-----w-   c:\program files\Vimicro Corporation
2012-08-08 13:37 . 2008-04-14 02:15   60032   -c--a-w-   c:\windows\system32\dllcache\usbaudio.sys
2012-08-08 13:37 . 2008-04-14 02:15   60032   ----a-w-   c:\windows\system32\drivers\USBAUDIO.sys
2012-08-08 13:26 . 2008-04-14 07:42   20992   ----a-w-   c:\windows\system32\dshowext.ax
2012-08-08 13:26 . 2008-04-14 02:16   121984   -c--a-w-   c:\windows\system32\dllcache\usbvideo.sys
2012-08-08 13:26 . 2008-04-14 02:16   121984   ----a-w-   c:\windows\system32\drivers\usbvideo.sys
2012-08-08 13:26 . 2008-04-14 02:15   32128   -c--a-w-   c:\windows\system32\dllcache\usbccgp.sys
2012-08-08 13:26 . 2008-04-14 02:15   32128   ----a-w-   c:\windows\system32\drivers\usbccgp.sys
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-06 13:58 . 2008-04-14 08:00   78336   ----a-w-   c:\windows\system32\browser.dll
2012-07-04 14:05 . 2010-09-27 20:42   139784   ----a-w-   c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2008-04-14 08:00   1866112   ----a-w-   c:\windows\system32\win32k.sys
2012-07-03 12:30 . 2012-07-03 12:30   21419   ----a-w-   c:\windows\system32\drivers\AegisP.sys
2012-07-02 17:49 . 2008-04-23 00:16   916992   ----a-w-   c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2008-07-12 19:10   43520   ----a-w-   c:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2008-04-23 00:16   1469440   ------w-   c:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2008-07-12 19:09   385024   ----a-w-   c:\windows\system32\html.iec
2012-06-26 11:03 . 2012-06-26 11:02   3796065   ----a-w-   c:\documents and settings\All Users\Application Data\sbsdwin95req.exe
2012-06-06 23:54 . 2012-06-06 23:54   404640   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-05 15:50 . 2008-04-14 08:00   1372672   ----a-w-   c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2008-04-14 08:00   1172480   ----a-w-   c:\windows\system32\msxml3.dll
2012-06-04 15:35 . 2010-09-27 20:44   210968   ----a-w-   c:\windows\system32\wuweb.dll
2012-06-04 04:32 . 2008-04-14 08:00   152576   ----a-w-   c:\windows\system32\schannel.dll
2012-06-02 13:19 . 2010-09-28 20:12   22040   ----a-w-   c:\windows\system32\wucltui.dll.mui
2012-06-02 13:19 . 2010-09-28 20:12   15384   ----a-w-   c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 13:19 . 2010-09-27 20:44   329240   ----a-w-   c:\windows\system32\wucltui.dll
2012-06-02 13:19 . 2010-09-27 20:44   219160   ----a-w-   c:\windows\system32\wuaucpl.cpl
2012-06-02 13:19 . 2010-09-28 20:12   45080   ----a-w-   c:\windows\system32\wups2.dll
2012-06-02 13:19 . 2010-09-28 20:12   15384   ----a-w-   c:\windows\system32\wuapi.dll.mui
2012-06-02 13:19 . 2010-09-27 20:44   53784   ----a-w-   c:\windows\system32\wuauclt.exe
2012-06-02 13:19 . 2010-09-27 20:44   35864   ----a-w-   c:\windows\system32\wups.dll
2012-06-02 13:19 . 2008-04-14 08:00   97304   ----a-w-   c:\windows\system32\cdm.dll
2012-06-02 13:19 . 2010-09-28 20:12   17944   ----a-w-   c:\windows\system32\wuaueng.dll.mui
2012-06-02 13:19 . 2010-09-27 20:44   577048   ----a-w-   c:\windows\system32\wuapi.dll
2012-06-02 13:19 . 2010-09-27 20:44   1933848   ----a-w-   c:\windows\system32\wuaueng.dll
2012-07-14 00:17 . 2012-08-21 15:56   136672   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-14 . 6A8B0B64F8D7EBEF70B16FF689C3C76D . 1423872 . . [6.00.2900.5512] . . c:\windows\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\dllcache\explorer.exe
[7] 2008-04-14 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512] . . c:\windows\system32\VITrans\explorer.exe
.
[-] 2008-04-14 . 702BE30013B178035BF81F08A1BF5C46 . 224256 . . [5.1.2600.5512] . . c:\windows\regedit.exe
[7] 2008-04-14 . 058710B720282CA82B909912D3EF28DB . 146432 . . [5.1.2600.5512] . . c:\windows\system32\dllcache\regedit.exe
[7] 2008-04-14 . 058710B720282CA82B909912D3EF28DB . 146432 . . [5.1.2600.5512] . . c:\windows\system32\VITrans\regedit.exe
.
[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2011-10-22 3077528]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 4777856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="c:\windows\htpatch.exe" [2002-10-30 28672]
"SiSUSBRG"="c:\windows\SiSUSBrg.exe" [2002-07-12 106496]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2010-09-10 143360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2012-7-3 1339392]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):76,69,73,74,61,75,69,2e,65,78,65,00
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54   551296   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EsetUninstaller]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58670:TCP"= 58670:TCP:Pando Media Booster
"58670:UDP"= 58670:UDP:Pando Media Booster
"58757:TCP"= 58757:TCP:Pando Media Booster
"58757:UDP"= 58757:UDP:Pando Media Booster
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22.7.2011 18:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12.7.2011 23:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12.8.2011 1:38 116608]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [28.8.2012 21:15 655944]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [28.8.2012 21:15 22344]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys --> c:\windows\system32\DRIVERS\ehdrv.sys [?]
S1 epfwtdir;epfwtdir;c:\windows\system32\DRIVERS\epfwtdir.sys --> c:\windows\system32\DRIVERS\epfwtdir.sys [?]
S2 ekrn;ESET Service;"c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe" --> c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [?]
S2 WCMVCAM;WebcamMax, WDM Video Capture;c:\windows\system32\drivers\wcmvcam.sys [23.6.2011 8:43 1068216]
S3 EsetUninstaller;ESET Uninstaller Service;c:\windows\ESETUninstaller(2).exe -Service --> c:\windows\ESETUninstaller(2).exe -Service [?]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [14.1.2008 12:06 21632]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [21.8.2012 17:56 113120]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [13.5.2011 3:21 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [13.5.2011 3:21 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [13.5.2011 3:21 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [13.5.2011 3:21 114280]
S3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\drivers\VMUVC.sys [8.8.2012 23:19 252928]
S3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [8.8.2012 23:19 399360]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.windowsxlive.net
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\SEMPRON 3000\Application Data\Mozilla\Firefox\Profiles\8oyt4nrc.default\
FF - prefs.js: browser.startup.homepage - www.google.rs
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-Vista Transformation Pack - c:\windows\system32\viwc.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-08-30 01:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  HTpatch = c:\windows\htpatch.exe?ows\CurrentVersion\Run???\???]??Z???????Z???Z???????????????? ??Z???Z?N?????Z$??????Z????????????{??Z???????????Z$?G~????(????~B~??G~?????~B~??G~???Z@???????d??????Z%??Zx??Zd??????Z,>?Z???Zv?B~Z|?Z{3?Z?2?Z????st.I????G??Z????d????<?Z?I?Z
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(492)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\cscui.dll
.
Completion time: 2012-08-30  01:11:13
ComboFix-quarantined-files.txt  2012-08-29 23:11
.
Pre-Run: 28.682.272.768 bytes free
Post-Run: 30.423.232.512 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - A8F1AE1EB902F09B6320F2B5D74CFEA5
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 14.0.1
mob
HTC 
Otvori Notepad i kopiraj tekst koji se nalazi ispod:

Kod:
FCopy::
c:\windows\system32\dllcache\explorer.exe|c:\windows\explorer.exe
c:\windows\system32\dllcache\regedit.exe|c:\windows\regedit.exe

Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58670:TCP"=-
"58670:UDP"=-
"58757:TCP"=-
"58757:UDP"=-

File::
c:\windows\system32\DRIVERS\ehdrv.sys
c:\windows\system32\DRIVERS\epfwtdir.sys
c:\windows\ESETUninstaller(2).exe

Folder::
c:\program files\ESET

Driver::
ehdrv
epfwtdir
ekrn
EsetUninstaller

Klikni na File\Save as i sacuvaj tekst kao CFScript na desktop




Prati uputstvo sa slike i prevuci CFScript.txt preko ikonice ComboFix.exe
To ce startovati ComboFix, mozda ce doci do restarta sistema (to je normalno)
Kada zavrsi,pojavice se log (C:\ComboFix.txt)
Posalji ComboFix log u sledecoj poruci.


IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Clan u razvoju

Zodijak
Pol
Poruke 26
OS
Windows XP
Browser
Mozilla Firefox 14.0.1
http://pastebin.com/ZhNBBbCA
Stalno me obavestava da je real time nod scener ukljucen,mozda ti to sta znaci.
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Trenutno vreme je: 24. Apr 2024, 18:42:55
nazadnapred
Prebaci se na:  

Poslednji odgovor u temi napisan je pre više od 6 meseci.  

Temu ne bi trebalo "iskopavati" osim u slučaju da imate nešto važno da dodate. Ako ipak želite napisati komentar, kliknite na dugme "Odgovori" u meniju iznad ove poruke. Postoje teme kod kojih su odgovori dobrodošli bez obzira na to koliko je vremena od prošlog prošlo. Npr. teme o određenom piscu, knjizi, muzičaru, glumcu i sl. Nemojte da vas ovaj spisak ograničava, ali nemojte ni pisati na teme koje su završena priča.

web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Domaci :: Morazzia :: TotalCar :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Alfaprevod

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.104 sec za 16 q. Powered by: SMF. © 2005, Simple Machines LLC.