Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
Trenutno vreme je: 27. Apr 2024, 19:14:02
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 1 gost pregledaju ovu temu.

 Napomena: Za sva pitanja u vezi kupovine novog hardware-a ili procene vrednosti i preporuke koristite - ovu temu

Spyware,sta je,kako radi,kako se zastititi? :: Kako rade mreze :: Burek Anti-virus software review :: Index tema koje ne treba propustiti

Idi dole
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: Rootkit problem  (Pročitano 3122 puta)
15. Mar 2010, 14:38:52
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
Cao svima. . . .  Komp mi je zarazen sa rootkit virusom.  Probao sam sve zive programe za njegovo eliminisanje medjutim nijedan nije uspeo da ga ocisti.  Na kraju sam pronasao software HijackThis sa kojim sam skenirao fajlove ali sam u dilemi koje da selektujem za ciscenje.  Potrebna mi je pomoc.  
Pozdrav


IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Moderator
Legenda foruma


Zodijak Taurus
Pol Muškarac
Poruke 31625
Zastava Beograd
OS
Windows 7
Browser
Opera 9.80
mob
Nokia 6120
Okaci log da vidimo.
IP sačuvana
social share
Pogledaj profil WWW
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
Ok.  
Logfile of Trend Micro HijackThis v2. 0. 2
Scan saved at 16:12:16, on 15. 3. 2010
Platform: Windows XP SP2 (WinNT 5. 01. 2600)
MSIE: Internet Explorer v6. 00 SP2 (6. 00. 2900. 2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss. exe
C:\WINDOWS\system32\winlogon. exe
C:\WINDOWS\system32\services. exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchost. exe
C:\WINDOWS\System32\svchost. exe
C:\WINDOWS\system32\spoolsv. exe
C:\Program Files\Avira\AntiVir Desktop\sched. exe
C:\WINDOWS\Explorer. EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice. exe
C:\Program Files\Avira\AntiVir Desktop\avguard. exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService. exe
C:\Program Files\Ashampoo\Ashampoo Magic Defrag\bin\aDefragService. exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc. exe
C:\Program Files\Bonjour\mDNSResponder. exe
C:\Program Files\Java\jre6\bin\jqs. exe
C:\WINDOWS\System32\nvsvc32. exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent. exe
C:\WINDOWS\System32\svchost. exe
C:\PROGRA~1\AVG\AVG8\avgam. exe
C:\PROGRA~1\AVG\AVG8\avgemc. exe
C:\PROGRA~1\AVG\AVG8\avgrsx. exe
C:\Program Files\AVG\AVG8\avgcsrvx. exe
C:\WINDOWS\system32\RUNDLL32. EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ. exe
C:\Program Files\Adobe\Adobe Photoshop Lightroom 1. 2\apdproxy. exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop. exe
C:\Program Files\HP\HP Software Update\HPWuSchd2. exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11. exe
C:\Program Files\HP\hpcoretech\hpcmpmgr. exe
C:\WINDOWS\system32\hphmon06. exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnd. exe
C:\Program Files\PowerISO\PWRISOVM. EXE
C:\PROGRA~1\AVG\AVG8\avgtray. exe
C:\Program Files\HP\HP Share-to-Web\hpgs2wnf. exe
C:\Program Files\iTunes\iTunesHelper. exe
C:\WINDOWS\system32\HPZipm12. exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007. exe
C:\Program Files\Java\jre6\bin\jusched. exe
C:\Program Files\Avira\AntiVir Desktop\avgnt. exe
C:\WINDOWS\system32\ctfmon. exe
C:\Program Files\Messenger\msmsgs. exe
C:\WINDOWS\System32\svchost. exe
C:\Program Files\Ashampoo\Ashampoo Magic Defrag\bin\aDefragCtrl. exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad. exe
C:\Program Files\WinZip\WZQKPICK. EXE
C:\Documents and Settings\Aleksandar\Application Data\Dropbox\bin\Dropbox. exe
C:\Program Files\iPod\bin\iPodService. exe
C:\PROGRA~1\AVG\AVG8\avgnsx. exe
C:\Program Files\uTorrent\uTorrent. exe
C:\Program Files\Mozilla Firefox\firefox. exe
C:\Program Files\trend micro\HijackThis\HijackThis. exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *. local
R3 - URLSearchHook: (no name) - *{f5c93451-2609-4723-a053-5c19516be1a8} - (no file)
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar. dll
F2 - REG:system. ini: UserInit=C:\WINDOWS\system32\userinit. exe,C:\WINDOWS\system32\svchust. exe,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5. 0\Reader\ActiveX\AcroIEHelper. ocx
O2 - BHO: WormRadar. com IESiteBlocker. NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie. dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar. dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2. dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3. 1. 807. 1746\swg. dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv. dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin. dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2. dll
O3 - Toolbar: Share Accelerator Toolbar - {f5c93451-2609-4723-a053-5c19516be1a8} - C:\Program Files\Share_Accelerator\tbShar. dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar. dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar. dll
O4 - HKLM\. . \Run: [NvCplDaemon] RUNDLL32. EXE C:\WINDOWS\System32\NvCpl. dll,NvStartup
O4 - HKLM\. . \Run: [nwiz] nwiz. exe /install
O4 - HKLM\. . \Run: [NvMediaCenter] RUNDLL32. EXE C:\WINDOWS\System32\NvMcTray. dll,NvTaskbarInit
O4 - HKLM\. . \Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck. exe
O4 - HKLM\. . \Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ. exe"
O4 - HKLM\. . \Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Adobe Photoshop Lightroom 1. 2\apdproxy. exe"
O4 - HKLM\. . \Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop. exe" /startup
O4 - HKLM\. . \Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2. exe"
O4 - HKLM\. . \Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11. exe
O4 - HKLM\. . \Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06. exe
O4 - HKLM\. . \Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr. exe"
O4 - HKLM\. . \Run: [HPHmon06] C:\WINDOWS\system32\hphmon06. exe
O4 - HKLM\. . \Run: [Share-to-Web Namespace Daemon] C:\Program Files\HP\HP Share-to-Web\hpgs2wnd. exe
O4 - HKLM\. . \Run: [PWRISOVM. EXE] C:\Program Files\PowerISO\PWRISOVM. EXE
O4 - HKLM\. . \Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray. exe
O4 - HKLM\. . \Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager. exe" -launchedbylogin
O4 - HKLM\. . \Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007. exe
O4 - HKLM\. . \Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask. exe" -atboottime
O4 - HKLM\. . \Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKLM\. . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched. exe"
O4 - HKLM\. . \Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\. . \Run: [PrevxRootkitRemovalTool] "C:\Documents and Settings\Aleksandar\My Documents\Downloads\E58A429. exe" -scan
O4 - HKLM\. . \Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt. exe" /min
O4 - HKCU\. . \Run: [ctfmon. exe] C:\WINDOWS\system32\ctfmon. exe
O4 - HKCU\. . \Run: [Google Update] "C:\Documents and Settings\Aleksandar\Local Settings\Application Data\Google\Update\GoogleUpdate. exe" /c
O4 - HKCU\. . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs. exe" /background
O4 - Startup: Dropbox. lnk = C:\Documents and Settings\Aleksandar\Application Data\Dropbox\bin\Dropbox. exe
O4 - Global Startup: Adobe Gamma Loader. lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader. exe
O4 - Global Startup: Ashampoo Magic Defrag. lnk = C:\Program Files\Ashampoo\Ashampoo Magic Defrag\bin\aDefragCtrl. exe
O4 - Global Startup: HP Digital Imaging Monitor. lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08. exe
O4 - Global Startup: HP Image Zone Fast Start. lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08. exe
O4 - Global Startup: NaturalColorLoad. lnk = ?
O4 - Global Startup: WinZip Quick Pick. lnk = C:\Program Files\WinZip\WZQKPICK. EXE
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos. scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL. EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs. exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs. exe
O12 - Plugin for . spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox. dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp. dll
O20 - AppInit_DLLs: c:\progra~1\google\google~1\goec62~1. dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO. DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx. dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice. exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc. exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched. exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard. exe
O23 - Service: Apple Mobile Device - Apple Inc.  - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService. exe
O23 - Service: AshampooDefragService -   - C:\Program Files\Ashampoo\Ashampoo Magic Defrag\bin\aDefragService. exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s. r. o.  - C:\PROGRA~1\AVG\AVG8\avgemc. exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s. r. o.  - C:\PROGRA~1\AVG\AVG8\avgwdsvc. exe
O23 - Service: Bonjour Service - Apple Inc.  - C:\Program Files\Bonjour\mDNSResponder. exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc.  - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService. exe
O23 - Service: Google Desktop Manager 5. 9. 911. 3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop. exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService. exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT. exe
O23 - Service: iPod Service - Apple Inc.  - C:\Program Files\iPod\bin\iPodService. exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc.  - C:\Program Files\Java\jre6\bin\jqs. exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32. exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12. exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc.  - C:\Program Files\Analog Devices\SoundMAX\SMAgent. exe

--
End of file - 10625 bytes
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
Nadam se da nije predugacak Smile
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 3.6
mob
HTC 
Deinstaliraj jedan antivirus program, preporuka je da ostavis Aviru.

Ovaj alat pokreni posle deinstalacije AVG-a  http://www.avg.com/ww-en/download-tools
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
ok
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
Hvala.
Obavesticu cim zavrsim
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
Uradjeno. Da li je potrebno jos nesto za skidanje rootkita_
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows 7
Browser
Mozilla Firefox 3.6
mob
HTC 
Pokreni HJT i cekiraj ovu liniju

Kod:
F2 - REG:system. ini: UserInit=C:\WINDOWS\system32\userinit. exe,C:\WINDOWS\system32\svchust. exe,

Klikni "Fix checked"

------------------------------------------------

Skini ovaj program  http://swandog46.geekstogo.com/avenger2/download.php
Raspakuj ga u folder
Dvoklikom pokreni avenger.exe
Iskopiraj ovaj tekst u beli prozor programa

Kod:
Files to delete:
C:\WINDOWS\system32\svchust. exe

Zatim klikni Execute pa dva puta Yes.
Kompjuter ce se restartovati, mozda dva puta.
Iskopiraj mi log fajl C:\avenger.txt

-----------------------------------------------------------------

Skini program Malearebytes  http://majorgeeks.com/downloadget.php?id=5756&file=15&evp=693ee0b20204960edfd909666f809b26
Dvoklikom pokreni instalaciju
Na samom pocetku proveri da li su stiklirane ove opcije
Update Malwarebytes' Anti-Malware
Launch Malwarebytes Anti-Malware

Zatim klikni Finish.

Izaberi opciju Perform Quick Scan i klikni Scan.
Po završetku procesa klikni OK, Show Results: u listi detektovanog malware-a proveri da li su obelezene sve stavke i klikni Remove Selected.

Po zavrsetku ciscenja zakaci MBAM log na forum.
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Pocetnik

Zodijak
Pol
Poruke 12
OS
Windows XP
Browser
Mozilla Firefox 3.6
ok.
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Trenutno vreme je: 27. Apr 2024, 19:14:02
nazadnapred
Prebaci se na:  

Poslednji odgovor u temi napisan je pre više od 6 meseci.  

Temu ne bi trebalo "iskopavati" osim u slučaju da imate nešto važno da dodate. Ako ipak želite napisati komentar, kliknite na dugme "Odgovori" u meniju iznad ove poruke. Postoje teme kod kojih su odgovori dobrodošli bez obzira na to koliko je vremena od prošlog prošlo. Npr. teme o određenom piscu, knjizi, muzičaru, glumcu i sl. Nemojte da vas ovaj spisak ograničava, ali nemojte ni pisati na teme koje su završena priča.

web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Domaci :: Morazzia :: TotalCar :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Alfaprevod

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.103 sec za 16 q. Powered by: SMF. © 2005, Simple Machines LLC.