Prijava na forum:
Ime:
Lozinka:
Prijavi me trajno:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:

ConQUIZtador
Trenutno vreme je: 21. Jul 2025, 01:10:39
nazadnapred
Korisnici koji su trenutno na forumu 0 članova i 0 gostiju pregledaju ovu temu.

 Napomena: Za sva pitanja u vezi kupovine novog hardware-a ili procene vrednosti i preporuke koristite - ovu temu

Spyware,sta je,kako radi,kako se zastititi? :: Kako rade mreze :: Burek Anti-virus software review :: Index tema koje ne treba propustiti

Idi dole
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Tema: system32 problem  (Pročitano 2591 puta)
17. Apr 2008, 12:50:55
Zodijak
Pol
Poruke 3
OS
Windows XP
Browser
Internet Explorer 6.0
 Smile
c:/windows/system32/wvuklbrp. dll mi je obrisan i ne pojavljuje se vise, ali

c:/windows/system32/kofierbq. dll mi se stalno ponovo pojavljuje Logfile of Trend Micro HijackThis v2. 0. 2

Scan saved at 11:36:29, on 17. 4. 2008
Platform: Windows XP SP2 (WinNT 5. 01. 2600)
MSIE: Internet Explorer v6. 00 SP2 (6. 00. 2900. 2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\Explorer. EXE
C:\WINDOWS\system32\igfxtray. exe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxpers. exe
C:\WINDOWS\RTHDCPL. EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp. exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ. exe
C:\Program Files\DAP\DAP. EXE
C:\Program Files\Java\jre1. 6. 0_05\bin\jusched. exe
C:\WINDOWS\system32\ctfmon. exe
C:\Program Files\Messenger\msmsgs. exe
C:\Program Files\Adobe\Reader 8. 0\Reader\reader_sl. exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr. exe
C:\Program Files\OpenOffice. org1. 1. 4\program\soffice. exe
C:\Program Files\Internet Explorer\IEXPLORE. EXE
C:\Program Files\Internet Explorer\IEXPLORE. EXE
C:\Documents and Settings\srdjan. orban\Desktop\HiJackThis. exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp:|| www. comtradegroup. com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = hxxp:|| www. comtradegroup. com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper. dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1. 6. 0_05\bin\ssv. dll
O2 - BHO: (no name) - {B68908B0-7FF8-434B-8EEA-F22C8A099F34} - (no file)
O2 - BHO: Mininova Toolbar - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files\Mininova\tbMini. dll
O3 - Toolbar: Mininova Toolbar - {f592709f-ff4a-4862-b659-4afabda56312} - C:\Program Files\Mininova\tbMini. dll
O4 - HKLM\. . \Run: [IgfxTray] C:\WINDOWS\system32\igfxtray. exe
O4 - HKLM\. . \Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd. exe
O4 - HKLM\. . \Run: [Persistence] C:\WINDOWS\system32\igfxpers. exe
O4 - HKLM\. . \Run: [RTHDCPL] RTHDCPL. EXE
O4 - HKLM\. . \Run: [SkyTel] SkyTel. EXE
O4 - HKLM\. . \Run: [Alcmtr] ALCMTR. EXE
O4 - HKLM\. . \Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp. exe
O4 - HKLM\. . \Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ. exe"
O4 - HKLM\. . \Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP. EXE" /STARTUP
O4 - HKLM\. . \Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1. 6. 0_05\bin\jusched. exe"
O4 - HKLM\. . \Run: [BM0b3d7342] Rundll32. exe "C:\WINDOWS\system32\kofierbq. dll",s
O4 - HKCU\. . \Run: [ctfmon. exe] C:\WINDOWS\system32\ctfmon. exe
O4 - HKCU\. . \Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs. exe" /background
O4 - HKUS\S-1-5-18\. . \Run: [CTFMON. EXE] C:\WINDOWS\system32\CTFMON. EXE (User 'SYSTEM')
O4 - HKUS\. DEFAULT\. . \Run: [CTFMON. EXE] C:\WINDOWS\system32\CTFMON. EXE (User 'Default user')
O4 - Startup: OpenOffice. org 1. 1. 4. lnk = C:\Program Files\OpenOffice. org1. 1. 4\program\quickstart. exe
O4 - Global Startup: Adobe Reader Speed Launch. lnk = C:\Program Files\Adobe\Reader 8. 0\Reader\reader_sl. exe
O4 - Global Startup: Adobe Reader Synchronizer. lnk = C:\Program Files\Adobe\Reader 8. 0\Reader\AdobeCollabSync. exe
O4 - Global Startup: Service Manager. lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr. exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie. htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie. htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2. htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL. EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1. 6. 0_05\bin\ssv. dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1. 6. 0_05\bin\ssv. dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR. DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs. exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs. exe
O14 - IERESET. INF: START_PAGE_URL=hxxp:|| www. comtradegroup. com
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1. 6. 0) - hxxp:|| javadl. sun. com/webapps/download/AutoDL?BundleId=19588
O17 - HKLM\System\CCS\Services\Tcpip\. . \{29069158-147F-4502-B2F2-5E4A2C745CC6}: NameServer = 82. 117. 194. 2,82. 117. 194. 3
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice. exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv. exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ. exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv. exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv. exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr. exe (file missing)
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent. EXE (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd.  - C:\Program Files\RealVNC\VNC4\WinVNC4. exe

--
End of file - 5591 bytes
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zodijak
Pol
Poruke 3
OS
Windows XP
Browser
Internet Explorer 6.0
Brisao sam hijackom vise puta ovaj c:/windows/system32/kofierbq.  dll,
ali se svaki put ponovo pojavljuje.
sta sada?


[Edit by filip93: Pisanje teksta velikim slovima [ALLCAPS] zabranjeno Pravilnikom Burek Foruma. Koristite blagodeti formatiranja teksta ako zelite nesto naglasiti!]
« Poslednja izmena: 17. Apr 2008, 14:10:27 od filip93 »
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Jet set burekdzija

Zodijak Scorpio
Pol
Poruke 7658
OS
Windows XP
Browser
Mozilla Firefox 2.0.0.13
ja bi fixovao ... sve ovo Smile

O2 - BHO: (no name) - {B68908B0-7FF8-434B-8EEA-F22C8A099F34} - (no file)
O4 - HKLM\. . \Run: [BM0b3d7342] Rundll32. exe "C:\WINDOWS\system32\kofierbq. dll",s
O4 - HKUS\. DEFAULT\. . \Run: [CTFMON. EXE] C:\WINDOWS\system32\CTFMON. EXE (User 'Default user')
017 - HKLM\System\CCS\Services\Tcpip\. . \{29069158-147F-4502-B2F2-5E4A2C745CC6}: NameServer = 82. 117. 194. 2,82. 117. 194. 3



fix ovo iz save moda...
nadji i pokreni neki registry cliner ili sistem mehanic 6 npr...

a sto se tice ovoga...c:/windows/system32/kofierbq.  dll
pa nadji i obrisi ga rucno...
contra panel/folder option/view/show hiden files and folders...
nadji sistem32 nadji i obrisi ga rucno shift i delite...
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zodijak
Pol
Poruke 3
OS
Windows XP
Browser
Internet Explorer 6.0
obrisao sam C:\WINDOWS\system32\kofierbq. dll",s ručno iz system32, ali se u hijack skeniranju stalno ponovo pojavljuje
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Moderator
Svedok stvaranja istorije


necu da ti kazem, chelavi...

Zodijak Libra
Pol Muškarac
Poruke 22020
Zastava La45.2590  Lo19.8330
OS
Windows XP
Browser
Mozilla Firefox 2.0.0.13
mob
Apple iPhone 12, S21
a kakav ti je problem sa racunarom?
IP sačuvana
social share
- A robot may not injure a human being or, through inaction, allow a human being to come to harm
- A robot must obey the orders given to it by human beings, except where such orders would conflict with the First Law
- A robot must protect its own existence as long as such protection does not conflict with the First or Second Laws
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Prijatelj foruma
Poznata licnost

MC- argus

Zodijak
Pol Muškarac
Poruke 4467
Zastava
OS
Windows XP
Browser
Mozilla Firefox 2.0.0.14
mob
HTC 
Probaj da iskljucis Rundll32.exe (start/msconfig/startup) pa onda obrisi taj  kofierbq. dll
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zodijak
Pol
Poruke 3
OS
Windows XP
Browser
Internet Explorer 6.0
kada se racunar upali, prijavljuje mi ovo
c:/windows/system32/wvuklbrp. dll - the specified module could not be found
objasni mi molim te kako da  zaustavim rundll. exe
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zodijak
Pol
Poruke 3
OS
Windows XP
Browser
Internet Explorer 6.0
hvala. resio sam problem
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Ucesnik diskusija


Zodijak Libra
Pol
Poruke 166
OS
Windows XP
Browser
Opera 9.02
Ovo lici na poznati adware Virtumondo, vrlo je komplikovan za ciscenje sa sistema jer se veze za Winlogon proces.  Ostavlja vise . dll fajlova sa razlicitim nasumicnim imenima u system32 folderu.  Naravno, upetlja se i u registry.  Ja sam nedavno imao isti problem, NOD32 je nasao fajlove ali nisam mogao da ih pobrisem iz windowsa nego iz Recovery konzole.  Takodje je bitno obrisati Temporary Internet Files, i ocistiti sve Temp foldere.  Nakon ovoga sam uklonio ostatak kljuceva iz registra sa Spybotom.
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Zodijak
Pol
Poruke 1
OS
Windows XP
Browser
Mozilla Firefox 2.0.0.15
dali neko koristi alat speed up my pc firme uniblue i kakva iskustva ima.  zahvaljujem
IP sačuvana
social share
Pogledaj profil
 
Prijava na forum:
Ime:
Lozinka:
Zelim biti prijavljen:
Trajanje:
Registruj nalog:
Ime:
Lozinka:
Ponovi Lozinku:
E-mail:
Idi gore
Stranice:
2  Sve
Počni novu temu Nova anketa Odgovor Štampaj Dodaj temu u favorite Pogledajte svoje poruke u temi
Trenutno vreme je: 21. Jul 2025, 01:10:39
nazadnapred
Prebaci se na:  
Upozorenje:ova tema je zaključana!
Samo administratori i moderatori mogu odgovoriti.
web design

Forum Info: Banneri Foruma :: Burek Toolbar :: Burek Prodavnica :: Burek Quiz :: Najcesca pitanja :: Tim Foruma :: Prijava zloupotrebe

Izvori vesti: Blic :: Wikipedia :: Mondo :: Press :: Naša mreža :: Sportska Centrala :: Glas Javnosti :: Kurir :: Mikro :: B92 Sport :: RTS :: Danas

Prijatelji foruma: Triviador :: Nova godina Beograd :: nova godina restorani :: FTW.rs :: MojaPijaca :: Pojacalo :: 011info :: Burgos :: Sudski tumač Novi Beograd

Pravne Informacije: Pravilnik Foruma :: Politika privatnosti :: Uslovi koriscenja :: O nama :: Marketing :: Kontakt :: Sitemap

All content on this website is property of "Burek.com" and, as such, they may not be used on other websites without written permission.

Copyright © 2002- "Burek.com", all rights reserved. Performance: 0.069 sec za 13 q. Powered by: SMF. © 2005, Simple Machines LLC.