brisanje virusa iz računara

brisanje virusa iz računara

offline
  • ilija7 
  • Novi MyCity građanin
  • Pridružio: 26 Jul 2008
  • Poruke: 4

Ne znam kako da uklonim viruse iz računara. Dešava mi se da mi kompjuter totalno ukoči, da ne radi, da otvara stranicu 2 minuta. A najviše se to ispoljava kad hoću interenet da koristim. Uđem preko google chrom-a i tad je otvaranje kao večnost.

Ovaj problem sam primetio pre 20 dana kada sam ubacio USB memoriju u kompjuter i kada mi je na tom istom USB napravljena neka prečica. Od tad ja taj USB ne mogu da otvorim, avast antivirus mi to ne dozvoljava.

Sve što mi antivirus izbacio Avast antivirus ja sam navodno obrisao i tih datoteka nema više u računaru, međutim zamenio sam antivirus program i instalirao Nod32 i on mi je detektovao u windows-u virus Win32 koga ja ne mogu da obrišem jer je u sistemu. A detekciju je pokazao i na Java programu.

Probao sam da obrišem neke zaražene programe ali je virus bio i dalje tu. A inače imam bežični internet sa protokom od 1536/768 kb/s.

E sad ovo što sam uradio sa DDS i Attach.

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.2180
Run by pc at 17:44:53 on 2013-03-29
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1279.495 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SearchProtect\bin\CltMngSvc.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://searchfunmoods.com/?f=1&a=fmtgl&cd=2XzuyEtN2Y1L1QzutDtD0EtDtBtD0A0C0DtB0FtA0BtAtAyDtN0D0Tzu0CtAyBzztN1L2XzutN1L1Czu1O1H2Z1N1I&cr=1251408273&ir=
uSearch Bar = hxxp://dts.search-results.com/sidebar.html?src=ssb&appid=101&systemid=406&sr=0
mStart Page = hxxp://searchfunmoods.com/?f=1&a=fmtgl&cd=2XzuyEtN2Y1L1QzutDtD0EtDtBtD0A0C0DtB0FtA0BtAtAyDtN0D0Tzu0CtAyBzztN1L2XzutN1L1Czu1O1H2Z1N1I&cr=1251408273&ir=
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
mSearchAssistant = hxxp://dts.search-results.com/sr?src=ieb&appid=101&systemid=406&sr=0&q={searchTerms}
uURLSearchHooks: SweetIM ToolbarURLSearchHook Class: {EEE6C35D-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgHelper.dll
uURLSearchHooks: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: HistoryTriggerBHO Class: {21A88CB9-84D2-4020-A2D1-B25A21034884} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: IE5BarLauncherBHO Class: {78F3A323-798E-4AEA-9A57-88F4B05FD5DD} - c:\program files\startsearch plugin\ssBarLcher.dll
BHO: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SweetIM Toolbar Helper: {EEE6C35C-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: iWin Toolbar: {CE0C2586-DA36-452B-ACDB-320D9BCB19BF} - c:\program files\iwin\prxtbiWi0.dll
TB: StartSearchToolBar: {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - c:\program files\startsearch plugin\ssBarLcher.dll
TB: SweetIM Toolbar for Internet Explorer: {EEE6C35B-6118-11DC-9C72-001320C79847} - c:\program files\sweetim\toolbars\internet explorer\mgToolbarIE.dll
TB: iWin Toolbar: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - c:\program files\iwin\prxtbiWi0.dll
TB: StartSearchToolBar: {7AC3E13B-3BCA-4158-B330-F66DBB03C1B5} - c:\program files\startsearch plugin\ssBarLcher.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\pc\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - hxxp://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{95B6BD40-9C41-4D68-8723-AE03143A1514} : DHCPNameServer = 10.151.102.2 10.200.1.30 10.200.1.31
TCP: Interfaces\{ED7F5DBF-2D8F-44D8-B264-FC00A219EBA0} : NameServer = 10.151.102.2 10.151.102.2
Handler: base64 - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: chrome - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
Handler: prox - {5ACE96C0-C70A-4A4D-AF14-2E7B869345E1} - <orphaned>
AppInit_DLLs= c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2013-3-29 368176]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2013-3-29 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-3-29 66336]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2013-3-29 45248]
R2 CltMngSvc;Search Protect by Conduit Updater;c:\program files\searchprotect\bin\CltMngSvc.exe [2012-12-26 87552]
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2012-4-21 233472]
R3 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-3-29 164736]
R3 cmipci;CMI8738/8768 Audio Driver;c:\windows\system32\drivers\cmipci.sys [2011-4-6 37888]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-4-21 36608]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 slnt;Silan SC92031 PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [2011-4-6 18004]
R4 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys --> c:\windows\system32\drivers\ehdrv.sys [?]
R4 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys --> c:\windows\system32\drivers\epfwtdir.sys [?]
S0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-3-29 49248]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2013-3-29 765736]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-12-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-12-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-12-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-12-23 25088]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
S3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2012-7-23 15896]
S3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\drivers\zghsmdm.sys [2012-7-23 113688]
.
=============== Created Last 30 ================
.
2013-03-29 16:36:30 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-03-29 16:36:29 164736 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-03-29 16:36:28 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-03-29 16:36:28 49248 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-03-29 16:35:42 41664 ----a-w- c:\windows\avastSS.scr
2013-03-29 16:34:57 -------- d-----w- c:\program files\AVAST Software
2013-03-29 16:31:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-28 00:48:39 -------- d-----w- c:\documents and settings\pc\local settings\application data\Temp
2013-03-26 15:02:39 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\Repository
2013-03-17 23:53:47 -------- d-----w- c:\documents and settings\all users\application data\Norton
2013-03-13 11:03:47 77824 --sha-w- c:\documents and settings\all users\ms0055AC65.dat
2013-03-07 13:57:20 -------- d-----w- c:\documents and settings\all users\application data\Alwil Software
.
==================== Find3M ====================
.
.
============= FINISH: 17:45:31.51 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/5/2011 7:14:44 PM
System Uptime: 3/29/2013 9:54:33 AM (8 hours ago)
.
Motherboard: | | VT8366-8233
Processor: Unknown CPU Type | Socket A | 1799/133mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 18 GiB total, 6.453 GiB free.
D: is FIXED (FAT32) - 59 GiB total, 12.881 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP589: 3/25/2013 12:42:28 PM - System Checkpoint
RP590: 3/26/2013 7:43:32 PM - System Checkpoint
RP591: 3/27/2013 9:44:37 PM - System Checkpoint
RP592: 3/28/2013 1:22:15 AM - avast! Free Antivirus Setup
RP593: 3/28/2013 12:16:23 PM - Installed ESET NOD32 Antivirus
RP594: 3/29/2013 12:35:04 PM - System Checkpoint
RP595: 3/29/2013 5:30:18 PM - Removed ESET NOD32 Antivirus
RP596: 3/29/2013 5:34:57 PM - avast! Free Antivirus Setup
.
==== Installed Programs ======================
.
Adobe Flash Player 10 ActiveX
Adobe Reader X (10.1.6)
Ahead Nero 6 Demo
Autodesk DWF Viewer
avast! Free Antivirus
Codec Pack - All In 1 6.0.3.0
Compatibility Pack for the 2007 Office system
Contrast PlanPlus 2006
FastStone Image Viewer 4.6
Free PDF to Word Doc Converter v1.1
GOM Player
Google Chrome
hp deskjet 3600
hp deskjet 3600 series
HP Memories Disc
HP Photo and Imaging 2.0 - Deskjet Series
hp print screen utility
Intel(R) 536EP Modem
iWin Toolbar
Java Auto Updater
Java(TM) 6 Update 30
Java(TM) SE Runtime Environment 6 Update 1
LG Bluetooth Drivers
LG United Mobile Drivers
LiveVDO plugin 1.3
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Calculator Plus
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MPEG2 Codec(libmpeg2/mad)
MSVC80_x86_v2
MSXML 4.0 SP2 Parser and SDK
Nokia Connectivity Cable Driver
Nokia PC Suite
PC Connectivity Solution
PDF4Free 3.0
PhotoScape
Picasa 3
SAMSUNG Mobile Composite Device Software
Samsung Mobile Modem Device Software
SAMSUNG Mobile Modem Driver Set
SAMSUNG Mobile Modem V2 Software
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung New PC Studio
Samsung New PC Studio USB Driver Installer
SAMSUNG SYMBIAN USB Download Driver
SAMSUNG USB Mobile Device Software
SamsungConnectivityCableDriver
Search Protect by conduit
SweetIM for Messenger 3.4
SweetIM Toolbar for Internet Explorer 4.1
Total Commander (Remove or Repair)
WebFldrs XP
Winamp
Winamp Detector Plug-in
Windows Driver Package - MobileTop (sshpmdm) Modem (01/26/2008 2.6.0.0)
Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia Modem (06/09/2010 7.01.0.8)
Windows Driver Package - Nokia Modem (10/07/2010 4.6)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinRAR archiver
YuRecnik
ZTE Handset USB Driver
.
==== Event Viewer Messages From Past Week ========
.
3/29/2013 4:13:35 PM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
3/27/2013 12:14:56 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Machine Debug Manager service to connect.
3/27/2013 12:14:56 PM, error: Service Control Manager [7000] - The Machine Debug Manager service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/26/2013 9:47:19 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
3/26/2013 9:47:19 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
3/25/2013 11:02:34 AM, error: Service Control Manager [7000] - The hpdj service failed to start due to the following error: The system cannot find the file specified.
.
==== End Of File ===========================

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Pozdrav,


Preuzmite program GMER sa donjeg linka na Desktop:


GMER download
Kliknite dati link;
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberite Desktop i kliknite Save.



Dvoklikom pokrenite GMER.
Sačekajte da se završi uvodno skeniranje - ukoliko se pojavi bilo kakav upit, kliknite No;

kliknite Scan i sačekajte da skeniranje bude završeno;

kliknite Save ... - izveštaj sačuvajte na Desktop (pod nazivom Gmer1);

kliknite desnim tasterom u prozor programa Gmer i odaberite Options > 3rd party - kliknite Scan;

po završetku skeniranja kliknite Save ... - izveštaj sačuvajte na Desktop (pod nazivom Gmer2);

kliknite taster >>> i odaberite Autostart karticu;

po završetku kratkotrajnog skeniranja, kliknite Copy;

otvorite Notepad i u njega postavite kopirani tekst - izveštaj sačuvajte na Desktop (pod nazivom Gmer3);


Slikoviti prikaz postupka

Priložite sva tri izveštaja uz poruku korišćenjem opcije Prikači fajl.

offline
  • ilija7 
  • Novi MyCity građanin
  • Pridružio: 26 Jul 2008
  • Poruke: 4

Sačuvao sam GMER na desktop-u i prilikom pokretenja svaki put mi se kompjuter restartuje sam i to sam 3 puta probao da pokrenem i neće.

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Ok, da probamo sa drugim programom...



Preuzmite program RootRepeal sa jednog od sledećih linkova na Desktop:


RootRepeal mirror #1
RootRepeal mirror #2
RootRepeal mirror #3


Kliknite desnim tasterom na link i odaberite opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberite Desktop i kliknite Save.




Raspakujte RootRepeal.zip u neki folder (uputstvo).
Dvoklikom pokrenite RootRepeal.exe;

odaberite Report karticu (klikom na Report taster, dole, desno);

kliknite Scan;

u prozoru koji se otvori (Select Scan), obeležite kućice ispred svih stavki i kliknite OK;

u narednom prozoru (Select Drives) obeležite kućicu ispred sistemskog diska (obično C:\) i kliknite OK.

po završetku, izveštaj (koji će biti automatski sačuvan na sistemskom disku kao RootRepeal report datum (vreme).txt) će se otvoriti u Notepad-u.


Slikoviti prikaz postupka

Priložite kreirani izveštaj uz poruku korišćenjem opcije Prikači fajl.

Napomena: tipična lokacija izveštaja je C:\RootRepeal report datum (vreme).txt [datum (vreme) - datum i vreme skeniranja)].

offline
  • ilija7 
  • Novi MyCity građanin
  • Pridružio: 26 Jul 2008
  • Poruke: 4

prilikom otvaranja zip-win rar pojavila mi se greška Eror-invalid PE image found i ja sam nastavio da skeniram i izbacio mi je fajl u notepad-u.
mycity.rs/must-login.png

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Na sistemu nije prisutan malware, ali je prisutno dosta "crap" softvera i dva antivirusa, tj. Avast i ostaci ESET-a, koje je potrebno ukloniti.


Korak 1.

* preuzmi avast! Uninstall Utility na Desktop
* restartuj racunar u Safe Mode po ovom uputstvu
* pokreni preuzeti alat i isprati uputstvo (maticni link je --> http://www.avast.com/uninstall-utility)



Korak 2.

Pokreni Control Panel --> Add or Remove Programs i obrisi sledece ukoliko ne koristis:
- iWin Toolbar
- Search Protect by conduit
- SweetIM for Messenger 3.4
- SweetIM Toolbar for Internet Explorer 4.1

Restartuj racunar!


Korak 3.

Preuzmi "Xplode"-ov AdwCleaner i sacuvaj ga na Desktop
Dvoklikom pokreni program i klikni na dugme [Search] .
Kada program zavrsi analizu otvorice notepad sa izvestajem. Zatvori taj notepad.

Klikni na dugme [Delete] i pricekaj da program zavrsi.
Program ce zatvoriti sve aktivne programe i izbaciti prozor sa tim upozorenjem. Klikni Ok kao potvrdu.
Na sledeca dva prozora koja se otvore (Informations i Restart required ) klikni Ok

Racunar ce se restartovati a potom otvoriti notepad (C:\AdwCleaner[S1].txt) sa izvestajem.
Sacuvaj taj notepad na Desktop i okaci ga uz poruku koristeci opciju "Prikaci fajl"

Napomena: Izvestaj ce takodje biti sacuvan na C:\AdwCleaner[S1].txt


Korak 4.

Ponovo pokreni DDS i dostavi mi svez DDS.txt log...

offline
  • ilija7 
  • Novi MyCity građanin
  • Pridružio: 26 Jul 2008
  • Poruke: 4

U control panelu izbrisao sam samo Search Protect by conduit, ostale nisam mogao.


mycity.rs/must-login.png


DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 6.0.2900.2180
Run by pc at 20:36:08 on 2013-03-29
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1279.732 [GMT 1:00]
.
.
============== Running Processes ================
.
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\pc\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uSearchAssistant = hxxp://www.google.com
mSearchAssistant = hxxp://www.google.com
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: HistoryTriggerBHO Class: {21A88CB9-84D2-4020-A2D1-B25A21034884} - LocalServer32 - <no file>
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\pc\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {B49C4597-8721-4789-9250-315DFBD9F525} - hxxp://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{95B6BD40-9C41-4D68-8723-AE03143A1514} : DHCPNameServer = 10.151.102.2 10.200.1.30 10.200.1.31
TCP: Interfaces\{ED7F5DBF-2D8F-44D8-B264-FC00A219EBA0} : NameServer = 10.151.102.2 10.151.102.2
AppInit_DLLs= c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll
.
============= SERVICES / DRIVERS ===============
.
R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2012-4-21 233472]
R3 cmipci;CMI8738/8768 Audio Driver;c:\windows\system32\drivers\cmipci.sys [2011-4-6 37888]
R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2012-4-21 36608]
R3 LgBttPort;LGE Bluetooth TransPort;c:\windows\system32\drivers\lgbtport.sys [2009-9-29 12160]
R3 lgbusenum;LG Bluetooth Bus Enumerator;c:\windows\system32\drivers\lgbtbus.sys [2009-9-29 10496]
R3 LGVMODEM;LGE Virtual Modem;c:\windows\system32\drivers\lgvmodem.sys [2009-9-29 12928]
R3 slnt;Silan SC92031 PCI Fast Ethernet Adapter;c:\windows\system32\drivers\slnt.sys [2011-4-6 18004]
S0 aswRvrt;aswRvrt; [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;\??\c:\windows\system32\drivers\aswmonflt.sys --> c:\windows\system32\drivers\aswMonFlt.sys [?]
S3 Andbus;LGE Android Platform Composite USB Device;c:\windows\system32\drivers\lgandbus.sys [2010-12-23 14336]
S3 AndDiag;LGE Android Platform USB Serial Port;c:\windows\system32\drivers\lganddiag.sys [2010-12-23 20736]
S3 AndGps;LGE Android Platform USB GPS NMEA Port;c:\windows\system32\drivers\lgandgps.sys [2010-12-23 20096]
S3 ANDModem;LGE Android Platform USB Modem;c:\windows\system32\drivers\lgandmodem.sys [2010-12-23 25088]
S3 aswVmm;aswVmm; [x]
S3 hwusbdev;Huawei DataCard USB PNP Device;c:\windows\system32\drivers\ewusbdev.sys --> c:\windows\system32\drivers\ewusbdev.sys [?]
S3 massfilter_hs;HS HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2012-7-23 15896]
S3 zghsmdm;ZTE General Handset USB Modem Proprietary;c:\windows\system32\drivers\zghsmdm.sys [2012-7-23 113688]
.
=============== Created Last 30 ================
.
2013-03-29 16:34:57 -------- d-----w- c:\program files\AVAST Software
2013-03-29 16:31:45 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software
2013-03-28 00:48:39 -------- d-----w- c:\documents and settings\pc\local settings\application data\Temp
2013-03-26 15:02:39 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\repository\FS
2013-03-18 23:58:48 -------- d-----w- c:\windows\system32\wbem\Repository
2013-03-17 23:53:47 -------- d-----w- c:\documents and settings\all users\application data\Norton
2013-03-13 11:03:47 77824 --sha-w- c:\documents and settings\all users\ms0055AC65.dat
2013-03-07 13:57:20 -------- d-----w- c:\documents and settings\all users\application data\Alwil Software
.
==================== Find3M ====================
.
.
============= FINISH: 20:36:23.72 ===============





mycity.rs/must-login.png


mycity.rs/must-login.png

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Arrow Preuzmi i pokreni sledeci fajl:

https://www.mycity.rs/must-login.png

Otvorice ti se log.txt koji se nalazi na Desktop-u. Ako je prazan zatvori, ako ima nekog sadrzaja iskopiraj ovde, ali pre toga restartuj racunar.


Arrow Dostavi mi i svez DDS.txt izvestaj.

Ko je trenutno na forumu
 

Ukupno su 946 korisnika na forumu :: 25 registrovanih, 2 sakrivenih i 919 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airsuba, Arahne, Bane san, Ben Roj, bobomicek, bojank, Brana01, DonRumataEstorski, Dorcolac, DPera, elenemste, goxin, kikisp, Mi lao shu, nemkea71, Panter, Parker, Prašinar, rodoljub, skvara, Srki94, Trpe Grozni, VJ, Volkhov-M, zillbg