Poslao: 27 Apr 2011 09:28
|
offline
- miland94
- Građanin
- Pridružio: 19 Apr 2011
- Poruke: 48
- Gde živiš: Beograd
|
Sve je pocelo iznenada,nakon sto sam obrisao virus komp mi se ubagovao,nije mogao da brise ili da instalira bilo sta,tj. nije mogao da pokrece exe filove kad god bi pokrenuo exe file izasla bi ova poruka:
[url=http://www.mycity.rs/slika.php?slika=252678_43463079_my%20city%202.jpg]
[/url]
Takodje poremetili su mi se desktop dedžeti ali uspeo sam da ih popravim sa reset gadgets programom, priložicu vam fajlove onih alata iz uputstva.
mycity.rs/must-login.png
attach fajl sto mi kaze da okacim.
sva tri fajla iz gmer programa okaci cu dole:
mycity.rs/must-login.png
mycity.rs/must-login.png
mycity.rs/must-login.png
|
|
|
|
Poslao: 27 Apr 2011 11:54
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Pozdrav
miland94
Nisi detaljno ispratio Korak #2 iz uputsva. Potreban nam je jos i DDS.txt log.
NIx Car
AMF Tim
|
|
|
|
Poslao: 27 Apr 2011 13:09
|
offline
- miland94
- Građanin
- Pridružio: 19 Apr 2011
- Poruke: 48
- Gde živiš: Beograd
|
Napisano: 27 Apr 2011 12:08
ok postavicu ga
Dopuna: 27 Apr 2011 12:09
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Ó·Ð Ô at 21:30:04,80 on uto 26.04.2011
Internet Explorer: 9.0.8112.16421
Microsoft Windows 7 Ultimate 6.1.7601.1.1251.381.1033.18.1789.328 [GMT 2:00]
.
AV: avast! Antivirus *Enabled/Outdated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: avast! Antivirus *Enabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_2125713eb213e7bb\STacSV.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\system32\conhost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_2125713eb213e7bb\aestsrv.exe
C:\Program Files\LSI SoftModem\agrsmsvc.exe
C:\Windows\System32\svchost.exe -k Akamai
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\AVG\AVG10\avgfws.exe
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
C:\Windows\system32\CISVC.EXE
C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe
C:\Windows\System32\svchost.exe -k LPDService
C:\Windows\system32\mqsvc.exe
C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
C:\Windows\System32\tcpsvcs.exe
C:\Windows\System32\snmp.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\nfsclnt.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Users\47DF~1\AppData\Local\Temp\Gvd.exe
C:\Windows\Gnulia.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Samsung\PanelMgr\SSMMgr.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Windows\System32\rundll32.exe
C:\Program Files\IDT\wdm\sttray.exe
C:\Program Files\Mobilni Internet\ModemListener.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\regsvr32.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\BitTorrent\BitTorrent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\Ìèëàí\AppData\Roaming\CBS Interactive\CNET TechTracker\TechTracker.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Mobilni Internet\HSPA USB MODEM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
c:\windows\system32\inetsrv\w3wp.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Windows\system32\rundll32.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\prevhost.exe
C:\Windows\system32\WUDFHost.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\sfc.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\Ìèëàí\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Program Files\AVG\AVG10\avgam.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\AVG\AVG10\avgui.exe
C:\Program Files\AVG\AVG10\avgmfapx.exe
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\AVG\AVG10\avgscanx.exe
C:\Windows\system32\conhost.exe
C:\Program Files\AVG\AVG10\avgcsrvx.exe
C:\Users\Ìèëàí\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://google.rs/
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google
mSearch Page = hxxp://downloads.phpnuke.org/en/index.php?rvs=google
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
mSearchAssistant = hxxp://start.facemoods.com/?a=bf&s={searchTerms}&f=4
uURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
uURLSearchHooks: H - No File
uURLSearchHooks: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\tbBrot.dll
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: Winamp Search Class: {57bca5fa-5dbb-45a2-b558-1755c3f6253b} - c:\program files\winamp toolbar\winamptb.dll
mURLSearchHooks: H - No File
mURLSearchHooks: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\tbBrot.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - c:\program files\winamp toolbar\winamptb.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\tbBrot.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - Google Toolbar Notifier BHO
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Ask Toolbar BHO: {d4027c7f-154a-4066-a1ad-4243d8127440} - Sammsoft Toolbar
BHO: brincome browser plug-in: {f30b014f-aef3-c6ef-8287-9d6352317a34} - c:\windows\system32\uqxhwracxxoyqavb.dll
TB: BrotherSoft Extreme Toolbar: {51a86bb3-6602-4c85-92a5-130ee4864f13} - c:\program files\brothersoft_extreme\tbBrot.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
TB: Sammsoft Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} -
TB: Conduit Engine: {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\ConduitEngine.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [BitTorrent] "c:\program files\bittorrent\BitTorrent.exe"
uRun: [0ESKOMO9JO] c:\users\47df~1\appdata\local\temp\Gvd.exe
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\ssmmgr.exe /autorun
mRun: [PWRISOVM.EXE] c:\program files\poweriso\PWRISOVM.EXE
mRun: [XeroxEndeavorBackgroundTask] rundll32.exe xrWCbgnd.dll,LaunchBgTask 1
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [ModemListener] c:\program files\mobilni internet\ModemListener.exe start
mRun: [messenger.exe] c:\program files\common files\microsoft shared\web components\messenger.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [bgwtviizugknhfu] c:\windows\system32\regsvr32.exe /s "c:\windows\system32\uqxhwracxxoyqavb.dll"
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
StartupFolder: c:\users\47df~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\cnette~1.lnk - c:\users\ìèëàí\appdata\roaming\cbs interactive\cnet techtracker\TechTracker.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp Search - c:\programdata\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {148863F4-BC37-44F4-BA12-2E321A6B74E0} = 195.178.38.3 195.178.38.8
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: c:\progra~1\imesha~1\mediabar\datamngr\datamngr.dll c:\progra~1\imesha~1\mediabar\datamngr\iebho.dll c:\progra~1\google\google~3\GO36F4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-04-26 19:28:57 -------- d--h--w- C:\$AVG
2011-04-26 18:53:37 -------- d-----w- c:\users\47df~1\appdata\roaming\AVG
2011-04-26 18:26:00 -------- d-----w- c:\users\47df~1\appdata\roaming\AVG10
2011-04-26 18:23:50 -------- d--h--w- c:\progra~2\Common Files
2011-04-26 18:21:43 -------- d-----w- c:\windows\system32\drivers\AVG
2011-04-26 18:21:43 -------- d-----w- c:\progra~2\AVG10
2011-04-26 18:21:21 -------- d-----w- c:\program files\AVG
2011-04-22 13:04:45 50306 ----a-w- c:\windows\system32\quoelandlfsvqiib.exe
2011-04-22 13:04:40 447483 ----a-w- c:\program files\Drivers_pack_v3.25.63.exe
2011-04-21 20:12:40 -------- d-----w- c:\users\47df~1\appdata\local\BuildAGadget Content
2011-04-21 19:12:20 -------- d-----w- c:\users\47df~1\appdata\local\{081A3B9A-CD32-4623-A168-DCD82E2E053A}
2011-04-15 10:01:34 765440 ----a-w- c:\windows\system32\uqxhwracxxoyqavb.dll
2011-04-14 21:05:28 -------- d-----w- c:\windows\system32\msmq
2011-04-14 21:05:28 -------- d-----w- c:\windows\system32\BestPractices
2011-04-14 21:05:24 -------- d-----w- c:\program files\Microsoft Games
2011-04-14 21:05:23 -------- d-----w- C:\inetpub
2011-04-14 17:28:43 2658 ----a-w- c:\windows\system32\zones.reg
2011-04-13 16:00:23 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-13 15:59:14 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-13 15:59:14 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-13 15:59:13 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-13 15:59:02 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-13 15:59:01 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-13 15:58:29 2333184 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 15:58:25 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 15:58:25 223232 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 15:58:25 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 15:58:24 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 15:58:23 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 15:58:20 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 15:58:18 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-13 15:58:18 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-04-13 15:58:15 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-13 15:58:15 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-13 15:45:32 167936 ----a-w- c:\windows\Gnulia.exe
2011-04-13 15:45:22 123392 --sha-r- c:\windows\system32\vpnikeo.dll
2011-04-10 12:38:43 -------- d-----w- c:\users\47df~1\appdata\local\{1CC39AE1-EA40-48CC-B244-A3662DA2ECED}
2011-04-09 13:40:15 -------- d-----w- c:\users\47df~1\appdata\local\{27A99604-F1E7-44EF-959C-8ED2664AB403}
2011-04-09 11:38:23 -------- d-----w- c:\progra~2\Skype Extras
2011-04-09 11:35:34 -------- d-----r- c:\program files\Skype
2011-04-01 16:40:29 -------- d-----w- c:\program files\common files\Protexis
2011-04-01 16:32:02 -------- d-----w- c:\program files\Corel
2011-04-01 16:28:36 93760 ----a-w- c:\program files\common files\microsoft shared\web components\messenger.exe
2011-04-01 15:58:47 -------- d-----w- c:\users\47df~1\appdata\local\{E8322545-99A2-491B-B4F5-C58CCABFDC65}
2011-03-30 15:17:06 134480 ----a-w- c:\windows\system32\drivers\AVGIDSDriver.sys
2011-03-28 14:33:18 93760 ----a-w- C:\messenger.exe
.
==================== Find3M ====================
.
2011-03-08 08:28:02 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2011-03-07 17:57:22 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2011-03-07 17:57:22 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2011-03-04 16:32:52 31552 ----a-w- c:\windows\system32\TURegOpt.exe
2011-03-04 16:28:14 21312 ----a-w- c:\windows\system32\authuitu.dll
2011-03-04 16:28:08 29504 ----a-w- c:\windows\system32\uxtuneup.dll
2011-02-27 14:20:30 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-02-19 06:30:54 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:30:51 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:30:50 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-12 20:31:20 6656 ----a-w- c:\windows\system32\bcmwlrc.dll
2011-02-07 09:10:41 91448 ----a-w- c:\windows\system32\bcmwlcoi.dll
2011-02-07 09:10:40 3866624 ----a-w- c:\windows\system32\bcmihvsrv.dll
2011-02-07 09:10:40 3555328 ----a-w- c:\windows\system32\bcmihvui.dll
2011-02-01 22:05:51 369952 ----a-w- c:\windows\system32\yk62x86.dll
.
============= FINISH: 21:34:54,06 ===============
mycity.rs/must-login.png
Dopuna: 27 Apr 2011 13:09
zdravo nix jel si pogledao?ima li nekih problema?
|
|
|
|
Poslao: 27 Apr 2011 15:42
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
U toku resavanja slucaja, zamolio bih te da se pridrzavas sledeceg:
Detaljno citati moja uputstva (ili uputstva kolega koji ce me zamenjivati) i raditi iskljucivo po njima;
Ne traziti istovremeno pomoc na drugom mestu;
Nemoj koristiti druge programe za uklanjanje malware-a, osim onih za koje budes dobio uputstvo;
U toku intervencije ne koristiti USB memorijske uredjaje, dok to ne budem zatrazio;
Ukoliko ne odgovorim u roku od 48h, osvezi temu novim post-om;
Ukoliko se ne javis u roku od 5 dana, zatvoricemo slucaj.
Za vise informacija o pravilima Ambulante MyCity foruma: LINK
-----------------------------------------
Kako bi presao na sledeci korak zamolio bih te da uklonis AVG (start-> control panel->add/remove programs,nadjes AVG na listi i kliknes change/remove).Posle deinstalacije AVGa preuzmi program koji ce obrisati ostatke AVGa. Program mozes skinuti sa sledece stranice: http://www.avg.com/us-en/download-tools i nosi naziv AVG Remover(32bit) 2011(avg_remover_stf_x86_2011_1322.exe)
-----------------------------------------
Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:
Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.
Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.
U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste. prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.
Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.
Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.
|
|
|
|
Poslao: 27 Apr 2011 18:04
|
offline
- miland94
- Građanin
- Pridružio: 19 Apr 2011
- Poruke: 48
- Gde živiš: Beograd
|
Napisano: 27 Apr 2011 16:08
Ok ja sam tu,praticu uputstva!
Dopuna: 27 Apr 2011 16:57
Mnogo traje ovaj combofix al cekam
Dopuna: 27 Apr 2011 18:04
kad krene instalacija izbaci mi i kaze da je fajl corrupt i da skinem svezu kopiju fajla ali nigde nemam ponudu da skinem taj svezi fajl.pocne neki proces krene da se puni zeleno dodje do kraja malo mu fali da zavrsi i traje mnogo dugo
|
|
|
|
Poslao: 27 Apr 2011 20:30
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Milane pojasni malo...kopiju kog fajla?
-------------------------------------------------
Preuzmi ponovo sUBSov Combofix http://download.bleepingcomputer.com/sUBs/ComboFix.exe i stavi ga na desktop
Udji u safe mode
uputsvo kako se ulazi u safe mode: http://www.mycity.rs/Uputstva/Kako-uci-u-Safe-Mode-2.html
zatim odradi sledece:
Start >> Run i otkucaj sledece:
"%userprofile%\desktop\combofix.exe" /killall
Zatim pritisni Enter.
U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste. prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.
Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.
Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.
|
|
|
|
Poslao: 27 Apr 2011 21:42
|
offline
- miland94
- Građanin
- Pridružio: 19 Apr 2011
- Poruke: 48
- Gde živiš: Beograd
|
kopiju combofixa kad ga pokrenem izadje poruka da skinem svezu kopiju combofixa,a te opcije nigde nema da ja skinem tu kopiju
|
|
|
|
Poslao: 27 Apr 2011 23:15
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Startuj racunar u Safe Modu (gore sam ti dao uputsvo) i pokreni combofix sa desktopa.
|
|
|
|
Poslao: 28 Apr 2011 17:24
|
offline
- miland94
- Građanin
- Pridružio: 19 Apr 2011
- Poruke: 48
- Gde živiš: Beograd
|
Da ali isto je,pratim uputstvo udjem u safe mode kad se startuje racunar pritiskam f8 i udjem u safe mode,ali isto neće,pokrenem combofix sa desktopa krene da se instalira stigne skoro do kraja treba mu pola milimetra da zavrsi i onda mi izadje poruka da je cmbofix fajl corrupt i da skinem svezu kopiju combofixa,nakon toga instalacija traje i traje,juce sam cekao oko 4 sata da se zavrsi ali nikako neće ima li neki alternativni program,tj.nesto umesto combofixa....
|
|
|
|
Poslao: 28 Apr 2011 22:54
|
offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Da li si ti obrisao AVG kao sto sam ti napisao u uputsvu?
|
|
|
|