Poslao: 26 Jan 2008 21:36
|
offline
- Pridružio: 18 Okt 2007
- Poruke: 70
- Gde živiš: Svilajnac
|
iron_sight ::(pokusam svaku alternativu kad nemam gde)Nece ni tako...
Da probam da prepisem?
----------------------------------------
Elem potrazio sam po folderu i nema C:\WINDOWS\bqxomdo.dll, kao ni : C:\WINDOWS\privacy_danger\index.htm
|
|
|
|
Poslao: 26 Jan 2008 21:49
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Molim te samo isprati ono sta sam ti napisao da uradis.
Dodaj one fajlove rucno u VundoFix i pusti njega da radi posao.
Kada zavrsi postavi mi ovde log.
|
|
|
|
Poslao: 26 Jan 2008 22:14
|
offline
- Pridružio: 18 Okt 2007
- Poruke: 70
- Gde živiš: Svilajnac
|
Ide...
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 20:24:22 26.1.2008
Listing files found while scanning....
C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTRMFile.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTAVIFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTRMFile.dll
C:\WINDOWS\system32\NCTRMFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\aswmklt.dll
C:\WINDOWS\aswmklt.dll Has been deleted!
Attempting to delete C:\WINDOWS\dpvtporrfd.dll
C:\WINDOWS\dpvtporrfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\elfwgps.dll
C:\WINDOWS\elfwgps.dll Has been deleted!
Attempting to delete C:\WINDOWS\fvqkfsp.exe
C:\WINDOWS\fvqkfsp.exe Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 22:07:39 26.1.2008
Listing files found while scanning....
No infected files were found.
|
|
|
|
Poslao: 26 Jan 2008 22:33
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Sta je sa ova dva:
C:\WINDOWS\fvqkfsp.exe
C:\WINDOWS\privacy_danger\index.htm
Nisi ih ubacio ili nije hteo da ih obrise?
|
|
|
|
Poslao: 26 Jan 2008 22:40
|
offline
- Pridružio: 18 Okt 2007
- Poruke: 70
- Gde živiš: Svilajnac
|
C:\WINDOWS\fvqkfsp.exe cini mi se da je u logu upisan kao ociscen,a
C:\WINDOWS\privacy_danger\index.htm a njega nisam nasao,ali sam i njega upisao u listu za brisanje!???
|
|
|
|
Poslao: 26 Jan 2008 22:48
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Moja greska, sledeci fajl nije obrisan:
C:\WINDOWS\bqxomdo.dll
Za onaj privacy_danger moramo da vidimo, to je onaj tvoj desktop koji zeza.
Sredi ti ovaj gornji DLL u VundoFixu, a ja cu da smislim kako da sredimo Desktop.
|
|
|
|
Poslao: 26 Jan 2008 23:16
|
offline
- Pridružio: 18 Okt 2007
- Poruke: 70
- Gde živiš: Svilajnac
|
OK,dada...on mi se jos uvek potkrada,pocinje da me iritira
upisao sam i vrsio brisanje a evo i loga:
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 20:24:22 26.1.2008
Listing files found while scanning....
C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTRMFile.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\NCTAVIFile.dll
C:\WINDOWS\system32\NCTAVIFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTQuickTimeFile.dll
C:\WINDOWS\system32\NCTQuickTimeFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTRMFile.dll
C:\WINDOWS\system32\NCTRMFile.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\NCTVideoCoreM.dll
C:\WINDOWS\system32\NCTVideoCoreM.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\aswmklt.dll
C:\WINDOWS\aswmklt.dll Has been deleted!
Attempting to delete C:\WINDOWS\dpvtporrfd.dll
C:\WINDOWS\dpvtporrfd.dll Has been deleted!
Attempting to delete C:\WINDOWS\elfwgps.dll
C:\WINDOWS\elfwgps.dll Has been deleted!
Attempting to delete C:\WINDOWS\fvqkfsp.exe
C:\WINDOWS\fvqkfsp.exe Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 22:07:39 26.1.2008
Listing files found while scanning....
No infected files were found.
Beginning removal...
Performing Repairs to the registry.
Done!
VundoFix V6.7.7
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 23:06:28 26.1.2008
Listing files found while scanning....
No infected files were found.
|
|
|
|
Poslao: 27 Jan 2008 00:48
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
Nece...
Ajmo ovako:
Skini program Avenger sa sledeceg linka:
http://swandog46.geekstogo.com/avenger.zip
Na prvom ekranu selektuj Input script manually pa klikni na ikonicu lupe.
U prozoru koji ce se pojavi unesi sledeci tekst:
Files to Delete:
C:\WINDOWS\bqxomdo.dll
C:\WINDOWS\privacy_danger\index.htm
Klikni na dugme Done.
Vratice te na prvi ekran gde je sada potrebno kliknuti na ikonicu semafora.
Ukoliko ti program sam ne zatrazi restart, onda ti sam restartuj racunar.
Nakon restartovanja bi folder trebao da bude obrisan, i backup napravljen u folderu c:\avenger.
Postavi ovde log koji bude napravljen na kraju.
|
|
|
|
Poslao: 27 Jan 2008 11:08
|
offline
- Pridružio: 18 Okt 2007
- Poruke: 70
- Gde živiš: Svilajnac
|
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Error: selected file does not appear to be a valid script.
Error code: 0
uopste nemogu da nadjem ove fajlove,probao sam sa search opcijom,ali ih nepronalazi...mozda su izbrisane u neko procesu odranije,ali mi desktop jos uvek modifikovan.
|
|
|
|
Poslao: 27 Jan 2008 11:24
|
offline
- bobby
- Administrator
- Pridružio: 04 Sep 2003
- Poruke: 24135
- Gde živiš: Wien
|
U Avengeru, jesi li zasigurno isao na opciju Input Script manually ?
Kada ti se pojavila ova poruka/log?
To sto ne mozes da nadjes fajlove, to je druga prica, ali to ne znaci da nisu tu.
|
|
|
|