Trazim ovde pomoc vec cetvrti put i postaje me malo sramota ali sta cu, moram da trazim pomoc kad drugi cackaju po svakakvim sajtevima pa zaraze komp a ja nzm da ga ocistim bez vase pomoci Neutral Confused Crying or Very sad

Problem se poceo pojavljivati danas i u pitanju su iskacuci prozori.

Internet koneckija je wireless 4mb/s BS Net Beska.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:26-07-2015
Ran by Marko (administrator) on MARKO-PC (28-07-2015 13:39:22)
Running from C:\Users\Marko\Desktop
Loaded Profiles: Marko (Available Profiles: Marko)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: geekstogo.com/forum/topic/335081-frst-t.....scan-tool/

Posto imas zastarelu verziju MalwareBytes-a, hajde da skeniramo racunar sa najnovijom.

Deinstalacija stare verzije

Preuzmi MBAM-clean i sacuvaj ga na Desktop.

Desni klik na mbam-clean.exe ikonicu i izaberi Run as Administrator da bi pokrenuo ovaj alat.
Nakon sto zavrsi, zatrazice ti da restartujes racinar.

Nakon toga isprati moje sledeci instrukcije za instalaciju najnovije verzije:

Skeniranje sa MalwareBytes

Preuzmi Malwarebytes Anti-Malware i sacuvaj instalaciju na Desktop.
Instaliraj program standardnim putem, samo sto na kraju instalacije mozes da iskljucis Trial verziju, ali i ne moras. Drugu opciju ostavi, MalwareBytes ce biti pokrenut i azuriran.
Nakon sto je to gotovo, klikni na Settings tab, na levoj strani izaberi Detctions & protection and obelezi Scan for rootkits ukoliko vec nije.
U istom prozoru, ispod PUP and PUM detections postavi da bude Treat detections as malware.
Zatim klikni na Scan tab, Izaberi Threat Scan i na kraju klikni na Scan Now.
Nakon sto i ukoliko je malware detektovan, klikni na Apply Actions. Zatim ce MalwareBytes krenuti sa uklanjanjem infekcije i zatrazice ti da restartujes racunar.
Nakon zavrsetka skeniranja (ili nakon restart), klikni na History tab.
Klikni na Application Logs, a zatim dvoklik na najnoviji Scan Log.
Na dnu prozora klikni na Export i izaberi Text file.

Sacuvaj izvestaj na Desktop i prikaci ga u sledecoj poruci.

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Deinstaliraj ovo:

Wander Burst

1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.rs/
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = https://search.yahoo.com/search?fr=vmn&type=vmn__webcompa__1_0__ya__ch_WCYID10099_swoc_campaign_150410__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = http://www.google.com/search?q={searchTerms}&rlz=1I7GUEA_enRS574
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = https://search.yahoo.com/search?fr=vmn&type=vmn__webcompa__1_0__ya__ch_WCYID10099_swoc_campaign_150410__yaie&p={searchTerms}
R2 Update Mgr WanderBurst; C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511\updater.exe [1024736 2015-07-28] ()
R2 Service Mgr WanderBurst; C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugincontainer.exe [1091808 2015-07-28] ()
2015-07-27 21:40 - 2015-07-28 12:49 - 00000000 ____D C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511
2015-07-27 21:40 - 2015-07-27 21:41 - 00000000 ____D C:\Program Files (x86)\Wander Burst
2015-07-27 21:38 - 2015-07-27 21:38 - 00411008 _____ C:\Users\Marko\Downloads\UmmyVD-Web-Loader-[132].exe

2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.

Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

Napisano: 28 Jul 2015 19:12


Nije pronasao nikakve malware, kad je zavrsio skeniranje izbacio je u donjem desnom cosku Non malware founded. Nije je trazio da nesto uklonim ili da restartujem komp. Poslednji korak ne mogu da uradim jer nema ono sto si ti rekao.

Dopuna: 28 Jul 2015 19:24

Non-Malware Detected*

Odgovorio sam, ali se nesto forum zabagovao, pogledaj prethodnu poruku.

U pravu si, ovu drugu poruku uopste nisam bio video.

Fix result of Farbar Recovery Scan Tool (x64) Version:26-07-2015
Ran by Marko at 2015-07-28 22:08:58 Run:1
Running from C:\Users\Marko\Desktop
Loaded Profiles: Marko (Available Profiles: Marko)
Boot Mode: Normal

fixlist content:
C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main,Search Page = microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main,Start Page = google.rs/
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = search.yahoo.com/search?fr=vmn&type=vm.....aie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = google.com/search?q={searchTerms}&rlz=1I7GUEA_enRS574
SearchScopes: HKU\S-1-5-21-825732486-3746734302-1360109509-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = search.yahoo.com/search?fr=vmn&type=vm.....aie&p={searchTerms}
R2 Update Mgr WanderBurst; C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511\updater.exe [1024736 2015-07-28] ()
R2 Service Mgr WanderBurst; C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511\plugincontainer.exe [1091808 2015-07-28] ()
2015-07-27 21:40 - 2015-07-28 12:49 - 00000000 ____D C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511
2015-07-27 21:40 - 2015-07-27 21:41 - 00000000 ____D C:\Program Files (x86)\Wander Burst
2015-07-27 21:38 - 2015-07-27 21:38 - 00411008 _____ C:\Users\Marko\Downloads\UmmyVD-Web-Loader-[132].exe

Processes closed successfully.
C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511 => moved successfully.
C:\Program Files (x86)\Common Files\fccb0821-00ee-466c-acb5-2a5cec258511 => moved successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Search Page => value removed successfully
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page => value removed successfully
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}" => key removed successfully
HKCR\CLSID\{012E1000-F331-11DB-8314-0800200C9A66} => key not found.
"HKU\S-1-5-21-825732486-3746734302-1360109509-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}" => key removed successfully
HKCR\CLSID\{C0C3A6C6-03BC-4195-8FCB-AEA091301353} => key not found.
Update Mgr WanderBurst => service removed successfully
Service Mgr WanderBurst => service removed successfully
"C:\ProgramData\fccb0821-00ee-466c-acb5-2a5cec258511" => File/Folder not found.
C:\Program Files (x86)\Wander Burst => moved successfully.
C:\Users\Marko\Downloads\UmmyVD-Web-Loader-[132].exe => moved successfully.
EmptyTemp: => 1.4 GB temporary data Removed.

The system needed a reboot..

==== End of Fixlog 22:12:24 ====

  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Da li je problem resen sada?

Nije resen, i dalje mi izbacuje ono za google chrome i da sam srecni dobitnik iili sta vec, a sa strane mi izbacuje ovo sa AVG Related searches.

Preuzmi smeenk-ov zoek.zip ili zoek.rar () sa ovog ili ovog linka i sačuvaj ga na Desktop.

Raspakuj arhivu u neki folder (uputstvo), a zatim:

zatvori browser i ostale pokrenute programe;
privremeno deaktiviraj zaštitni softver ( ukoliko je to potrebno ) Uputstvo ;
dvoklikom pokreni zoek na ikonicu programa ;
pričekaj da se alat startuje ...

U beli okvir prozora iskopiraj sledeći tekst:


Klikni na dugme i pričekaj da se skeniranje završi.

zoek ce po potrebi, restartovati Windows a na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.

Napomena:Izveštaj će biti sačuvan pod nazivom zoek-results.log na sistemskoj particiji (tipična lokacija: C:\zoek-results.log)

Arrow Kopiraj sadrzaj tog loga u poruku.

Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Marko on 29.07.2015 at 13:04:01,99.
Microsoft Windows 7 Ultimate 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Marko\Desktop\zoek.scr [Scan all users] [Script inserted]

==== System Restore Info ======================

29.07.2015 13:04:52 Zoek.exe System Restore Point Created Successfully.

==== Reset Google Chrome ======================

C:\Users\Marko\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Marko\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Marko\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Marko\AppData\Local\Google\Chrome\User Data\Default\Web Data copy was reset successfully
C:\Users\Marko\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=0 folders=0 0 bytes)

==== EOF on 29.07.2015 at 13:05:14,36 ======================

