Ovo je ujakov računar.

Imam pristup preko Team Viewera, pa se može desiti da ne mogu odmah odgovoriti ovde.
Računar je bio u očajnom stanju. Nije bilo mesta uopšte na sistemskoj particiji, užas RAM usage itd.

Očistio sam koliko sam mogao, zatim sam odradio AdwCleaner skeniranje i čišćenje a potom i MBAM proveru, koja je pronašla više od 1400 fajlova. Četiri fajla su okategorisana kao malware, ostalo je bilo PUP. Jedan od malware-a je imao Crypt u naslovu.
Sve fajlove sam ubacio u karantin.
Logovi obe aplikacije dostavljeni na kraju posta.

Možete li da proverite da li je računar čist ?
Hvala Ziveli

Malwarebytes Log :

AdwCleaner Logovi :

FRST nije pokrenut sa Desktopa.

Otvori Notepad i iskopiraj sljedeći tekst koji se nalazi unutar Kod polja.

CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
FF Extension: No Name - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ [not found]
FF Extension: No Name - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ [not found]
FF Extension: HulaToo 1.0.1 - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\{c933aa85-a419-42da-9957-2f32a4c0601a}.xpi [2015-12-24] [not signed]
CHR StartupUrls: Default -> "hxxp://"
Task: {E39A301A-AEA2-4216-8FB1-E10EC147D740} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {F5C331CD-FF66-4F0D-AFC8-9CA8B4EAEE75} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\se
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YTDownloader
FirewallRules: [{E835D373-47B2-402D-A83B-039125117801}] => (Allow) C:\Users\WinPC\Downloads\CodecPerformerSetup.exe
FirewallRules: [{D432770E-EB8E-4E28-B14D-B6E618DB14F1}] => (Allow) C:\Users\WinPC\Downloads\CodecPerformerSetup.exe
C:\Program Files\cOPunke
C:\Program Files\coopuunk
C:\Program Files\Common Files\System\SysMenu.dll
C:\Program Files\YTDownloader
C:\Program Files\prefs.js

U okviru Notepad-a klikni na File --> Save As
Fajl nazovi Fixlist i sačuvaj na Desktop
Dvoklikom ponovo pokreni FRST.exe
Klikni na Fix i sačekaj dok program ne završi.
Ukoliko program zatraži restart računara, omogući mu da to nesmetano obavi.
Nakon završetka rada, otvoriće se fixlog.txt, sa sadržajem koji treba da kopiraš u temu.
Takođe, na Desktop-u će se nalaziti (fixlog.txt).

Moja greška za pokretanje van Desktopa.

Fix result of Farbar Recovery Scan Tool (x86) Version:07-01-2015
Ran by WinPC (2016-01-08 18:22:07) Run:1
Running from C:\Users\WinPC\Desktop
Loaded Profiles: WinPC & UpdatusUser (Available Profiles: WinPC & UpdatusUser)
Boot Mode: Normal


fixlist content:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
FF Extension: No Name - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ [not found]
FF Extension: No Name - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ [not found]
FF Extension: HulaToo 1.0.1 - C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\{c933aa85-a419-42da-9957-2f32a4c0601a}.xpi [2015-12-24] [not signed]
CHR StartupUrls: Default -> "hxxp://"
Task: {E39A301A-AEA2-4216-8FB1-E10EC147D740} - System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update3 <==== ATTENTION
Task: {F5C331CD-FF66-4F0D-AFC8-9CA8B4EAEE75} - System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => Rundll32.exe C:\PROGRA~1\COMMON~1\System\SysMenu.dll ,Command701 update2 <==== ATTENTION
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\se
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YTDownloader
FirewallRules: [{E835D373-47B2-402D-A83B-039125117801}] => (Allow) C:\Users\WinPC\Downloads\CodecPerformerSetup.exe
FirewallRules: [{D432770E-EB8E-4E28-B14D-B6E618DB14F1}] => (Allow) C:\Users\WinPC\Downloads\CodecPerformerSetup.exe
C:\Program Files\cOPunke
C:\Program Files\coopuunk
C:\Program Files\Common Files\System\SysMenu.dll
C:\Program Files\YTDownloader
C:\Program Files\prefs.js

"HKLM\SOFTWARE\Policies\Google" => key removed successfully.
C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ => path removed successfully.
C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\ => path removed successfully.
C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\{c933aa85-a419-42da-9957-2f32a4c0601a}.xpi => moved successfully
C:\Users\WinPC\AppData\Roaming\Mozilla\Firefox\Profiles\tjeephz4.default\extensions\{c933aa85-a419-42da-9957-2f32a4c0601a}.xpi => path removed successfully.
Chrome StartupUrls => removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E39A301A-AEA2-4216-8FB1-E10EC147D740}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E39A301A-AEA2-4216-8FB1-E10EC147D740}" => key removed successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Multimedia\SMupdate3 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SMupdate3" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F5C331CD-FF66-4F0D-AFC8-9CA8B4EAEE75}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5C331CD-FF66-4F0D-AFC8-9CA8B4EAEE75}" => key removed successfully.
C:\Windows\System32\Tasks\Microsoft\Windows\Maintenance\SMupdate2 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\SMupdate2" => key removed successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\se => key removed successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\YTDownloader => key removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E835D373-47B2-402D-A83B-039125117801} => value removed successfully.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D432770E-EB8E-4E28-B14D-B6E618DB14F1} => value removed successfully.
C:\Program Files\cOPunke => moved successfully
C:\Program Files\coopuunk => moved successfully
"C:\Program Files\Common Files\System\SysMenu.dll" => not found.
"C:\Users\WinPC\AppData\Roaming\SkypEmoticons" => not found.
"C:\Program Files\YTDownloader" => not found.
C:\Program Files\prefs.js => moved successfully
"C:\Users\WinPC\Downloads\CodecPerformerSetup.exe" => not found.
EmptyTemp: => 6.4 GB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 18:23:30 ====

Preuzmi Malwarebytes Anti-Rootkit (MBAR) sa sledeceg linka i sacuvaj ga na Desktop.

Dvoklikom pokreni MBAR () na ikonicu programa:
- Klikni OK na sledecem prozoru da bi dozvolio raspakivanje u zaseban mbar folder na desktop-u;
- mbar.exe ce biti startovan. Na nekim sistemima to moze da potraje nekoliko dodatnih sekundi, te pricekati pokretanje.;
- U uvodnom prozoru klikni dugme Next ukoliko si saglasan;

• Na 'Update Database' prozoru klik na dugme Update da bi preuzeo sveze definicije. Kada se ispise poruka 'Success: Database was successfully updated' klik na dugme Next;
• Pod sekcijom 'Scan Targets' proveri da su sve opcije stiklirane, te klikni na dugme Scan;

Obavestenje: sa nekim infekcijama moze se desiti da se prikaze neka od sledecih poruka:
- 'Could not load protection driver' => u tom slucaju klikni OK.
- 'Could not load DDA driver' => klikni Yes na to obavestenje da bi dozvolio ucitavanje nakon restarta. Dozvoli restart i nastavi sa ostatkom instrukcija posle restarta.

>> Ukoliko malware nije detektovan, klik na Exit dugme da zatvoris program. U sledecu poruku postavi mbar-log-year-month-day (sat-minuti-sekundi).txt i system-log.txt izveštaje.

>> Ukoliko su infekcija/e pronadjene, proveriti da li je obelezena opcija 'Create Restore Point' i klikni na dugme Cleanup! da bi uklonili pretnje.
- Procedura uklanjanje malware-a (scheduled) ce biti zakazana po restartu, bice prikazano obavestenje u pop-up prozoru. Klikni dugme Yes i sistem bi trebao da se restartuje i da zavrsi proceduru ciscenja.

Obavestenje! samo ukoliko je RootKit detektovan: - postaraj se da pokrenes fixdamage.exe alat koji se nalazi u mbar folderu, \Plugins\fixdamage.exe:
- Dvoklikom pokreni fixdamage, u crnom prozoru koji se otvori (command prompt) ukucaj Y (Y stoji za Yes) da bi nastavio izvrsenje, pricekati da alat odradi sve popravke ...
- Kada vidis poruku 'press any key to exit' popravka je kompletirana. Pritisnuti bilo koju tipku na tastaturi da bi se prozor zatvorio. Restartovati sistem.

Sledeci izvestaji ce biti formirani u mbar folderu.
1. mbar-log-year-month-day (hour-minute-second).txt
2. system-log.txt

Iskopiraj sadrzaj mbar log-a u poruku a system log okaci uz poruku koristeci opciju Prikači fajl.

  • Pridružio: 14 Feb 2008
  • Poruke: 12403

Nepoželjne apliakcije smo uklonili.

Sledeća procedura će implementirati završno čišćenje.

Arrow Preuzmi "Xplode"-ov DelFix alat i snimi ga na Desktop.
Dvoklikom pokreni alat i štikliraj kućice ispred sledećih opcija;

Remove disinfection tools
Create registry backup
Purge System Restore

Klikni na dugme Run i pričekaj trenutak dok alat ne završi svoj rad.
Od ovog trenutka, svi korišćeni alati u ovoj temi bi trebali biti obrisani.
Alat će takođe formirati izveštaj za tebe. (C:\DelFix.txt)

Alat će snimiti i zdravo stanje registy-ja i napraviti backup koristeci integrisan program "ERUNT" u %windir%\ERUNT\DelFix
Alat briše stare system restore tačke i pravi novu, svežu tačku nakon čišćenja.


Taj računar ima samo 1GiB RAM-a pa bi trebalo razmotriti ubacvanje još RAM-a.

Preporučujem ti da instaliraš Service Pack 1 za tvoj Windows 7 operativni sistem.
Možeš ga preuzeti sa ovog linka:

Windows 7 SP1 x86

# DelFix v1.011 - Logfile created 10/01/2016 at 19:17:16
# Updated 18/08/2015 by Xplode
# Username : WinPC - WINPC-PC
# Operating System : Windows 7 Ultimate  (32 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\WinPC\Desktop\mbar
Deleted : C:\Users\WinPC\Desktop\Fixlog.txt
Deleted : C:\Users\WinPC\Desktop\FRST.exe
Deleted : HKLM\SOFTWARE\AdwCleaner

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #231 [Windows Update | 01/10/2016 17:31:02]

New restore point created !

########## - EOF - ##########

Instaliraću im SP1 a nadogradnja RAM-a zavisi od njih. Već sam predložio to kao rešenje "tromog rada".

Hvala Sass,


