|
Poslao: 13 Okt 2015 19:15
|
offline
- magna86
- Anti Malware Fighter
Rank 2
- Pridružio: 21 Jun 2008
- Poruke: 6104
|
Takodje, odradi i sledece;
Preuzmi Nicolas Coolman-ov ZHPCleaner alatku sa ovog linka (plavo 'TÉLÉCHARGER !' dugme) i sacuvaj ga na desktop:
http://www.nicolascoolman.fr/download/zhpcleaner-2/
- Dvoklikom pokreni alat i klik na I Agree;
- Klik na opciju/dugme Scanner i sacekaj da alatka prikupi informacije i zavrsi skeniranje;
- Alatka po zavrsetku formira ZHPCleaner.txt izvestaj na desktop-u.
- Molim, postaviti formirani izvestaj uz poruku koristeci opciju Prikači fajl
(kopija izvestaja ce takodje biti spremljena na %AppData%\ZHP direktorijumu)
|
|
|
|
Poslao: 13 Okt 2015 19:19
|
offline
- Pridružio: 25 Jan 2015
- Poruke: 33
|
Napisano: 13 Okt 2015 19:18
mycity.rs/must-login.png
Fix result of Farbar Recovery Scan Tool (x64) Version:12-10-2015
Ran by Bojan (2015-10-13 10:10:36) Run:6
Running from C:\Users\Bojan\Desktop
Loaded Profiles: Bojan (Available Profiles: Bojan)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Reboot:
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}
DeleteKey: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}
CMD: Reg: reg query "HKCR\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s
*****************
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122} => could not remove at first attempt (ErrorCode: C0000121), see next line.
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122} => key removed successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122} => key not found.
========= Reg: reg query "HKCR\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s =========
'Reg:' is not recognized as an internal or external command,
operable program or batch file.
========= End of CMD: =========
The system needed a reboot.
==== End of Fixlog 10:10:44 ====
mycity.rs/must-login.png
mycity.rs/must-login.png
Farbar Recovery Scan Tool (x64) Version:12-10-2015
Ran by Bojan (2015-10-13 10:16:47)
Running from C:\Users\Bojan\Desktop
Boot Mode: Normal
================== Search Files: "visadd;WalletDealsFactory;vh2.great-offer;eshopcomp" =============
====== End of Search ======
Dopuna: 13 Okt 2015 19:19
Nisam video najnoviju poruku, sadaq cu odraditi i to.
|
|
|
|
Poslao: 13 Okt 2015 19:26
|
offline
- magna86
- Anti Malware Fighter
Rank 2
- Pridružio: 21 Jun 2008
- Poruke: 6104
|
Ok, a potom izvrsi i ovaj fixlist, postavi fixlog gornja sckripta je sacinjavala malu gresku pa ...
Start
Reg: reg query "HKCR\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s
Reg: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s
End
|
|
|
|
Poslao: 13 Okt 2015 19:38
|
offline
- Pridružio: 25 Jan 2015
- Poruke: 33
|
Fix result of Farbar Recovery Scan Tool (x64) Version:12-10-2015
Ran by Bojan (2015-10-13 10:35:48) Run:7
Running from C:\Users\Bojan\Desktop
Loaded Profiles: Bojan (Available Profiles: Bojan)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
Reg: reg query "HKCR\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s
Reg: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s
End
*****************
========= reg query "HKCR\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s =========
ERROR: The system was unable to find the specified registry key or value.
========= End of Reg: =========
========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{84C22490-C68A-4492-B3A6-3B7CB17FA122}" /s =========
ERROR: The system was unable to find the specified registry key or value.
========= End of Reg: =========
==== End of Fixlog 10:35:48 ====
mycity.rs/must-login.png
mycity.rs/must-login.png
Evo i jednog i drugog sada.
|
|
|
|
Poslao: 13 Okt 2015 19:46
|
offline
- magna86
- Anti Malware Fighter
Rank 2
- Pridružio: 21 Jun 2008
- Poruke: 6104
|
Jbg, to bi bilo to. Zadnji fixlog je potvrdio da malicioznih kljuceva vise nema, sve pretrage izlaze bez detekcija, specijalizovani sceneri ne nalaze nista. Ne znam gde da ga lovim vise.
Da li i dalje primas malwarebytes upozorenja?
|
|
|
|
Poslao: 13 Okt 2015 20:26
|
offline
- Pridružio: 25 Jan 2015
- Poruke: 33
|
Napisano: 13 Okt 2015 19:51
Sada cu da proverim.
Ove sve programe da unistaliram/brisem?
Da brisem Avast i Malwarebytes?
Dopuna: 13 Okt 2015 20:26
I dalje imam malwarebytes upozorenja.
|
|
|
|
Poslao: 13 Okt 2015 21:09
|
offline
- magna86
- Anti Malware Fighter
Rank 2
- Pridružio: 21 Jun 2008
- Poruke: 6104
|
Ne, ne da brises programe, nemozemo biti gotovi dok ne otkrijemo izvor.
Nista, ponovo pokreni FRST alat, stikliraj Addition i Shortcut opciju i lupi Scan. Postavi mi sveze FRST.txt, Addition.txt i Shortcut.txt izvestaje na uvid. FRST log iskopiraj, ostale prikaci uz poruku.
|
|
|
|
|
Poslao: 13 Okt 2015 21:46
|
offline
- Pridružio: 25 Jan 2015
- Poruke: 33
|
Napisano: 13 Okt 2015 21:19
Odradio sam to, sada moram da sacekam koji minut da vidim da li ce mi opet izlaziti upozorenje, a ako izadje, odradicu opet to sa FRST-om.
Dopuna: 13 Okt 2015 21:46
Evo neko vreme vec nista ne izbacuje.
Ostavicu ove alate bar do sutra, i tada javljam stanje.
|
|
|
|