|
Poslao: 24 Jun 2012 12:55
|
offline
- TwinHeadedEagle
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
Pozdrav, Dusan.cz
Preuzmi Rootkit Unhooker na Desktop.
Dvoklikom pokreni program;
odaberi Report karticu;
klikni Scan i u prozoru koji se otvori štrikliraj stavke:
SSDT
Shadow SSDT
Processes
Drivers
Stealth Code
Files
Code Hooks
klikni OK i sačekaj završetak skeniranja.
Kada skeniranje bude završeno, klikni File > Save Report i sačuvaj izveštaj.
Izveštaj programa Rootkit Unhooker priloži uz poruku korišćenjem opcije Prikači fajl.
|
|
|
|
Poslao: 24 Jun 2012 12:59
|
offline
- Dusan.cz
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Počasni građanin
- Pridružio: 18 Jun 2012
- Poruke: 986
|
Pokusavao sam puno puta i nece.Cim uradim sve to i pocne Scan komp mi zakuca i mora da se restartuje
|
|
|
|
|
|
Poslao: 24 Jun 2012 15:58
|
offline
- TwinHeadedEagle
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Anti Malware Fighter
Rank 2
- Pridružio: 09 Avg 2011
- Poruke: 15879
- Gde živiš: Beograd
|
Korak 1
Ponovo pokreni program OTL dvoklikom na ikonu.
U bijeli okvir prozora gdje piše Custom Scans/Fixes iskopirati sljedeći tekst:
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutDtDtCyD0FtBtCzztCtDyCyCtAyC0AtDtN0D0TzutBtDtCtBtDyCtCyD&cr=468824574
E - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes,DefaultScope = {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
IE - HKLM\..\SearchScopes\{651564E4-A131-5A6F-ADB1-44088F62A263}: "URL" = http://home.allgameshome.com/results.php?category=web&s={searchTerms}
IE - HKLM\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutDtDtCyD0FtBtCzztCtDyCyCtAyC0AtDtN0D0TzutBtDtCtBtDyCtCyD&cr=468824574
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?babsrc=HP_ss&affID=101246&mntrId=4caa36a00000000000000015f2181066
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://blekko.com/ws/?source=c3348dd4&toolbarid=blekkotb_031&u=B07AFEFA3E4D237E4BB4F84FDED061F0&tbp=homepage
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {CFF4DB9B-135F-47c0-9269-B4C6572FD61A}
IE - HKCU\..\SearchScopes,DefaultScope = {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
IE - HKCU\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=bf2&s={searchTerms}&f=4
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=SP_ss&affID=101241&mntrId=4caa36a00000000000000015f2181066
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://tbsearch.ask.com/redirect?client=ie&tb=DAT&o=15240&src=crm&q={searchTerms}&locale=en_US
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb_031&u=B07AFEFA3E4D237E4BB4F84FDED061F0&q={searchTerms}
IE - HKCU\..\SearchScopes\{651564E4-A131-5A6F-ADB1-44088F62A263}: "URL" = http://mystart.incredibar.com/mb139/?search={searchTerms}&loc=IB_DS&a=6R8piW5Chd&i=26
IE - HKCU\..\SearchScopes\{86F14831-D88C-4BC8-B871-C8FB24D95D9B}: "URL" = http://www.questbasic.com/?prt=qbdantasdns&keywords={searchTerms}
IE - HKCU\..\SearchScopes\{A890ECA1-E797-4D12-A1C1-C88203294DB1}: "URL" = http://start.funmoods.com/results.php?f=4&a=nv1&q={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=nv1&chnl=nv1&cd=2XzutAtN2Y1L1QzutDtDtCyD0FtBtCzztCtDyCyCtAyC0AtDtN0D0TzutBtDtCtBtDyCtCyD&cr=468824574
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
FF - prefs.js..backup.old.browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..backup.old.browser.search.selectedEngine: "MyStart Search"
FF - prefs.js..browser.search.order.1: "Blekko"
FF - prefs.js..browser.search.selectedEngine: "Blekko"
[2012/01/16 15:11:04 | 000,000,000 | ---D | M] (AllGamesHome Toolbar) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\{C178BB02-BFCF-4E69-AB7C-DED3BD0291BD}
[2012/04/08 17:04:00 | 000,000,000 | ---D | M] (TheBflix) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\4f807a2ad4342@4f807a2ad4344.info
[2012/02/16 19:21:15 | 000,000,000 | ---D | M] (Browser Companion Helper) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\bbrs_002@blabbers.com
[2012/02/16 19:21:31 | 000,000,000 | ---D | M] (Babylon) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\ffxtlbr@babylon.com
[2012/06/15 18:01:10 | 000,000,000 | ---D | M] (Funmoods.com) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\ffxtlbr@funmoods.com
[2012/04/08 17:05:57 | 000,000,000 | ---D | M] (incredibar.com) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\extensions\ffxtlbr@incredibar.com
[2011/11/10 05:02:10 | 000,002,015 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\searchplugins\allgameshome-search.xml
[2012/02/26 19:25:10 | 000,001,797 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\searchplugins\funmoods.xml
[2012/04/08 17:05:26 | 000,002,203 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\nkc1yje4.default\searchplugins\MyStart Search.xml
[2012/01/15 22:51:17 | 000,000,000 | ---D | M] (QuestBasic) -- C:\Program Files\Mozilla Firefox\extensions\{1CE72EFA-E2D1-48FA-A5EC-D7111C2C5BB6}
[2011/10/20 19:38:24 | 000,002,046 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\fcmdSrch.xml
[2012/02/16 19:21:23 | 000,002,288 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
[2012/06/15 17:58:32 | 000,302,425 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\funmoods-speeddial.crx
[2012/06/15 17:58:30 | 000,031,470 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\funmoods.crx
:COMMANDS
[purity]
[emptytemp]
[reboot]
Klikni taster Run Fix;
Izvještaj koji dobiješ iskopiraj ovde u poruci.
Korak 2
Ponovo pokreni OTL, klikni na Run Scan i postavi novi OTL izvještaj.
|
|
|
|
|
|
Poslao: 24 Jun 2012 22:42
|
offline
- Dusan.cz
![Male](https://www.mycity.rs/templates/simplified/images2/user-sex.gif)
- Počasni građanin
- Pridružio: 18 Jun 2012
- Poruke: 986
|
To sam odradio i sve je ok
Hvala na pomoci
Da li mislis da bi bolje radio kada se reinstalira?
Koji OS bi mi preporucio?
I preko kog programa mogu da ti posaljem koje sve programe imam na kopmu? Posto imam dosta stvari koje mi nicemu ne sluze ali neznam sta ne smem da brisem de ne bi oborio sistem
|
|
|
|
|