Virusi - komp zablokirao

2

Virusi - komp zablokirao

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Napisano: 27 Jun 2009 21:09

Ne mogu da ga pokrenem, jedino da uradim preko safe moda i sa Hijack Thisom- ako moze.

Dopuna: 27 Jun 2009 21:28

[Link mogu videti samo ulogovani korisnici]

Evo preko safe moda sta sam dobio sa Hijack Thisom-tu je izvestaj

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:21:06, on 27.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 191.192.59.33 anubis.iseclab.org
O1 - Hosts: 130.61.228.180 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 253.234.138.98 threatexpert.com
O1 - Hosts: 17.59.9.63 cwsandbox.org
O1 - Hosts: 252.243.134.189 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 111.87.4.51 u20.eset.com
O1 - Hosts: 37.157.120.122 u21.eset.com
O1 - Hosts: 205.133.17.231 u22.eset.com
O1 - Hosts: 46.122.233.228 u23.eset.com
O1 - Hosts: 46.142.212.218 u24.eset.com
O1 - Hosts: 77.100.124.93 u30.eset.com
O1 - Hosts: 161.39.128.31 u31.eset.com
O1 - Hosts: 115.188.84.50 u32.eset.com
O1 - Hosts: 6.88.129.33 u33.eset.com
O1 - Hosts: 29.252.20.77 u34.eset.com
O1 - Hosts: 100.57.201.190 u35.eset.com
O1 - Hosts: 49.147.100.177 u36.eset.com
O1 - Hosts: 211.245.27.41 u37.eset.com
O1 - Hosts: 107.151.148.70 u38.eset.com
O1 - Hosts: 111.169.111.29 u39.eset.com
O1 - Hosts: 96.74.61.112 u40.eset.com
O1 - Hosts: 221.6.232.223 u41.eset.com
O1 - Hosts: 8.100.128.134 u42.eset.com
O1 - Hosts: 105.76.83.28 u43.eset.com
O1 - Hosts: 222.185.209.7 u44.eset.com
O1 - Hosts: 36.149.183.128 u45.eset.com
O1 - Hosts: 16.39.82.40 u46.eset.com
O1 - Hosts: 157.106.0.183 u47.eset.com
O1 - Hosts: 187.210.56.48 u48.eset.com
O1 - Hosts: 171.46.169.170 u49.eset.com
O1 - Hosts: 61.193.206.169 f-secure.com
O1 - Hosts: 193.211.5.151 symantec.com
O1 - Hosts: 15.176.250.213 127.99.45.207
O1 - Hosts: 212.231.10.242 virusscan.jotti.org
O1 - Hosts: 53.201.215.2 download.ahnlab.com
O1 - Hosts: 81.106.187.159 msn.ahnlab.com
O1 - Hosts: 192.37.98.159 acc.pdbox.co.kr
O1 - Hosts: 166.117.152.112 pcsafe.hanafos.com
O1 - Hosts: 89.149.180.48 viruschaser.com
O1 - Hosts: 85.182.158.126 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 223.205.77.132 info.ahnlab.com
O1 - Hosts: 159.57.91.75 v.chol.com
O1 - Hosts: 24.76.108.199 securitycenter.co.kr
O1 - Hosts: 55.120.147.187 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 237.32.123.92 sandbox.norman.com
O1 - Hosts: 137.81.237.210 norman.com
O1 - Hosts: 60.118.138.134 sandbox.norman.no
O1 - Hosts: 145.177.63.78 norman.no
O1 - Hosts: 177.250.92.236 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 194.169.211.6 kaspersky.pl
O1 - Hosts: 187.140.250.223 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 252.60.88.36 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 6.183.102.123 kaspersky.telechargement.fr
O1 - Hosts: 20.140.198.41 kaspersky.de
O1 - Hosts: 229.212.110.59 kaspersky.co.nz
O1 - Hosts: 170.183.93.93 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 254.175.4.209 kaspersky-antivirus.dk
O1 - Hosts: 101.126.146.38 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 85.174.67.40 kaspersky-me.com
O1 - Hosts: 18.117.43.133 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 11.198.34.251 kaspersky.co.uk
O1 - Hosts: 171.20.31.157 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 199.130.148.45 kaspersky.com.au
O1 - Hosts: 179.148.169.23 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 154.18.220.21 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 160.169.101.104 kasperskyusa.com
O1 - Hosts: 119.29.238.199 agnitum.com
O1 - Hosts: 219.116.118.116 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 54.240.101.141 smb.sygate.com
O1 - Hosts: 203.95.66.124 vic.zonelabs.com
O1 - Hosts: 175.115.126.191 download.zonelabs.com
O1 - Hosts: 121.58.191.80 zonelabs.com
O1 - Hosts: 222.238.180.103 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 186.167.75.233 freebyte.com
O1 - Hosts: 156.43.92.184 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 241.101.24.187 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 223.84.89.204 bitdefender.com
O1 - Hosts: 219.85.161.102 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 154.51.94.65 virus-radar.com
O1 - Hosts: 236.224.65.180 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 26.55.198.22 nod32.com
O1 - Hosts: 197.170.191.225 avg-antivirus.net
O1 - Hosts: 133.204.236.227 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 168.141.3.60 antivirus.about.com
O1 - Hosts: 216.10.168.225 vet.com.au
O1 - Hosts: 142.236.201.142 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 136.160.201.54 avgbulgaria.com
O1 - Hosts: 196.87.243.223 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 30.46.176.160 windowsupdate.microsoft.com
O1 - Hosts: 23.115.95.251 update.microsoft.com
O1 - Hosts: 114.76.232.232 virusbtn.com
O1 - Hosts: 22.68.207.79 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 243.129.228.39 drsolomon.com
O1 - Hosts: 221.181.234.26 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 254.241.185.86 teamanti-virus.org
O1 - Hosts: 247.128.67.102 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 63.110.117.187 virustotal.com
O1 - Hosts: 75.90.111.86 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 44.72.124.151 microsoft.com
O1 - Hosts: 150.116.186.65 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 5.78.218.32 cert.org
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - [Link mogu videti samo ulogovani korisnici]\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 9507 bytes



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Pokreni HJT ponovo, stikliraj kvadratice pored sledecih linija:

O1 - Hosts: 191.192.59.33 anubis.iseclab.org
O1 - Hosts: 130.61.228.180 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 253.234.138.98 threatexpert.com
O1 - Hosts: 17.59.9.63 cwsandbox.org
O1 - Hosts: 252.243.134.189 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 111.87.4.51 u20.eset.com
O1 - Hosts: 37.157.120.122 u21.eset.com
O1 - Hosts: 205.133.17.231 u22.eset.com
O1 - Hosts: 46.122.233.228 u23.eset.com
O1 - Hosts: 46.142.212.218 u24.eset.com
O1 - Hosts: 77.100.124.93 u30.eset.com
O1 - Hosts: 161.39.128.31 u31.eset.com
O1 - Hosts: 115.188.84.50 u32.eset.com
O1 - Hosts: 6.88.129.33 u33.eset.com
O1 - Hosts: 29.252.20.77 u34.eset.com
O1 - Hosts: 100.57.201.190 u35.eset.com
O1 - Hosts: 49.147.100.177 u36.eset.com
O1 - Hosts: 211.245.27.41 u37.eset.com
O1 - Hosts: 107.151.148.70 u38.eset.com
O1 - Hosts: 111.169.111.29 u39.eset.com
O1 - Hosts: 96.74.61.112 u40.eset.com
O1 - Hosts: 221.6.232.223 u41.eset.com
O1 - Hosts: 8.100.128.134 u42.eset.com
O1 - Hosts: 105.76.83.28 u43.eset.com
O1 - Hosts: 222.185.209.7 u44.eset.com
O1 - Hosts: 36.149.183.128 u45.eset.com
O1 - Hosts: 16.39.82.40 u46.eset.com
O1 - Hosts: 157.106.0.183 u47.eset.com
O1 - Hosts: 187.210.56.48 u48.eset.com
O1 - Hosts: 171.46.169.170 u49.eset.com
O1 - Hosts: 61.193.206.169 f-secure.com
O1 - Hosts: 193.211.5.151 symantec.com
O1 - Hosts: 15.176.250.213 127.99.45.207
O1 - Hosts: 212.231.10.242 virusscan.jotti.org
O1 - Hosts: 53.201.215.2 download.ahnlab.com
O1 - Hosts: 81.106.187.159 msn.ahnlab.com
O1 - Hosts: 192.37.98.159 acc.pdbox.co.kr
O1 - Hosts: 166.117.152.112 pcsafe.hanafos.com
O1 - Hosts: 89.149.180.48 viruschaser.com
O1 - Hosts: 85.182.158.126 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 223.205.77.132 info.ahnlab.com
O1 - Hosts: 159.57.91.75 v.chol.com
O1 - Hosts: 24.76.108.199 securitycenter.co.kr
O1 - Hosts: 55.120.147.187 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 237.32.123.92 sandbox.norman.com
O1 - Hosts: 137.81.237.210 norman.com
O1 - Hosts: 60.118.138.134 sandbox.norman.no
O1 - Hosts: 145.177.63.78 norman.no
O1 - Hosts: 177.250.92.236 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 194.169.211.6 kaspersky.pl
O1 - Hosts: 187.140.250.223 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 252.60.88.36 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 6.183.102.123 kaspersky.telechargement.fr
O1 - Hosts: 20.140.198.41 kaspersky.de
O1 - Hosts: 229.212.110.59 kaspersky.co.nz
O1 - Hosts: 170.183.93.93 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 254.175.4.209 kaspersky-antivirus.dk
O1 - Hosts: 101.126.146.38 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 85.174.67.40 kaspersky-me.com
O1 - Hosts: 18.117.43.133 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 11.198.34.251 kaspersky.co.uk
O1 - Hosts: 171.20.31.157 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 199.130.148.45 kaspersky.com.au
O1 - Hosts: 179.148.169.23 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 154.18.220.21 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 160.169.101.104 kasperskyusa.com
O1 - Hosts: 119.29.238.199 agnitum.com
O1 - Hosts: 219.116.118.116 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 54.240.101.141 smb.sygate.com
O1 - Hosts: 203.95.66.124 vic.zonelabs.com
O1 - Hosts: 175.115.126.191 download.zonelabs.com
O1 - Hosts: 121.58.191.80 zonelabs.com
O1 - Hosts: 222.238.180.103 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 186.167.75.233 freebyte.com
O1 - Hosts: 156.43.92.184 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 241.101.24.187 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 223.84.89.204 bitdefender.com
O1 - Hosts: 219.85.161.102 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 154.51.94.65 virus-radar.com
O1 - Hosts: 236.224.65.180 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 26.55.198.22 nod32.com
O1 - Hosts: 197.170.191.225 avg-antivirus.net
O1 - Hosts: 133.204.236.227 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 168.141.3.60 antivirus.about.com
O1 - Hosts: 216.10.168.225 vet.com.au
O1 - Hosts: 142.236.201.142 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 136.160.201.54 avgbulgaria.com
O1 - Hosts: 196.87.243.223 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 30.46.176.160 windowsupdate.microsoft.com
O1 - Hosts: 23.115.95.251 update.microsoft.com
O1 - Hosts: 114.76.232.232 virusbtn.com
O1 - Hosts: 22.68.207.79 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 243.129.228.39 drsolomon.com
O1 - Hosts: 221.181.234.26 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 254.241.185.86 teamanti-virus.org
O1 - Hosts: 247.128.67.102 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 63.110.117.187 virustotal.com
O1 - Hosts: 75.90.111.86 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 44.72.124.151 microsoft.com
O1 - Hosts: 150.116.186.65 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 5.78.218.32 cert.org


i klikni FIX CHECKED pa mi postavi novi log.



offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Uradio sam i to pa pogledaj
[Link mogu videti samo ulogovani korisnici]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:23, on 28.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 88.99.250.80 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 16.221.14.52 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 186.174.95.178 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 246.222.19.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 65.230.118.207 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 69.57.192.16 [Link mogu videti samo ulogovani korisnici]
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - [Link mogu videti samo ulogovani korisnici]\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 8670 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Slabo napredujemo, ali imaj nade Wink

I sledeci put mi ovde kopiraj/nalepi log, nemoj ga uploadovati.

Pokreni HJT, skeniraj i stikliraj sledece kvadratice:

O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 88.99.250.80 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 16.221.14.52 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 186.174.95.178 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 246.222.19.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 65.230.118.207 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 69.57.192.16 [Link mogu videti samo ulogovani korisnici]
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Klikni FIX checked.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

ne mogu da ga prekopiram ovde zato sto ja ne mogu nista da otvorim u kompu osim interneta,a sa HJT radim u safe modu, pa posto restartujem komp ja ti samo uploadujem log ne znam da li tako odgovara da nastavim i sa ovim ili sta vec da radim?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Onda tako nastavi uz malu ispravku:

Skini program sa ovog sajta: [Link mogu videti samo ulogovani korisnici]

Pokreni HostsXpert

Klikni na Restore MS Hosts File pa Ok
Zatim klikni na Make Writable (ako je dostupan)
Zatvori program.

---------
Onda pokreni HJT i stikliraj sledece linije:

O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Klikni FIX checked.

i postavi mi log kako mozes.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Sa HostXpert-om nisam uspeo nista uraditi nisam imao nigde ikonice za restore ms Host File a na Make Writable je zakljucan.

Uradio sam ovo sa HJT
[Link mogu videti samo ulogovani korisnici]

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:53, on 28.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 88.99.250.80 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 16.221.14.52 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 186.174.95.178 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 246.222.19.250 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 65.230.118.207 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 [Link mogu videti samo ulogovani korisnici]
O1 - Hosts: 69.57.192.16 [Link mogu videti samo ulogovani korisnici]
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - [Link mogu videti samo ulogovani korisnici]\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 8141 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Hajde sada probaj da skeniras u Normal modu sa HJT-om, RSIT-om.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Napisano: 28 Jun 2009 12:55

Ne mogu nista u Normal modu da uradim.

Dopuna: 28 Jun 2009 13:05

Hoces da u safe modu uradim sa RSIT

Sta sam ja ovo pokupio, kakav je ovo virus?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8620
  • Gde živiš: Novi Beograd

Ovo skeniranje isto obavi u Safe Modu:

Preuzmi sUBs-ov ComboFix sa jedne od sledećih adresa na Desktop:


Bleeping Computer . . . . . Geeks to Go!
Klikni desnim tasterom na neki od linkova i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
zatvori pokrenute programe;
deaktiviraj zaštitni softver (uputstvo);
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

Ko je trenutno na forumu
 

Ukupno su 1110 korisnika na forumu :: 93 registrovanih, 11 sakrivenih i 1006 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 015, _Rade, acov34, Areal84, arezina, Asteker, Avalon015, Azzo, Ba4e, babaroga, Banovo Brdo, bojan581, boromir, Bosnjo, bpvl, Centauro, Cian, Clouseau, cyprus, daedal, debeli, Dioniss, Dorcolac, dozorni, dukajov, Dzoni2412, Feller, GAGI, GeoM, Gogi_avio, Goran_, icemilos, Inner-Cell, ivan1973, ivan_8282, Jonbonjovi, JosipRi, Još malo pa deda, Kawasaki1000, Kobrim, Kubovac, kunktator, kuntalo, Lester Freamon, Lucije Kvint, M74AB3, Mackomen, Malahit, markolopin, marsovac 2, Miki 24pbr, miki kv, Milan A. Nikolic, milenko crazy north, milutin134, mm1811, neutrino, Nobunaga, nobutado, Novakomp, novator, Parker, pisac12, PlayerOne, Povratak1912, predragc, PrincipL, proka89, RAKITNICA, raptorsi, repac, Ripanjac, Sagotolio, Shadow soldier, sixpac, Srki98, Srle993, stankolich, stokssone, tehnika, tomigun, Trpe Grozni, Tunguska55, ujke, vathra, Vatreni Zmaj, voja64, vuksa72, W123, XBMC, yiyi, YugoSlav, zmajbre