pomoc oko trojanca

2

pomoc oko trojanca

offline
  • Pridružio: 18 Apr 2009
  • Poruke: 34

Napisano: 20 Apr 2009 20:23

da iskljucim avast

Dopuna: 21 Apr 2009 3:07

mycity.rs/must-login.png

mycity.rs/must-login.png

mycity.rs/must-login.png

Dopuna: 21 Apr 2009 13:11

odradio sam ponovo al mislim da je isto

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ažuriraj a-squared i ponovi skeniranje.
Da li još uvek detektuje isto?

offline
  • Pridružio: 18 Apr 2009
  • Poruke: 34

Napisano: 23 Apr 2009 15:43

evo napokon je zavrsio
-----------------------------------------------------------------------------------------
mycity.rs/must-login.png

Dopuna: 23 Apr 2009 15:47

problem je sto kad pustim da mi skenira sistem imam opcije hocu li Quick,Smart,Deep ili Custom,i rezultati su uvek razliciti.Ovo sto sam upload-ovao je Deep

Dopuna: 23 Apr 2009 16:09

a-squared Free - Version 4.0
Last update: 21.4.2009 23:14:33

Scan settings:

Objects: Memory, Traces, Cookies, C:\, E:\, F:\
Scan archives: On
Heuristics: Off
ADS Scan: On

Scan start: 22.4.2009 14:46:46

c:\documents and settings\vuk\application data\bsplayer pro detected: Trace.Directory.BSplayer!A2
c:\documents and settings\vuk\application data\bsplayer pro\bsplayer.xml detected: Trace.File.BSplayer!A2
Value: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\Software\BST\bsplayerv1 --> AppPath detected: Trace.Registry.BSplayer!A2
Value: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\Software\BST\bsplayerv1 --> AppVer detected: Trace.Registry.BSplayer!A2
Key: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\software\kazaa detected: Trace.Registry.KaZaA!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:25 detected: Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:73 detected: Trace.TrackingCookie.ad.httpool.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:102 detected: Trace.TrackingCookie.www6.addfreestats.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:112 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:119 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:120 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:128 detected: Trace.TrackingCookie.www.burstnet.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:133 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:134 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:135 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:136 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:137 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:190 detected: Trace.TrackingCookie.media!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:193 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:194 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:195 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:296 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:297 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:298 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:321 detected: Trace.TrackingCookie.statse.webtrendslive!A2
C:\Documents and Settings\vuk\Desktop\New Folder\gmer.exe detected: Trojan.Win32.Agent!IK
C:\Documents and Settings\vuk\Local Settings\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\Cache\3594E876d01/gmer.exe detected: Trojan.Win32.Agent!IK
C:\System Volume Information\_restore{28EF7E52-A297-4ED3-8E57-8DBF6E5D26A4}\RP12\A0004847.exe detected: Riskware.RiskTool.Win32.Reboot.f!A2
E:\Gotovo\CyberLink.PowerDVD.Deluxe.v9.0.1428.Multilingual.Incl.Keymaker-CORE\keygen.exe detected: Trojan.Generic!IK
E:\Gotovo\Popcap Games\alchemy\alchemy.deluxe.1.2.keygen-tsrh.exe detected: Riskware.Keygen.AlchemyDeluxe!IK
E:\Gotovo\Popcap Games\atomica\atomica.deluxe.2.52.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\big money\big.money.deluxe.1.22.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\bookworm\bookworm.deluxe.1.0.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\mummy maze\mummy.maze.deluxe.1.1.keygen-tsrh.exe detected: Riskware.Keygen.MMazze!IK
E:\Gotovo\Popcap Games\naoh`s ark\noah.s.ark.deluxe.1.1.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\ningpo\ningpo.mahjong.deluxe.1.04.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\rocket mania\rocket.mania.deluxe.1.0.keygen-tsrh.exe detected: Gen.Trojan!IK
E:\Gotovo\Popcap Games\seven-seas\seven.seas.deluxe.1.13.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\tiptop\tiptop.deluxe.1.1.keygen-tsrh.exe detected: P2P-Worm.Win32.SpyBot.gl!IK
E:\Gotovo\Popcap Games\typershark\typer.shark.deluxe.1.0.keygen-tsrh.exe detected: Riskware.Keygen.HyperShark!IK
F:\New Folder\novi programi\AVAST\Avast.Pro.v4.8.1227.Incl.Keymaker-CORE.rar/keygen.exe detected: Riskware.Keygen.Avast!IK
F:\New Folder\novi programi\Avast.Professional.v4.7.1098.Incl.KeyMaker-DVT.rar/KeyMaker.exe detected: Riskware.Keygen.AvastPro!IK
F:\New Folder\novi programi\NOD32\NOD32_v3_FiX_1.1-TemDono.exe detected: Riskware.Patch.ESET!IK
F:\New Folder\novi programi\Programi za VIZITKE\New Folder\Business_Card_Designer_Plus_v7.1.1.0.zip/bcdp_keymaker.exe detected: Riskware.Hacktool.Keygen.bcdP!IK
F:\New Folder\novi programi\Tune up utilities 2007\keygen.exe detected: Riskware.Keygen.TuneUP!IK
F:\New Folder\novi programi\YoutubeGet_v4.9.7_WinAll_Regged_-_CRD\Setup\Setup\yg.exe detected: Backdoor.Hupigon!IK
F:\New Folder\PROGRAMI\Antivirusi\NOD32 Complete 2008\Antivirus\Nod32Patch.exe detected: Riskware.Hacktool.Patch.NOD32!IK
F:\New Folder\PROGRAMI\CORE-TuneUp.2008.v7.0\TuneUp.Utilities.2008.v7.0.8007.Keymaker.Only-CORE\keygen.exe detected: Riskware.Hacktool.Keygen.tuneup2008!IK
F:\New Folder\PROGRAMI\Your Uninstaller 2008 PRO v6.1.1236\(zabranjeno)\Keygen.exe detected: Riskware.keygen.UninstallerPro!IK
F:\New Folder\PROGRAMI\youruninstaler\youruninstaler 2008\Keygen.rar/Keygen.exe detected: Riskware.keygen.UninstallerPro!IK
F:\System Volume Information\_restore{6F058938-D7F6-48B5-B749-5EE723C18168}\RP2\A0001793.EXE detected: Virus.W32.Sality!IK
F:\System Volume Information\_restore{6F058938-D7F6-48B5-B749-5EE723C18168}\RP2\A0001794.exe detected: W32.Sality!IK
F:\System Volume Information\_restore{6F058938-D7F6-48B5-B749-5EE723C18168}\RP2\A0001816.exe detected: Virus.Win32.Sality!IK
F:\System Volume Information\_restore{6F058938-D7F6-48B5-B749-5EE723C18168}\RP2\A0001817.exe detected: Virus.Win32.Sality!IK
F:\System Volume Information\_restore{6F058938-D7F6-48B5-B749-5EE723C18168}\RP2\A0001818.exe detected: Virus.Win32.Sality!IK

Scanned

Files: 48355
Traces: 591375
Cookies: 396
Processes: 28

Found

Files: 30
Traces: 5
Cookies: 22
Processes: 0
Registry keys: 0

Scan end: 22.4.2009 22:21:05
Scan time: 7:34:19

Dopuna: 23 Apr 2009 18:27

ovo je Smart
-----------------------------------------------------------------------------------------

Dopuna: 23 Apr 2009 18:41

mycity.rs/must-login.png

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Arrow Preuzmi CatchMe.

Dvoklikom pokreni catchme.exe i pređi na Script tab.
U (beli) prozor programa iskopiraj tekst koji se nalazi unutar kod polja:

files:
C:\WINDOWS\system32\KERNEL32.dll
c:\windows\system32\dmserver.dll
c:\windows\system32\wuauserv.dll


Klikni na taster Run.

Kada se pojavi poruka sa obaveštenjem, kliknuti OK.


Po završetku procesa, na Desktopu će se nalaziti file catchme.zip.
Uploaduj ga preko sledeće forme: http://www.mycity.rs/ambulanta-upload.php



-------------------------------------------------------------------------------------



Arrow Za ovaj korak može ti biti potreban Windows Setup CD.

Klikni Start, zatim Run. Ukucaj sledeće:

SFC /SCANNOW

i pritisni Enter.


Po završetku procesa, ponovi skeniranje a2-om. Potrebno je da odradiš skeniranje koje je dalo rezultate kao u ovom post-u:
http://www.mycity.rs/Ambulanta/pomoc-oko-trojanca.html#907035

Prvenstveno su bitne te prve detekcije (linije koje započinju sa ''['')

offline
  • Pridružio: 18 Apr 2009
  • Poruke: 34

Upload-ovao sam zip file


-----------------------------------------------------------------------------------------


a-squared Free - Version 4.0
Last update: 24.4.2009 22:47:50

Scan settings:

Objects: Memory, Traces, Cookies, C:\WINDOWS\, C:\Program Files
Scan archives: On
Heuristics: Off
ADS Scan: On

Scan start: 24.4.2009 22:53:15

c:\documents and settings\vuk\application data\bsplayer pro detected: Trace.Directory.BSplayer!A2
c:\documents and settings\vuk\application data\bsplayer pro\bsplayer.xml detected: Trace.File.BSplayer!A2
Value: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\Software\BST\bsplayerv1 --> AppPath detected: Trace.Registry.BSplayer!A2
Value: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\Software\BST\bsplayerv1 --> AppVer detected: Trace.Registry.BSplayer!A2
Key: HKEY_USERS\S-1-5-21-1078081533-1580818891-854245398-1003\software\kazaa detected: Trace.Registry.KaZaA!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:28 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:29 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:30 detected: Trace.TrackingCookie.ad.yieldmanager.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:50 detected: Trace.TrackingCookie.ad.httpool.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:53 detected: Trace.TrackingCookie.doubleclick.net!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:136 detected: Trace.TrackingCookie.www6.addfreestats.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:146 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:153 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:154 detected: Trace.TrackingCookie.casalemedia.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:162 detected: Trace.TrackingCookie.www.burstnet.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:165 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:166 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:167 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:168 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:169 detected: Trace.TrackingCookie.tribalfusion.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:210 detected: Trace.TrackingCookie.media!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:303 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:304 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:305 detected: Trace.TrackingCookie.zedo.com!A2
C:\Documents and Settings\vuk\Application Data\Mozilla\Firefox\Profiles\d83s4qwv.default\cookies.txt:328 detected: Trace.TrackingCookie.statse.webtrendslive!A2

Scanned

Files: 29056
Traces: 595827
Cookies: 402
Processes: 29

Found

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Ovo bi trebalo biti čisto.

To što a2 detektuje bi trebalo da možeš ukloniti bez ikakvih problema (gomila cookie-ja i reference prema BSPlayer-u i Kazaa-i).

offline
  • Pridružio: 18 Apr 2009
  • Poruke: 34

Valjda je gotovo,hvala doco!

Ko je trenutno na forumu
 

Ukupno su 1052 korisnika na forumu :: 29 registrovanih, 3 sakrivenih i 1020 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airsuba, ajo baba, Ben Roj, bojank, cavatina, cenejac111, Denaya, Dorcolac, indja, ivica976, Jakov01, jukeboxer, Lucije Kvint, mercedesamg, milos.cbr, nebkv, nenad81, oldtimer, operniki, panzerwaffe, procesor, Romibrat, Sirius, stankolich, Tvrtko I, VJ, vukovi, 1107, 223223