Kako da uklonim ovaj virus

poruka: 23
|
čitano: 4.359
|
moderatori: pirat, XXX-Man, vincimus
1
+/- sve poruke
ravni prikaz
starije poruke gore
15 godina
neaktivan
offline
Kako da uklonim ovaj virus

evo opet mi se pojavio ovaj

virus, zadnji put sam

rušio windows

i love my peaunt

dali ima neki jednostavan program da 

ga maknem

rappy
Moj PC  
0 0 hvala 0
16 godina
offline
Kako da uklonim ovaj virus
Moj PC  
0 0 hvala 0
15 godina
neaktivan
offline
Re: Kako da uklonim ovaj virus

ma gledo sam to ali ne 

kužim k. . . 

kako da to uradim

 

rappy
16 godina
neaktivan
offline
Kako da uklonim ovaj virus

S kojim si ga do sada programima pokušao ukloniti? Kada si rušio winse da li su ti ostale nedirnute ostale particije?

http://www.youtube.com/watch?v=ZEB3JG4T72Q&feature=related
 
0 0 hvala 0
15 godina
neaktivan
offline
Re: Kako da uklonim ovaj virus

pa srušio sam windowse

i onda ga nije bilo i sad

opet, imam još dvije particije 

na koje sumnjam da se skriva

 a ne mogu formatirat te 

particije jer imam 500gb podataka koji 

su mi važni i trebaju mi.

rappy
17 godina
online
Kako da uklonim ovaj virus

Evo sa foruma na PCEkspertu:

 

Eeeeee to sam i ja imao! Isto se pojavio nakon friške instalacije OS-a, mislim da sam ga pokupio preko USB sticka ipak. To ti je neki trojan kojega sam jedva priklao uz pomoć frenda koji se malo bolje kuži u takve stvari. Nakon nekog vremena uopće nisam mogao otvarati particiju kad bih kliknuo na nju nego bi izbacivao neki error. Uglavnom, problem je riješio Malwarebytes' Anti-malware i manualno klanje trojanca preko DOS prompta, jedino tako jer bi se konvencionalnim traženjem ponovno oživljavao, bio je skriven u root file-u. Dakle prvo nađi tu njegovu autorun datoteku u DOS promptu i izbriši ju manualno pa onda skeniras i prikolji kikirikija do kraja sa Malwarebytes'-om.

Jednom ću biti toliko bogat da ću otvoriti jogurt i ne polizati poklopac!
Moj PC  
1 0 hvala 1
17 godina
online
Kako da uklonim ovaj virus

Evo jos par citata sa PcEksper foruma:

 

  • USPJEŠNO riješeno,išao sam preko cmd-a,našao autorun.info u D,izbrisao,restarto, i to je to. Svaka čast majstore,hvala.
  • Combofix sve rijesava u kombinaciji s malwarebyte-om.Za svaki slucaj u safe mode i pogasit system restore

 

Znaci samo pogledas ovaj dio: ->

Citiraj:

Follow the set of commands below to show and delete the autorun.inf

1. Open Start>>Run and type cmd and press enter. This will open a command prompt window. On this command prompt window type the following steps.

2. napises tu D: ( i otvori ti D particiju) onda ovako izgleda "D:\>" i onda dalje ides ovo ispod..

3. type attrib -r -h -s autorun.inf

4. type del autorun.inf

Restart your system and your trouble will be fixed.

 

-------------------------------------------------------------------------

 

BTW: koji antivirus si imao/imas?

Jednom ću biti toliko bogat da ću otvoriti jogurt i ne polizati poklopac!
Poruka je uređivana zadnji put sri 15.6.2011 0:00 (djigibao).
Moj PC  
0 0 hvala 0
15 godina
neaktivan
offline
Kako da uklonim ovaj virus

imam aviru, ali evo našo sam

mapu iz koje se je pokrećo

i izbriso je 

sa unlocker

rappy
Moj PC  
0 0 hvala 0
17 godina
online
Re: Kako da uklonim ovaj virus
Mislis da je sad sve cisto?
Provjeri jos jednom sa MBAM-om (full scan) i sa HitmanPRO i sa Superantispywerom (full scan) da budes totalno siguran.
...mogao bi razmislit i o promjeni free antivirusa (Aviri) i stavit neki drugi (Avast, Panda Cloud...).
Jednom ću biti toliko bogat da ću otvoriti jogurt i ne polizati poklopac!
15 godina
neaktivan
offline
Re: Kako da uklonim ovaj virus

Išo sam sa MBAM-OM I ćisto

je jer sam izbriso ga i više

nema onog da se pojavljuje

a što se tiče antivirusa,

avira je ok, jer prijatelj

mi ima avast a od njega sam

pokupio taj virus 

sa prijenosnog hard diska

i njemu je isto se bilo

tako pojavilo kao kod

 mene. imam kaspersky 2011

koji sam kupio,

ali mi je onda komp

usporen šou, da ne mogu 

ništa radit. neznam zašto

 

 

rappy
14 godina
protjeran
offline
Kako da uklonim ovaj virus

Evo problemcica!

Prilikom svakoga pokretanja Firefoxa dobijam Avast poruku o zarazenosti Firefoxa?

Pretrazivac radi ali usporeno!

Scan sam obavio sa Avastom,SAS i MAM-om sve clean!

Mamutu mi nista nije javljao IKADA od kada ga imam!

Jedini problemcic koji imam vec dugo je taj da Qtorrent nikako ne mogu ukloniti kao startup program

(evo opet Avast poruka kada sam linkao ovo gore)

 

DaBog da se prevrnula na me,prikolica puna pica!
Moj PC  
0 0 hvala 0
16 godina
offline
Re: Kako da uklonim ovaj virus
Godfahter kaže...

Evo problemcica!

Prilikom svakoga pokretanja Firefoxa dobijam Avast poruku o zarazenosti Firefoxa?

Pretrazivac radi ali usporeno!

Scan sam obavio sa Avastom,SAS i MAM-om sve clean!

Mamutu mi nista nije javljao IKADA od kada ga imam!

Jedini problemcic koji imam vec dugo je taj da Qtorrent nikako ne mogu ukloniti kao startup program

(evo opet Avast poruka kada sam linkao ovo gore)

 

  Vidiš koju adresu avast blokira? my-trusted-content itd...

Dakle nešto iz firefoxa se spaja na tu stranicu. E sad možda je neki toolbar ili neka ekstenzija. Možda se nešto sakrilo u hosts file, provjeri to.

R.I.P. EnlightenedPhoenix 24.6.2011.
16 godina
neaktivan
offline
Kako da uklonim ovaj virus

daj ako hoćeš log od hijackthisa ovdje(copy/paste),možda se riješi i taj strartup problem

Moj PC  
0 0 hvala 1
14 godina
protjeran
offline
Re: Kako da uklonim ovaj virus
mind_challenge kaže..

  Vidiš koju adresu avast blokira? my-trusted-content itd...

Dakle nešto iz firefoxa se spaja na tu stranicu. E sad možda je neki toolbar ili neka ekstenzija. Možda se nešto sakrilo u hosts file, provjeri to.

Nista nisam pronasao,osim Qtorrent toolbara,ali on mi je uvjek bio OK!

seneka kaže...

daj ako hoćeš log od hijackthisa ovdje(copy/paste),možda se riješi i taj strartup problem

Nakon par upozorenja i errora(prilikom otvaranja hijackthisa) evo poduzeg loga:

 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:05:12, on 1.7.2011.
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Mamutu\mamutu.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\SysWOW64\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [Mamutu Guard] "C:\PROGRAM FILES (X86)\MAMUTU\mamutu.exe" /silent
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\nvidia corporation\networkaccessmanager\bin32\nvlsp.dll
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @appmgmts.dll,-3250 (AppMgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files (x86)\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\cscsvc.dll,-200 (CscService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\irmon.dll,-2000 (Irmon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\srvsvc.dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wkssvc.dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Mamutu Service (Mamutu) - Emsi Software GmbH - C:\Program Files (x86)\Mamutu\a2service.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\peerdistsvc.dll,-9000 (PeerDistSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SCardSvr.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tapisrv.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: TeamViewer 6 (TeamViewer6) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\umrdp.dll,-1000 (UmRdpService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wcncsvc.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\webclnt.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchIndexer.exe
O23 - Service: @%systemroot%\system32\wuaueng.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe

--
End of file - 20680 bytes

DaBog da se prevrnula na me,prikolica puna pica!
16 godina
neaktivan
offline
Kako da uklonim ovaj virus

ovo možeš odma fixat u hijackthisu:
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
tražim i ne vidim ništa,obrati pažnju na ovo:
C:\Windows\SysWOW64\DllHost.exe

imaš ovu stavku :
 O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
tvoj problem je qtorrent,njega ne vidim

ovdje zalijepi log pa ga analiziraj,pogledaj sam,ako nešto fixaš,hijackthis radi backup,može se vratiti
ove dll-ove označene crveno nemoj brisati,eventualno ih proguglaj

i daj ga proskeniraj još s ovim,ne moraš ga instalirati

Poruka je uređivana zadnji put pet 1.7.2011 12:56 (seneka).
Moj PC  
0 0 hvala 1
14 godina
protjeran
offline
Re: Kako da uklonim ovaj virus
seneka kaže...

ovo možeš odma fixat u hijackthisu:
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
tražim i ne vidim ništa,obrati pažnju na ovo:
C:\Windows\SysWOW64\DllHost.exe

imaš ovu stavku :
 O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
tvoj problem je qtorrent,njega ne vidim

ovdje zalijepi log pa ga analiziraj,pogledaj sam,ako nešto fixaš,hijackthis radi backup,može se vratiti
ove dll-ove označene crveno nemoj brisati,eventualno ih proguglaj

i daj ga proskeniraj još s ovim,ne moraš ga instalirati

Fixao sam navedeno!

SysWOW64  -koliko sam googlao sasvim normalna aplikacija za 64 bit OS.

Pod ovdje dobijam ovo(slika)

Scan Hitmanom je nasao hrpu cookiesa,pustio sam da izbrise!

 

Nista od ovoga nije pomoglo,Qtorrent je jos uvjek startup,a Avast jos uvjek vristi na Mozzilu!

 

DaBog da se prevrnula na me,prikolica puna pica!
17 godina
neaktivan
offline
Kako da uklonim ovaj virus

uradi ovako , pa da vidimo o čemu se radi

 
0 0 hvala 1
14 godina
protjeran
offline
Re: Kako da uklonim ovaj virus
total kaže...

uradi ovako , pa da vidimo o čemu se radi

Care odmah fail na pocetku Rouge killera!

Ne mogu ga otvoriti!

DaBog da se prevrnula na me,prikolica puna pica!
17 godina
neaktivan
offline
Kako da uklonim ovaj virus

care preimenuj rouge killer u winlogon.com , isto tako uradi i za OTS za slučaj da se ne može pokreniti

 
0 0 hvala 1
14 godina
protjeran
offline
Re: Kako da uklonim ovaj virus
total kaže...

care preimenuj rouge killer u winlogon.com , isto tako uradi i za OTS za slučaj da se ne može pokreniti

Kakav sam debilius,a fino mi pisalo da preimenujem!

Evo:

http://www.speedyshare.com/files/29249899/log.rar

DaBog da se prevrnula na me,prikolica puna pica!
17 godina
neaktivan
offline
Kako da uklonim ovaj virus

otvori OTS i ovo kopiraj u prazno polje

 

[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-1421505931-943457131-1721380511-1001\] > ->
YN -> HKEY_USERS\S-1-5-21-1421505931-943457131-1721380511-1001\: Main\\"Start Page Redirect Cache_TIMESTAMP" -> 0B 62 1A 3F 08 16 CC 01  [binary data]
< FireFox Extensions [Program Folders] > ->
YN -> No name found ->
< Run [HKEY_USERS\S-1-5-21-1421505931-943457131-1721380511-1001\] > -> HKEY_USERS\S-1-5-21-1421505931-943457131-1721380511-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "ASRockIES" -> []
YN -> "ASRockOCTuner" -> []
YN -> "uTorrent" -> C:\Program Files (x86)\uTorrent\uTorrent.exe ["C:\Program Files (x86)\uTorrent\uTorrent.exe"]
YN -> "zASRockInstantBoot" -> []
< 64bit-SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" [HKLM] -> Reg Error: Key error. [WebCheck]
[Files/Folders - Created Within 30 Days]
NY ->  1 C:\Users\Gothfather\*.tmp files -> C:\Users\Gothfather\*.tmp
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
[ClearAllRestorePoints]

 

klik na RUN FIX

-log koji dobiješ kopiraj

 

sa combofixom ćemo viditi zašto se javlja avast (mislim da je fp)

 

-skini combofix i spremi na desktop, isključi antivirus i pokreni combfix (desni klik mišem na ikonu combofix.exe i odabrati run as administrator)

-na sve što combofix traži odgovri potvrdno

-log koji dobijš kopiraj

 
0 0 hvala 1
14 godina
protjeran
offline
Re: Kako da uklonim ovaj virus
total kaže...

 

klik na RUN FIX

-log koji dobiješ kopiraj

 

sa combofixom ćemo viditi zašto se javlja avast (mislim da je fp)

 

-skini combofix i spremi na desktop, isključi antivirus i pokreni combfix (desni klik mišem na ikonu combofix.exe i odabrati run as administrator)

-na sve što combofix traži odgovri potvrdno

-log koji dobijš kopiraj

E ovako sa opcijom RUN FIX,koliko sam vidio Qtorrent si mi rjesio sa startupa-Kapa dolje!

Combofix mi je radio scan ukupno 5 sati,dosao do neke tocke 4 i nije ni mislio prestati scan,dojadilo mi je i scan sam prekinuo!

Na nagovor dobrog frenda sa foruma,izbrisao sam Avasta i instalirao sam kopiju Nortona internet security 2011(trail 90 dana) i on mi je nasao,

36 komada gamadi,tj jedan koji se duplicirao tzv. Gamemon.des.

Prije sam imao org Nortona i nikada me nije razocarao,te cu svakako sada na sljedecoj placi kupiti orginal-uopce ne znam koji mi vrag bi da instaliram Avasta!

 

U svakom slucaju problem je rjesen-nema virusa,Mozzila leti!

Hvala svima na pomoci!

DaBog da se prevrnula na me,prikolica puna pica!
17 godina
neaktivan
offline
Kako da uklonim ovaj virus

izbriši combofix

start/search/ kopira ovo boldano i potvrdi combofix /uninstall

 

izbriši i OTS >otvori program i klik na clean up

 
0 0 hvala 1
1
Nova poruka
E-mail:
Lozinka:
 
vrh stranice