C:\Win\lsass.exe

C:\Win\lsass.exe

offline
  • LazaVP 
  • Novi MyCity građanin
  • Pridružio: 16 Jun 2009
  • Poruke: 8

i ja imam isti problem



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:05:25 PM, on 6/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Win\lsass.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Documents and Settings\lazar\reader_s.exe
C:\WINDOWS\system32\3361\services.exe
C:\WINDOWS\DLL\RUNDLL32.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Manson\liser.exe
C:\WINDOWS\system32\sopidkc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\12.tmp
C:\Documents and Settings\lazar\Desktop\New Folder\TR3.exe

F3 - REG:win.ini: load=C:\WINDOWS\system32\msvmf.exe
F3 - REG:win.ini: run=C:\WINDOWS\system32\mshhgsut.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [reader_s] C:\Documents and Settings\lazar\reader_s.exe
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\mszfobu.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: Y'z Shadow.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: c:\progra~1\Manson\liser.dll
O20 - Winlogon Notify: unzdxp - C:\WINDOWS\SYSTEM32\unzdxp.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Dhcp server (DhcpSrv) - Unknown owner - C:\WINDOWS\DLL\RUNDLL32.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: mxfjxrtus435tiksr5735dghdsgwy80 - Unknown owner - C:\WINDOWS\mxfjxrtus435tiksr5735dghdsgwy81.exe
O23 - Service: sopidkc Service (sopidkc) - Elecard Lt - C:\WINDOWS\system32\sopidkc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 4464 bytes



offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Pozdrav...


Upload-uj file: C:\WINDOWS\System32\reader_s.exe

preko ovg linka: [Link mogu videti samo ulogovani korisnici]



offline
  • LazaVP 
  • Novi MyCity građanin
  • Pridružio: 16 Jun 2009
  • Poruke: 8

pozz
nemam taj file!!!

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

Hajdemo ovako (da ne gubimo vreme ni ti ni ja)...

Ovaj kompjuter je prepun malware-a. Između ostaloga, Virut virus je prisutan.

Ovde ništa ne možemo uraditi. Potrebno je da formatiraš sistemsku particiju (C: disk) i instaliraš Windows. Odmah nakon toga treba da skeniraš sve preostale diskove (ako postoje) kako bi očistio file-ove inficirane virusom.

Inače, poželjno je da koristiš antivirus program kako ne bi dolazio u ovakve situacije.

Ko je trenutno na forumu
 

Ukupno su 1336 korisnika na forumu :: 66 registrovanih, 7 sakrivenih i 1263 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 4thFlavian, A.R.Chafee.Jr., alke12, Apis Dr, Apok, bigvlada, BOXRR, d.arsenal321, dejan1972, Dioniss, Doca, DonRumataEstorski, Dzoni2412, engel, goxin, Hamo77, Herman Terrance Aubrey, herrDule, HogarStrashni, Ikica977, Jaxupa, Jeremiah, Još malo pa deda, Kole1975, lanishtefm, lord sir giga, marre, mean_machine, Medojed, Miler88, Mili026, milos.cbr, mrgud2025, mrm, MrNo, nebidrag, nesa1962, neutrino, NklJov123, nobutado, orfanel, Oscar2, pablojepao, Parker, pein, Perudin_92, pisac12, proka89, raptorsi, Ray1973, SamoGledam, sap, Sir Budimir, Srpska zauvjek, stingD, Toper, tritonus, troki1971, Tumansky, UncleSAM, vathra, VBoss, Velizar Laro, VJ, vlad4, Vlada78