Facebook problem

1

Facebook problem

offline
  • Pridružio: 14 Dec 2009
  • Poruke: 154

Otvorio sam neki link na facebook-u i od tada samo na taj site ne mogu da udjem.

Ovo je log iz OTL-a:

mycity.rs/must-login.png

Hvala unapred. Ziveli

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Preuzmi HostsXpert - Hosts File Manager.
Raspakuj HostsXpert.zip
Dvoklikom pokreni HostsXpert.exe
Ukoliko je dostupan, klikni na taster Make Writable? u gornjem levom uglu
Klikni na taster Restore MS Hosts File a zatim na taster OK
Zatvori program klikom na X
Napomena: Ukoliko koristiš modifikovani Hosts file, moraćeš željene stavke ponovo uneti




Restartuj racunar. Zatim mi kazi jel mozes da udje na fejs.

offline
  • Pridružio: 14 Dec 2009
  • Poruke: 154

Uspelo je!
Hvala puno!!

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix;
u prozoru koji se otvori klikni "I Agree".

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 14 Dec 2009
  • Poruke: 154

Napisano: 01 Nov 2011 18:54

ComboFix 11-11-01.04 - Nikola i Ana 11/01/2011 18:47:20.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.1474 [GMT 1:00]
Running from: c:\users\Nikola i Ana\Desktop\ComboFix.exe
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\av_ico
c:\windows\av_ico\ico_avira_start.ico
c:\windows\av_ico\ico_mcafee_start.ico
c:\windows\btc_client_iplist.txt
c:\windows\front_ip_list.txt
c:\windows\geoiplist
c:\windows\geoiplist.rar
c:\windows\iecheck_iplist.txt
c:\windows\info1
c:\windows\iplist.txt
c:\windows\loader2.exe_ok
c:\windows\phoenix
c:\windows\phoenix.rar
c:\windows\phoenix\kernels\phatk\__init__.py
c:\windows\phoenix\kernels\phatk\__init__.pyc
c:\windows\phoenix\kernels\phatk\BFIPatcher.py
c:\windows\phoenix\kernels\phatk\kernel.cl
c:\windows\phoenix\kernels\poclbm\__init__.py
c:\windows\phoenix\kernels\poclbm\__init__.pyc
c:\windows\phoenix\kernels\poclbm\BFIPatcher.py
c:\windows\phoenix\kernels\poclbm\kernel.cl
c:\windows\phoenix\phoenix.exe
c:\windows\proc_list1.log
c:\windows\rpcminer.rar
c:\windows\system32\drivers\etc\HSTS~1
c:\windows\ufa.rar
c:\windows\update.1
c:\windows\update.2
c:\windows\update.5.0
c:\windows\update.tray-8-0-lnk
c:\windows\update.tray-8-0
c:\windows\winlog-dirs.txt
c:\windows\winlog-ids.txt
c:\windows\winsetupapi.log
.
.
((((((((((((((((((((((((( Files Created from 2011-10-01 to 2011-11-01 )))))))))))))))))))))))))))))))
.
.
2011-11-01 17:50 . 2011-11-01 17:50 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\temp
2011-11-01 17:50 . 2011-11-01 17:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-31 17:42 . 2011-10-31 17:45 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-10-31 17:42 . 2011-10-31 17:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-10-31 17:29 . 2011-10-31 17:29 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\CyberLink
2011-10-31 17:15 . 2011-10-31 17:15 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\ElevatedDiagnostics
2011-10-31 16:29 . 2011-10-31 16:29 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\ESET
2011-10-31 16:28 . 2011-10-31 16:28 -------- d-----w- c:\program files\ESET
2011-10-31 15:33 . 2011-10-31 15:33 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\Media Player Classic
2011-10-31 15:08 . 2011-10-31 15:08 -------- d-----w- c:\program files\TeamViewer
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\Malwarebytes
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\programdata\Malwarebytes
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-31 14:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-31 09:29 . 2011-10-31 09:29 -------- d-----w- c:\windows\ufa
2011-10-31 09:26 . 2011-10-31 09:29 246272 ----a-w- c:\windows\unrar.exe
2011-10-31 09:24 . 2011-10-31 15:00 -------- d--h--w- c:\windows\update.tray-9-0
2011-10-31 09:24 . 2011-10-31 15:00 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-10-26 18:07 . 2011-10-26 18:07 -------- d-----w- C:\Games
2011-10-26 17:27 . 2011-10-26 17:27 -------- d-----w- C:\pre2
2011-10-26 17:15 . 2011-10-26 17:15 -------- d-----w- C:\prehistorik2
2011-10-26 17:15 . 2011-10-26 17:15 -------- d-----w- c:\users\Nikola i Ana\New folder
2011-10-26 16:51 . 2011-10-26 18:15 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\DOSBox
2011-10-26 16:43 . 2011-10-26 16:43 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\Apps
2011-10-26 16:43 . 2011-10-26 16:43 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\Deployment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2004-12-20 33792]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-08-29 143360]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-06-24 2202704]
.
c:\users\Nikola i Ana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\Drivers\VMUVC.sys [2009-05-25 252416]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [2008-07-01 398720]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-06-24 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 41312]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-08-06 239648]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1221546997-4118530777-871473291-1000Core.job
- c:\users\Nikola i Ana\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-09 16:25]
.
2011-11-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1221546997-4118530777-871473291-1000UA.job
- c:\users\Nikola i Ana\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-09 16:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll
Toolbar-{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c} - c:\progra~1\BEARSH~1\MediaBar\Datamngr\ToolBar\bsdtxmltbpi.dll
Toolbar-10 - (no file)
HKLM-Run-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
HKLM-Run-tray_ico - (no file)
HKLM-Run-tray_ico2 - (no file)
HKLM-Run-tray_ico3 - (no file)
HKLM-Run-tray_ico4 - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-01 18:51:53
ComboFix-quarantined-files.txt 2011-11-01 17:51
.
Pre-Run: 79,726,067,712 bytes free
Post-Run: 80,734,437,376 bytes free
.
- - End Of File - - 1908E2492BC795D1885B15AA10054236

Dopuna: 01 Nov 2011 18:54

Evo ga! Sve je uradjeno kao sto si mi rekao... Smile

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Otvoriti Notepad i iskopirati sledeci tekst:

File::
c:\windows\unrar.exe

Folder::
c:\windows\ufa
c:\windows\update.tray-9-0
c:\windows\update.tray-9-0-lnk


Snimiti na Desktop fajl iz Notepada kao "CFScript"




Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.

offline
  • Pridružio: 14 Dec 2009
  • Poruke: 154

ComboFix 11-11-01.04 - Nikola i Ana 11/03/2011 16:37:16.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2047.1403 [GMT 1:00]
Running from: c:\users\Nikola i Ana\Desktop\ComboFix.exe
Command switches used :: c:\users\Nikola i Ana\Desktop\CFScript.txt
AV: ESET Smart Security 4.2 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 4.2 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
.
FILE ::
"c:\windows\unrar.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\ufa
c:\windows\ufa\ufa.exe
c:\windows\unrar.exe
c:\windows\update.tray-9-0-lnk
c:\windows\update.tray-9-0
.
.
((((((((((((((((((((((((( Files Created from 2011-10-03 to 2011-11-03 )))))))))))))))))))))))))))))))
.
.
2011-11-03 15:40 . 2011-11-03 15:40 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\temp
2011-11-03 15:40 . 2011-11-03 15:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-10-31 17:42 . 2011-10-31 17:45 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2011-10-31 17:42 . 2011-10-31 17:44 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-10-31 17:29 . 2011-10-31 17:29 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\CyberLink
2011-10-31 17:15 . 2011-10-31 17:15 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\ElevatedDiagnostics
2011-10-31 16:29 . 2011-10-31 16:29 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\ESET
2011-10-31 16:28 . 2011-10-31 16:28 -------- d-----w- c:\program files\ESET
2011-10-31 15:33 . 2011-10-31 15:33 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\Media Player Classic
2011-10-31 15:08 . 2011-10-31 15:08 -------- d-----w- c:\program files\TeamViewer
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\users\Nikola i Ana\AppData\Roaming\Malwarebytes
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\programdata\Malwarebytes
2011-10-31 14:40 . 2011-10-31 14:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-31 14:40 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-26 18:07 . 2011-10-26 18:07 -------- d-----w- C:\Games
2011-10-26 17:27 . 2011-10-26 17:27 -------- d-----w- C:\pre2
2011-10-26 17:15 . 2011-10-26 17:15 -------- d-----w- C:\prehistorik2
2011-10-26 17:15 . 2011-10-26 17:15 -------- d-----w- c:\users\Nikola i Ana\New folder
2011-10-26 16:51 . 2011-10-26 18:15 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\DOSBox
2011-10-26 16:43 . 2011-10-26 16:43 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\Apps
2011-10-26 16:43 . 2011-10-26 16:43 -------- d-----w- c:\users\Nikola i Ana\AppData\Local\Deployment
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2004-12-20 33792]
"VMonitorVMUVC"="c:\program files\Vimicro Corporation\VMUVC\VMonitor.exe" [2008-08-29 143360]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2010-06-24 2202704]
.
c:\users\Nikola i Ana\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-8-24 101784]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableSecureUIAPaths"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux4"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 VMUVC;Vimicro Camera Service VMUVC;c:\windows\system32\Drivers\VMUVC.sys [2009-05-25 252416]
R3 vvftUVC;Vimicro Camera Filter Service VMUVC;c:\windows\system32\drivers\vvftUVC.sys [2008-07-01 398720]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2010-04-28 114984]
S2 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys [2010-06-24 136120]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2010-06-24 810144]
S2 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys [2010-04-28 41312]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-08-06 239648]
S2 TeamViewer6;TeamViewer 6;c:\program files\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1221546997-4118530777-871473291-1000Core.job
- c:\users\Nikola i Ana\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-09 16:25]
.
2011-11-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1221546997-4118530777-871473291-1000UA.job
- c:\users\Nikola i Ana\AppData\Local\Google\Update\GoogleUpdate.exe [2010-11-09 16:25]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.bearshare.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-03 16:42:06
ComboFix-quarantined-files.txt 2011-11-03 15:42
ComboFix2.txt 2011-11-01 17:51
.
Pre-Run: 81,373,020,160 bytes free
Post-Run: 81,192,804,352 bytes free
.
- - End Of File - - 29556020A529AFDB8F9A106607F050D0

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

offline
  • Pridružio: 14 Dec 2009
  • Poruke: 154

I to je onda kraj?

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Da.

Ko je trenutno na forumu
 

Ukupno su 976 korisnika na forumu :: 35 registrovanih, 5 sakrivenih i 936 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 2413 - dana 03 Okt 2019 05:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., aleksandar_tatic, aramis s, Aslani Samir, awathorn, Bloody, d.arsenal321, djordje92sm, dragoljub11987, dtrivun, Ehinacea, gile58, goxin, gromche2, Joja2, jovan.simovic97, kalens021, Kruger, Kubovac, kybonacci, MB120mm, MikeHammer, Mixelotti, nuke92, repac, Roman, sasa.zoric, Sirius, soonne, SsssssNOVI, tokivoki01, Toni, Viceroy2, zodiac94, |_MeD_|