Problem sa Chrome browserom - pomoć

2

Problem sa Chrome browserom - pomoć

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 16:38

Oprosti mi. Potrudiću se da manje grešim. Ja sam shvatio da je MalwareBytes izveštaj ovo:
https://www.mycity.rs/must-login.png
molim te ako grešim pomozi mi gde mogu da ga nadjem. Evo ponamljam postupak za FRST i kačim fajlove.

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

Dopuna: 13 Apr 2016 16:52

Evo pronašao sam još jedan MalwareBytes izveštaj (ko je to to).

https://www.mycity.rs/must-login.png

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Ne, to je izvestaj od Zemana Anti-Malware. Za MalwareBytes, sam ti rekao kako da ih pribavis. Ako ne mozes, nije bitno.

Citat:Pokreni MalwareBytes --> History --> Application Logs, klikni na Scan Log (ili ako ih ima vise jedan po jedan), zatim na Export --> TXT file i sacuvaj ih na desktop. Zatim prikaci ovde sve izvestaje ili vec koliko ih ima od kad si skenirao.


1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

createrestorepoint:
closeprocesses:
emptytemp:
zip: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs
Task: {830FA5B6-3E71-40F4-B4A9-945886EC4812} - System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => pcalua.exe -a "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe"
Task: {88D6A193-DC32-41AC-AE21-BDCD22032DBC} - \Clteyghuwph System -> No File <==== ATTENTION
Task: {9B04A5CD-B74A-4260-9D4C-B0820C3A56D6} - \Sosition Reports -> No File <==== ATTENTION
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
cmd: netsh winsock reset
C:\Program Files (x86)\Tencent
FirewallRules: [{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9}] => (Allow) 㩃啜敳獲䑜步屩灁䑰瑡屡潒浡湩屧獳屮獳⹮硥e
FirewallRules: [{B06450FF-C51F-4663-8F46-139574B89B37}] => (Allow) 㩃啜敳獲䑜步屩灁䑰瑡屡潒浡湩屧獳屮慳敶灵攮數
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\...\Run: [C] => cmd /c(@attrib -H -R -S C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@att (the data entry has 99 more characters).
2016-04-13 05:08 - 2016-04-13 05:11 - 00000000 ____D C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-04-13 05:08 - 2016-04-13 05:09 - 00000464 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\Downloads\已录制的视频
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\UCBrowser
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\Geckofx
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2016-04-13 05:08 - 2016-03-28 14:46 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-13 05:05 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\badu
2016-04-13 05:04 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\hohobnd
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Sosition
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Clteyghuwph
2016-04-13 05:04 - 2016-04-13 05:05 - 00000000 ____D C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 01:22 - 2016-04-13 13:20 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-04-13 01:22 - 2016-04-13 01:22 - 00000008 __RSH C:\Users\Deki\ntuser.pol
2016-04-13 02:55 - 2016-04-13 02:55 - 00000129 _____ C:\WINDOWS\SysWOW64\L


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 18:00

https://www.mycity.rs/must-login.png

Dopuna: 13 Apr 2016 18:31

Fix result of Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
Ran by Deki (2016-04-13 18:25:20) Run:1
Running from C:\Users\Deki\Desktop
Loaded Profiles: Deki (Available Profiles: Deki)
Boot Mode: Normal
==============================================

fixlist content:
*****************
createrestorepoint:
closeprocesses:
emptytemp:
zip: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs
Task: {830FA5B6-3E71-40F4-B4A9-945886EC4812} - System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => pcalua.exe -a "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe"
Task: {88D6A193-DC32-41AC-AE21-BDCD22032DBC} - \Clteyghuwph System -> No File <==== ATTENTION
Task: {9B04A5CD-B74A-4260-9D4C-B0820C3A56D6} - \Sosition Reports -> No File <==== ATTENTION
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
cmd: netsh winsock reset
C:\Program Files (x86)\Tencent
FirewallRules: [{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9}] => (Allow) ????????????????????e
FirewallRules: [{B06450FF-C51F-4663-8F46-139574B89B37}] => (Allow) ??????????????????????
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\...\Run: [C] => cmd /c(@attrib -H -R -S C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@att (the data entry has 99 more characters).
2016-04-13 05:08 - 2016-04-13 05:11 - 00000000 ____D C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???
2016-04-13 05:08 - 2016-04-13 05:09 - 00000464 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\Downloads\??????
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\UCBrowser
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\Geckofx
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2016-04-13 05:08 - 2016-03-28 14:46 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-13 05:05 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\badu
2016-04-13 05:04 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\hohobnd
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Sosition
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Clteyghuwph
2016-04-13 05:04 - 2016-04-13 05:05 - 00000000 ____D C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 01:22 - 2016-04-13 13:20 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-04-13 01:22 - 2016-04-13 01:22 - 00000008 __RSH C:\Users\Deki\ntuser.pol
2016-04-13 02:55 - 2016-04-13 02:55 - 00000129 _____ C:\WINDOWS\SysWOW64\L

*****************

Restore point was successfully created.
Processes closed successfully.
================== Zip: ===================
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs -> copied successfully to C:\Users\Deki\Desktop\Upload.zip
=========== Zip: End ===========
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{830FA5B6-3E71-40F4-B4A9-945886EC4812}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{830FA5B6-3E71-40F4-B4A9-945886EC4812}" => key removed successfully
C:\WINDOWS\System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88D6A193-DC32-41AC-AE21-BDCD22032DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88D6A193-DC32-41AC-AE21-BDCD22032DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Clteyghuwph System" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B04A5CD-B74A-4260-9D4C-B0820C3A56D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B04A5CD-B74A-4260-9D4C-B0820C3A56D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sosition Reports" => key removed successfully
Winsock: Catalog5 000000000001\\LibraryPath => restored successfully (%SystemRoot%\system32\napinsp.dll)
Winsock: Catalog5 000000000002\\LibraryPath => restored successfully (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000003\\LibraryPath => restored successfully (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000004\\LibraryPath => restored successfully (%SystemRoot%\system32\NLAapi.dll)
Winsock: Catalog5 000000000005\\LibraryPath => restored successfully (%SystemRoot%\System32\mswsock.dll)
Winsock: Catalog5 000000000006\\LibraryPath => restored successfully (%SystemRoot%\System32\winrnr.dll)

========= netsh winsock reset =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========

"C:\Program Files (x86)\Tencent" => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B06450FF-C51F-4663-8F46-139574B89B37} => value removed successfully
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\Software\Microsoft\Windows\CurrentVersion\Run\\C => value removed successfully

=========== "C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???" ==========

not found

========= End -> "C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???" ========

C:\WINDOWS\Tasks\UCBrowserUpdater.job => moved successfully

=========== "C:\Users\Deki\Downloads\??????" ==========

not found

========= End -> "C:\Users\Deki\Downloads\??????" ========

C:\Users\Deki\AppData\Local\UCBrowser => moved successfully
C:\Users\Deki\AppData\Local\Geckofx => moved successfully
C:\Program Files (x86)\UCBrowser => moved successfully
C:\WINDOWS\system32\Drivers\ucguard.sys => moved successfully
C:\Program Files (x86)\badu => moved successfully
C:\Program Files (x86)\hohobnd => moved successfully
C:\Program Files (x86)\Sosition => moved successfully
C:\Program Files (x86)\Clteyghuwph => moved successfully
C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 => moved successfully
C:\ProgramData\ntuser.pol => moved successfully
C:\Users\Deki\ntuser.pol => moved successfully
C:\WINDOWS\SysWOW64\L => moved successfully
EmptyTemp: => 400.5 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 18:26:42 ====

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Odlicno. Na Desktopu bi sada trebao da imas Upload.zip fajl.

Uplaoduj ga preko ovog linka: https://www.sendspace.com/

I za kraj kazi mi da li je sada sve u redu?

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 18:52

E, Jebiga ja obrisao tu ZIP datoteku misleći da mi je ostala kao rep od trajal verzije Malwarebytes. Inače za sada je sve ok.

Dopuna: 13 Apr 2016 18:54

Mnogo ti hvala na strpljenju, pomoći i razumevanju. Ovakvih nespretnjakovića kao što sam ja.

offline
  • Research Engineer @MalwareBytes
  • Pridružio: 09 Avg 2011
  • Poruke: 15874
  • Gde živiš: Beograd

Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop

Dvoklikom pokreni program.

Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings


Klikni na dugme "Run" i pričekaj da program završi rad.
Alat ce ukloniti sve koriscene alate u ovoj temi...
Kada alat završi, otvoriće izvestaj u notepadu.
Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt

Nije potrebno dostavljati izvestaj.

Ko je trenutno na forumu
 

Ukupno su 656 korisnika na forumu :: 27 registrovanih, 0 sakrivenih i 629 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3028 - dana 22 Nov 2019 07:47

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Cobi026, d bos, Dipl.ing., doom83, Dorcolac2, Dusko Nikolin, goxin, ivance95, Kaplar2, Kubovac, KUZMAR, Ljubitelj, Milan.1976, MILO-VAN, milos.cbr, NenadG, nradukic, Oluj2.1, operniki, Pavlov A.A., Profica, Recce, reidmihajilo, S-lash, Srna2, TITAN DUDIN JARAN