Problem sa Chrome browserom - pomoć

2

Problem sa Chrome browserom - pomoć

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 16:38

Oprosti mi. Potrudiću se da manje grešim. Ja sam shvatio da je MalwareBytes izveštaj ovo:
[Link mogu videti samo ulogovani korisnici]
molim te ako grešim pomozi mi gde mogu da ga nadjem. Evo ponamljam postupak za FRST i kačim fajlove.

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]

Dopuna: 13 Apr 2016 16:52

Evo pronašao sam još jedan MalwareBytes izveštaj (ko je to to).

[Link mogu videti samo ulogovani korisnici]



offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Ne, to je izvestaj od Zemana Anti-Malware. Za MalwareBytes, sam ti rekao kako da ih pribavis. Ako ne mozes, nije bitno.

Citat:Pokreni MalwareBytes --> History --> Application Logs, klikni na Scan Log (ili ako ih ima vise jedan po jedan), zatim na Export --> TXT file i sacuvaj ih na desktop. Zatim prikaci ovde sve izvestaje ili vec koliko ih ima od kad si skenirao.


1. Otvori Notepad (Text Document) i iskopiraj sledeći tekst unutar kod polja ispod:

createrestorepoint:
closeprocesses:
emptytemp:
zip: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs
Task: {830FA5B6-3E71-40F4-B4A9-945886EC4812} - System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => pcalua.exe -a "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe"
Task: {88D6A193-DC32-41AC-AE21-BDCD22032DBC} - \Clteyghuwph System -> No File <==== ATTENTION
Task: {9B04A5CD-B74A-4260-9D4C-B0820C3A56D6} - \Sosition Reports -> No File <==== ATTENTION
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
cmd: netsh winsock reset
C:\Program Files (x86)\Tencent
FirewallRules: [{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9}] => (Allow) 㩃啜敳獲䑜步屩灁䑰瑡屡潒浡湩屧獳屮獳⹮硥e
FirewallRules: [{B06450FF-C51F-4663-8F46-139574B89B37}] => (Allow) 㩃啜敳獲䑜步屩灁䑰瑡屡潒浡湩屧獳屮慳敶灵攮數
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\...\Run: [C] => cmd /c(@attrib -H -R -S C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@att (the data entry has 99 more characters).
2016-04-13 05:08 - 2016-04-13 05:11 - 00000000 ____D C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC浏览器
2016-04-13 05:08 - 2016-04-13 05:09 - 00000464 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\Downloads\已录制的视频
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\UCBrowser
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\Geckofx
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2016-04-13 05:08 - 2016-03-28 14:46 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-13 05:05 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\badu
2016-04-13 05:04 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\hohobnd
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Sosition
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Clteyghuwph
2016-04-13 05:04 - 2016-04-13 05:05 - 00000000 ____D C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 01:22 - 2016-04-13 13:20 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-04-13 01:22 - 2016-04-13 01:22 - 00000008 __RSH C:\Users\Deki\ntuser.pol
2016-04-13 02:55 - 2016-04-13 02:55 - 00000129 _____ C:\WINDOWS\SysWOW64\L


2. Sačuvaj notepad na Desktop pod nazivom fixlist.txt
To možes uraditi i iz notepad-a => klik na File potom na Save As i u novom prozoru, dole pod File Name: staviš za naziv fixlist.txt
Napomena: Važno je da se oba fajla, FRST i fixlist nalaze na istoj lokaciji jer u suprotnom fix nece raditi.

3. Ponovo pokreni FRST/FRST64, klikni jednom na dugme Fix i sačekaj.
Ukoliko alat zatraži restart sistema, dozvoli mu i postaraj se da alat kompletira fix nakon restarta sistema.



Alat će formirati log (Fixlog.txt) na Desktop-u. Potrebno je sadržaj tog loga iskopirati u poruku.
Napomena: Ukoliko te alat upozori da postoji novija verzija, postaraj se da preuzmes i koristiš ažuriranu kopiju FRST-a.



offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 18:00

[Link mogu videti samo ulogovani korisnici]

Dopuna: 13 Apr 2016 18:31

Fix result of Farbar Recovery Scan Tool (x64) Version:10-04-2016 01
Ran by Deki (2016-04-13 18:25:20) Run:1
Running from C:\Users\Deki\Desktop
Loaded Profiles: Deki (Available Profiles: Deki)
Boot Mode: Normal
==============================================

fixlist content:
*****************
createrestorepoint:
closeprocesses:
emptytemp:
zip: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs
Task: {830FA5B6-3E71-40F4-B4A9-945886EC4812} - System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => pcalua.exe -a "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17339.217\Uninst.exe"
Task: {88D6A193-DC32-41AC-AE21-BDCD22032DBC} - \Clteyghuwph System -> No File <==== ATTENTION
Task: {9B04A5CD-B74A-4260-9D4C-B0820C3A56D6} - \Sosition Reports -> No File <==== ATTENTION
Winsock: Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [55808 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\napinsp.dll"
Winsock: Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [70656 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\pnrpnsp.dll"
Winsock: Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [65024 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [312160 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [23552 2015-10-30] (Microsoft Corporation)ATTENTION: LibraryPath should be "%SystemRoot%\System32\winrnr.dll"
cmd: netsh winsock reset
C:\Program Files (x86)\Tencent
FirewallRules: [{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9}] => (Allow) ????????????????????e
FirewallRules: [{B06450FF-C51F-4663-8F46-139574B89B37}] => (Allow) ??????????????????????
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\...\Run: [C] => cmd /c(@attrib -H -R -S C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@copy/b/y C:\WINDOWS\system32\GroupPolicy\Machine\R C:\WINDOWS\system32\GroupPolicy\Machine\Registry.pol >nul)&(@att (the data entry has 99 more characters).
2016-04-13 05:08 - 2016-04-13 05:11 - 00000000 ____D C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???
2016-04-13 05:08 - 2016-04-13 05:09 - 00000464 _____ C:\WINDOWS\Tasks\UCBrowserUpdater.job
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\Downloads\??????
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\UCBrowser
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Users\Deki\AppData\Local\Geckofx
2016-04-13 05:08 - 2016-04-13 05:08 - 00000000 ____D C:\Program Files (x86)\UCBrowser
2016-04-13 05:08 - 2016-03-28 14:46 - 00080768 _____ (Huorong Borui (Beijing) Technology Co., Ltd.) C:\WINDOWS\system32\Drivers\ucguard.sys
2016-04-13 05:05 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\badu
2016-04-13 05:04 - 2016-04-13 14:24 - 00000000 ____D C:\Program Files (x86)\hohobnd
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Sosition
2016-04-13 05:04 - 2016-04-13 13:20 - 00000000 ____D C:\Program Files (x86)\Clteyghuwph
2016-04-13 05:04 - 2016-04-13 05:05 - 00000000 ____D C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108
2016-04-13 01:22 - 2016-04-13 13:20 - 00000258 __RSH C:\ProgramData\ntuser.pol
2016-04-13 01:22 - 2016-04-13 01:22 - 00000008 __RSH C:\Users\Deki\ntuser.pol
2016-04-13 02:55 - 2016-04-13 02:55 - 00000129 _____ C:\WINDOWS\SysWOW64\L

*****************

Restore point was successfully created.
Processes closed successfully.
================== Zip: ===================
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs -> copied successfully to C:\Users\Deki\Desktop\Upload.zip
=========== Zip: End ===========
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{830FA5B6-3E71-40F4-B4A9-945886EC4812}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{830FA5B6-3E71-40F4-B4A9-945886EC4812}" => key removed successfully
C:\WINDOWS\System32\Tasks\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B85083CC-DED4-4A53-8B8C-56B2E308F4A1}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{88D6A193-DC32-41AC-AE21-BDCD22032DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{88D6A193-DC32-41AC-AE21-BDCD22032DBC}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Clteyghuwph System" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9B04A5CD-B74A-4260-9D4C-B0820C3A56D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B04A5CD-B74A-4260-9D4C-B0820C3A56D6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Sosition Reports" => key removed successfully
Winsock: Catalog5 000000000001\\LibraryPath => restored successfully (%SystemRoot%\system32\napinsp.dll)
Winsock: Catalog5 000000000002\\LibraryPath => restored successfully (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000003\\LibraryPath => restored successfully (%SystemRoot%\system32\pnrpnsp.dll)
Winsock: Catalog5 000000000004\\LibraryPath => restored successfully (%SystemRoot%\system32\NLAapi.dll)
Winsock: Catalog5 000000000005\\LibraryPath => restored successfully (%SystemRoot%\System32\mswsock.dll)
Winsock: Catalog5 000000000006\\LibraryPath => restored successfully (%SystemRoot%\System32\winrnr.dll)

========= netsh winsock reset =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========

"C:\Program Files (x86)\Tencent" => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3AF5331D-A05C-424D-9D61-3FABA0C1AFB9} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B06450FF-C51F-4663-8F46-139574B89B37} => value removed successfully
HKU\S-1-5-21-3839879188-1321709098-44954216-1001\Software\Microsoft\Windows\CurrentVersion\Run\\C => value removed successfully

=========== "C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???" ==========

not found

========= End -> "C:\Users\Deki\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UC???" ========

C:\WINDOWS\Tasks\UCBrowserUpdater.job => moved successfully

=========== "C:\Users\Deki\Downloads\??????" ==========

not found

========= End -> "C:\Users\Deki\Downloads\??????" ========

C:\Users\Deki\AppData\Local\UCBrowser => moved successfully
C:\Users\Deki\AppData\Local\Geckofx => moved successfully
C:\Program Files (x86)\UCBrowser => moved successfully
C:\WINDOWS\system32\Drivers\ucguard.sys => moved successfully
C:\Program Files (x86)\badu => moved successfully
C:\Program Files (x86)\hohobnd => moved successfully
C:\Program Files (x86)\Sosition => moved successfully
C:\Program Files (x86)\Clteyghuwph => moved successfully
C:\Users\Deki\AppData\Local\3810282D-6C19-47B0-8283-5C6C29A7E108 => moved successfully
C:\ProgramData\ntuser.pol => moved successfully
C:\Users\Deki\ntuser.pol => moved successfully
C:\WINDOWS\SysWOW64\L => moved successfully
EmptyTemp: => 400.5 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 18:26:42 ====

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Odlicno. Na Desktopu bi sada trebao da imas Upload.zip fajl.

Uplaoduj ga preko ovog linka: [Link mogu videti samo ulogovani korisnici]

I za kraj kazi mi da li je sada sve u redu?

offline
  • Pridružio: 17 Okt 2011
  • Poruke: 311

Napisano: 13 Apr 2016 18:52

E, Jebiga ja obrisao tu ZIP datoteku misleći da mi je ostala kao rep od trajal verzije Malwarebytes. Inače za sada je sve ok.

Dopuna: 13 Apr 2016 18:54

Mnogo ti hvala na strpljenju, pomoći i razumevanju. Ovakvih nespretnjakovića kao što sam ja.

offline
  • Pridružio: 09 Avg 2011
  • Poruke: 15879
  • Gde živiš: Beograd

Preuzmi "Xplode"-ov DelFix i sačuvaj ga na Desktop

Dvoklikom pokreni program.

Štikliraj sledeće opcije:
Remove disinfection tools
Purge System Restore
Reset system settings


Klikni na dugme "Run" i pričekaj da program završi rad.
Alat ce ukloniti sve koriscene alate u ovoj temi...
Kada alat završi, otvoriće izvestaj u notepadu.
Napomena: Izvestaj ce takodje biti sacuvan na C:\DelFix.txt

Nije potrebno dostavljati izvestaj.

Ko je trenutno na forumu
 

Ukupno su 1056 korisnika na forumu :: 231 registrovanih, 17 sakrivenih i 808 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 15694 - dana 01 Feb 2026 12:23

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -[CoA]-, -Max-, A.R.Chafee.Jr., Abebe Bikila, Agape, Air_Force_82, ALEKSICMILE, AMCXXL, Andrija357, Apok, Asparagus, ast13, Asteker, avalon, Barista, bato_banjaluka, Ben Roj, bilisrbija, Blair, Boba, bobo85, bojanM84, Bojcca, bojcistv, Bombona, Boris.A, Boris90, Borkanović, bpredic, branko87, brkan1, Bronx, Brzi voz, Burovnyak, BZ, celt, CHARLIE JA., Cirkon, Coficab, curiosity, d.arsenal321, Daba75, dane007, Dannyboy, darionis, dejan1972, Desmond, Despot Đurađ, Dimitrije Paunovic, djboj, Djokislav, djonsule, djukapfc, Dogma21, DonRumataEstorski, DovlaODR, draganl, dragoljub11987, dule10savic, dulleo, DzigiNS, Dzumanga, ekozelj, EVIDENTICAR, Flanker-G, Fulcrum-A, gaga23, gasazem, GH69, goran.vvv, Goran_, GrammaticalAnalysis, Grochow, GveX, Hans Gajger, havoc995, hellenic, hnjo, istina, IvanMiletic, j-22orao, Jakonjveliki, jalos, Jan, jeen yuhs, JK, Jomini, Jovan.D, jugoslav.70, K a s p e r, K2, kaput21, Karla, Kenanjoz, kinez88, king111, KizJ, komenski, koom0001, Kozi-RS, kreker, krkalon, Kruger, Kubovac, Kuroje, kybonacci, lafa008, Leonov, Levi, lima, lord sir giga, LUDI, luka35, M74AB3, MadMike, maksi007, MarijaC84, Marko00, marsi, MaschinenPistole, medaTT, mercedesamg, Metanoja, mgolub, Mig 29, miki kv, Miki01, MIKI63, mikrimaus, Milan Miscevic, Milun24, mir, Mis uz pusku, mm1811, mmelezovic, narandzasti, nenad81, novator, nuke92, obsidian, ostoja, paja69, paladin71, Panta1992, Papadubi, Pegggio, pein, pera bager, Petar25, picknick, Plavi Jadran, PlayerOne, Polemarchoi, popinz, Povratak1912, Prečanin30, PuškeiPlavuše, Radoslava, RajkoB, razumihin, rebro1974, rednap, Remarqe, renvoi, Robin, rovac, sales, Samo gledam, samocitam, SamoLAgan0, SamostalniReferent, Sharpshooter, shiro, shlauf, sisi, Skakac7, skvara, Smiljkovich, srecko81, stevo svinja, Stoilkovic, styg, Superastro, Tafocus, tanakadzo, Tandrčak, Tastatura ratnik, theNedjeljko, tomo2, Topaz9, Totem, TRZH92, tubular, Tumansky, Underwood, uruk, v0idmp3, Valter071, vargas, vaso1, Vatreni Zmaj, vazduh, veljko82, Veljko™, vidra1, VJ, vladanan, vladom6, VPV, Vrač, vrlenija, vukovi, vuksa72, Welky, Wepp, Wrangler, Yekaterinburg, Yemk0, zajcev1, Zanzibar, Zastava, Zeka_Peka, zemljanin, ZetaMan, zil10, zixmix, zlaya011, zombicar153, zoran77, Zoran_Partizan, zule2