Reklame

1

Reklame

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Pozdrav!
Danas sam primetio,dok sam surfovao u Operi,da mi je iskocio pop-up prozor (iako ja ninasta nisam kliknuo) i u njemu je pocelo da skenira moj ceo komp a predhodno je izaslo obavestenje da AVG (posto mi je to trenutni anti virus) nesto poceo da skenira...Odmah sam primetio da je to pop-up prozor,a vec znam kako izgledaju,navodno,anti virusi koji nadju neke probleme ili infekcije i traze da platite a u stvari je sve fol (http://www.informacija.rs/Recnik/Scareware.html) Very Happy

Takodje,pre nekoliko dana dok je moj brat bio na kompu,izasao mu je pop-up prozor reklama za travian...

E sad,meni je pre radio DDS program ali sad pocne da skenira i ni posle 10-15 minuta ne izlaze logovi (a pre kazem radilo je sve i u roku od 2-3 minuta sve je gotovo) pa sam morao da prekinem i to nekoliko puta pa ne mogu staviti logove iz DDS-a ali sam racunar skenirao sa Malwarebytes programom i evo njegovog loga:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5363

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2/9/2011 3:27:42 PM
mbam-log-2011-02-09 (15-27-42).txt

Scan type: Full scan (C:\|D:\Smajli
Objects scanned: 166294
Time elapsed: 1 hour(s), 12 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
d:\system volume information\_restore{a430eb07-3de8-4c83-9a56-02fd863e79dd}\RP272\A0240376.exe (HackTool.Brutus) -> Quarantined and deleted successfully.
d:\HK\deface page generator v1.0.exe (Malware.Packer) -> Quarantined and deleted successfully.
d:\HK\project neptune\dissembler lib.dll (Trojan.Agent) -> Quarantined and deleted successfully.
d:\Igrice\desktopgames.exe (Joke.Stressreducer) -> Quarantined and deleted successfully.


GMER logovi:

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Pokreni program OTL imas ga u uputstvu,

Samo napomena da necu moci veceras da prregledam logove, premoren sam, tek sutra pre podne.

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

https://www.mycity.rs/must-login.png

https://www.mycity.rs/must-login.png

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Preuzmi sUBs-ov ComboFix sa sledeće adrese na Desktop:


Bleeping Computer
Klikni desnim tasterom na link i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
deaktiviraj zaštitni softver (uputstvo);
zatvori pokrenute programe;
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
obavezno prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Sad nece ni Combofix koji je radio pre isto kao i DDS Sad
Ukljucio sam skeniranje u 18:05 a sad kad sam dosao kuci u 22:20 i dalje je radilo i prekinuo sam!

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Obriši taj file koji si skinuo, a zatim ga ponovo skini:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe


Restartuj PC u Safe Mode: http://www.mycity.rs/Uputstva/Kako-uci-u-Safe-Mode-2.html


U Safe Mode-u pokreni ComboFix i isprati postupak

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Napisano: 11 Feb 2011 14:48

Nece Sad
Od 13:15 do 14:45 je radilo i nista...

Dopuna: 11 Feb 2011 19:53

Jos nesto,ova adresa 178.223.96.132 koja mi je sada dodeljena je navodno adresa koriscena za spam posto na nekoliko sajtova na koje sam probao da udjem su mi izasla ta obavestenja i morao sam CAPTCHU da popunjavam i mislim da mi se to nikada do sada nije desavalo...Videcu kad mi se IP adresa opet promeni da li ce biti isto :S

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Ponovo pokreni program OTL dvoklikom na ikonicu;

U beli okvir prozora gde piše Custom Scans/Fixes iskopirati sledeći tekst:

:OTL
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.turkojan.com/
O4 - HKLM..\Run: [HTC Sync]  File not found
O33 - MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\Shell\AutoplAY\command - "" = G:\nkamfy.pif
O33 - MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\Shell\AutoRun\command - "" = G:\nkamfy.pif
O33 - MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\Shell\ExPlOrE\COmMANd - "" = G:\nkamfy.pif
O33 - MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\Shell\oPen\coMmand - "" = G:\nkamfy.pif
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2011/02/09 18:06:51 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Miki\Desktop\17z3g77b.exe

:reg
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\Programi\Turkojan\Client.exe" =-
"C:\Documents and Settings\Miki\Desktop\CyberGate v1.04.8\CyberGate v1.04.8.exe" =-
"D:\Hacker Kit 2009\CyberGate v1.04.8\CyberGate v1.04.8.exe" =-
"D:\Hacker Kit 2009\CyberGate v1.05.1\CyberGate v1.05.1.exe" =-
"C:\Documents and Settings\Miki\Desktop\CyberGate v1.04.8\CyberGate v1.04.8.exe" =-
"D:\Hacker Kit 2009\CyberGate v1.05.1\CyberGate v1.05.1.exe" =-

:files
Turkojan /alldrives
Hacker Kit 2009 /alldrives
nkamfy.pif /alldrives
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[resethosts]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]


Klikni taster Run Fix;


Log koji dobiješ iskopiraj ovde u poruci.


--------------------------

Sledeci korak!

Desinstaliraj AVG pa onda pokeni Comborix.

offline
  • Pridružio: 02 Jan 2008
  • Poruke: 2167

Napisano: 11 Feb 2011 21:34

All processes killed
========== OTL ==========
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HTC Sync deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
File G:\nkamfy.pif not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
File G:\nkamfy.pif not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
File G:\nkamfy.pif not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d63ce72b-285d-11e0-8a86-001802f45c80}\ not found.
File G:\nkamfy.pif not found.
C:\WINDOWS\DUMP9615.tmp deleted successfully.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET4.tmp deleted successfully.
C:\WINDOWS\SET8.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET151.tmp deleted successfully.
C:\Documents and Settings\Miki\Desktop\17z3g77b.exe moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\D:\Programi\Turkojan\Client.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Documents and Settings\Miki\Desktop\CyberGate v1.04.8\CyberGate v1.04.8.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\D:\Hacker Kit 2009\CyberGate v1.04.8\CyberGate v1.04.8.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\D:\Hacker Kit 2009\CyberGate v1.05.1\CyberGate v1.05.1.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\C:\Documents and Settings\Miki\Desktop\CyberGate v1.04.8\CyberGate v1.04.8.exe not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List\\D:\Hacker Kit 2009\CyberGate v1.05.1\CyberGate v1.05.1.exe not found.
========== FILES ==========
Turkojan not found in C:\
Turkojan not found in D:\
Hacker Kit 2009 not found in C:\
Hacker Kit 2009 not found in D:\
nkamfy.pif not found in C:\
nkamfy.pif not found in D:\
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Miki\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Miki\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temporary Internet Files folder emptied: 32768 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Miki
->Temp folder emptied: 70629951 bytes
->Temporary Internet Files folder emptied: 2493188 bytes
->Java cache emptied: 560741 bytes
->FireFox cache emptied: 81394801 bytes
->Flash cache emptied: 49664 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1074522 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 149.00 mb

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService

User: Miki
->Flash cache emptied: 0 bytes

User: NetworkService

Total Flash Files Cleaned = 0.00 mb

Restore points cleared and new OTL Restore Point set!

OTL by OldTimer - Version 3.2.20.6 log created on 02112011_213107

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Dopuna: 11 Feb 2011 21:35

Sa Combofix-om cu sutra raditi... Smile

Dopuna: 12 Feb 2011 10:21

Nece Combofix Sad

rip
  • argus  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 27 Apr 2008
  • Poruke: 9160
  • Gde živiš: Prokuplje

Jesi deinstalirao AVG. Combofix nece da radi sa AVG

Ovde imas Uninstaller http://www.mycity.rs/Antivirus-programi/Programi-z.....tvera.html


U principu tebi je racunar cist, samo sam hteo nesto da proverim sa Combofixom.

Pogledaj koliko imas ostataka u registry-u od raznoraznih Antivirusa koje si lose deinstalirao.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]


Imas onaj link, pa pokreci svaki alat i ocisti racunar od tih ostatka .

Definisi sta znaci "Nece Combofix"

Jel izbazuje neku gresku, sta ...

Ko je trenutno na forumu
 

Ukupno su 896 korisnika na forumu :: 52 registrovanih, 7 sakrivenih i 837 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: antonije64, Atomski čoban, Buzdovan, CikaKURE, cinoeye, comi_pfc, Dimitrije Paunovic, djboj, Djokislav, dozorni, dragoljub11987, dushan, FOX, hyla, ikan, jackreacher011011, Karla, Komentator, Koridor, Krusarac, kuntalo, kybonacci, Litostroton, Lošmi, Marko Marković, menges, mercedesamg, Mercury, milutin134, Mlav, mnn2, nebojsag, nedeljkovici, Oscar, Pikac-47, Rakenica, raptorsi, raso7, repac, RJ, royst33, Sirius, Sićko, slonic_tonic, sokojet, SR-3m, Trpe Grozni, vathra, VP6919, vukdra, zeo, šumar bk2