Virus mi resetuje racunar!

3

Virus mi resetuje racunar!

offline
  • Pridružio: 11 Avg 2010
  • Poruke: 36

Auuuuuuu, SHIT!!!! Negde na oko 38% skeniranja D: particije, ponovo mi se resetovao racunar!!!! Ne mogu da verujem!

Ne znam da li si ovo trazio, ali ako sam pogresio reci mi:

Log iz ESET-a:

8/12/2010 9:06:57 PM Real-time file system protection file C:\Users\Milan\AppData\Local\Temp\Av-test.txt Eicar test file cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\ComboFix\CF29966.cfxxe.
8/11/2010 8:45:21 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 5:56:20 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 5:53:48 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 5:50:27 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 5:45:34 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 4:40:38 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 3:55:35 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 3:09:45 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 12:31:45 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean
8/11/2010 12:31:08 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 7:30:21 AM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 7:23:42 AM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 12:34:21 AM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/11/2010 12:27:00 AM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean
8/11/2010 12:26:06 AM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/10/2010 7:50:54 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/10/2010 7:40:02 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/10/2010 7:29:53 PM Startup scanner boot sector active boot sector of the 2. physical disk probably unknown TSR.BOOT virus unable to clean Milan-PC\Milan
8/10/2010 4:53:58 PM Startup scanner boot sector active boot sector of the 3. physical disk probably unknown TSR.BOOT virus unable to clean
8/9/2010 6:48:14 PM Startup scanner boot sector active boot sector of the 3. physical disk probably unknown TSR.BOOT virus unable to clean
8/9/2010 5:31:53 PM Real-time file system protection file K:\Rapidshare\GAMES\AC-II.SKiDROW\SKIDROW\ubiorbitapi_r2.dll a variant of Win32/Packed.VMProtect.AAA trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\Nero\Nero 10\Nero Burning ROM\nero.exe.
8/9/2010 5:30:06 PM Real-time file system protection file K:\Rapidshare\GAMES\ac-two\sr-acii\ubiorbitapi_r2.dll a variant of Win32/Packed.VMProtect.AAA trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 8:40:55 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:39:52 PM Real-time file system protection file C:\downloads\husajn11__1_\Keymaker.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:39:45 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 8:39:00 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:38:12 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\ESET\ESET Smart Security\egui.exe.
8/6/2010 8:37:01 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:35:29 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:35:13 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 8:33:27 PM Real-time file system protection file C:\downloads\Keymaker.Nero.9.4.26\Keymaker.Nero.9.4.26.0.exe MSIL/TrojanDropper.Agent.W trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 8:26:06 PM Real-time file system protection file C:\downloads\husajn11__1_\Keymaker.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 8:24:52 PM Real-time file system protection file C:\downloads\husajn11__1_\Keymaker.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 8:24:02 PM Real-time file system protection file C:\downloads\husajn11__1_\Keymaker.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.
8/6/2010 5:42:55 PM Real-time file system protection file C:\Users\Milan\AppData\Local\Temp\checkupd.exe NSIS/TrojanDownloader.FakeAlert.DC trojan deleted - quarantined Milan-PC\Milan Event occurred on a new file created by the application: K:\HotFile\OptimisticxDelusion.cw\SystemMechanicPro.exe.
8/6/2010 11:12:04 AM Real-time file system protection file D:\RapidShare\PROGRAMI\ACDSee Pro 2.0.238\keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred during an attempt to access the file by the application: C:\Program Files\TC UP\TOTALCMD.EXE.
8/6/2010 11:11:34 AM Real-time file system protection file C:\downloads\ACDSee Pro v2.5.335\keygen.exe probably a variant of Win32/Agent trojan cleaned by deleting - quarantined Milan-PC\Milan Event occurred on a new file created by the application: C:\Program Files\Winrar\WinRAR.exe.



offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Dual-boot? Na D particiji je XP?



offline
  • Pridružio: 11 Avg 2010
  • Poruke: 36

Napisano: 12 Avg 2010 23:38

???? NIKAKO!!!! Nemam nigde Windows direktorijum na D particiji! Ne znam kako to da proverim, ali sam poprilicno siguran da nikada u zivotu nisam instalirao XP na D:

Dopuna: 12 Avg 2010 23:42



Ovde pise samo Windows7, i nista vise!

Dopuna: 12 Avg 2010 23:44

Imam na particiji D .iso fajl od XP-a, koji mi samo tu stoji kao i svi drugi programi!

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Ovde je sve u redu.. Poslednja detekcija je bila pre dva dana. E sad sto se komp resetuje prilikom skena, to zaista ne znam. I smanji malo upotrebu krekova. Verovatno je tako i doslo do zaraze.. Pa ti vidi dal se isplati skidati sa neproverenih sajtova krekove.

offline
  • Pridružio: 11 Avg 2010
  • Poruke: 36

OK, ja sam sada krenuo folder po folder da pretrazujem na D: particiji, jer sam primetio da kada idem korak po korak u pretrazivanju foldera, ESET mi odmah izbaci poruku sta je zarazeno i pita me sta da radim! Ja ga lepo obrisem i evo polako privodim D: particiju kraju. Ali me stvarno cudi zasto mi ESET resetuje racunar kada stikliram da mi pretrazuje D: i cim naidje na neki zarazeni fajl, izbaci mi onu poruku "infiltration" i resetuje se!!!! Stvarno ne razumem o cemu se radi, ali ajde sada!!!!

Puno hvala na pomoci!!! Wink

offline
  • diarno  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 15 Jun 2007
  • Poruke: 5572

Uradi jos ovo :

Potrebno je deinstalirati ComboFix:
klikni start (ili ), a zatim RUN.

Na Visti koristiti Start Search polje ukoliko Run nije dostupan.

U liniju za unos teksta ukucaj (iskopiraj) sledeće:

ComboFix /Uninstall

Primeti da postoji razmak između "ComboFix" i "/Uninstall".



a zatim klikni OK (ili pritisni Enter).


Sačekaj da se proces deinstalacije završi.

To bi bilo to.. Pozzz Smile

Ko je trenutno na forumu
 

Ukupno su 1697 korisnika na forumu :: 35 registrovanih, 7 sakrivenih i 1655 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 20624 - dana 04 Apr 2026 04:18

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: airliners, Aleksa 3215, boj.an, Boris.A, boromir, cekic, croato, Deki Duga Devetka, doom83, ghoost, Ikica977, IvanMiletic, Joint Chief, Krin, kybonacci, littlebunny, Mane88, marsi, Metanoja, Mihailo Gazdić, milos97, N.e.m.a.nj.a., Naj-Turs, Natuzzi, nelezele, nixos, ormanj, Radula, shone34, sony771, Tumansky, vaso1, Woya, zil10, zlaya011