Virusi - komp zablokirao

2

Virusi - komp zablokirao

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Napisano: 27 Jun 2009 21:09

Ne mogu da ga pokrenem, jedino da uradim preko safe moda i sa Hijack Thisom- ako moze.

Dopuna: 27 Jun 2009 21:28

mycity.rs/must-login.png

Evo preko safe moda sta sam dobio sa Hijack Thisom-tu je izvestaj

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:21:06, on 27.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 191.192.59.33 anubis.iseclab.org
O1 - Hosts: 130.61.228.180 threatexpert.com
O1 - Hosts: 253.234.138.98 threatexpert.com
O1 - Hosts: 17.59.9.63 cwsandbox.org
O1 - Hosts: 252.243.134.189 cwsandbox.org
O1 - Hosts: 111.87.4.51 u20.eset.com
O1 - Hosts: 37.157.120.122 u21.eset.com
O1 - Hosts: 205.133.17.231 u22.eset.com
O1 - Hosts: 46.122.233.228 u23.eset.com
O1 - Hosts: 46.142.212.218 u24.eset.com
O1 - Hosts: 77.100.124.93 u30.eset.com
O1 - Hosts: 161.39.128.31 u31.eset.com
O1 - Hosts: 115.188.84.50 u32.eset.com
O1 - Hosts: 6.88.129.33 u33.eset.com
O1 - Hosts: 29.252.20.77 u34.eset.com
O1 - Hosts: 100.57.201.190 u35.eset.com
O1 - Hosts: 49.147.100.177 u36.eset.com
O1 - Hosts: 211.245.27.41 u37.eset.com
O1 - Hosts: 107.151.148.70 u38.eset.com
O1 - Hosts: 111.169.111.29 u39.eset.com
O1 - Hosts: 96.74.61.112 u40.eset.com
O1 - Hosts: 221.6.232.223 u41.eset.com
O1 - Hosts: 8.100.128.134 u42.eset.com
O1 - Hosts: 105.76.83.28 u43.eset.com
O1 - Hosts: 222.185.209.7 u44.eset.com
O1 - Hosts: 36.149.183.128 u45.eset.com
O1 - Hosts: 16.39.82.40 u46.eset.com
O1 - Hosts: 157.106.0.183 u47.eset.com
O1 - Hosts: 187.210.56.48 u48.eset.com
O1 - Hosts: 171.46.169.170 u49.eset.com
O1 - Hosts: 61.193.206.169 f-secure.com
O1 - Hosts: 193.211.5.151 symantec.com
O1 - Hosts: 15.176.250.213 127.99.45.207
O1 - Hosts: 212.231.10.242 virusscan.jotti.org
O1 - Hosts: 53.201.215.2 download.ahnlab.com
O1 - Hosts: 81.106.187.159 msn.ahnlab.com
O1 - Hosts: 192.37.98.159 acc.pdbox.co.kr
O1 - Hosts: 166.117.152.112 pcsafe.hanafos.com
O1 - Hosts: 89.149.180.48 viruschaser.com
O1 - Hosts: 85.182.158.126 viruschaser.com
O1 - Hosts: 223.205.77.132 info.ahnlab.com
O1 - Hosts: 159.57.91.75 v.chol.com
O1 - Hosts: 24.76.108.199 securitycenter.co.kr
O1 - Hosts: 55.120.147.187 securitycenter.co.kr
O1 - Hosts: 237.32.123.92 sandbox.norman.com
O1 - Hosts: 137.81.237.210 norman.com
O1 - Hosts: 60.118.138.134 sandbox.norman.no
O1 - Hosts: 145.177.63.78 norman.no
O1 - Hosts: 177.250.92.236 norman.no
O1 - Hosts: 194.169.211.6 kaspersky.pl
O1 - Hosts: 187.140.250.223 kaspersky.pl
O1 - Hosts: 252.60.88.36 kaspersky.telechargement.fr
O1 - Hosts: 6.183.102.123 kaspersky.telechargement.fr
O1 - Hosts: 20.140.198.41 kaspersky.de
O1 - Hosts: 229.212.110.59 kaspersky.co.nz
O1 - Hosts: 170.183.93.93 kaspersky.co.nz
O1 - Hosts: 254.175.4.209 kaspersky-antivirus.dk
O1 - Hosts: 101.126.146.38 kaspersky-antivirus.dk
O1 - Hosts: 85.174.67.40 kaspersky-me.com
O1 - Hosts: 18.117.43.133 kaspersky-me.com
O1 - Hosts: 11.198.34.251 kaspersky.co.uk
O1 - Hosts: 171.20.31.157 kaspersky.co.uk
O1 - Hosts: 199.130.148.45 kaspersky.com.au
O1 - Hosts: 179.148.169.23 kaspersky.com.au
O1 - Hosts: 154.18.220.21 kasperskyusa.com
O1 - Hosts: 160.169.101.104 kasperskyusa.com
O1 - Hosts: 119.29.238.199 agnitum.com
O1 - Hosts: 219.116.118.116 agnitum.com
O1 - Hosts: 54.240.101.141 smb.sygate.com
O1 - Hosts: 203.95.66.124 vic.zonelabs.com
O1 - Hosts: 175.115.126.191 download.zonelabs.com
O1 - Hosts: 121.58.191.80 zonelabs.com
O1 - Hosts: 222.238.180.103 zonelabs.com
O1 - Hosts: 186.167.75.233 freebyte.com
O1 - Hosts: 156.43.92.184 freebyte.com
O1 - Hosts: 241.101.24.187 bitdefender.com
O1 - Hosts: 223.84.89.204 bitdefender.com
O1 - Hosts: 219.85.161.102 virus-radar.com
O1 - Hosts: 154.51.94.65 virus-radar.com
O1 - Hosts: 236.224.65.180 nod32.com
O1 - Hosts: 26.55.198.22 nod32.com
O1 - Hosts: 197.170.191.225 avg-antivirus.net
O1 - Hosts: 133.204.236.227 avg-antivirus.net
O1 - Hosts: 168.141.3.60 antivirus.about.com
O1 - Hosts: 216.10.168.225 vet.com.au
O1 - Hosts: 142.236.201.142 vet.com.au
O1 - Hosts: 136.160.201.54 avgbulgaria.com
O1 - Hosts: 196.87.243.223 avgbulgaria.com
O1 - Hosts: 30.46.176.160 windowsupdate.microsoft.com
O1 - Hosts: 23.115.95.251 update.microsoft.com
O1 - Hosts: 114.76.232.232 virusbtn.com
O1 - Hosts: 22.68.207.79 virusbtn.com
O1 - Hosts: 243.129.228.39 drsolomon.com
O1 - Hosts: 221.181.234.26 drsolomon.com
O1 - Hosts: 254.241.185.86 teamanti-virus.org
O1 - Hosts: 247.128.67.102 teamanti-virus.org
O1 - Hosts: 63.110.117.187 virustotal.com
O1 - Hosts: 75.90.111.86 virustotal.com
O1 - Hosts: 44.72.124.151 microsoft.com
O1 - Hosts: 150.116.186.65 microsoft.com
O1 - Hosts: 5.78.218.32 cert.org
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 9507 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Pokreni HJT ponovo, stikliraj kvadratice pored sledecih linija:

O1 - Hosts: 191.192.59.33 anubis.iseclab.org
O1 - Hosts: 130.61.228.180 www.threatexpert.com
O1 - Hosts: 253.234.138.98 threatexpert.com
O1 - Hosts: 17.59.9.63 cwsandbox.org
O1 - Hosts: 252.243.134.189 www.cwsandbox.org
O1 - Hosts: 111.87.4.51 u20.eset.com
O1 - Hosts: 37.157.120.122 u21.eset.com
O1 - Hosts: 205.133.17.231 u22.eset.com
O1 - Hosts: 46.122.233.228 u23.eset.com
O1 - Hosts: 46.142.212.218 u24.eset.com
O1 - Hosts: 77.100.124.93 u30.eset.com
O1 - Hosts: 161.39.128.31 u31.eset.com
O1 - Hosts: 115.188.84.50 u32.eset.com
O1 - Hosts: 6.88.129.33 u33.eset.com
O1 - Hosts: 29.252.20.77 u34.eset.com
O1 - Hosts: 100.57.201.190 u35.eset.com
O1 - Hosts: 49.147.100.177 u36.eset.com
O1 - Hosts: 211.245.27.41 u37.eset.com
O1 - Hosts: 107.151.148.70 u38.eset.com
O1 - Hosts: 111.169.111.29 u39.eset.com
O1 - Hosts: 96.74.61.112 u40.eset.com
O1 - Hosts: 221.6.232.223 u41.eset.com
O1 - Hosts: 8.100.128.134 u42.eset.com
O1 - Hosts: 105.76.83.28 u43.eset.com
O1 - Hosts: 222.185.209.7 u44.eset.com
O1 - Hosts: 36.149.183.128 u45.eset.com
O1 - Hosts: 16.39.82.40 u46.eset.com
O1 - Hosts: 157.106.0.183 u47.eset.com
O1 - Hosts: 187.210.56.48 u48.eset.com
O1 - Hosts: 171.46.169.170 u49.eset.com
O1 - Hosts: 61.193.206.169 f-secure.com
O1 - Hosts: 193.211.5.151 symantec.com
O1 - Hosts: 15.176.250.213 127.99.45.207
O1 - Hosts: 212.231.10.242 virusscan.jotti.org
O1 - Hosts: 53.201.215.2 download.ahnlab.com
O1 - Hosts: 81.106.187.159 msn.ahnlab.com
O1 - Hosts: 192.37.98.159 acc.pdbox.co.kr
O1 - Hosts: 166.117.152.112 pcsafe.hanafos.com
O1 - Hosts: 89.149.180.48 viruschaser.com
O1 - Hosts: 85.182.158.126 www.viruschaser.com
O1 - Hosts: 223.205.77.132 info.ahnlab.com
O1 - Hosts: 159.57.91.75 v.chol.com
O1 - Hosts: 24.76.108.199 securitycenter.co.kr
O1 - Hosts: 55.120.147.187 www.securitycenter.co.kr
O1 - Hosts: 237.32.123.92 sandbox.norman.com
O1 - Hosts: 137.81.237.210 norman.com
O1 - Hosts: 60.118.138.134 sandbox.norman.no
O1 - Hosts: 145.177.63.78 norman.no
O1 - Hosts: 177.250.92.236 www.norman.no
O1 - Hosts: 194.169.211.6 kaspersky.pl
O1 - Hosts: 187.140.250.223 www.kaspersky.pl
O1 - Hosts: 252.60.88.36 www.kaspersky.telechargement.fr
O1 - Hosts: 6.183.102.123 kaspersky.telechargement.fr
O1 - Hosts: 20.140.198.41 kaspersky.de
O1 - Hosts: 229.212.110.59 kaspersky.co.nz
O1 - Hosts: 170.183.93.93 www.kaspersky.co.nz
O1 - Hosts: 254.175.4.209 kaspersky-antivirus.dk
O1 - Hosts: 101.126.146.38 www.kaspersky-antivirus.dk
O1 - Hosts: 85.174.67.40 kaspersky-me.com
O1 - Hosts: 18.117.43.133 www.kaspersky-me.com
O1 - Hosts: 11.198.34.251 kaspersky.co.uk
O1 - Hosts: 171.20.31.157 www.kaspersky.co.uk
O1 - Hosts: 199.130.148.45 kaspersky.com.au
O1 - Hosts: 179.148.169.23 www.kaspersky.com.au
O1 - Hosts: 154.18.220.21 www.kasperskyusa.com
O1 - Hosts: 160.169.101.104 kasperskyusa.com
O1 - Hosts: 119.29.238.199 agnitum.com
O1 - Hosts: 219.116.118.116 www.agnitum.com
O1 - Hosts: 54.240.101.141 smb.sygate.com
O1 - Hosts: 203.95.66.124 vic.zonelabs.com
O1 - Hosts: 175.115.126.191 download.zonelabs.com
O1 - Hosts: 121.58.191.80 zonelabs.com
O1 - Hosts: 222.238.180.103 www.zonelabs.com
O1 - Hosts: 186.167.75.233 freebyte.com
O1 - Hosts: 156.43.92.184 www.freebyte.com
O1 - Hosts: 241.101.24.187 www.bitdefender.com
O1 - Hosts: 223.84.89.204 bitdefender.com
O1 - Hosts: 219.85.161.102 www.virus-radar.com
O1 - Hosts: 154.51.94.65 virus-radar.com
O1 - Hosts: 236.224.65.180 www.nod32.com
O1 - Hosts: 26.55.198.22 nod32.com
O1 - Hosts: 197.170.191.225 avg-antivirus.net
O1 - Hosts: 133.204.236.227 www.avg-antivirus.net
O1 - Hosts: 168.141.3.60 antivirus.about.com
O1 - Hosts: 216.10.168.225 vet.com.au
O1 - Hosts: 142.236.201.142 www.vet.com.au
O1 - Hosts: 136.160.201.54 avgbulgaria.com
O1 - Hosts: 196.87.243.223 www.avgbulgaria.com
O1 - Hosts: 30.46.176.160 windowsupdate.microsoft.com
O1 - Hosts: 23.115.95.251 update.microsoft.com
O1 - Hosts: 114.76.232.232 virusbtn.com
O1 - Hosts: 22.68.207.79 www.virusbtn.com
O1 - Hosts: 243.129.228.39 drsolomon.com
O1 - Hosts: 221.181.234.26 www.drsolomon.com
O1 - Hosts: 254.241.185.86 teamanti-virus.org
O1 - Hosts: 247.128.67.102 www.teamanti-virus.org
O1 - Hosts: 63.110.117.187 virustotal.com
O1 - Hosts: 75.90.111.86 www.virustotal.com
O1 - Hosts: 44.72.124.151 microsoft.com
O1 - Hosts: 150.116.186.65 www.microsoft.com
O1 - Hosts: 5.78.218.32 cert.org


i klikni FIX CHECKED pa mi postavi novi log.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Uradio sam i to pa pogledaj
mycity.rs/must-login.png

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:23, on 28.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 avast.com
O1 - Hosts: 88.99.250.80 free-av.com
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 clamav.net
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 grisoft.com
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 vsantivirus.com
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 pc-cillin.com
O1 - Hosts: 16.221.14.52 pandasoftware.com
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 trendmicro-europe.com
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 nai.com
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 my-etrust.com
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 shopmcafee.com
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 mcafeestore.com
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 ca.com
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 networkassociates.com
O1 - Hosts: 186.174.95.178 kaspersky.com
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 avp.com
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 f-prot.com
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 f-secure.com
O1 - Hosts: 246.222.19.250 f-secure.de
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 viruslist.com
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 mcafee.com
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 sophos.com
O1 - Hosts: 65.230.118.207 sarc.com
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 symantecstore.com
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 symantec.com
O1 - Hosts: 69.57.192.16 trendmicro.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 8670 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Slabo napredujemo, ali imaj nade Wink

I sledeci put mi ovde kopiraj/nalepi log, nemoj ga uploadovati.

Pokreni HJT, skeniraj i stikliraj sledece kvadratice:

O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 www.avast.com
O1 - Hosts: 88.99.250.80 www.free-av.com
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 www.clamav.net
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 www.grisoft.com
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 www.vsantivirus.com
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 www.pc-cillin.com
O1 - Hosts: 16.221.14.52 www.pandasoftware.com
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 www.trendmicro-europe.com
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 www.nai.com
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 www.my-etrust.com
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 www.shopmcafee.com
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 www.mcafeestore.com
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 www.ca.com
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 www.networkassociates.com
O1 - Hosts: 186.174.95.178 www.kaspersky.com
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 www.avp.com
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 www.f-prot.com
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 www.f-secure.com
O1 - Hosts: 246.222.19.250 www.f-secure.de
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 www.viruslist.com
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 www.mcafee.com
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 www.sophos.com
O1 - Hosts: 65.230.118.207 www.sarc.com
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 www.symantecstore.com
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 www.symantec.com
O1 - Hosts: 69.57.192.16 www.trendmicro.com
O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Klikni FIX checked.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

ne mogu da ga prekopiram ovde zato sto ja ne mogu nista da otvorim u kompu osim interneta,a sa HJT radim u safe modu, pa posto restartujem komp ja ti samo uploadujem log ne znam da li tako odgovara da nastavim i sa ovim ili sta vec da radim?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Onda tako nastavi uz malu ispravku:

Skini program sa ovog sajta: http://www.funkytoad.com/download/HostsXpert.zip?2.....2ea2384fd7

Pokreni HostsXpert

Klikni na Restore MS Hosts File pa Ok
Zatim klikni na Make Writable (ako je dostupan)
Zatvori program.

---------
Onda pokreni HJT i stikliraj sledece linije:

O4 - HKLM\..\Run: [run32] C:\Win\lsass.exe
O4 - HKLM\..\Run: [Microsoft Update] msnmsgrs.exe
O4 - HKLM\..\Run: [Windows Dynamic Library Cache] dllcache.exe
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld11.exe
O4 - HKLM\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O4 - HKCU\..\Policies\Explorer\Run: [Windows Logon Servicer] "C:\Documents and Settings\Sandra\Application Data\WinNT\winlogon.exe"
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Klikni FIX checked.

i postavi mi log kako mozes.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Sa HostXpert-om nisam uspeo nista uraditi nisam imao nigde ikonice za restore ms Host File a na Make Writable je zakljucan.

Uradio sam ovo sa HJT
mycity.rs/must-login.png

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:53, on 28.6.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Sandra\Desktop\pomoc\TR3.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe,c:\windows\system32\wscript.exe
O1 - Hosts: 134.172.12.13 avast.com
O1 - Hosts: 197.82.58.75 avast.com
O1 - Hosts: 88.99.250.80 free-av.com
O1 - Hosts: 189.74.85.4 free-av.com
O1 - Hosts: 251.49.181.245 clamav.net
O1 - Hosts: 73.33.35.208 clamav.net
O1 - Hosts: 245.147.91.175 grisoft.com
O1 - Hosts: 4.236.145.47 grisoft.com
O1 - Hosts: 170.45.2.249 free.grisoft.com
O1 - Hosts: 173.213.140.11 vsantivirus.com
O1 - Hosts: 70.206.139.250 vsantivirus.com
O1 - Hosts: 19.195.156.13 pc-cillin.com
O1 - Hosts: 49.77.8.189 pc-cillin.com
O1 - Hosts: 16.221.14.52 pandasoftware.com
O1 - Hosts: 23.176.168.172 pandasoftware.com
O1 - Hosts: 32.92.45.200 trendmicro-europe.com
O1 - Hosts: 125.163.64.111 de.trendmicro-europe.com
O1 - Hosts: 117.44.16.147 nl.trendmicro-europe.com
O1 - Hosts: 107.196.86.140 trendmicro-europe.com
O1 - Hosts: 175.88.115.107 housecall65.trendmicro.com
O1 - Hosts: 30.183.76.218 housecall.trendmicro.com
O1 - Hosts: 147.208.33.17 trendmicro.com
O1 - Hosts: 81.18.13.75 download.mcafee.com
O1 - Hosts: 223.247.109.223 rads.mcafee.com
O1 - Hosts: 146.20.80.246 mcafee.net
O1 - Hosts: 38.132.63.197 us.mcafee.com
O1 - Hosts: 44.174.236.9 update.symantec.com
O1 - Hosts: 189.175.46.14 updates.symantec.com
O1 - Hosts: 153.219.61.114 vil.nai.com
O1 - Hosts: 61.184.170.5 nai.com
O1 - Hosts: 140.202.140.106 nai.com
O1 - Hosts: 144.178.55.95 secure.nai.com
O1 - Hosts: 131.213.32.74 dispatch.mcafee.com
O1 - Hosts: 14.39.54.247 my-etrust.com
O1 - Hosts: 243.199.71.40 my-etrust.com
O1 - Hosts: 44.133.194.88 shopmcafee.com
O1 - Hosts: 254.252.121.86 shopmcafee.com
O1 - Hosts: 62.100.152.32 mcafeestore.com
O1 - Hosts: 51.66.143.157 mcafeestore.com
O1 - Hosts: 193.16.148.35 vil.mcafee.com
O1 - Hosts: 235.147.2.90 mcafeeasap.com
O1 - Hosts: 188.237.184.115 de.mcafee.comwww.mcafeeasap.com
O1 - Hosts: 48.162.189.89 cn.mcafee.com
O1 - Hosts: 172.41.76.34 tw.mcafee.com
O1 - Hosts: 43.176.4.18 uk.mcafee.com
O1 - Hosts: 9.56.128.101 no.mcafee.com
O1 - Hosts: 183.178.225.42 mx.mcafee.com
O1 - Hosts: 199.170.177.125 ca.mcafee.com
O1 - Hosts: 109.206.41.73 mast.mcafee.com
O1 - Hosts: 8.197.44.119 store.ca.com
O1 - Hosts: 208.163.15.57 ca.com
O1 - Hosts: 182.253.9.54 www3.ca.com
O1 - Hosts: 3.223.70.98 ca.com
O1 - Hosts: 83.46.152.204 networkassociates.com
O1 - Hosts: 11.42.52.12 networkassociates.com
O1 - Hosts: 186.174.95.178 kaspersky.com
O1 - Hosts: 172.218.49.111 avp.com
O1 - Hosts: 136.179.25.54 avp.com
O1 - Hosts: 77.131.95.31 kaspersky-labs.com
O1 - Hosts: 2.249.220.82 kaspersky.com
O1 - Hosts: 234.74.138.185 f-prot.com
O1 - Hosts: 153.208.190.68 f-prot.com
O1 - Hosts: 165.13.27.112 f-secure.com
O1 - Hosts: 246.222.19.250 f-secure.de
O1 - Hosts: 81.95.149.88 f-secure.de
O1 - Hosts: 156.203.47.213 viruslist.com
O1 - Hosts: 157.206.52.146 viruslist.com
O1 - Hosts: 142.43.78.170 liveupdate.symantecliveupdate.com
O1 - Hosts: 79.0.1.188 liveupdate.symantec.com
O1 - Hosts: 154.64.241.169 customer.symantec.com
O1 - Hosts: 4.17.15.185 mcafee.com
O1 - Hosts: 157.15.228.5 mcafee.com
O1 - Hosts: 8.214.185.195 sophos.com
O1 - Hosts: 227.184.191.110 sophos.com
O1 - Hosts: 65.230.118.207 sarc.com
O1 - Hosts: 158.173.8.101 sarc.com
O1 - Hosts: 158.103.187.69 service1.symantec.com
O1 - Hosts: 90.50.85.209 symantecstore.com
O1 - Hosts: 37.65.108.254 symantecstore.com
O1 - Hosts: 144.41.18.239 securityresponse.symantec.com
O1 - Hosts: 131.20.96.36 symantec.com
O1 - Hosts: 69.57.192.16 trendmicro.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll
O3 - Toolbar: iMesh MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
O4 - HKLM\..\Run: [VMonitorVMUVC] "C:\Program Files\Vimicro Corporation\VMUVC\VMonitor.exe" VMUVC
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [15881874] C:\Documents and Settings\All Users\Application Data\15881874\15881874.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [kell] C:\program Files\Manson\liser.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - Gopher Prefix:
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\MANSON\LISER.DLL C:\PROGRA~1\GOOGLE\GOOGLE~1\GOEC62~1.DLL,c:\progra~1\Manson\liser.dll
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

--
End of file - 8141 bytes

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Hajde sada probaj da skeniras u Normal modu sa HJT-om, RSIT-om.

offline
  • Dragan Đurašinović
  • Pridružio: 20 Dec 2008
  • Poruke: 82

Napisano: 28 Jun 2009 12:55

Ne mogu nista u Normal modu da uradim.

Dopuna: 28 Jun 2009 13:05

Hoces da u safe modu uradim sa RSIT

Sta sam ja ovo pokupio, kakav je ovo virus?

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8617
  • Gde živiš: Novi Beograd

Ovo skeniranje isto obavi u Safe Modu:

Preuzmi sUBs-ov ComboFix sa jedne od sledećih adresa na Desktop:


Bleeping Computer . . . . . Geeks to Go!
Klikni desnim tasterom na neki od linkova i odaberi opciju Save Target As... (Save Link As..., Save Linked Content As... ili sličnu);
Kada se otvori dijalog za izbor lokacije na kojoj treba sačuvati file, odaberi Desktop i klikni Save.




Kada preuzimanje programa bude završeno:
zatvori pokrenute programe;
deaktiviraj zaštitni softver (uputstvo);
dvoklikom pokreni program ComboFix.

U toku rada, ComboFix će:proveriti postoji li novija verzija programa:
klikni Yes ako bude ponuđeno preuzimanje iste.
prikazati DISCLAIMER OF WARRANTY ON SOFTWARE:
klikni Yes kako bi proces bio nastavljen.
ako Recovery Console nije instalirana, ponuditi instalaciju:
prihvati klikom na Yes i isprati postupak.
postaviti/dati određeni broj upita/obaveštenja:
prihvati klikom na Yes ili OK.
po potrebi, restartovati Windows (više puta);
na kraju rada, otvoriti Notepad sa izveštajem o skeniranju.


Iskopiraj izveštaj koji je ComboFix napravio u temu na forumu:
klikni desnim tasterom miša u prozor Notepad-a i izaberi Select All;
klikni desnim tasterom miša na obeleženi tekst i izaberi Copy;
klikni desnim tasterom miša u polje za pisanje poruke i izaberi Paste.


Napomena:Izveštaj će biti sačuvan pod nazivom ComboFix.txt na sistemskoj particiji (tipična lokacija: C:\ComboFix.txt);
Ukoliko nakon slanja poruke primetiš da izveštaj nije kompletan, iskoristi opciju Prikači fajl za prilaganje file-a C:\ComboFix.txt uz poruku.

Ko je trenutno na forumu
 

Ukupno su 968 korisnika na forumu :: 15 registrovanih, 2 sakrivenih i 951 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Aleksandar Tomić, bbogdan, comi_pfc, Dannyboy, djboj, Djokislav, esx66, kolle.the.kid, Lazarus, Milos82, Mixelotti, nuke92, operniki, procesor, 125