[helen1]Trojanac - potrebna pomoć

2

[helen1]Trojanac - potrebna pomoć

offline
  • Brok  Male
  • Moderator foruma
  • Mihajlo Bogdanović
  • Linux driver - fighter - warrior
  • Pridružio: 04 Maj 2005
  • Poruke: 3270
  • Gde živiš: u gradu Kraljeva

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:21:54, on 24.9.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SRPSKEY.EXE
C:\Program Files\ClocX\ClocX.exe
C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\FastStone Capture\FSCapture.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Documents and Settings\Administrator\Desktop\Nova fascikla\TR3.exe..exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [Link mogu videti samo ulogovani korisnici]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [Link mogu videti samo ulogovani korisnici]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [Link mogu videti samo ulogovani korisnici]
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = [Link mogu videti samo ulogovani korisnici]*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
R3 - URLSearchHook: (no name) - {e0c7b854-d5ce-4db6-9804-be1438603d89} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O4 - HKLM\..\Run: [srpskey] C:\WINDOWS\SYSTEM32\SRPSKEY.EXE
O4 - HKLM\..\Run: [ClocX] C:\Program Files\ClocX\ClocX.exe
O4 - HKLM\..\Run: [SmartRAM] C:\Program Files\IObit\Advanced WindowsCare V2\MemCleaner.exe /m
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: FastStone Capture.lnk = C:\Program Files\FastStone Capture\FSCapture.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
O24 - Desktop Component 0: (no name) - [Link mogu videti samo ulogovani korisnici]

--
End of file - 5052 bytes



offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8628
  • Gde živiš: Novi Beograd

Log je cist. Nema vise znakova malwera.

Uradi jos ovo:


Klikni START a zatim RUN
U liniju za unos teksta ukucaj Combofix /u i klikni OK





Sačekaj da se proces deinstalacije završi

Gornja procedura će:
Obrisati sledeće:
ComboFix i njegove file-ove i foldere
VundoFix Backups folder, ako postoji
C:\Deckard folder, ako postoji
C:\OtMoveIt folder, ako postoji

Resetovati podešavanja sata na kompjuteru
Sakriti ekstenzije file-ova, ako je potrebno
Sakriti sistemske/skrivene file-ove/foldere, ako je potrebno
Resetovati System Restore




Sto se tice ikonice, probaj ovo:

Control Panel > System: na Advanced tabu, Performanse Settings: čekirati Use drop shadows for icon labels on the desktop.

Mozda pomogne. Nemam te probleme pa ne znam.


Pozzzz



offline
  • Brok  Male
  • Moderator foruma
  • Mihajlo Bogdanović
  • Linux driver - fighter - warrior
  • Pridružio: 04 Maj 2005
  • Poruke: 3270
  • Gde živiš: u gradu Kraljeva

Odradio sam sve, kada sam restartovao dok si proveravao zadnji log, a i sada, radi sve kao i ranije pre trojanca, ako ne i bolje. Sredio sam i ovo sa ikonicama, do duše na drugi način, ali sve je Ok.

E sada bar meni ide onaj najneprijatniji deo Embarassed , od hvala nemaš nešto posebno, a ja ne znam kako da ti se odužim. Imaš moj nik ili e-mail pa ako nešto zatreba, znaj da možeš računati na mene.


Na kraju hvala ti puno helen1 i živeo. Very Happy

offline
  • helen1  Male
  • Anti Malware Fighter
    Rank 2
  • Master učitelj
  • Pridružio: 27 Avg 2005
  • Poruke: 8628
  • Gde živiš: Novi Beograd

Taxista ::a ja ne znam kako da ti se odužim. Imaš moj nik ili e-mail pa ako nešto zatreba, znaj da možeš računati na mene.


Na kraju hvala ti puno helen1 i živeo. Very Happy


Meni je dovoljno samo da mi kazes i hvala Wink


Ziveli

Ko je trenutno na forumu
 

Ukupno su 2003 korisnika na forumu :: 116 registrovanih, 16 sakrivenih i 1871 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 5253 - dana 09 Dec 2025 16:26

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: -[CoA]-, 4thFlavian, AleksandarFKS, alex71, amaterSRB, AndrejPetar, Aristotle2002, Avalon015, B61, Bbbggg1979, Ben Roj, boj.an, bokisha253, bpop, BraneS, Branko Matić, BrcakRS, Cirkon, DavidA, Demi87, Denaya, Despot Đurađ, Dogma21, doktor097, DonRumataEstorski, drgrozozo, Duh sa sekirom, dzada, Ervin19955, EXIT78, g_g, gajasvi, GeoM, gobrad, goxin, gradimirb, Hardenberg, Hemi, iceburn, In_hero, Insan, Iskander, ISOF, Jager715510, jodzula, Jonbonjovi, Jose, Jozo74, Još malo pa deda, kaskadija, Kawasaki1000, Kobrim, Kurgan, kybonacci, ladro, lcc, Lester Freamon, ljuba, ljubo70, Maki1981, mexo, miki kv, Miki281, milenko crazy north, mir juzni, mishkooo, mist-mist, mnn2, morava_01, mrav pesadinac, nebkv, Nemanja.M, nenad81, nick79, nikolabb, Nole, opt1, orah, Orc, Orlova, Otto Grunf, Peruta, Pilence, Polifon, Povratak1912, precan, proka89, Prometeus, Razdroid, rednap, repac, royst33, rr559, Smajser, Srle993, Srpska zauvjek, stefanmpurtic, strn, TRZH92, Tumansky, Vanderx, vargas, VBoss, Velibor Radoja, Visionary, vladaa012, Vlado82, VonDrobac, vukovi, Wepp, zivojin32, Zoca, Zoran1959, Zorge, zubri, 79693