zakachio ZLOB(molim pomoc)

zakachio ZLOB(molim pomoc)

offline
  • Nikola Radukic
  • Pridružio: 02 Avg 2007
  • Poruke: 37
  • Gde živiš: The City of Nis

svi znamo kako ZLOB ulazi na PC.moja nesreca je u tome sto je u pitanju racunar na poslu.instalirao sam kasperski 6.0 nesto je skinuo ali ne sve.pojavljuje mi se ikonica u tool bar sistem alert.....
probao sam i ad aware, spydoctor,spybot....
probao sam da direktno iz registara brishem sumnjive fajlove ali ima ih mnogo.
any sugestions?-(



offline
  • Dusan  Male
  • SuperModerator
  • Supermoderator opštih foruma
  • Pridružio: 26 Jul 2006
  • Poruke: 11118

nradukic@
Uštedi si vreme i pregledaj:
[Link mogu videti samo ulogovani korisnici]
uradi po uputstvu, pa će ti se javiti neko od naših doktora, čim bude slobodan... Wink



offline
  • Nikola Radukic
  • Pridružio: 02 Avg 2007
  • Poruke: 37
  • Gde živiš: The City of Nis

Logfile of HijackThis v1.99.1
Scan saved at 14:07:45, on 2.8.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\POP Peeper\POPPeeper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Laza\Desktop\victory\tr3.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Crypkey License - Unknown owner - C:\WINDOWS\SYSTEM32\crypserv.exe

offline
  • DEMIAN  Male
  • Legendarni građanin
  • IT Manager
  • Pridružio: 25 Mar 2005
  • Poruke: 3706
  • Gde živiš: The darkest place on earth..

Zdravo nradukic,
Isprati samo ovo uputstvo koje sam ti postovao ispod. Kada budem video log programa SmitfraudFix reći ću ti da li eventualno ima potrebe za još nekom intervencijom..
-----------------------------------

1) Preuzmi program SmitfraudFix sa ovog linka.

2.) Extract-uj program na desktop. (Takodje na ovaj način pripremi i program Hijack This koje će se kasnije koristiti)

3.) Restartuj računar i podigni sistem u Safe Mode-u. [ Safe Mode info link

4.) Pronadji na desktop-u folder gde si raspakovao SmitfraudFix program i dvoklikom pokreni fajl SmitfraudFix.cmd.
Kada se alat za uklanjanje prvi put startuje pokazaće ti se ekran za odobrenje. Jednostavno pretisni bilo koje dugme na tastaturi da bi prešao na sledeći nivo.

5.)



6.) Program će početi sa čišćenjem kompjutera. Posle završenog čišćenja SmitfraudFix-om
pokrenuće ti se Windows-ov program Disk Cleanup.



Nakon sto SmitFraudFix zavrsi svoj posao, postavi nam ovde log koji se nalazi na C:\rapport.txt i svez HJT log.

offline
  • Nikola Radukic
  • Pridružio: 02 Avg 2007
  • Poruke: 37
  • Gde živiš: The City of Nis

Logfile of HijackThis v1.99.1
Scan saved at 8:34:40, on 3.8.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\POP Peeper\POPPeeper.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Laza\Desktop\nikolini programi\victory\tr3.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [POP Peeper] "C:\Program Files\POP Peeper\POPPeeper.exe" -min
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - [Link mogu videti samo ulogovani korisnici]\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O17 - HKLM\System\CS1\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O17 - HKLM\System\CS2\Services\Tcpip\..\{36F12772-8225-4B4C-AD26-F7311DA3265E}: NameServer = 82.117.194.2,82.117.194.3
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Crypkey License - Unknown owner - C:\WINDOWS\SYSTEM32\crypserv.exe

problem je resen Hvala

Ko je trenutno na forumu
 

Ukupno su 2648 korisnika na forumu :: 90 registrovanih, 8 sakrivenih i 2550 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 4719 - dana 07 Dec 2025 13:00

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: acatomic, Agape, alex71, alexbr, Apok, bankulen, Belac91, Bobrock1, Bombarder, boracbl1389, Boris BM, borya90, Chainsaw, cifra, darkkran, dekan.m, Despot Đurađ, Dimitrije Paunovic, Dimitrise93, Dioniss, draganl, dukajov, Electron, ElvisP, galerija, gomago, Hans Gajger, ikan, Jaxupa, jeen yuhs, jodzula, K a s p e r, Kajzer Soze, Kawasaki1000, KimiMR, Kontrausluga, korin911, lacko, ladro, Leonov, Lep1na, Litostroton, ljuba, Ljusa, lord sir giga, Lucije Kvint, Malahit, mat, Mcdado, mexo, milan radosavljevic, milutin134, Niki2024, niksa517, nobutado, Paklenica, Papadubi, pceklic, Pekman, Peruta, Prečanin30, proka89, RajkoB, raso76, rodoljub, Romibrat, sajorg, samocitam, sasa87, Scarecrow994, Sevatar, starlights, stegonosa, Tomo988, tooljan, vathra, Velizar Laro, veljkovicdani, vensla, vidra boy, vjetar, Vlada1389, Vlada78, vuksa72, x011, Yekaterinburg, yrraf, zillbg, zubri, ZZZ