HijackThis - izvestaj posle skeniranja - molim objasnjenje?

samo da pitam jednu stvar, da li su ovo virusi ili koja god vrsta gamadi (sto mi je toske1 rekao da kopiram u beli prozor onog programa):

Kod:
Files to delete:
c:\windows\system32\drivers\av5flt.sys
c:\program files\dealio\DealioAU.exe
c:\program files\search settings\SearchSettings.exe

Drivers to delete:
AvFlt

Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run | SearchSettings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run | au
 
Nema na cemu,evo ti jos jedan program da jos jednom prodjes citav sistem:Spybot - Search & Destroy
http://www.safer-networking.org/en/index.html

instalirala sam ga jos juce, i skenirala sa njim par puta, dva-tri puta mi je nasao neke cookies i tracing, tako nesto, imam i izvestaje, ali nakon treceg-cetvrtog skeniranja mi nije nista vise nasao (naravno, ove pre sto mi je nalazio sam zadala da obrise)
 
Evo izvestaja od Avengera:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: file "c:\windows\system32\drivers\av5flt.sys" not found!
Deletion of file "c:\windows\system32\drivers\av5flt.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "c:\program files\dealio\DealioAU.exe"
Deletion of file "c:\program files\dealio\DealioAU.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: could not open file "c:\program files\search settings\SearchSettings.exe"
Deletion of file "c:\program files\search settings\SearchSettings.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist


Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\AvFlt" not found!
Deletion of driver "AvFlt" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run|SearchSettings"
Deletion of registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run|SearchSettings" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run|au"
Deletion of registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run|au" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.
 
Nesto nije odradjeno kako treba. Ok idemo na drugu varijantu. Molim te da pazljivo i precizno uradis kako sam napisao, znaci tacno tako.

Skini ovaj program na desktop http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Iskljuci Avasta, desni klik na ikonicu pored sata, pa iskljuci stalnu zastitu.
Pokreni Combofix sa desktopa.
Odgovori potvrdno za sve sto te pita, znaci yes ili ok.
Kad zavrsi skeniranje izbacice ti log koji ces mi kopirati ovde.

Nista ne cackaj dok ovaj program radi, samo radi po uputstvu.
Log mozes da zakacis tako sto imas iznad prozora za odgovor znak spajalice i pise prilozi. Tako ga postavis kao attachment.
 
Poslednja izmena:
To je to ali nije ceo log. Ovako ti si skinula Combofix, nalazi se negde na tvom racunaru, znaci ja ne znam gde ga skidas kad ides preko Firefoxa recimo
Prebaci ga na desktop i odatle ga pokreni. To je veoma vazno. Drugo, imad dva antivirusa, Kaspersky i Avast, jedan ces morati da deinstaliras obavezno, zato i nije odradiop kako treba, jer je jedan antivirus obrisao neku komponentu combofixa. Plus imala si ostatke od Pande antivirusa koji sam ja hteo da uklonim. Dva antivirusa na kompu i moze da ti padne sistem, to je veoma opasno.
Znaci da rezimiramo, deinstaliraj jedan koji hoces pa tek onda drugi iskljuci i pokreni Combofix sa desktopa. Razumela?

C:\Documents and Settings\Jelena i Jovana\My Documents\Downloads\ComboFix.exe

evo gde ga skida, znaci tu ga obrisi i prebaci na desktop i odatle pokreni.

Pazi ovo

AV: avast! antivirus 4.8.1356 [VPS 091118-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: ESET Personal firewall *disabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

Da li si deinstalirala ove antiviruse ili ne, znaci tri komada, plus onaj drajver koji je bio aktivan od Pande.
 
Poslednja izmena:

Back
Top