Nisam u toku, kakav problem je u pitanju? Da ne trazim sad unazad, ako moze ukratko, o cemu se radi.
Donji video prikazuje kako da instalirate aplikaciju na početni ekran svog uređaja.
Napomena: This feature may not be available in some browsers.
Secam se.A zar nisi rekla da ces formatirati?
![]()
Ne znam sta bi mogla...Jedino da probas combofix, mozda bi mogao da pomogne, ali sa njim bas i ne radim..
Kad bi se kolega toske1 javio..
Nisam u toku, kakav problem je u pitanju? Da ne trazim sad unazad, ako moze ukratko, o cemu se radi.
...
Prvo je kompjuter počeo da mi se restartira bezveze, u toku rada.
Onda sam uključila antivirusni program i on bi mi pokazao prisutnost Exploit.PDF-JS.Gen, ali ne bi završio proces nego bi se kompjuter nakon nekog vremena ponovo restartirao. Taj antivirusni program se zove CounterSpy i iako sam ga ja stavila kao anti-spyware program drugi antivirusni programi (koje sam stavila kasnije) su ga kasnije prepoznali kao Vipre antivirus. Jednom ili dvaput (od desetak puta koliko sam pokretala taj antivirusni program) skeniranje je završeno do kraja i nije pokazivalo ništa, ali bi se već pri slijedećem skeniranju (što sam uvijek činila da bih provjerila da je konačno sve u redu) ponovo restartirao.
Inače uz CounterSpy sam imala instaliran i Norton, ali s Nortonom bi se nakon nekog vremena od uključivanja kompjuter restartirao i to je sve.
Onda sam promijenila 2 druga antivirusna programa (Avira i ESET Smart Security). Ni jedan ne može završiti skeniranje bez resetiranja kompjutera.
Onda sam došla na Krstaricu i pročitala onu temu dr Bore: Uputstvo za traženje pomoći oko problema vezanih za Malware (viruse, crve, adware...), učinila ono što kaže u toj temi, ali još uvijek bez rezultata...
...
Evo:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:11:26, on 19.12.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Advanced System Optimizer 3\systemprotector.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SystemProtector] "C:\Program Files\Advanced System Optimizer 3\systemprotector.exe" /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{20CD3C71-A12C-4EBB-8B9F-76A2AB3C1FD3}: NameServer = 85.114.32.7,85.114.32.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{20CD3C71-A12C-4EBB-8B9F-76A2AB3C1FD3}: NameServer = 85.114.32.7,85.114.32.8
O17 - HKLM\System\CS2\Services\Tcpip\..\{20CD3C71-A12C-4EBB-8B9F-76A2AB3C1FD3}: NameServer = 85.114.32.7,85.114.32.8
O17 - HKLM\System\CS3\Services\Tcpip\..\{20CD3C71-A12C-4EBB-8B9F-76A2AB3C1FD3}: NameServer = 85.114.32.7,85.114.32.8
O17 - HKLM\System\CS4\Services\Tcpip\..\{20CD3C71-A12C-4EBB-8B9F-76A2AB3C1FD3}: NameServer = 85.114.32.7,85.114.32.8
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASO3DiskOptimizer - Systweak Inc. - C:\Program Files\Advanced System Optimizer 3\ASO3DefragSrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
--
End of file - 7085 bytes
Log izgleda cist..jedino mozes ovo fixati R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
...
Ovaj HJT log mi deluje cisto, mozemo da napravimo jos jednu proveru sa programom DDS
Skini ga i pokreni http://download.bleepingcomputer.com/sUBs/dds.scr
Nista ne diraj dok odradi i na kraju klikni ok.
Zatim mi iskopiraj log pod nazivom DDS.txt (veliki log)
sve ukupno traje nepun minut.
Ugasi antivirus obavezno ...
Imas aktivan drajver od Zone Alarm-a sve jedno pokreni Combofix i postavi mi log, samo bez panike![]()
Koji antivirus si deinstalirala, imas Aviru, Kaspersky ..
nemoj nikad da imas vise od jednog antivirusa, prakticno ti je sistem pred padom.
Ne smem da ti petljam po sistemu, malware, nemas ali koliko si ti Antivirusa i antimalware programa koristila to je neverovatno.
Imala si i Nod i Norton.
Evo ti za Aviru cleaner http://dl.antivir.de/down/windows/registrycleaner_en.zip
Za Kasoersky http://support.kaspersky.com/downloads/utils/kavremover10.zip
Koristila si AdAware imas ostatke
Counterspy (ako koristis obrisi)
mbam
SUPERAntiSpyware
Advanced System Optimizer (deinstaliraj)
ComodoCleaner (deinstaliraj)
Ne znam da li sam neki omasio. Sve to instalira svoje drajvere i system ti je toliko opterecen da nije ni cudo da lose radi. ?
Deinstaliraj Combofix
Srat \ run \ Combofix /uninstall enter i sacekaj da se deinstalira.
Najbolje da skines posle svega CCleaner i lepo ocistis registry. Skini RevoUninstaler pa sa njim deinstaliraj gore navedene programe.
----------------------------------------------------------------
Mislim da ti se sada ne restartuje kom, da li sam u pravu?
pa mogu da budu neke druge stvari, ne mora da znaci da su virusi. a ne mozes, odnosno, mozes da imas 2 antivirusa, ali onda puca sistem. jedna je dovoljan i pored njega jos neki tipa malwarebytes, spybot ili a-squared.