BlackFoot pet 12.11.2010 16:43
Luxy2501 kaže...

nemogu uopce odabrati task manager! 

Hajde onda ako nisi skenirao komp na malware to učini prvo s Malwarebytes Anti-Malware pa s ostala dva ( linkove za preuzimanje imaš u prethodnom postu ), instaliraj, preuzmi najnovije nadogradnje, skeniraj, ako što pronađu ukloni i i onda javi. Možda i nisu malwarei, vidjet ćemo. 

Luxy2501 pet 12.11.2010 16:51

eo mbam log 

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

 

Database version: 5100

 

Windows 6.1.7600

Internet Explorer 8.0.7600.16385

 

12.11.2010. 16:50:30

mbam-log-2010-11-12 (16-50-30).txt

 

Scan type: Quick scan

Objects scanned: 143396

Time elapsed: 3 minute(s), 51 second(s)

 

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 8

Registry Values Infected: 8

Registry Data Items Infected: 2

Folders Infected: 6

Files Infected: 36

 

Memory Processes Infected:

(No malicious items detected)

 

Memory Modules Infected:

(No malicious items detected)

 

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{74ccfe84-xk0a-141d-5201-u2g6u1r0ng5l} (Generic.Bot.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{cbfe80jn-hvn0-8vb4-00hc-30164jipym6h} (Generic.Bot.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{k7t7807o-8f37-v7eu-7hu8-fosmjk02ov5f} (Generic.Bot.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{kwngbv81-ngqt-23ox-s422-h1ya4iu345j0} (Generic.Bot.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{r3m5v0t6-o4ug-8058-4cj3-p7tk24drs6sk} (Generic.Bot.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.

HKEY_CURRENT_USER\Software\VB and VBA Program Settings\SrvID (Malware.Trace) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> No action taken.

 

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\audio hd driver (Trojan.Agent) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\policies (Backdoor.Bot) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\audio hd driver (Trojan.Downloader) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hkcu (Backdoor.Bot) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows_update.exe (Trojan.Downloader) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\policies (Backdoor.Bot) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\audio hd driver (Backdoor.SpyNet) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\hklm (Backdoor.Bot) -> No action taken.

 

Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

 

Folders Infected:

C:\Program Files (x86)\FunWebProducts (Adware.MyWebSearch) -> No action taken.

C:\Program Files (x86)\FunWebProducts\Installr (Adware.MyWebSearch) -> No action taken.

C:\Program Files (x86)\FunWebProducts\Installr\1.bin (Adware.MyWebSearch) -> No action taken.

C:\Windows\System32\28463 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\Microsoft_KB57H43 (Trojan.Backdoor) -> No action taken.

C:\Windows\System32\spynet (Trojan.Backdoor) -> No action taken.

 

Files Infected:

C:\Windows\main\explorer.exe\install\iexplorer.exe (Generic.Bot.H) -> No action taken.

C:\Users\User\AppData\Roaming\rzr-cod4.exe (Trojan.Agent.CK) -> No action taken.

C:\Users\User\AppData\Roaming\WinFx64.exe (Trojan.PWS) -> No action taken.

C:\Users\User\AppData\Local\Temp\Hide My IP 2009 Patch.exe (Trojan.Dropper) -> No action taken.

C:\Users\User\downloads\Crazy Hacker.exe (Worm.PushBot) -> No action taken.

C:\Users\User\downloads\EasyAccount.exe (RiskWare.Tool.CK) -> No action taken.

C:\Users\User\downloads\Hacktool.exe (Worm.Rebhip) -> No action taken.

C:\Users\User\downloads\Retrogamer.exe (Adware.Iwon) -> No action taken.

C:\Users\User\downloads\Steam Keygen v7.1.exe (Heuristics.Shuriken) -> No action taken.

C:\Program Files (x86)\FunWebProducts\Installr\1.bin\F3EZSETP.DLL (Adware.MyWebSearch) -> No action taken.

C:\Windows\System32\28463\AKV.exe (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.001 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.002 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.005 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.009 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.009.tmp (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\IUBP.exe (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\LVEK.001 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\LVEK.002 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\LVEK.006 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\LVEK.007 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\QUEV.001 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\QUEV.002 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\QUEV.006 (Keylogger.Ardamax) -> No action taken.

C:\Windows\System32\28463\QUEV.007 (Keylogger.Ardamax) -> No action taken.

C:\Users\User\AppData\Roaming\data.dat (Stolen.Data) -> No action taken.

C:\Users\User\AppData\Roaming\logs.dat (Bifrose.Trace) -> No action taken.

C:\Users\User\AppData\Roaming\SystemDriver.exe (Trojan.Agent) -> No action taken.

C:\Users\User\AppData\Roaming\Userlog.dat (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svchost.exe (Backdoor.Bot) -> No action taken.

C:\Windows\System32\secushr.dat (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Local\Temp\MSN.abc (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Local\Temp\UuU.uUu (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Local\Temp\XxX.xXx (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Local\Temp\xxxyyyzzz.dat (Malware.Trace) -> No action taken.

C:\Users\User\AppData\Local\Temp\SystemDriver.exe (Trojan.Downloader) -> No action taken.

 

XXX-Man pet 12.11.2010 17:05
Luxy2501 kaže...
Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> No action taken.

 


 

trebalo bi ti sve bit jasno

BlackFoot pet 12.11.2010 17:20
Luxy2501 kaže...

nod32

Ako je neka crack verzija NOD 32 ili slična predlažem ti da ju ukloniš i instaliraš nešto od besplatnih antivirusnih programa. I paid verzija propušta ali ove druge su blago rečeno sumnjive u svojoj učinkovitosti.{#}

pointer041 pet 16.9.2011 18:08

..to se događa zato što nije samo antivirus dovoljan za zaštitu od napasnika...potrebno je imati i neki antispyware(aka Spyware Terminator) i zaštitu od promjene postavki(aka Arovax Shield), te dakako neki dobar vatrozid sa definicijama za trojanske konje;..a i u pregledniku bi trebalo imati advisora za zaštitu od tkz. otvaranja sumnjivih stranica(McAfee SiteAdvisor).

Izzy pet 16.9.2011 19:01

Pa da. Točno tako, evo što ja koristim već godinu dana tj. otkako sam reinstalirao OS i iskreno preporučam drugima:

 

1. kao antivirusni program Aviru free

 

2. kao Anti-malware/Anti-spyware Malwarebytes i SuperAntiSpyware

 

3. kao taj tzv. site advisor koristim WoT koji mi je stalno uključen i NoScript koji samo ponekad uključim i ta 2 dodatka su mi integrirana u Firefox

 

4. u svrhu sveukupne zaštite od gamadi kada surfam i nešto skidam preko µTorrenta koristim Sandboxie (ukratko, program za izolaciju)

 

5. za pregled cijelog sustava i pregled aktivnihh stvari (onih koji se podižu sa sustavom i rade u pozadini...) i pregled mogućih skrivenih napasnika koristim HiJackThis

 

6. i za čišćenje računala od smeća i uvođenje reda koristim CCleaner i Glary Utilities

 

Sa Avirom, Malwarebytesom i SuperAntiSpywareom skeniram obično 1 put tjedno ( i to bude obično sve u isti dan i na "full scan"), a HiJackThis programom 1 put u par mjeseci (izvještaj provjerim ovdje). CCleaner skoro pa svaki dan, a Glary Utilities 1 put tjedno. Za Firewall koristim onaj u Windowsima.

 

Eto, to vam iskreno preporučam!!! Meni računalo radi odlično, bez ikakvih problema i zastajkivanja, a vjerujte mi, u ovih godinu dana sam išao na svakakve stranice!!!

aco77 čet 30.5.2013 22:14

ja imam isti problem,nemogu da pokrenem task manager,on ga otvori al tako se brzo ugasi crni prozor da ne vidim sta pise,danas isao full scan sa MalwareBitesom odradio nasao 9 virusa,cudno al mi nije trazio restart,ne vidim u karantinu da je ista ubacio,malo prije isao Qvick scan izbacio da nema virusa.

Sada radim Full Scan sa Esetom pa cu viditi sta ce biti,i dalje nemogu da udjem u task manager.

Dal trazi restart nakon sto pronadje viruse Malwarebytes,zaboravio sam nisam dugo isao scan,imal ko da mi pomogne,nemojte samo reci da cu morati dizati sistem?