pranja_dakovo pon 23.9.2013 15:57
191x7 kaže...

Preuzmi http://www.geekuninstaller.com/download i uninstaliraj sve što ti ne treba ili ti je sumnjivo/nepoznato.

 

Preuzmi http://www.surfright.nl/en i prođi punu provjeru, očisti što nađe.

 

Nitko ne kaže da sve što ti je spominjano moraš skinuti na tom računalu, slobodno skini na nekom drugom i prebaci preko sticka, cd-a, dvd-a...

probat cu sad s laptopa, al fascinira me skidanje, pojavi se program koji skidam i kad se skine izbrise se {#}

pranja_dakovo pon 23.9.2013 16:11
djigibao kaže...
191x7 kaže...

To definitivno radi malware. Zato se i preporuča:

ComboFix

HitmanPro

SuperAntiSpyware

Malwarebytes Anti-malware

AdwCleaner (možda čak njega i prvog)

 

Nakon toga CCLeaner, Glary Utilities, ...

 

Slazem se...

 

Mozda najprvo RKill (da ubije malware) i RogueKiller

191x7- nemog nista od tog instalirat, a rkill mi je ovo izbacio

Rkill 2.6.1 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 09/23/2013 04:10:51 PM in x64 mode.
Windows Version: Windows 7 Ultimate

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * No malware processes found to kill.

Possibly Patched Files.

 * C:\Windows\Explorer.EXE

Checking Registry for malware related settings:

 * Explorer Policy Removed:  NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
 C:\Users\ukucani\Desktop\rkill\rkill-09-23-2013-04-10-55.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * Windows Defender Disabled

   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001

 * Windows Firewall Disabled

   [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
   "EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

 * Windows Defender (WinDefend) is not Running.
   Startup Type set to: Manual

Searching for Missing Digital Signatures:

 * C:\Windows\explorer.exe : 2.868.224 : 08/30/2013 00:15 AM : 28107d542963792730aab94fdc1af45e [NoSig]
 +-> C:\Windows\SysWOW64\explorer.exe : 2.613.248 : 07/14/2009 03:14 AM : 15bc38a7492befe831966adb477cf76f [Pos Repl]
 +-> C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe : 2.868.224 : 08/30/2013 00:15 AM : 28107d542963792730aab94fdc1af45e [Pos Repl]
 +-> C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe : 2.613.248 : 07/14/2009 03:14 AM : 15bc38a7492befe831966adb477cf76f [Pos Repl]

Checking HOSTS File:

 * No issues found.

Program finished at: 09/23/2013 04:11:04 PM
Execution time: 0 hours(s), 0 minute(s), and 12 seconds(s)



HITMANpro kad dodje do malware skeniranja, odma program dont responding, probat cu iz safemoda


djigibao pon 23.9.2013 16:21
pranja_dakovo kaže...
djigibao kaže...
Da li imas neku temu instaliranu tj. neki skin za Windows?
Cini se da Explorer nije original.

Jesi pokrenuo RogueKiller?

jesam, al ga nekontam bas

191x7 odma se crasha kad dodje do malware testa

 

Pokreni ga i stisni SCAN (1), nakon sto zavrsi skeniranje obrisi sve sta nadje (2) a mozes i stavit LOG ovdje ili na Pastebin

pranja_dakovo pon 23.9.2013 16:24
djigibao kaže...
pranja_dakovo kaže...
djigibao kaže...
Da li imas neku temu instaliranu tj. neki skin za Windows?
Cini se da Explorer nije original.

Jesi pokrenuo RogueKiller?

jesam, al ga nekontam bas

191x7 odma se crasha kad dodje do malware testa

 

Pokreni ga i stisni SCAN (1), nakon sto zavrsi skeniranje obrisi sve sta nadje (2) a mozes i stavit LOG ovdje ili na Pastebin

jesam, i to je sad ovaj link pastebin.com/rz1irE7N   moram rucno psiat sve kad nema kopiranja po mozili, samo iz bloka za pisanje

djigibao pon 23.9.2013 16:45
djigibao kaže...

Probaj skinut ovaj portabilni program - KLIK

Ako nemozes onda otvori My computer pa u adresnu traku zalijepi ovaj link i enter (trebao bi pocet skidat):

www.tweaking.com/files/setups/tweaking.com_windows_repair_aio.zip

 

Bilo bi dobro kad bi ovaj program stavio na komp pa probao popravit Windowse s njim.

  

Da ga probas skinut u Safe Modu with Networking ili na drugom kompu.

pranja_dakovo pon 23.9.2013 16:53
djigibao kaže...
djigibao kaže...

Probaj skinut ovaj portabilni program - KLIK

Ako nemozes onda otvori My computer pa u adresnu traku zalijepi ovaj link i enter (trebao bi pocet skidat):

www.tweaking.com/files/setups/tweaking.com_windows_repair_aio.zip

 

Bilo bi dobro kad bi ovaj program stavio na komp pa probao popravit Windowse s njim.

  

Da ga probas skinut u Safe Modu with Networking ili na drugom kompu.

jel mi mos zaljepit link, jer me stalno hebe nes, dok upalim safe mod.

pranja_dakovo pon 23.9.2013 21:55
plavi08 kaže...

Ubuduće malo pripazi. Jer ovakve malware stvarno treba znati naći {#}

a mislim da sam preko torenta vrlo lako skinio :L nije prvi put. Jednom su u cijelome gradu iskljucili internet tj prije 2 godine, neki zlocudni im je odavde poceo spamati cak u Zg.