Virus-kako ga uklonit?

poruka: 24
|
čitano: 6.106
|
moderatori: pirat, Lazarus Long, XXX-Man, vincimus
1
+/- sve poruke
ravni prikaz
starije poruke gore
9 godina
neaktivan
offline
Virus-kako ga uklonit????

Poštovanje

Novi sam tu i trazio sam po forumu dali je netko imao taj virus al nisam nasao pa se nadam da se tema ne ponavlja.

Svaki anti virusni program mi nadje virus MBR://PHYSICALDRIVER0   MBR:Backboot-E(rtk) al ga sa nijednim nemogu uklonit.

 

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:   
Windows Version:  Windows 7 Ultimate Edition
Windows Information:  Service Pack 1 (build 7601), 32-bit
Base Board Manufacturer: Hewlett-Packard
BIOS Manufacturer:  Hewlett-Packard
System Manufacturer:  Hewlett-Packard
System Product Name:  Compaq Presario CQ61 Notebook PC
Logical Drives Mask:  0x0000001c

Kernel Drivers (total 203):
  0x8324F000 \SystemRoot\system32\ntkrnlpa.exe
  0x83218000 \SystemRoot\system32\halmacpi.dll
  0x80BA8000 \SystemRoot\system32\kdcom.dll
  0x88A16000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
  0x88A9B000 \SystemRoot\system32\PSHED.dll
  0x88AAC000 \SystemRoot\system32\BOOTVID.dll
  0x88AB4000 \SystemRoot\system32\CLFS.SYS
  0x88AF6000 \SystemRoot\system32\CI.dll
  0x88C3A000 \SystemRoot\system32\drivers\Wdf01000.sys
  0x88CBB000 \SystemRoot\system32\drivers\WDFLDR.SYS
  0x88CC9000 \SystemRoot\system32\drivers\ACPI.sys
  0x88D11000 \SystemRoot\system32\drivers\WMILIB.SYS
  0x88D1A000 \SystemRoot\system32\drivers\msisadrv.sys
  0x88D22000 \SystemRoot\system32\drivers\pci.sys
  0x88D4C000 \SystemRoot\system32\drivers\vdrvroot.sys
  0x88D57000 \SystemRoot\System32\drivers\partmgr.sys
  0x88D68000 \SystemRoot\system32\DRIVERS\compbatt.sys
  0x88D70000 \SystemRoot\system32\DRIVERS\BATTC.SYS
  0x88D7B000 \SystemRoot\system32\drivers\volmgr.sys
  0x88D8B000 \SystemRoot\System32\drivers\volmgrx.sys
  0x88DD6000 \SystemRoot\System32\drivers\mountmgr.sys
  0x88C00000 \SystemRoot\system32\drivers\vmbus.sys
  0x88DEC000 \SystemRoot\system32\drivers\winhv.sys
  0x88C2A000 \SystemRoot\system32\drivers\atapi.sys
  0x88BA1000 \SystemRoot\system32\drivers\ataport.SYS
  0x88BC4000 \SystemRoot\system32\drivers\msahci.sys
  0x88BCE000 \SystemRoot\system32\drivers\PCIIDEX.SYS
  0x88BDC000 \SystemRoot\system32\drivers\amdxata.sys
  0x88E1E000 \SystemRoot\system32\drivers\fltmgr.sys
  0x88E52000 \SystemRoot\system32\drivers\fileinfo.sys
  0x88E63000 \SystemRoot\System32\Drivers\Ntfs.sys
  0x88F92000 \SystemRoot\System32\Drivers\msrpc.sys
  0x88FBD000 \SystemRoot\System32\Drivers\ksecdd.sys
  0x89034000 \SystemRoot\System32\Drivers\cng.sys
  0x89091000 \SystemRoot\System32\drivers\pcw.sys
  0x8909F000 \SystemRoot\System32\Drivers\Fs_Rec.sys
  0x890A8000 \SystemRoot\system32\drivers\ndis.sys
  0x8915F000 \SystemRoot\system32\drivers\NETIO.SYS
  0x8919D000 \SystemRoot\System32\Drivers\ksecpkg.sys
  0x8921B000 \SystemRoot\System32\drivers\tcpip.sys
  0x89367000 \SystemRoot\System32\drivers\fwpkclnt.sys
  0x89398000 \SystemRoot\system32\drivers\vmstorfl.sys
  0x893A1000 \SystemRoot\system32\drivers\volsnap.sys
  0x893E0000 \SystemRoot\System32\Drivers\spldr.sys
  0x891C3000 \SystemRoot\System32\drivers\rdyboost.sys
  0x893E8000 \SystemRoot\System32\Drivers\mup.sys
  0x893F8000 \SystemRoot\System32\drivers\hwpolicy.sys
  0x89000000 \SystemRoot\System32\DRIVERS\fvevol.sys
  0x89200000 \SystemRoot\system32\DRIVERS\disk.sys
  0x88FD0000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
  0x89417000 \SystemRoot\System32\Drivers\aswVmm.sys
  0x89444000 \SystemRoot\System32\Drivers\aswRvrt.sys
  0x89481000 \SystemRoot\system32\drivers\cdrom.sys
  0x894A0000 \SystemRoot\system32\drivers\aswSnx.sys
  0x89561000 \SystemRoot\system32\drivers\aswSP.sys
  0x895C4000 \SystemRoot\System32\Drivers\Null.SYS
  0x895CB000 \SystemRoot\System32\Drivers\Beep.SYS
  0x895D2000 \SystemRoot\System32\drivers\vga.sys
  0x895DE000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
  0x89400000 \SystemRoot\System32\drivers\watchdog.sys
  0x8940D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
  0x89211000 \SystemRoot\system32\drivers\rdpencdd.sys
  0x891F0000 \SystemRoot\system32\drivers\rdprefmp.sys
  0x88FF5000 \SystemRoot\System32\Drivers\Msfs.SYS
  0x88E00000 \SystemRoot\System32\Drivers\Npfs.SYS
  0x88BE5000 \SystemRoot\system32\DRIVERS\tdx.sys
  0x88E0E000 \SystemRoot\system32\DRIVERS\TDI.SYS
  0x8DE0D000 \SystemRoot\System32\DRIVERS\netbt.sys
  0x8DE3F000 \SystemRoot\system32\drivers\afd.sys
  0x8DE99000 \SystemRoot\system32\drivers\aswRdr2.sys
  0x8DEB2000 \SystemRoot\system32\drivers\ws2ifsl.sys
  0x8DEBB000 \SystemRoot\system32\DRIVERS\wfplwf.sys
  0x8DEC2000 \SystemRoot\system32\DRIVERS\pacer.sys
  0x8DEE1000 \SystemRoot\system32\DRIVERS\vwififlt.sys
  0x8DEF2000 \SystemRoot\system32\DRIVERS\netbios.sys
  0x8DF00000 \SystemRoot\system32\DRIVERS\wanarp.sys
  0x8DF13000 \SystemRoot\system32\drivers\termdd.sys
  0x8DF24000 \SystemRoot\system32\DRIVERS\rdbss.sys
  0x8DF65000 \SystemRoot\system32\drivers\nsiproxy.sys
  0x8DF6F000 \SystemRoot\system32\drivers\mssmbios.sys
  0x8DF79000 \SystemRoot\System32\drivers\discache.sys
  0x8DF85000 \SystemRoot\system32\drivers\csc.sys
  0x8EE1C000 \SystemRoot\System32\Drivers\dfsc.sys
  0x8EE34000 \SystemRoot\system32\DRIVERS\blbdrive.sys
  0x8EE42000 \SystemRoot\system32\DRIVERS\tunnel.sys
  0x8EE63000 \SystemRoot\system32\DRIVERS\intelppm.sys
  0x8EE75000 \SystemRoot\system32\DRIVERS\CmBatt.sys
  0x90202000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
  0x90B1F000 \SystemRoot\System32\drivers\dxgkrnl.sys
  0x8EE79000 \SystemRoot\System32\drivers\dxgmms1.sys
  0x90BD7000 \SystemRoot\system32\DRIVERS\usbuhci.sys
  0x8EEB2000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
  0x90BE2000 \SystemRoot\system32\DRIVERS\usbehci.sys
  0x8EEFD000 \SystemRoot\system32\drivers\HDAudBus.sys
  0x95E3B000 \SystemRoot\system32\DRIVERS\athr.sys
  0x95F5E000 \SystemRoot\system32\DRIVERS\vwifibus.sys
  0x95F8D000 \SystemRoot\system32\drivers\i8042prt.sys
  0x95FA5000 \SystemRoot\system32\drivers\kbdclass.sys
  0x95FB2000 \SystemRoot\system32\DRIVERS\SynTP.sys
  0x95FED000 \SystemRoot\system32\DRIVERS\USBD.SYS
  0x95FEF000 \SystemRoot\system32\drivers\mouclass.sys
  0x95E00000 \SystemRoot\system32\drivers\wmiacpi.sys
  0x95E09000 \SystemRoot\system32\drivers\CompositeBus.sys
  0x95E16000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
  0x95F68000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
  0x95F80000 \SystemRoot\system32\DRIVERS\ndistapi.sys
  0x8EF1C000 \SystemRoot\system32\DRIVERS\ndiswan.sys
  0x8EF3E000 \SystemRoot\system32\DRIVERS\raspppoe.sys
  0x8EF56000 \SystemRoot\system32\DRIVERS\raspptp.sys
  0x8EF6D000 \SystemRoot\system32\DRIVERS\rassstp.sys
  0x95E28000 \SystemRoot\system32\DRIVERS\rdpbus.sys
  0x95E32000 \SystemRoot\system32\drivers\swenum.sys
  0x8EF84000 \SystemRoot\system32\drivers\ks.sys
  0x90BF1000 \SystemRoot\system32\drivers\umbus.sys
  0x8EFB8000 \SystemRoot\system32\DRIVERS\usbhub.sys
  0x8EE00000 \SystemRoot\System32\Drivers\NDProxy.SYS
  0x96C07000 \SystemRoot\system32\DRIVERS\stwrt.sys
  0x96C73000 \SystemRoot\system32\DRIVERS\portcls.sys
  0x96CA2000 \SystemRoot\system32\DRIVERS\drmk.sys
  0x96CBB000 \SystemRoot\system32\drivers\HdAudio.sys
  0x82200000 \SystemRoot\System32\win32k.sys
  0x96D0B000 \SystemRoot\System32\drivers\Dxapi.sys
  0x96D15000 \SystemRoot\System32\Drivers\crashdmp.sys
  0x96D22000 \SystemRoot\System32\Drivers\dump_dumpata.sys
  0x96D2D000 \SystemRoot\System32\Drivers\dump_msahci.sys
  0x96D37000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
  0x96D48000 \SystemRoot\system32\DRIVERS\usbccgp.sys
  0x96D5F000 \SystemRoot\System32\Drivers\usbvideo.sys
  0x96D83000 \SystemRoot\system32\DRIVERS\monitor.sys
  0x82470000 \SystemRoot\System32\TSDDD.dll
  0x824A0000 \SystemRoot\System32\cdd.dll
  0x96D8E000 \SystemRoot\system32\drivers\luafv.sys
  0x96DA9000 \SystemRoot\system32\drivers\aswMonFlt.sys
  0x96DC6000 \??\C:\Windows\system32\drivers\mbam.sys
  0x96DCF000 \SystemRoot\system32\drivers\aswStm.sys
  0x96DE3000 \SystemRoot\system32\DRIVERS\lltdio.sys
  0x96238000 \SystemRoot\system32\DRIVERS\nwifi.sys
  0x9627E000 \SystemRoot\system32\DRIVERS\ndisuio.sys
  0x9628E000 \SystemRoot\system32\DRIVERS\rspndr.sys
  0x962A1000 \SystemRoot\system32\DRIVERS\vwifimp.sys
  0x962AA000 \SystemRoot\system32\drivers\HTTP.sys
  0x9632F000 \SystemRoot\system32\DRIVERS\bowser.sys
  0x96348000 \SystemRoot\System32\drivers\mpsdrv.sys
  0x9635A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
  0x9637D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
  0x963B8000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
  0x963EB000 \SystemRoot\system32\drivers\aswHwid.sys
  0xAD817000 \SystemRoot\system32\drivers\peauth.sys
  0xAD8AE000 \SystemRoot\System32\Drivers\secdrv.SYS
  0xAD8B8000 \SystemRoot\System32\DRIVERS\srvnet.sys
  0xAD8D9000 \SystemRoot\System32\drivers\tcpipreg.sys
  0xAD8E6000 \??\C:\Program Files\CyberLink\PowerDVD\000.fcl
  0xAD8E8000 \SystemRoot\System32\DRIVERS\srv2.sys
  0xAD938000 \SystemRoot\System32\DRIVERS\srv.sys
  0xAD98A000 \??\C:\Windows\system32\drivers\mwac.sys
  0xAD999000 \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
  0x77900000 \Windows\System32\ntdll.dll
  0x480A0000 \Windows\System32\smss.exe
  0x77B40000 \Windows\System32\apisetschema.dll
  0x00C70000 \Windows\System32\autochk.exe
  0x77A50000 \Windows\System32\kernel32.dll
  0x778A0000 \Windows\System32\difxapi.dll
  0x77850000 \Windows\System32\Wldap32.dll
  0x777B0000 \Windows\System32\advapi32.dll
  0x77A40000 \Windows\System32\nsi.dll
  0x776E0000 \Windows\System32\msctf.dll
  0x776C0000 \Windows\System32\sechost.dll
  0x77690000 \Windows\System32\imagehlp.dll
  0x775E0000 \Windows\System32\msvcrt.dll
  0x77440000 \Windows\System32\setupapi.dll
  0x772E0000 \Windows\System32\ole32.dll
  0x772A0000 \Windows\System32\ws2_32.dll
  0x77290000 \Windows\System32\normaliz.dll
  0x77280000 \Windows\System32\psapi.dll
  0x771E0000 \Windows\System32\usp10.dll
  0x77110000 \Windows\System32\user32.dll
  0x77080000 \Windows\System32\clbcatq.dll
  0x77020000 \Windows\System32\shlwapi.dll
  0x76FA0000 \Windows\System32\comdlg32.dll
  0x76EF0000 \Windows\System32\rpcrt4.dll
  0x76ED0000 \Windows\System32\imm32.dll
  0x76E80000 \Windows\System32\gdi32.dll
  0x76D50000 \Windows\System32\urlmon.dll
  0x76D40000 \Windows\System32\lpk.dll
  0x76B20000 \Windows\System32\iertutil.dll
  0x76960000 \Windows\System32\wininet.dll
  0x768D0000 \Windows\System32\oleaut32.dll
  0x75C80000 \Windows\System32\shell32.dll
  0x75C30000 \Windows\System32\KernelBase.dll
  0x75C00000 \Windows\System32\cfgmgr32.dll
  0x75BF0000 \Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
  0x75BD0000 \Windows\System32\userenv.dll
  0x75BA0000 \Windows\System32\wintrust.dll
  0x75B90000 \Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
  0x75B80000 \Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
  0x75A60000 \Windows\System32\crypt32.dll
  0x75A50000 \Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
  0x75A30000 \Windows\System32\devobj.dll
  0x759A0000 \Windows\System32\comctl32.dll
  0x75990000 \Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
  0x75980000 \Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
  0x75970000 \Windows\System32\profapi.dll
  0x75960000 \Windows\System32\msasn1.dll

Processes (total 65):
       0 System Idle Process
       4 System
     296 C:\Windows\System32\smss.exe
     396 csrss.exe
     432 C:\Windows\System32\wininit.exe
     452 csrss.exe
     488 C:\Windows\System32\services.exe
     508 C:\Windows\System32\lsass.exe
     520 C:\Windows\System32\lsm.exe
     576 C:\Windows\System32\winlogon.exe
     676 C:\Windows\System32\svchost.exe
     772 C:\Windows\System32\svchost.exe
     864 C:\Windows\System32\svchost.exe
     900 C:\Windows\System32\svchost.exe
     924 C:\Windows\System32\svchost.exe
     948 C:\Windows\System32\svchost.exe
    1044 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\stacsv.exe
    1372 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    1592 C:\Windows\System32\dwm.exe
    1616 C:\Windows\explorer.exe
    1672 C:\Windows\System32\taskhost.exe
    1760 C:\Windows\System32\spoolsv.exe
    1788 C:\Windows\System32\svchost.exe
    1940 C:\Windows\System32\svchost.exe
     328 C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9691412ff1876250\AEstSrv.exe
     456 C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
     692 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
     844 C:\Program Files\IDT\WDM\sttray.exe
    1808 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    2016 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    2032 C:\Windows\System32\igfxtray.exe
     372 C:\Windows\System32\hkcmd.exe
    1536 C:\Windows\System32\igfxpers.exe
    1520 C:\Program Files\AVAST Software\Avast\avastui.exe
    2212 C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
    2224 C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
    2252 C:\Program Files\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
    2304 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    2356 C:\Program Files\CyberLink\Shared files\RichVideo.exe
    2396 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    2564 C:\Windows\System32\svchost.exe
    2596 C:\Windows\System32\svchost.exe
    2620 C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
    2680 C:\Program Files\iLivid\iLivid.exe
    2696 C:\Program Files\Samsung\Kies\Kies.exe
    3312 C:\Windows\System32\SearchIndexer.exe
    3492 WmiPrvSE.exe
    3328 C:\Program Files\Internet Explorer\iexplore.exe
    3612 C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
    2204 C:\Windows\System32\wbem\unsecapp.exe
    1300 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    2408 C:\Windows\System32\svchost.exe
    2712 C:\Windows\System32\svchost.exe
    3152 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
     980 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    9832 C:\Program Files\Internet Explorer\iexplore.exe
    6304 C:\Windows\System32\taskeng.exe
    1572 C:\Program Files\Internet Explorer\iexplore.exe
    5940 C:\Windows\System32\audiodg.exe
    2872 C:\Windows\System32\SearchProtocolHost.exe
    7716 C:\Windows\System32\SearchFilterHost.exe
    6808 C:\Windows\System32\SearchProtocolHost.exe
    4996 C:\Users\pc\Downloads\MBRCheck.exe
    3332 C:\Windows\System32\conhost.exe
    8988 C:\Windows\System32\dllhost.exe

\\.\C: - \\.\PhysicalDrive0 at offset 0x00000000`06500000  (NTFS)
\\.\D: - \\.\PhysicalDrive0 at offset 0x00000022`2e100000  (NTFS)

PhysicalDrive0 Model Number: SAMSUNGHM321HI, Rev: 2AJ10001

      Size  Device Name          MBR Status
  --------------------------------------------
    298 GB \\.\PhysicalDrive0   Unknown MBR code
            SHA1: 499C658660951C3719FC746D779911AC40E72D7D


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
  [1] Dump the MBR of a physical disk to file.
  [2] Restore the MBR of a physical disk with a standard boot code.
  [3] Exit.

Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 2Available MBR codes:
 [ 0] Default (Windows 7)
 [ 1] Windows XP
 [ 2] Windows Server 2003
 [ 3] Windows Vista
 [ 4] Windows 2008
 [ 5] Windows 7
 [-1] Cancel

Please select the MBR code to write to this drive: 5
Do you want to fix the MBR code?  Type 'YES' and hit ENTER to continue: YES
Error opening disk (2)!


Done!

 

 

MOZDA OVO NEKOM POMOGNE DA SE MOJ PROBLEM RIJESI

 
0 0 hvala 0
15 godina
offline
Virus-kako ga uklonit????

...evo ovdje imaš par alata i samo prati uputstva.. http://techlogon.com/2012/01/15/how-to-check-for-and-fix-mbr-virus-infection/

Moj PC  
0 0 hvala 1
16 godina
offline
Virus-kako ga uklonit????

skini si neki od rescue diskova koje nude proizvođači antivirusa, digni sistem putem tog diska i probaj očistiti

 

bitdefender rescue disk

http://download.bitdefender.com/rescue_cd/

 

kaspersky

http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/kav_rescue_10.iso

 

 

 

 

Moj PC  
0 0 hvala 1
9 godina
neaktivan
offline
Re: Virus-kako ga uklonit????
Wolverine kaže...

skini si neki od rescue diskova koje nude proizvođači antivirusa, digni sistem putem tog diska i probaj očistiti

 

bitdefender rescue disk

http://download.bitdefender.com/rescue_cd/

 

kaspersky

http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/kav_rescue_10.iso

 

 

 

 

skinuo sam kaspersky na cd al kako ga pokrenut iz safe moda?

kad odem na cd imam par foldera pa neznam sta trebam dalje napravit,koji otvorit.

 

9 godina
neaktivan
offline
Re: Virus-kako ga uklonit????

probao sam sa avastom al nije pomoglo

9 godina
neaktivan
offline
Re: Virus-kako ga uklonit????
lion002 kaže...

...evo ovdje imaš par alata i samo prati uputstva.. http://techlogon.com/2012/01/15/how-to-check-for-and-fix-mbr-virus-infection/

ovdje sam probao preko avasta al nije uspijelo

15 godina
offline
Virus-kako ga uklonit?

probaj ovako

 

skini TDSSKiller i spremi na desktop

-desni klik mišem klik na run as administrator

-otvori program >klik na change paratmeters> sve označi
-klik na start scan
-ako program zatraži restart dozvoli

(u ovakom načinu rada tdsskiller će pokazati i false positive, zato nemoj ništa drugo označavati za brisanje osim onog što je tdsskiler označio)
-log se nalazi u C:/ i izgleda otprilike ovako
C:\TDSSKiller.2.4.7_23.07.2014_15.31.43_log.txt

 

log file copy/paste na pastebin.com >klik na submit

link koji dobiješ zaljepi da pogledam

 

2. skini Farbar Recovery Scan Tool  i spremi na desktop

-pokrnei program >klik na scan

-kad završi scan dobit ćeš FRST.txt i Additional.txt koje ćeš isto tako copy/paste na pastebin i poslat linkove da pogledam

 

 
2 0 hvala 0
9 godina
neaktivan
offline
Re: Virus-kako ga uklonit?
total kaže...

probaj ovako

 

skini TDSSKiller i spremi na desktop

-desni klik mišem klik na run as administrator

-otvori program >klik na change paratmeters> sve označi
-klik na start scan
-ako program zatraži restart dozvoli

(u ovakom načinu rada tdsskiller će pokazati i false positive, zato nemoj ništa drugo označavati za brisanje osim onog što je tdsskiler označio)
-log se nalazi u C:/ i izgleda otprilike ovako
C:\TDSSKiller.2.4.7_23.07.2014_15.31.43_log.txt

 

log file copy/paste na pastebin.com >klik na submit

link koji dobiješ zaljepi da pogledam

 

2. skini Farbar Recovery Scan Tool  i spremi na desktop

-pokrnei program >klik na scan

-kad završi scan dobit ćeš FRST.txt i Additional.txt koje ćeš isto tako copy/paste na pastebin i poslat linkove da pogledam

 

http://pastebin.com/uEYAErhF

 

 

valjda si tako mislio

9 godina
neaktivan
offline
 
0 0 hvala 0
15 godina
offline
Re: Virus-kako ga uklonit?

jeli izbrisan rootkit ?

ponovo pokreni tdsskiller, i ako pronađe opet rootkit odaberi delete/clean

 

14:01:49.0637 0x0c7c  Detected object count: 1
14:01:49.0637 0x0c7c  Actual detected object count: 1
14:03:54.0967 0x0c7c  \Device\Harddisk0\DR0\# - copied to quarantine
14:03:54.0967 0x0c7c  \Device\Harddisk0\DR0 - copied to quarantine
14:03:54.0967 0x0c7c  \Device\Harddisk0\DR0 ( Rootkit.Boot.Backboot.c ) - User select action: Quarantine

 

ostalo je manje više ok, imaš dosta adwarea na računalu kojeg ćemo sada pobrisati

 

prebaci Farbar Recovery Scan Tool s Downloads na Desktop

 

otvori notepad i ovo kopiraj u notepad

 

CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
BHO: No Name -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} ->  No File
BHO: No Name -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} ->  No File
Handler: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} -  No File
S2 Application Updater; "C:\Program Files\Application Updater\ApplicationUpdater.exe" [X]
S3 catchme; \??\C:\Users\pc\AppData\Local\Temp\catchme.sys [X]
S3 CFcatchme; \??\C:\Users\pc\AppData\Local\Temp\CFcatchme.sys [X]
Task: {0DA7927F-1C52-4990-95B9-E85E967A5A99} - \5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5 No Task File <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{62A0D750-DED9-448C-B693-406B34BB0892}\InprocServer32 -> C:\Users\pc\AppData\Local\Google\Update\1.3.21.145\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{634059C0-D264-4B2C-AE80-F73E48D33E5B}\InprocServer32 -> C:\Users\pc\AppData\Local\Google\Update\1.3.21.123\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{6D7374DE-63AA-473C-8C02-60D9CDCD84C5}\InprocServer32 -> C:\Users\pc\AppData\Local\Google\Update\1.3.21.153\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 -> C:\Program Files\Skype\Plugin Manager\ezPMUtils.dll No File
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{095A2EEC-F7FE-42E8-96FB-C20E53081908}\InprocServer32 -> C:\Users\pc\AppData\Local\Google\Update\1.3.21.99\psuser.dll No File
CustomCLSID: HKU\S-1-5-21-1790169903-100120260-3156938750-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\pc\AppData\Local\Google\Update\1.3.23.9\psuser.dll No File
Task: {0DA7927F-1C52-4990-95B9-E85E967A5A99} - \5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-5 No Task File <==== ATTENTION
Task: {586200D4-01A8-47AA-9ADE-1B27F4BF60C1} - \5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-3 No Task File <==== ATTENTION
Task: {5EE6D424-D66E-4170-984F-8B00935FD7D7} - \5748f13f-0b3f-4c50-ac16-cb29efb4c5b9-4 No Task File <==== ATTENTION
CMD: ipconfig /flushdns
CMD: DEL %TEMP%\*.* /F /S /Q
EmptyTemp:
REBOOT:

 

zatvori notepad i spremi kao FIXLIST.txt na desktop

 

otvori Farbar Recovery Scan Tool i klik na Fix

 

logfile kojeg ćeš dobiti nakon restarta copy/paste na pastebin

 

 

2. skini adwcleaner i spremi na desktop

-pokreni program klikom na scan, kad završi scan klik na Clean

-log koji dobiješ isto tako kopiraj da pogledam

 

3.ponovo pokreni Farbar Recovery Scan Tool scan

-log isto kopiraj

 

 

9 godina
neaktivan
offline
Virus-kako ga uklonit?

cini se da sam uspio izbrisat rootkit,vise ga ne pronalazi {#}

 

pokusao sam sa notepad al mi ne uspijeva pise mi no fixlist.txt found

 
0 0 hvala 0
15 godina
offline
Re: Virus-kako ga uklonit?
josips100 kaže...

cini se da sam uspio izbrisat rootkit,vise ga ne pronalazi {#}

 

pokusao sam sa notepad al mi ne uspijeva pise mi no fixlist.txt found

jesi li spremio farbar na desktop ?

 

i fixlist.txt isto tako mora biti na desktopu

 

na računalu nema više virusa, jedino što imaš je adware, za veliku većinu će biti dovoljno da pokreneš adwcleaner. ako se ne snalaziš baš s notpedima pokreni samo adwcleaner{#}

 

kad završiš s čiščenjem, uradi još ovo

 

skini delfix i spremi na desktop

pokreni program,označi

-remove disinfection tools

-purge system restore

-reset system setings

-klik na run

 

 

 

9 godina
neaktivan
offline
Virus-kako ga uklonit?

http://pastebin.com/ZXG1ZjVT

 

jedan zadatk rijesio

 
0 0 hvala 0
9 godina
neaktivan
offline
Virus-kako ga uklonit?

delfix

 

# DelFix v10.8 - Logfile created 15/09/2014 at 22:03:17
# Updated 29/07/2014 by Xplode
# Username : pc - PC-PC
# Operating System : Windows 7 Ultimate Service Pack 1 (32 bits)

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\FRST
Deleted : C:\TDSSKiller_Quarantine
Deleted : C:\AdwCleaner
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.3.0.0.40_15.09.2014_13.54.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.40_15.09.2014_13.58.19_log.txt
Deleted : C:\TDSSKiller.3.0.0.40_15.09.2014_19.03.41_log.txt
Deleted : C:\TDSSKiller.3.0.0.40_15.09.2014_19.11.27_log.txt
Deleted : C:\TDSSKiller.3.0.0.40_15.09.2014_19.13.09_log.txt
Deleted : C:\Users\pc\Desktop\AdwCleaner - Shortcut.lnk
Deleted : C:\Users\pc\Desktop\aswMBR.txt
Deleted : C:\Users\pc\Desktop\FRST - Shortcut.lnk
Deleted : C:\Users\pc\Desktop\MBR.dat
Deleted : C:\Users\pc\Desktop\MBRCheck_09.11.14_09.53.05.txt
Deleted : C:\Users\pc\Desktop\tdsskiller - Shortcut.lnk
Deleted : C:\Users\pc\Downloads\Addition.txt
Deleted : C:\Users\pc\Downloads\AdwCleaner.exe
Deleted : C:\Users\pc\Downloads\FRST.exe
Deleted : C:\Users\pc\Downloads\FRST.txt
Deleted : C:\Users\pc\Downloads\MBRCheck.exe
Deleted : C:\Users\pc\Downloads\Search.txt
Deleted : C:\Users\pc\Downloads\tdsskiller.exe
Deleted : C:\Windows\grep.exe
Deleted : C:\Windows\PEV.exe
Deleted : C:\Windows\NIRCMD.exe
Deleted : C:\Windows\MBR.exe
Deleted : C:\Windows\SED.exe
Deleted : C:\Windows\SWREG.exe
Deleted : C:\Windows\SWSC.exe
Deleted : C:\Windows\SWXCACLS.exe
Deleted : C:\Windows\Zip.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe
Deleted : HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ASWMBR

~ Cleaning system restore ...

Deleted : RP #672 [AA11 | 09/05/2014 16:56:29]
Deleted : RP #673 [Windows Update | 09/06/2014 06:11:29]
Deleted : RP #674 [AA11 | 09/06/2014 17:53:05]
Deleted : RP #675 [Windows Update | 09/09/2014 07:46:47]
Deleted : RP #676 [Windows Update | 09/10/2014 13:05:25]
Deleted : RP #677 [Windows Update | 09/11/2014 06:02:36]
Deleted : RP #678 [Windows Update | 09/12/2014 08:20:31]
Deleted : RP #679 [Windows Update | 09/12/2014 08:55:25]
Deleted : RP #680 [Removed Samsung Kies | 09/14/2014 20:58:21]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########

 
0 0 hvala 0
9 godina
neaktivan
offline
Virus-kako ga uklonit?

Hvala Vam ljudi

 

Cini se da sam problem riješio,zasad radi normalno{#}

 

Skuzio sam da mi malo steka kad gledam nesto na laptopu al to je mozda do veze

Morat cu dati malome da isproba crtane na youtubu .))

 
0 0 hvala 0
11 godina
offline
Re: Virus-kako ga uklonit?
josips100 kaže...

Hvala Vam ljudi

 

Cini se da sam problem riješio,zasad radi normalno{#}

 

Skuzio sam da mi malo steka kad gledam nesto na laptopu al to je mozda do veze

Morat cu dati malome da isproba crtane na youtubu .))

Flash je pretežak za taj Sempron pa zato youtube šteka sada bi trebo sredit drivere za integriranu Radeonku HD4200 da UVD2 proradi pa će bilo koji video (mislim da je do 1080p) radit bez problema.

Kill or be killed.
9 godina
neaktivan
offline
Re: Virus-kako ga uklonit?
breader kaže...
josips100 kaže...

Hvala Vam ljudi

 

Cini se da sam problem riješio,zasad radi normalno{#}

 

Skuzio sam da mi malo steka kad gledam nesto na laptopu al to je mozda do veze

Morat cu dati malome da isproba crtane na youtubu .))

Flash je pretežak za taj Sempron pa zato youtube šteka sada bi trebo sredit drivere za integriranu Radeonku HD4200 da UVD2 proradi pa će bilo koji video (mislim da je do 1080p) radit bez problema.

Drivere mogu skinuti negdje sa neta ili moram to na neki drugi nacin rijesit??

14 godina
offline
Re: Virus-kako ga uklonit?
josips100 kaže...
breader kaže...
josips100 kaže...

Hvala Vam ljudi

 

Cini se da sam problem riješio,zasad radi normalno{#}

 

Skuzio sam da mi malo steka kad gledam nesto na laptopu al to je mozda do veze

Morat cu dati malome da isproba crtane na youtubu .))

Flash je pretežak za taj Sempron pa zato youtube šteka sada bi trebo sredit drivere za integriranu Radeonku HD4200 da UVD2 proradi pa će bilo koji video (mislim da je do 1080p) radit bez problema.

Drivere mogu skinuti negdje sa neta ili moram to na neki drugi nacin rijesit??

Da, imaš na HP-ovoj stranici. Možeš ručno ili pomoću ovog utilityja.

Ne obaziri se na TD. To su trollovi.
9 godina
neaktivan
offline
Virus-kako ga uklonit?

HP was unable to verify that you have this product, but did find other products.

 

Com. Presario ......
» Software & driver downloads
» Support & troubleshooting
» Learn how to help HP find your product

 
0 0 hvala 0
14 godina
offline
Re: Virus-kako ga uklonit?
josips100 kaže...

HP was unable to verify that you have this product, but did find other products.

 

Com. Presario ......
» Software & driver downloads
» Support & troubleshooting
» Learn how to help HP find your product

Napiši mi točan model laptopa.

Ne obaziri se na TD. To su trollovi.
9 godina
neaktivan
offline
Re: Virus-kako ga uklonit?

Compaq Presario CQ61 Notebook PC

 

dali ti je ovo dovoljno??laptop sam kupovao prije 4,5 god tako da se vise ne sjecam detalja

 

 

14 godina
offline
Re: Virus-kako ga uklonit?
josips100 kaže...

Compaq Presario CQ61 Notebook PC

 

dali ti je ovo dovoljno??laptop sam kupovao prije 4,5 god tako da se vise ne sjecam detalja

 

 

Nije. Trebam točan model jer s ovime ne mogu ništa. Ima preko 80 modela s tom oznakom.

Ne obaziri se na TD. To su trollovi.
9 godina
neaktivan
offline
Virus-kako ga uklonit?

MODEL

CQ61-425EM

 
0 0 hvala 0
15 godina
offline
Re: Virus-kako ga uklonit?
1
Nova poruka
E-mail:
Lozinka:
 
vrh stranice