![]() |
problemi s internetom
koristim mozillu firefox. kad sam na internetu, svakih nekoliko minuta mi se otvaraju neke čudne stranice. Kupite ovo kupite ono....
Stalno stiskam back i uvik me prokinu dok nešto radim. Spybot ništa ne nađe, a AdAware mi bloka. Kako se rješit toga. Evo baš mi se otvorilo. Ova stranica mi se otvara većinom puta http://www.deal-pro.com/normal/yyy102.html |
Logfile of HijackThis v1.99.1
Scan saved at 20:34:30, on 20.11.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\SpywareBlaster\spywareblaster.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\Kraljević\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank O4 - HKCU\..\Run: [Cydoor] CD_Load.exe O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{9B8AF4B8-37B2-4843-B58A-38A839B80C9E}: NameServer = 195.29.150.3 195.29.150.4 O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\t6r80g9ue6.dll O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe |
dajte pomozite. upilalo me. ne mogu ništa normalno radit bez ovih reklama
|
probaj ubiti ovo:
O4 - HKCU\..\Run: [Cydoor] CD_Load.exe O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\t6r80g9ue6.dll |
makni taj spyware blaster, to ne koristi kurcu.
a ukloni slijedece: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about :blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about :blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about :blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about :blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about :blank O4 - HKCU\..\Run: [Cydoor] CD_Load.exe O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\t6r80g9ue6.dll O20 - Winlogon Notify: msctl32.dll - C:\WINDOWS\system32\msctl32.dll (file missing) O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) provrti malo sa cwshredderom. program sam uklanja sve inace cool web search trojana. restart. ad-aware ili spy-bot - scan (u ad-aware neka ti bude ukljuceno scan within archives. budi siguran da ti je verzija up to date) nakon toga hijack this, i copy paste ovdje. |
takodjer u control panelu pogledaj da ti se nije instalirao neki toolbar, internet optmizer neki ad-watcher ili neka slicna gamad. uninstall. takodjer izbrisi foldere iz program files.
pod documents and settings/ odredjeni username/ local settings / temp pogledaj da nemash kakav exe sumnjivi imenom poput ovih gore programcica. delete. da bi mogao vidjeti local settings morash imati ukljuceno show hidden files and folders. |
nije pomoglo opet me jebe
Logfile of HijackThis v1.99.1 Scan saved at 14:59:39, on 21.11.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Documents and Settings\Kraljević\Desktop\hijackthis\HijackThis.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O17 - HKLM\System\CCS\Services\Tcpip\..\{9B8AF4B8-37B2-4843-B58A-38A839B80C9E}: NameServer = 195.29.150.3 195.29.150.4 O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\irl8l53u1.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\irl8l53u1.dll
ovo ne mogu ubit |
Citiraj:
|
Citiraj:
ides pod services i ugasis ga. ako nece niti tako, downloadaj ovaj programcic, i upisi puni path do tog dll-a, dakle: C:\WINDOWS\system32\irl8l53u1.dll ukljuci delete on reboot i restartaj. program "ubija" procese dok kazes keks. ........ keks. :D to bi trebalo biti to. |
Citiraj:
|
ma ne može ga ni ovaj izbrisat. Možda ima neki drugi način. jel možeš malo detaljnije objasnit kako se stavi da izbriše nakon resetiranja
Kad stavim "delete file" kaže da ne može O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\ir80l5lm1.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
evo uspija sam izbrisat, ali kad god izbrišem pojavi se ista stvar,samo sa drugim .dll fileom
evo sad O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O17 - HKLM\System\CCS\Services\Tcpip\..\{9B8AF4B8-37B2-4843-B58A-38A839B80C9E}: NameServer = 195.29.150.3 195.29.150.4 O20 - Winlogon Notify: Group Policy - C:\WINDOWS\system32\hr0005dme.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: NVIDIA Driver Helper Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
Mali & Brz. Pali uvjek. Format C:
Bez zejebancije.... Najbolje riješenje... Ulovi vremena i napravi :smoke: |
eh, sad vishe ni sam ne znam. duboko je u registryu, trebalobi ga odandje brisati, a i dobro prouciti registry.
probaj mozda prvo sa spysweeperom ocistiti po disku, on zna ukloniti ovog parazita koji otvara pop-upove. i jos jedna stvar. mislim da je vrijeme da prestanesh koristiti IE, jer sto taj moze smeca nabrati, cudo jedno... |
Ma ne koristim IE nego firefox, ali san bija instalira kazaa, i od tada je sve otišlo u kurac
|
spy cleaner je sve rješija. više nema problema, radi k'o puška
hvala svima na pomoći |
spysweeper i spycleaner su mi uvijek kao posljednje sanse, jer su rijetko rjeshavale probleme, super da ti je pomoglo.
ajd pazi ubuduce na spyware. surf safely! :beer: |
Sva vremena su GMT +2. Sada je 14:49. |
Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
© 1999-2024 PC Ekspert - Sva prava pridržana ISSN 1334-2940
Ad Management by RedTyger