11.03.2004., 08:35
|
#11
|
Moderator
Datum registracije: Aug 2003
Lokacija: Zagreb
Postovi: 3,193
|
Citiraj:
Originally posted by vsantek5
E, dragi moji evo famozni log od "HijackThis"-a, pa ako netko kuži i zna kaj mi to živi u kanti bez mog znanja, i jo bolje kako to istrijebiti neka slobodno, uz veliku zahvalu, javi...
|
U jebote. Sta si ti radio, tj. gdje si ti sve bio
Code:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.htnet.hr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about :blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about :blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about :blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about :blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about :blank
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - D:\PROGRA~1\STARDO~1\SDIEInt.dll
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.c...37990.725162037
Restartaj komp pa opet postaj log.
Vidim da je pokrenut "D:\DOCUME~1\ChoroDj\LOCALS~1\Temp\svshost.exe", a ne mogu naci pomocu cega. Vjerovatno koristi neku skriptu ili se smjestio negdje gdje HijackThis ne smatra da je opasno. Uglavnom, izbrisi "D:\DOCUME~1\ChoroDj\LOCALS~1\Temp\svshost.exe". Ako ce ti se javljati greska da file ne postoji pri loadanju Windowsa onda jednostavno pokrenes regedit (START>RUN i upises regedit", pozicioniras se u sam root (na pocetak) i pretrazis za svshost i pazi kaj brises jer sigurno se smjestio u liniju nekog korsnog programa.
|
|
|