Jump to content

SUBIECTE NOI
« 1 / 5 »
RSS
Mezina familiei, Merida BigNine

The Tattooist of Auschwitz (2024)

Se poate recupera numar de telefo...

Upgrade de la MacBook Pro M1 cu 8...
 Ce tip de monitor am nevoie pt of...

Resoftare camera supraveghere

Cu ce va aparati de cainii agresi...

Nu imi platiti coletul cu cardul ...
 Exista vreun plan de terorizare p...

Schimbare adresa DNS IPv4 pe rout...

Recomandare Barebone

Monede JO 2024
 Suprasolicitare sistem electric

CIV auto import

Mutare in MOZAMBIC - pareri, expe...

Scoatere antifurt airtag de pe ha...
 

Virus

- - - - -
  • Please log in to reply
30 replies to this topic

#1
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Aseara am descoperit ca nu pot accesa siteuri care contin numele SUPERAntiSpyware ,virus si urmatoarele :
spyware
malware
rootkit
defender
microsoft
symantec
norton
mcafee
trendmicro
sophos
panda
etrust
networkassociates
computerassociates
f-secure
kaspersky
jotti
f-prot
nod32
eset
grisoft
drweb
centralcommand
ahnlab
esafe
avast
avira
quickheal
comodo
clamav
ewido
fortinet
gdata
hacksoft
hauri
ikarus
k7computing
norman
pctools
prevx
rising
securecomputing
sunbelt
emsisoft
arcabit
cpsecure
spamhaus
castlecops
threatexpert
wilderssecurity
windowsupdate

Incerc sa scanez cu Avira si scanarea nu are loc ..trece la 100% scan completed fara sa scaneze ceva
Cred ca am nevoie de ajutor

Postez un log hijackthis

Logfile of Trend Micro HiJackThis v2.0.2
Scan saved at 12:27:32, on 1/12/2009
Platform: Windows XP SP3, v.3244 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.3244)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\OEM02Mon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.ro
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cool-digitv.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.ro
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.ro
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.ro
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.ro
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.google.ro
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.ro
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.mi...b?1229646725744
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4FEECD9-E5CF-453D-8162-8F512C8E7293}: NameServer = 141.85.0.81 141.85.0.82
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs:  C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\WINDOWS\system32\DRIVERS\xaudio.exe

--
End of file - 9335 bytes

#2
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,228
  • Înscris: 10.02.2006
alecs, descarca si instaleaza update-ul Microsoft.
Apoi, descarca de aici arhiva de curatare: http://rapidshare.co...ownadup.Gen.zip.
Extrage si apoi ruleaza Anti-Downadup-graphics.exe din arhiva.

Succes!

#3
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
nu ma lasa sa intru pe http://www.microsoft...;DisplayLang=en     :confuzzled:

Aveam WORM... am dat restart la calc si acum am scanat din nou si mi-a zis ca sistem clean, acum vad ca ma lasa sa intru pe siteuri :D ma lasa sa fac update la superantispyware

Vai si-a revenit complet..nu imi vine sa cred..mii de multumiri  pykko sa traiesti 1000 de ani  :OK: :worthy: :worthy: : :worthy: :worthy:
A mers doar cu Anti-Downadup-graphics.exe
Daca poti sa ma lamuresti de unde m-am pricopsit cu un asa virus sau ce era ala worm..

Edited by p_alecs, 12 January 2009 - 14:54.


#4
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,228
  • Înscris: 10.02.2006
E un nou virus care circula pe internet. Detalii aici: http://www.malwareci...emoval-326.html

Descarca acel update de la Microsoft pentru e preveni reinfectarea.

#5
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
Si incearca sa tii Windows Update la zi ;)

#6
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Da am instalat si update-ul , va multumesc tare mult m-ati salvat..eram cat pe ce sa formatez iar C-ul

Ar mai fi o problema..dau la tools folder options si show hidden files ....si nu face asa ceva..ii dau apply si degeaba ramane tot pe hidden.. asta nu am idee de la ce ar putea sa fie.

#7
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Am pus Avira premium .. am scanat..aseara .. am scanat si cu bitdefender online, am scanat si cu bit scanerul acela tot de la bit pt win32 downdup si era totul OK

Acum ma vrut sa accesez un site antivirus si mi-am dat seama ca imi da acea eroare..am scanat iar cu Anti-Downadup-graphics.exe si IAR am virusul :( ..credeam ca am scapat de el..se pare ca a reaparut

#8
rootkit

rootkit

    Awake. Security DNA

  • Grup: Senior Members
  • Posts: 34,883
  • Înscris: 07.02.2007
http://www.faravirus...se-ce-pot-face/

Ia vezi asta :)

#9
lityroby

lityroby

    New Member

  • Grup: Members
  • Posts: 20
  • Înscris: 29.10.2008
Uita'te in Control Panel-Internet Option-Security-Restricted sites si vezi daca este vre'un site trecut acolo. Daca nu icearca alt browser sa vezi daca merge.

#10
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
crysty2k5, mersi o sa ma uit imediat

Edited by p_alecs, 14 January 2009 - 17:03.


#11
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Tot nu mi-a rezolvat problema cu view hidden files ....

SI pt problema cu win32downdup . sistem restore il las OFF?

Edited by p_alecs, 14 January 2009 - 17:37.


#12
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,228
  • Înscris: 10.02.2006
System Restore il poti reactiva.
Legat de view hidden files and folders, descarca arhiva atasata, extrage Repara.inf pe Desktop, click-dreapta pe el si alege Install. Apoi restarteaza PC-ul.

Attached Files



#13
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Tot nu merge :( se pare ca e mai complicat decat credeam cu view hidden files

Il legatura cu win32downadup , am aflat ca este in toata reteaua..am net din camin cica il au cam toti :(

#14
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,228
  • Înscris: 10.02.2006
p_alecs, du-te la Start-> Run si scrie acolo regedit si apasa Enter.
Navigheaza la HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL.
In dreapta sterge cheia: CheckedValue, apoi da click-dreapta intr-o zona alba din dreapta si creeaza o noua valoare Dword pe care numeste-o CheckedValue. Da dublu-click pe ea si seteaza valoarea 1.

#15
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
:coolspeak:   :thumbup:  in sfarsit merge, mersi mult ca ti-ai batut capul cu problemele mele   :worthy:

#16
frexxl

frexxl

    Active Member

  • Grup: Members
  • Posts: 1,589
  • Înscris: 16.05.2005
ce chestie , cat haos a facut virusul asta in ultima vreme

#17
p_alecs

p_alecs

    Junior Member

  • Grup: Members
  • Posts: 171
  • Înscris: 23.05.2007
Am verificat mai multe pc-uri si la toate nu puteam da view hidden files... Face ravagii virusul asta..nu gluma  :death:
Poti trece aceasta solutie si la tine pe Blog :|

am facut testul de pe blog la comodo si am obtinut Score 30/340      :confuzzled:

Edited by p_alecs, 14 January 2009 - 22:54.


#18
pykko

pykko

    I love, therefore I am

  • Grup: Senior Members
  • Posts: 7,228
  • Înscris: 10.02.2006
Cu placere alecs.
Conform F-Secure, sunt peste 4 milioane de Pc-uri infectate momentan.
Romania se afla undeva pe locul 8-9 ca numar de infectii. Suntem si noi undeva printre primii intr-un clasament. :D

Anunturi

Chirurgia spinală minim invazivă Chirurgia spinală minim invazivă

Chirurgia spinală minim invazivă oferă pacienților oportunitatea unui tratament eficient, permițându-le o recuperare ultra rapidă și nu în ultimul rând minimizând leziunile induse chirurgical.

Echipa noastră utilizează un spectru larg de tehnici minim invazive, din care enumerăm câteva: endoscopia cu variantele ei (transnazală, transtoracică, transmusculară, etc), microscopul operator, abordurile trans tubulare și nu în ultimul rând infiltrațiile la toate nivelurile coloanei vertebrale.

www.neurohope.ro

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Forumul Softpedia foloseste "cookies" pentru a imbunatati experienta utilizatorilor Accept
Pentru detalii si optiuni legate de cookies si datele personale, consultati Politica de utilizare cookies si Politica de confidentialitate