Šta je novo?

Ne mogu da podignem XP u safe modu

gagivozi

Slavan
Učlanjen(a)
16.01.2007
Poruke
32
Poena
304
U pitanju je neki virus koji mi ne dozvoljava da udjem u registry, a ne mogu ni da podignem OS u safe modu. Ima li neko ideju? Iskenirao sam ga launch om, nod32, i nasao je puno virusa i hostova. Medjutim i dalje ne mogu da udjem u registry, a ni da podignem racunar u safe modu.

Iskljucio sam sistem restore, obrisao temp fajlove, cookije...

A sada sam napravio glupost No1
U msconfigu sam ukljucio opciju da se podigne sistem u safe modu i sada mogu da se slikam..
Ne mogu vise nikako da podignem OS, dodje do xp slicice i resetuje se
Ukoliko ima neko neku ideju sta da radim..

Eh.. Izgleda da svi spavaju..
Nista.. Necu vise da gubim vreme uradicu ponovo instalaciju..
Mada je problem veoma interesantan..
Pozz
 
Poslednja izmena od urednika:
Bio je virus u pitanju. Da ne verujes. Malwarebytes' Anti-Malware je resio sve probleme za 5 minuta.
A ja se mucio ceo dan..
Pozz svima
 
Ali I DALJE NE MOGU DA UDJEM U SAFE MODE!!!
NEVEROVATNO! Ovo jos nisam doziveo..
 
Poslednja izmena:
Pa, da ni tako ni kada ga u msconfig podesis - neeeece..
A nemam vise viruse (iskenirao sa sto antivirusa).
I jos nesto - ne mogu da se ulogujem kao administrator (mislim onaj njegov administrator). Inace moj nalog ima sva prava i sada mogu da editujem i registri i sve ostalo...
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:09:35, on 1/26/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Borland\InterBase\bin\ibguard.exe
C:\Program Files\Borland\InterBase\bin\ibserver.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\totalcmd\TOTALCMD.EXE
F:\Antivirus\Malware\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: artlbbdll.dll - {5A041F13-A111-12A4-B0CF-F99818AA68A5} - (no file)
O2 - BHO: archibidll.dll - {5A041F13-A111-12A5-B0CF-F99818AA68A5} - (no file)
O2 - BHO: armoyudll.dll - {5A041F13-A111-12B0-B0CF-F99818AA68A5} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [put120] put120.exe
O4 - HKLM\..\Policies\Explorer\Run: [kne12] kne12.exe
O4 - HKLM\..\Policies\Explorer\Run: [nwiz] alitte32.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{BCB970EA-BE19-41E6-A4C2-0E754994C5D8}: NameServer = 192.168.3.1
O20 - AppInit_DLLs: qzyerd.dll,HBQQXX.dll
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibguard.exe
O23 - Service: InterBase Server (InterBaseServer) - Borland Software Corporation - C:\Program Files\Borland\InterBase\bin\ibserver.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 4785 bytes
 
Deinstaliraj taj Nod pa skini Kaspersky trial verziju i pusti da ti ocisti komp. Znaci taj virus koji ti je ostao na kompu kaspersky ima definicije za njega, tako bar pise

alitte32.exe - Identified as Trojan-Spy.Win32.Agent.gmo by Kaspersky antivirus.

Imas ga na nekoliko mesta u logu, ako ne uspes, javi pa cemo da probamo nesto drugo.
 
Nazad
Vrh Dno