Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Help: Otvaranje porno stranica

745 views
Skip to first unread message

Anthony

unread,
Nov 30, 2005, 10:47:21 AM11/30/05
to
Imam jedan problem koji trebam rijesit sto prije. Naime, na poslu su se samo
odjednom pocele otvarati nekakvi sex-explorer i sl. stranice svakih pola
sata-sat. Provjerim sve spyware i nista ne pronadje. Kako to rijesit s
obzirom da dolaze i stranke koje mogu vidjeti tako nesto ako se odjednom
otvori.


makni ovo @gmail.com <-- tOO -->

unread,
Nov 30, 2005, 12:35:34 PM11/30/05
to

"Anthony" <adem...@inet.hr> wrote in message
news:dmkhsa$7s$2...@bagan.srce.hr...

hahaha...koja lolčina.....probaj sam ad-awareom...meni uvijek sve nadze....
pozdrav
tOO


Miner

unread,
Nov 30, 2005, 2:35:34 PM11/30/05
to

"<-- tOO -->" <tookiehr makni ovo @gmail.com> wrote in message
news:dmknr5$q5c$1...@ss405.t-com.hr...
>Ad-aware, Spybot i CWShredder. Skini zadnje definicije za Ad-aware i
>Spybot. Potom s sva tri alata napravi ful scan. Ako se nesto ne moze
>izbrisati onda sve isto ponovi iz Safe Moda.


Anthony

unread,
Nov 30, 2005, 3:58:23 PM11/30/05
to
Upravo sa prva 2 programa sa zadnjom definicijom sam napravio full scan,
nesto je nasao i obrisao, ali jos uvijek se otvara, ne vidim nista ni u
control panelu na add remove programs. Ne znam kakav je ovaj CWShedder.
Mozda da i njega probam...

"Miner" <ivan....@st.t-com.hr> wrote in message
news:dmkutr$f11$1...@ss405.t-com.hr...

Kostur

unread,
Nov 30, 2005, 7:57:58 PM11/30/05
to
Pa pokusaj napisati KONKRETNO sto ti se otvara, znaci ime ili adresu
stranice i procese koji su ti u systemu. Dobro ti je covjek na
hr.comp.software rekao ima i strucnijih ljudi


Anthony

unread,
Dec 1, 2005, 5:00:37 AM12/1/05
to
Evo linkova nekih stranica koje se otvaraju

http://www.whatpornsite.com/websiteReviews/teen/index.shtml

http://www.sex-explorer.com/?cntid=746&login=793680&nums=EAJCBaCAAA-EAFWDoVAAA

http://www.sex.giantexplorer.com/sex_enhancers/result/penis-enlargement&source=Sexgoleo-accountlemonc

http://access.rapid-pass.net/?id=1344&login=793680&nums=EABiA.FAAA-EAFWBCdAAA

http://best-warez.us/search.php?q=free+porn

Hijackthis izlista ovo:

Logfile of HijackThis v1.99.1
Scan saved at 10:53:28, on 1.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\ActivCard\accoca.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Program Files\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\Program Files\ActivCard\ActivCard Gold\agquickp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Sophos SWEEP for NT\ICMON.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP2SWK.EXE
C:\WINDOWS\system32\NALDESK.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Dobrila\Local Settings\Temp\wze481\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.htnet.hr/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program
Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [gemstrmw] C:\WINDOWS\system32\gemstrmw.exe /r
O4 - HKLM\..\Run: [QuickPassword] C:\Program Files\ActivCard\ActivCard
Gold\agquickp.exe
O4 - HKLM\..\Run: [CAP2ON]
C:\WINDOWS\system32\Spool\Drivers\w32x86\3\CAP2ONN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Global Startup: Canon LASER SHOT LBP-1210 Status Window.LNK =
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP2LAK.EXE
O4 - Global Startup: InterCheck Monitor.LNK = C:\Program Files\Sophos SWEEP
for NT\ICMON.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O17 -
HKLM\System\CCS\Services\Tcpip\..\{2BFB1EC5-6B6C-4CA9-AA5E-B52A89F795C0}:
NameServer = 195.29.150.3,195.29.150.4
O23 - Service: ActivCard Gold service (Accoca) - ActivCard - C:\Program
Files\Common Files\ActivCard\accoca.exe
O23 - Service: Ati HotKey Poller - Unknown owner -
C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation -
C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Remote management (Novell WUser Agent) - Novell, Inc. -
C:\NOVELL\ZENRC\wuser32.exe
O23 - Service: Sophos Anti-Virus Network (SweepNet) - Sophos Plc -
C:\Program Files\Sophos SWEEP for NT\SWNETSUP.EXE
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program
Files\Sophos SWEEP for NT\SWEEPSRV.SYS
O23 - Service: WUOLservice (WUOLService) - Novell, Inc. -
C:\NOVELL\ZENRC\WUOLService.exe

"Kostur" <kos...@net.hr> wrote in message
news:dmlhoo$f8o$1...@bagan.srce.hr...

Para

unread,
Dec 1, 2005, 5:06:30 PM12/1/05
to
Ni ja ti nemogu sa sigurnoscu reci sto da zbrises u HijackThis-u...doduse,
ja sebi redovito brisem sve kaj mi je sumnjivo pa nemam nikakvih problema ;)
Spybot i slicna sranja ne koristim nakon jednog gadnog spyware koji me
ubijao dok nisam puko...

Dakle, prvo bih ti preporucio da si skines sa neta program REGISTRAR LITE.
to je freeware
Upisi to samo u google i skini ga. On je programcic tipa regedit koji dolazi
sa windowsima ali je 5 puta bolji.
Naime, meni se desilo da mi Regedit od windowsa nije vidio jedan entry u
HKLM\...\Run folderu, a ovaj je.
Probaj sljedece: Skini taj program i procesljaj po registry-u ove foldere:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce

Pregledaj ih i u REGISTRAR Lite-u i u obicnom regedit-u pa vidi da li imas
neki entry kojeg ne vidis u regedit-u.
Ako nadjes nekog, stisni u Registrar-u na njega desni gumb pa properties a
onda pogledaj pod value:
Tamo ce ti onda pisat ime nekog file-a u windows\system\ folderu koji se
uvalio tamo i stalno generira nova sranja svaki put pod drugim imenom.
To je mene izludjivalo...a mozda je i tebi nesto tipa toga ako ti bas niti
jedan program nece nista sredit.

Ja HijackThis-om cistim sebi sistem sam...kada opalim scan, imam samo 20 th
objekata jer me uzasno zivciraju svi ti nepotrebni procesi i sl.
Ne zelim ti nesto krivo reci, niti te krivo savjetovati ali evo, ipak cu ti
napisati kaj bi ja sve zbrisao iz ovog tvog log-a:

ZENRC tray?! Nemam pojma kaj je to! Ako ni ti neznas sta ti se to pali svaki
put sa sistemom, zbrisi.
Nista se nebi trebalo crashirat...samo kaj se nece automatski dici sljeeci
put. Ako vidis da ti to ipak treba, onda ga vrati sa backup u HijackThis-u.


O4 - HKLM\..\Run: [ZENRC Tray Icon] zentray.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE

Isto...ako neznas cemu sluzi, ja bi zbriso:


O4 - HKLM\..\Run: [gemstrmw] C:\WINDOWS\system32\gemstrmw.exe /r

Ovo je od e-bankarstva vjerojatno...to si ostavi ;)


O4 - HKLM\..\Run: [QuickPassword] C:\Program
Files\ActivCard\ActivCardGold\agquickp.exe

Checker ti treba, bas kao i ctfmon.exe. To nemoj brisat.


O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

Ovo bi ja isto delete-ao:


O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"


Ovo je ono microsoft messenger smece...to bi odmah deinstalirao:
Ako i ti to pozelis, stisni Start, pa run pa upisi ovo: RunDll32
advpack.dll,LaunchINFSection %windir%\INF\msmsgs.inf,BLC.Remove

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O17 -

Neznam kaj je ovo, a to bi mi bio dovoljan razlog da i to zbrisem ;)


HKLM\System\CCS\Services\Tcpip\..\{2BFB1EC5-6B6C-4CA9-AA5E-B52A89F795C0}:
NameServer = 195.29.150.3,195.29.150.4

Znaci, brisi sve kaj ti je sumnjivo ;)
Ali, nemoj poludit ako se nesto crashira ;) Namjera je bila najbolja ;)


Kostur

unread,
Dec 1, 2005, 8:40:39 PM12/1/05
to
Pokusaj jos instalirati
1. Giant antispyware
2. Pestpatrol

Imas i popratne crack dodatke za oba na netu

Malo poznati programi ali ODLICNI. Samo update i onda scan. Pestpatrol mozes
podesiti da ti i jace skenira sistem i trazi vise stetocina. Moja topla
preporuka


Anthony

unread,
Dec 2, 2005, 7:20:36 AM12/2/05
to
Sve isto sto nadje Regedit nadje i Registar Lite, nema razlika.

"Para" <par...@yahoo.com> wrote in message
news:dmnru7$adq$1...@ss405.t-com.hr...

0 new messages