|
|
Poslao: 14 Dec 2008 19:25
|
offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
Malware anti bytes 16infected files troja.vundo a negde trojan.vundo.h sad cu uradiiti i nod scan .. sliku iz proces explrer ne mogu da posaljem jer kad idem prikaci sliku pa browse uoste ne reaguje....
Ovo sfc /scannow ne znam da li smem da uradim jer imam sp3 a na tom cd je integrisan sp2
PS Da li da je removujem taj vundo pomocu malware anti bytes
|
|
|
|
|
Poslao: 14 Dec 2008 20:31
|
offline
- veljko-94
- Zaslužni građanin
- Pridružio: 29 Jul 2008
- Poruke: 615
- Gde živiš: Zemun
|
Malwarebytes' Anti-Malware 1.31
To je log trazio je da restartujem komp jer ne moze odmah da izbrise 2 fajla.Posle restarta sve radi normalno barem za sada!
Database version: 1500
Windows 5.1.2600 Service Pack 3
12/14/2008 7:31:33 PM
mbam-log-2008-12-14 (19-31-33).txt
Scan type: Quick Scan
Objects scanned: 56382
Time elapsed: 3 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 8
Registry Values Infected: 1
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 6
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
C:\WINDOWS\system32\rqRLedbC.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\rqRKAQHA.dll (Trojan.Vundo) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04e29d03-9f42-4bd0-9d09-e3bad63b3524} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{04e29d03-9f42-4bd0-9d09-e3bad63b3524} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqrkaqha (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\rqrledbc -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\rqrledbc -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\rqRLedbC.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\CbdeLRqr.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\CbdeLRqr.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rqRKAQHA.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Documents and Settings\FlAmE of HeLl\Local Settings\Temporary Internet Files\Content.IE5\5SM8S25V\divx[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
Dopuna: 14 Dec 2008 20:31
Windows explorer mi je otvorio stranu sa nekakvim 360 antivirusom.....Ne verujem bash da je to antivirus..
|
|
|
|
Poslao: 14 Dec 2008 20:35
|
offline
- diarno
- Anti Malware Fighter
Rank 2
- Pridružio: 15 Jun 2007
- Poruke: 5572
|
Otvori temu u Ambulanti...
I nemoj da ga dpwnloadujes.
|
|
|
|