offline
- 1l padr1n0
- Anti Malware Fighter
Rank 2
- Pridružio: 02 Feb 2008
- Poruke: 14018
- Gde živiš: Nish
|
Izvinjavam se sto malo kasnim sa odgovorom.
Otvoriti Notepad i iskopirati sledeci tekst:
SecCenter::
{C37D8F93-0602-E43C-40AA-47DAD597F308}
{77DEAFED-8149-104B-25A1-21771CA47CD1}
{781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
{CCBF4E09-A773-1FC5-1F11-1A056723366C}
KillAll::
File::
c:\windows\Xtahyg.exe
c:\windows\Xtahyf.exe
c:\windows\Xtahye.exe
c:\windows\Xtahyd.exe
c:\windows\Xtahyc.exe
c:\windows\Xtahyb.exe
c:\windows\Xtahya.exe
DirLook::
c:\programdata\jFlJhAn08501
c:\windows\system32\%APPDATA%
DDS::
uStart Page = hxxp://start.facemoods.com/?a=wbst
Firefox::
FF - ProfilePath - c:\users\lelic\AppData\Roaming\Mozilla\Firefox\Profiles\rcmc0tal.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.facemoods.com/?a=wbst
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZLman000&ptb=5TNF9DFAo.9gt1GP0UVApA&psa=&ind=2010111506&ptnrS=ZLman000&si=&st=kwd&n=77cfde12&searchfor=
FF - Ext: Facemoods: ffxtlbr@Facemoods.com - %profile%\extensions\ffxtlbr@Facemoods.com
RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d8,9e,da,34,95,c5,50,4c,b7,1a,cf,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d8,9e,da,34,95,c5,50,4c,b7,1a,cf,\
[HKEY_USERS\S-1-5-21-83685119-447350358-3884237969-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
[HKEY_USERS\S-1-5-21-83685119-447350358-3884237969-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
goran9888 (AMF Tim)
|