offline
- NIx Car
- Legendarni građanin
- Més que un club
- Glavni vokal @ Harpun
- Pridružio: 27 Feb 2009
- Poruke: 3898
- Gde živiš: Novi Sad,Klisa
|
Korak 1:
Otvoriti Notepad i iskopirati sledeci tekst:
Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{908abdd0-74d6-433b-aed5-8f3e7f792319}"=-
"{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{908abdd0-74d6-433b-aed5-8f3e7f792319}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{908abdd0-74d6-433b-aed5-8f3e7f792319}"=-
[-HKEY_CLASSES_ROOT\TYPELIB\{908abdd0-74d6-433b-aed5-8f3e7f792319}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{908ABDD0-74D6-433B-AED5-8F3E7F792319}"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"Windows Defender"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost]
"netsvcs"=hex(7):36,74,6f,34,00,41,70,70,4d,67,6d,74,00,41,75,64,69,6f,53,72,\
76,00,42,72,6f,77,73,65,72,00,43,72,79,70,74,53,76,63,00,44,4d,53,65,72,76,\
65,72,00,44,48,43,50,00,45,52,53,76,63,00,45,76,65,6e,74,53,79,73,74,65,6d,\
00,46,61,73,74,55,73,65,72,53,77,69,74,63,68,69,6e,67,43,6f,6d,70,61,74,69,\
62,69,6c,69,74,79,00,48,69,64,53,65,72,76,00,49,61,73,00,49,70,72,69,70,00,\
49,72,6d,6f,6e,00,4c,61,6e,6d,61,6e,53,65,72,76,65,72,00,4c,61,6e,6d,61,6e,\
57,6f,72,6b,73,74,61,74,69,6f,6e,00,4d,65,73,73,65,6e,67,65,72,00,4e,65,74,\
6d,61,6e,00,4e,6c,61,00,4e,74,6d,73,73,76,63,00,4e,57,43,57,6f,72,6b,73,74,\
61,74,69,6f,6e,00,4e,77,73,61,70,61,67,65,6e,74,00,52,61,73,61,75,74,6f,00,\
52,61,73,6d,61,6e,00,52,65,6d,6f,74,65,61,63,63,65,73,73,00,53,63,68,65,64,\
75,6c,65,00,53,65,63,6c,6f,67,6f,6e,00,53,45,4e,53,00,53,68,61,72,65,64,61,\
63,63,65,73,73,00,53,52,53,65,72,76,69,63,65,00,54,61,70,69,73,72,76,00,54,\
68,65,6d,65,73,00,54,72,6b,57,6b,73,00,57,33,32,54,69,6d,65,00,57,5a,43,53,\
56,43,00,57,6d,69,00,57,6d,64,6d,50,6d,53,70,00,77,69,6e,6d,67,6d,74,00,77,\
73,63,73,76,63,00,78,6d,6c,70,72,6f,76,00,6e,61,70,61,67,65,6e,74,00,68,6b,\
6d,73,76,63,00,42,49,54,53,00,77,75,61,75,73,65,72,76,00,53,68,65,6c,6c,48,\
57,44,65,74,65,63,74,69,6f,6e,00,68,65,6c,70,73,76,63,00,57,6d,64,6d,50,6d,\
53,4e,00,00
Driver::
pcouffin
afs2k
spmgr
symlcbrd
afs2k
spmgr
symlcbrd
NwSapAgent
backupexecnotificationserver
nvport
sscdbhk5
ppmoucls
gbpoll
pxfhbus
enethusb
hpci
wacomvhid
symids
netdevio
aswlsvc
pdlnshay
starwindservice
k750obex
MA8032U
pserve
MSSQL$MSSMLBIZ
BCM43XV
mcstrm
bthenum
Defrag32
AmdIde
avg7core
oracleorahomepagingserver
USBDongle
ZuneWlanCfgSvc
wap3gx
gmer
sentinel
AVWLP_USB
truecrypt
stylexphelper
DVDVRRdr_xp
LKbdFlt2
WSIMD
cpsvc
pxfhmdm
cdudf_xp
regservice
pdlndint
nvidesm
hibernation
IWCA
oracleoradb10g_home1isql*plus
SE2Dmgmt
adfs
idebusdr
ntpr_nic_service2
MRESP50
amon
se45mdfl
sysplant
transactional
ser2plms
StillCam
DELL_A02
Invoker
U3sHlpDr
ndiscm
mdmxsdk
ProcObsrv
P16X
AmdLLD
mysql
CVPNDRVA
wintabservice
AF15BDA
mqdmmdm
w22n51
LCcfltr
mdc8021x
downloadmanagerlite
REVOSENS
pnkbstra
DevUpper
tgsrvc_smartagent
ino_fltr
l8042pr2
PNDIS5
CBTNDIS5
om518p
mcafeeframework
nicser_wmp11
p2psvc
2wirepcp
npapimon
trackcam4
MSMQTriggers
AsIO
pinnacleupdatesvc
ONSIO
FINEPIX_PCC
ccsetmgr
w200bus
Cinemsup
Mtlstrm
s616mdm
liveupdate
RDID1027
yats32
SWNC8U51
SSFS0BB9
odclientservice
djsnetcn
pdscheduler
SE2Bobex
roammgr
apfiltrservice
wampapache
filterservice
exfat
incdfs
navapsvc
proxyserverservice
imonitor
se59mdm
SrvcSSIOMngr
ibmpmdrv
acrsch2svc
iaimfp2
vci
UlSata
sleepy
hpqcxs08
dvpapi
oraclemtsrecoveryservice
mhn
websensepolicyserver
w550bus
AsuhfivrO
mssql$sqlexpress
pchost
a016obex
zebrmdfl
SeratoUsb
LMS
GoToAssist
ssdiagn
Shockprf
naimagent32
s116mdm
VRADFIL
hsf_dpv
spbbcdrv
STV680
SECYPUSB
smcservice
jobserver_report
TMBMServer
whoisd32
hpconfig
PcdrNt
s616mgmt
prepdrvr
incdrm
usbatapi2000
GoProto
NMSAccessU
vaiomediaplatform-videoserver-appserver
sscdmdfl
ntsyslog
prtg4service
vsbus
clcapsvc
orbmediaservice
rmedia
SE2Dmdm
bmwebcfg
thkeys
pdlndtdl
s716nd5
SetupSys
USB_RNDIS_XP
cmdmon
se59mgmt
CnxTrLan
commserver
ELkbd
fshttps
bgs_sdservice
msgsrvservice
kbfiltr
AFGSp50
epson_pm_rpcv2_01
VIAPFD
mindretrieve
WD_FireWire_HID
GT891x
mcp
besclient
lemsgt
easdrv
AdobeActiveFileMonitor6.0
cfosspeed
rampartsvc
snac
alertmanager
enum1394
raysatxsi5_0server
pdlnemsg
db2
PAC7302
venturi2
prodrv06
USRpdA
USR1806V
steamdvr
vxsvc
mrpostman
pdengine
Tb2RCAssist
se45nd5
se44mgmt
lxrjd31s
xaudioservice
CSRBC
vmauthdservice
syntp
mr2kserv
winvnc4
adobeactivefilemonitor4.0
ifxspmgtsrv
nhcDriverDevice
iomegaaccess
nmwcdcm
dnsexit
nsm1serd
P17xfi
LRMINIPORT
LVRS
mfeapfk
AN983
Folder::
c:\program files\MjTunes.com
File::
c:\documents and settings\P4\Application Data\explorer.exe
DDS::
MigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm941YYRS&fl=0&ptb=k1WhwAhCwxJo1YKz62Hesw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}
Firefox::
FF - ProfilePath - c:\documents and settings\P4\Application Data\Mozilla\Firefox\Profiles\vpjidu5e.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1750559&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZCxdm941YYRS&fl=0&ptb=k1WhwAhCwxJo1YKz62Hesw&st=kwd&o=kwd&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&searchfor=
Snimiti na Desktop fajl iz Notepada kao "CFScript"
Prevuci snimljeni skript/tekst na ComboFix ikonicu kao na slici.
Postaviti u sledecoj poruci log koji bude bio napravljen na kraju ciscenja/skeniranja.
Korak 2
Spakuj u ZIP ili RAR arhivu sledeći folder:
C:\Qoobox\Quarantine
i pošalji ga preko sledećeg linka:
http://www.mycity.rs/ambulanta-upload.php
NIx Car (AMF Tim)
|