[ bykoki @ 17.09.2010. 10:19 ] @
Pozdrav, od juce mi se desava da mi se prekida internet, sa Malwarebytes' Anti-Malware mi prikazuje
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msodesnv7 (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

Inficirani podaci u registru:
(Maliciozne stavke nisu pronađene)

Inficirane fascikle:
(Maliciozne stavke nisu pronađene)

Inficirane datoteke:
C:\WINDOWS\system32\msvmiode.exe (Trojan.FakeAlert.H) -> Delete on reboot.
C:\RECYCLER\S-1-5-21-4456262612-4903033749-606910049-5773\syscr.exe

---------------------------------------------------------------------
Odem u safe mode i obrisem a on se vraca kasnije!
Sa HijackThis isto analiziram,

O4 - HKLM\..\Policies\Explorer\Run: [Microsoft Driver Setup] C:\WINDOWS\cfdrive32.exe
O4 - HKLM\..\Run: [Microsoft Driver Setup] C:\WINDOWS\cfdrive32.exe

Cekiram cfdrive32.exe na dva mesta i opet nanovo nakon gasenja kompa
Unapred hvala!







[Ovu poruku je menjao bykoki dana 17.09.2010. u 11:40 GMT+1]