[ bykoki @ 08.10.2010. 17:57 ] @
Pozdrav, od prepodne mi se desava da mi se prekida internet, sa Malwarebytes' Anti-Malware mi prikazuje
--------------------------------------------------------
Inficirani procesi u memoriji:
C:\WINDOWS\system32\msvmiode.exe (Backdoor.Bot) -> Unloaded process successfully.
C:\WINDOWS\cfdrive32.exe (Trojan.Agent) -> Failed to unload process.

Inficirani moduli u memoriji:
(Maliciozne stavke nisu pronađene)

Inficirani ključevi u registru:
(Maliciozne stavke nisu pronađene)

Inficirane vrednosti u registru:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msodesnv7 (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft driver setup (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\microsoft driver setup (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\shell (Worm.Palevo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Worm.Palevo) -> Quarantined and deleted successfully.

Inficirani podaci u registru:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (C:\RECYCLER\S-1-5-21-1412536315-7278018949-042774263-0837\syscr.exe,explorer.exe,C:\Documents and Settings\KOKI\Application Data\ltzqai.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.

Inficirane fascikle:
(Maliciozne stavke nisu pronađene)
-------------------------------------------------------------------------------
Odem u safe mode i obrisem a isto mi se vraca i dolazi do prekida interneta pa onda opet u safe mod i jovo nanovo!
Koristim 32-bitni Windows i kablovski internet
Unapred hvala!