[ -V-O-Y-A-G-E-R- @ 07.09.2004. 13:52 ] @
Cim se konektujem primetim da mi nesto zagusuje protok, upload i radi, ali primanje podataka je otezano. Kad ubijem winrtx.exe sve se unormali. Cemu sluzi taj fajl i zasto pravi problem.
[ filo @ 07.09.2004. 14:19 ] @
da te obradujem
http://www.sophos.com/virusinfo/analyses/w32agobotoz.html
drugim recima
W32/Agobot-OZ
Citat:
W32/Agobot-OZ is a backdoor Trojan and worm which spreads to computers
protected by weak passwords.

When first run, W32/Agobot-OZ copies itself to the Windows system folder as
winrtx.exe and creates the following registry entries to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Configurations Loader = winrtx.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Configurations Loader = winrtx.exe

The Trojan runs continuously in the background providing backdoor access to
the computer.

The Trojan attempts to terminate and disable various anti-virus and security-
related programs and modifies the HOSTS file located at
%WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus
websites to the loopback address 127.0.0.1 in an attempt to prevent access to these sites. Typically the following mappings will be appended to the HOSTS file:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com

trecim recima - nabavi neki DOBAR antivirus i ne surfuj bez njega i firewalla
[ -V-O-Y-A-G-E-R- @ 07.09.2004. 15:04 ] @
E super! :) Imao sam Nortona, ali iz nekog nepoznatog mi razloga (sad je poznat:) nije hteo da se updatuje, pa sam ga skinuo pre par dana, a jos uvek ima Zone Alarm Pro 5.
Hvala.
[ filo @ 07.09.2004. 22:52 ] @
za pocetak nadji neki antivirus
mislim da cak i stinger cisti taj tvoj problem
a kao privremeno resenje na kom radi update imas besplatne avg ili avast home antivirus
[ -V-O-Y-A-G-E-R- @ 07.09.2004. 23:13 ] @
Jesi video da je u hostovima blokiran i nai.com :)
Stinger mi je prvi i pao na pamet. Sredicu to sutra.
Hvala na brzom odgovoru! :)