Join Today
+ Odgovori na temu
Prikazujem rezultate 1 do 3 od 3

Tema: virus?

  1. #1
    Pravi forumaš Postignuća:
    Veteran5000 Experience Points

    Datum registracije
    Dec 2006
    Lokacija
    Novska
    Mobitel
    k800
    Operater
    t-mobile
    Godina
    45
    Postova
    108
    Bodovi
    9.579
    Nivo
    23
    Bodovi: 9.579, Nivo: 23
    Bodovi: 9.579, Nivo: 23
    Ukupna aktivnost: 0%
    Ukupna aktivnost: 0%
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    virus?

    koristim AVG i nasao je neki virus u system volume information a zove se win32/pepatch? sto je to? kako djeluje ili je on samo onak da se pojavi?

  2. #2
    Hardcore forumaš Postignuća:
    VeteranTagger Second Class10000 Experience Points

    Datum registracije
    Jan 2007
    Lokacija
    http://localhost/
    Godina
    33
    Postova
    748
    Bodovi
    18.575
    Nivo
    33
    Bodovi: 18.575, Nivo: 33
    Bodovi: 18.575, Nivo: 33
    Ukupna aktivnost: 0%
    Ukupna aktivnost: 0%
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Backdoor ime mu je Rbot.FAY evo riješenja na eng.
    turn off system restore...delete the"SRDISKID.DAT" in the _restore folder...either the one on c:\, d:\, e:\, ect. depends how many partitions and drives you have.
    check your msconfig startup items. Make sure there is not 2 IEXPLORE's running there. If there is, look to see if one has a zero (0) instead of an oh (o). Delete/disable it if it has a zero, as well as delete it's corresponding registry key.restart the computer.
    make sure you have a good software firewall to make sure it is not "sending out" any info.

    Virus Name: Rbot.FAY
    Pervasiveness:
    3 of 5
    Destructiveness:
    3 of 5
    Wildness:
    2 of 5
    Type: Worm
    Aliases: [Win32/]Rbot.FAY; [Win32/]Spybot.4wq!Worm (InoculateIT); [Win32/]Packed.Win32.PePatch.aw (Kaspersky); [Win32/]Rbot.FAY;

    Date Modified: 11-May-2006
    Date Published: 11-May-2006

    Description:

    Win32.Rbot.FAY is an IRC controlled backdoor (or "bot") that can be used to gain unauthorized access to a victim's machine. It can also exhibit worm-like functionality by exploiting weak passwords on administrative shares and by exploiting many different software vulnerabilities, as well as backdoors created by other malware. There are many variants of Rbot, and more are discovered regularly. Rbot is highly configurable, and is being very actively developed, however the core functionality is quite consistent between variants.

    This particular variant of Rbot is distributed as a 71,578 byte, Win32 executable that exhibits the following specific characteristics:

    When executed this variant copies itself to the %System% directory as W1nUpdate.exe and makes the following modifications to the registry to ensure that this file is executed at each Windows system start:

    HKLM\Software\Microsoft\Wind ows\CurrentVersion\Run\Microsoft Windows Update Service = "w1nupdate.exe"
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run Services\Microsoft Windows Update Service = "w1nupdate.exe"

    Note: '%System%' and '%Windows%' are variable locations. The determines the location of these folders by querying the operating system. The default location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32. The default installation location for the Windows directory for Windows 2000 and NT is C:\Winnt; for 95,98 and ME is C:\Windows; and for XP is C:\Windows.
    Reply With Quote
    Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like. My crime is that of outsmarting you, something that you will never forgive me for.

  3. #3
    Pravi forumaš Postignuća:
    Veteran5000 Experience Points

    Datum registracije
    Dec 2006
    Lokacija
    Novska
    Mobitel
    k800
    Operater
    t-mobile
    Godina
    45
    Postova
    108
    Bodovi
    9.579
    Nivo
    23
    Bodovi: 9.579, Nivo: 23
    Bodovi: 9.579, Nivo: 23
    Ukupna aktivnost: 0%
    Ukupna aktivnost: 0%
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    "SRDISKID.DAT" nisam ga nasao,avg je uklonio sve,virus je bio u deamon tool cracku

    thx


 
+ Odgovori na temu

Slične teme

  1. virus!!??
    By T o m o T in forum Internet i zaštita
    Odgovora: 6
    Posljednji post: 09-06-2007, 15:16
  2. Virus na cd- u
    By nix1001 in forum Internet i zaštita
    Odgovora: 8
    Posljednji post: 29-01-2007, 00:52
  3. Virus
    By FatalERROR in forum Internet i zaštita
    Odgovora: 6
    Posljednji post: 29-12-2006, 13:38
  4. Virus
    By >>RENEGADE<< in forum Internet i zaštita
    Odgovora: 6
    Posljednji post: 18-12-2004, 00:57

Bookmarks

Pravila postanja

  • Ne možeš stvarati nove teme
  • Ne možeš odgovarati na postove
  • Ne možeš slati privitke
  • Ne možeš mijenjati svoje postove