Tema: Ats.: Re:Ats.: Ilindo koks tai sudas, kaip pagauti?
Autorius: siGis
Data: 2017-02-10 16:35:52
Procesu eksploreris is sysinternlo startuoja su langais. Naudoju 
vietoje Task menedzerio, nes informatyvesnis. Pameginsiu ta funkcija 
su virus total, bet regis ten reikes kiekviena procesiuka atskirai 
cekint, jei per ta laiko hemoroju insitaisysiu tai gal geriau nereikia 
:)

Brudo instalerius lyg ir radau C:\Windows\TEMP\rewB8A6.tmp\secondu71\ 
kataloge. Issitryne klusniai, daug nesisakojo. Praskanavus "360 Total 
Security" (labai neblogas ir visiskai nemokamas antiviruiokas) dar 
suranda pora trojanu363 ir viena chrome.lnk. Sitie jau is kitos 
melodijos, bet kazkodel neiveikia ju sutvarkyti.

Gal to ir uzteks. Dabar tik svarstau likti su Windous Essential, ar 
naudotis kitu antivirusu.

------------------------
Type:
Win32/Trojan.363

Grouping:
Process loading module

Scan Engine:
360 Cloud Scan Engine

File path:
c:\programdata\microsoft\devicesync\localbackup.dll

File size:
476K (487,424 Bytes)

MD5:
611323a332dc48fdf0059bf1d277c526

Process ID:
2528

Process path:
C:\Windows\System32\svchost.exe

Suggestion:
Quarantined files
---------------------------------------


Type:
Win32/Trojan.363

Grouping:
Process loading module

Scan Engine:
360 Cloud Scan Engine

File path:
c:\programdata\microsoft\office\office_updater.dll

File size:
475.5K (486,912 Bytes)

MD5:
6deadb4ccce334ad108ce403e65ca0cc

Process ID:
2504

Process path:
C:\Windows\System32\svchost.exe

Suggestion:
Quarantined files
------------------------------------------------


Type:
Invalid shortcut:Google Chrome.lnk

Description:
The file pointed to by this shortcut does not exist; this may be 
because the program is not completely uninstalled or the shortcut is a 
Trojan remnant.

Scan Engine:
System Repair Engine

Suggestion:
Delete
---------------------------------------






"marijonas"  parašė naujienų news:o7jnsl$o3m$1@trimpas.omnitel.net...

"siGis" <o.@.o> Wrote in message:
> Nelabai paprasti budai.
>
> "nezinomas"  parašė naujienų 
> news:o7fvar$3ch$1@trimpas.omnitel.net...
>
> atjungi PC nuo interneto, lupi HDD lauk arba bootinies is kokio live
> usb/cd
> su portable OS ir skanuoji su antivirusu visa HDD
> paprastas variantas: atjungi nuo interneto PC, per USB flasha suseri
> PC
> Trojan removeri, ADW cleaner praskenuoji su jais po to papildomai su
> antivirusine kokia nori
>
> "siGis" <o.@.o> wrote in message
> news:o7fv1l$39o$1@trimpas.omnitel.net...
>> Koks tai sudeliakas slapta vis isntaliuoja Chrome, Mozilla, aMuleC,
>> dar kazkokias programeles, isjungia Microsoft essentials, pakeicia
>> pagrinidnes narsykles nustatyma, ikelia visokiu nuorodu, narsykles
>> instaliuoja be uninstaleriu. Niekaip nensiseka pagauti.
>>
>> siGis
>> ---------------------------------- 
>>
>

Nu jei offline per sudetinga, tai parsisiunti process explorer is
sysinternals, options nurodai kad failus patikrintu su
virustotal.
Ir ziurai..
-- 


----Android NewsGroup Reader----
http://usenet.sinaapp.com/