treba mi OTS.txt file koji si dobio nakon skeniranja, posalo si mi OTS. exe :)
xD nisam obraco paznju
otvori OTS i ovo kopiraj u prazno polje
[Unregister Dlls]
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: URLSearchHooks\\"{472734EA-242A-422b-ADF8-83D1E48CC825}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
YN -> "{AEB6717E-7E19-11d0-97EE-00C04FD91972}" [HKLM] -> Reg Error: Key error. []
[Files/Folders - Created Within 30 Days]
NY -> bI42900NbGpL42900 -> C:\Documents and Settings\All Users\Application Data\bI42900NbGpL42900
[Files/Folders - Modified Within 30 Days]
NY -> yikcodf.sys -> C:\WINDOWS\System32\drivers\yikcodf.sys
NY -> 9gdczk.png -> C:\Documents and Settings\Maras\My Documents\9gdczk.png
NY -> 8 C:\WINDOWS\Temp\*.tmp files -> C:\WINDOWS\Temp\*.tmp
NY -> 138 C:\Documents and Settings\Maras\Local Settings\temp\*.tmp files -> C:\Documents and Settings\Maras\Local Settings\temp\*.tmp
NY -> 138 C:\Documents and Settings\Maras\Local Settings\temp\*.tmp files -> C:\Documents and Settings\Maras\Local Settings\temp\*.tmp
[Files - No Company Name]
NY -> yikcodf.sys -> C:\WINDOWS\System32\drivers\yikcodf.sys
NY -> 9gdczk.png -> C:\Documents and Settings\Maras\My Documents\9gdczk.png
NY -> oafcpcef.qqj -> C:\Documents and Settings\All Users\Application Data\oafcpcef.qqj
[File - Lop Check]
NY -> bI42900NbGpL42900 -> C:\Documents and Settings\All Users\Application Data\bI42900NbGpL42900
[Alternate Data Streams]
NY -> @Alternate Data Stream - 1007 bytes -> C:\Documents and Settings\Maras\Local Settings\Application Data\MAtCSWW4I58pB:busLQG7HzwVCQeJwsb
NY -> @Alternate Data Stream - 1059 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:xstSF6WI2cHlw05f0rabJa
NY -> @Alternate Data Stream - 109 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
NY -> @Alternate Data Stream - 1152 bytes -> C:\Program Files\WindowsUpdate:vcVoraHlSpkgzPB9PnPTjDbO
NY -> @Alternate Data Stream - 1172 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:cZZToU1FAXZm330BMKFvytlsv
:files
c:\program files\eidos interactive
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
klik na RUN FIX
-nakon restarta ćeš dobiti novi log kojeg ćeš isto kopirati
2.skini combofix i spremi na desktop
-isključi antivirus realtime zaštitu
-pokreni combofix i na sve što traži odgovori potvrdno
-log koji dobiješ kopiraj