@spock1
Nasao virut na jos par mesta. Zanimljivo je da mu se nesto dopadaju Realtek driveri
Ocistio komp ali win se i dalje gasi. Upravo instaliram novi win. Ne vredi drugacije.
SBB server zaražen sa W32/Virut.Gen,prilikom podizanja sistema dok se još nisu pokrenuli antivirusni programi zaraženi svi pokrenuti sistemski windows fajlovi,napominjem da internet ne radi jer nije plaćen,samo je putem mrežnog kabla komp povezan sa modemom
Begin scan in 'C:\WINDOWS\system32\drivers\sysdrv32.sys'
C:\WINDOWS\system32\drivers\sysdrv32.sys
[DETECTION] Is the TR/Hacktool.Tcpz.A Trojan
[NOTE] The registration entry <HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\sysdrv32\ImagePath> was removed successfully.
[NOTE] The registration entry <HKEY_LOCAL_MACHINE\System\ControlSet001\Services\sysdrv32\ImagePath> was removed successfully.
[NOTE] The file was moved to the quarantine directory under the name '4f1b559f.qua'.
Begin scan in 'C:\WINDOWS\system32\vssvc.exe'
C:\WINDOWS\system32\vssvc.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was moved to the quarantine directory under the name '05d32a03.qua'.
Begin scan in 'C:\WINDOWS\system32\dllhost.exe'
C:\WINDOWS\system32\dllhost.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was moved to the quarantine directory under the name '267b492c.qua'.
Begin scan in 'C:\WINDOWS\system32\24.scr'
C:\WINDOWS\system32\24.scr
[DETECTION] Is the TR/Hamweq.A Trojan
[NOTE] The file was repaired!
[NOTE] The file was moved to the quarantine directory under the name '4f5e547b.qua'.
Begin scan in 'C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2J6M96XF\x[1]'
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\2J6M96XF\x[1]
[DETECTION] Is the TR/Hamweq.A Trojan
[NOTE] The file was moved to the quarantine directory under the name '05bb2b91.qua'.
Begin scan in 'C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe'
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\Program Files\Messenger\msmsgs.exe'
C:\Program Files\Messenger\msmsgs.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\rsmsink.exe'
C:\WINDOWS\system32\rsmsink.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was moved to the quarantine directory under the name '267a499d.qua'.
Begin scan in 'C:\WINDOWS\inf\unregmp2.exe'
C:\WINDOWS\inf\unregmp2.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\regedit.exe'
C:\WINDOWS\regedit.exe
[DETECTION] Is the TR/Patched.IT.1 Trojan
[NOTE] The file was repaired!
[NOTE] The file was moved to the quarantine directory under the name '59677132.qua'.
Begin scan in 'C:\WINDOWS\system32\ati2sgag.exe'
C:\WINDOWS\system32\ati2sgag.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\cisvc.exe'
C:\WINDOWS\system32\cisvc.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\clipsrv.exe'
C:\WINDOWS\system32\clipsrv.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\dmadmin.exe'
C:\WINDOWS\system32\dmadmin.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\drwtsn32.exe'
C:\WINDOWS\system32\drwtsn32.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\ie4uinit.exe'
C:\WINDOWS\system32\ie4uinit.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\imapi.exe'
C:\WINDOWS\system32\imapi.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\locator.exe'
C:\WINDOWS\system32\locator.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\logon.scr'
C:\WINDOWS\system32\logon.scr
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\logonui.exe'
C:\WINDOWS\system32\logonui.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\magnify.exe'
C:\WINDOWS\system32\magnify.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\mnmsrvc.exe'
C:\WINDOWS\system32\mnmsrvc.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\mshta.exe'
C:\WINDOWS\system32\mshta.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\netdde.exe'
C:\WINDOWS\system32\netdde.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\notepad.exe'
C:\WINDOWS\system32\notepad.exe
[DETECTION] Is the TR/Patched.IT Trojan
[NOTE] The file was repaired!
[NOTE] The file was moved to the quarantine directory under the name '15c05d5c.qua'.
Begin scan in 'C:\WINDOWS\system32\ntsd.exe'
C:\WINDOWS\system32\ntsd.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\ntvdm.exe'
C:\WINDOWS\system32\ntvdm.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\osk.exe'
C:\WINDOWS\system32\osk.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\rdpclip.exe'
C:\WINDOWS\system32\rdpclip.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\regsvr32.exe'
C:\WINDOWS\system32\regsvr32.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\rsvp.exe'
C:\WINDOWS\system32\rsvp.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\WINDOWS\system32\rundll32.exe'
C:\WINDOWS\system32\rundll32.exe
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was repaired!
Begin scan in 'C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVSCAN-20101116-221516-7FDBA906\ARKE.tmp'
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\AVSCAN-20101116-221516-7FDBA906\ARKE.tmp
[DETECTION] Contains code of the W32/Virut.Gen Windows virus
[NOTE] The file was moved to the quarantine directory under the name '44f938b5.qua'.