U pitanju je malware:
U c:\windows\system32 folderu ti se nalazi "lazni" notepad.exe koji radi sledece: pri startovanju bilo kog *.txt file-a on se pokrece, kopira sebe pod imenom svchost.exe u c:\windows\ i ubacuje ti gomilu sajtova u favorites listu (a verovatno radi i stosta drugo :wall: ) Posto ga ni Panda Platinum nije pronasla :trust: , a meni su se stalno pojavljivale "nezeljene"
😀 stranice, nasao sam ga rucno :type: ( ne bi ni posumnjao da nije tog "bug"-a ), tako sto sam pronasao notepad.exe (pravi) i video da radi, znaci da je u windows reg. promenjena putonja do file-a. I pored pokusaja da ga obrisem (taj svchost.exe, koliko me secanje sluzi tezi oko 3kb) u safe modu, stalno se vracao, pa sam posumnjao da ga nesto drugo pokrece, pa sam skontao da ga pokrece bas "lazni" notepad.exe, tako da sam ga lepo stavio u quarantine, i poslao Panda labs-u.
Evo dela njihovog mail-a:
Dear customer:
We are enclosing a link to the updated signature file.
http://www.pandasoftware.com/virus_info/disclaimer.htm
This file has been created in order to detect and disinfect your
malware. We will shortly make available to all our customers the new
certified signature file, which will be accessible through the automatic
updates.
Once the virus signature file is downloaded, please follow the procedure
below:
1.- Decompress the PAV.ZIP file in the directory where your Panda
product is installed.
2.- Restart your computer and use your antivirus normally.
Should you have any question about this process, you may contact our
technical support department (
[email protected]), where you
will be given the appropriate indications.
The file notepad.exe belongs to the spyware of type adware detected as
Adware/BestSearch by Panda products that offer protection against this
kind of
malware.
The following advice will help you to eliminate the Adware/BestSearch
and protect
yourself against it in future.
Visit our web page with information about the malware:
http://www.pandasoftware.com/virus_info/enc/overview.aspx?idvirus=47923
Follow the instructions on how to eliminate the malware:
http://www.pandasoftware.com/virus_info/enc/solution.aspx?idvirus=47923
If your computer has Windows Millennium or Windows XP installed, you can
find information to permanently remove all trace of the virus in the
following URL:
Windows Milenium
http://www.pandasoftware.com/support/card.aspx?id=17&IdIdioma=2
Windows XP
http://www.pandasoftware.com/support/card.aspx?id=18&IdIdioma=2
At
http://www.pandasoftware.com/virus_info there is extensive
information on all malware detected by our antivirus, as well as the
steps to take to remove them from your system.
If you want more information on how to update your antivirus and the
action to take when new viruses appear, visit our Support pages at:
http://www.pandasoftware.com/support/. You will also find full
information and FAQs about your product.
We hope this answer has been helpful and do not hesitate to contact us
should you need any suspicious file analyzed in future.
Znaci ni hvala mi nisu rekli
😀 😀 😀
Boldovao sam ti link sa uputstvima za odstranjivanje, mada meni nakon quarantine-a nije bio potreban.
Nadam se da ce ti ovo pomoci.
Poz!
Edit: ako je moguce promenite naziv thread-a, da bi se znalo da je u pitanju virus.