UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.4.26.0.cab (SysInfo Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
:Services
AVTasks2
AVBackup
ArcaRemoteService
:Files
C:\Program Files\Google\Update
C:\Documents and Settings\zoltar\Menu Start\Programy\Autostart\PowerReg Scheduler.exe
C:\RECYCLER
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\mgxoschk.ini
C:\Documents and Settings\zoltar\Moje dokumenty\cc_20111212_122901.reg
C:\WINDOWS\PEV.exe
C:\WINDOWS\sed.exe
C:\WINDOWS\grep.exe
C:\WINDOWS\zip.exe
C:\WINDOWS\System32\lua5.1a_gui.exe
C:\WINDOWS\System32\lua5.1a.exe
C:\WINDOWS\System32\lua5.1a.dll
C:\Documents and Settings\LocalService\Dane aplikacji\ArcaBit
:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"=-
[HKEY_USERS\S-1-5-21-1644491937-1482476501-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"=-
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"50000:TCP"=-
"50001:TCP"=-
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
Files to delete:
E:\autorun.inf
E:\kyme.exe
E:\w9.exe
:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search bar = http://search.msn.com/spbasic.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [Binary data over 100 bytes]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Services
gupdatem
gupdate
:Files
C:\RECYCLER
C:\ComboFix
C:\UsbFix_Upload_Me_PECET.zip
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
:Services
gupdate
gupdatem
:Files
kyme.exe /alldrives
w9.exe /alldrives
C:\found.00*
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: could not open file "E:\autorun.inf"
Deletion of file "E:\autorun.inf" failed!
Status: 0xc0000102 (STATUS_FILE_CORRUPT_ERROR)
Error: could not open file "E:\kyme.exe"
Deletion of file "E:\kyme.exe" failed!
Status: 0xc0000102 (STATUS_FILE_CORRUPT_ERROR)
Error: could not open file "E:\w9.exe"
Deletion of file "E:\w9.exe" failed!
Status: 0xc0000102 (STATUS_FILE_CORRUPT_ERROR)
Completed script processing.
*******************
Finished! Terminate.
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
:OTL
:Files
C:\RECYCLER
C:\Avenger
:Commands
[clearallrestorepoints]
[emptytemp]
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
c:\documents and settings\all users\dokumenty\TRANSFER\driver.genius.pro. pl.v8.0+keygen\keygen.exe (Trojan.Dropper.PGen)No action taken.
c:\program files\gothic iii\crack\Gothic3.exe (RiskWare.Tool.CK)No action taken.
c:\program files\Pinnacle\studio 11\programs\Keygen.exe (Trojan.Downloader)No action taken.
c:\program files\WinRAR\keygenpatch.exe (Malware.Packer.Gen)No action taken.
e:\FILM\convertxtodvd_4.0.9.322a\convertxtodvd 4.0.9.322a [pl] [+keygen brd]\Keygen.exe (Trojan.Agent.CK)No action taken.
f:\Satelita\Odzysk 2\wypal nowe\abbyy.fine.reader.v7.0.pl\key generator\hgo-fr7p.exe (Malware.Packer.Gen)No action taken.
f:\Satelita\Odzysk 2\Instalki\nero\Keygen.exe (Trojan.Downloader)No action taken.
f:\Satelita\Odzysk 2\pliki z torrenta\win_xp_sp2\legalizator\program i klucz\keyfinder.exe (RiskWare.Tool.CK)No action taken.
f:\obrazy iso\Assasin\004 megawarez.eu\crack assassin's creed 2\crack assassins cred ii\assassins.creed.ii-skidrow-crackonly-rw\assassins.creed.ii-skidrow-crackonly-rw\SKIDROW\ubiorbitapi_r2.dll (Trojan.Agent.CK)No action taken.
Odzysk\gry małe instalki\tumblebugs.+.keygen\keygen.exe (RiskWare.Tool.CK)
No action taken.
DC\keygen.exe (Malware.Gen)
No action taken.
UA: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
mati8898 napisał(a):Czy nie masz czasem na tej pamięci jakiejś blokady zapisu lub czegoś podobnego??? Bo dziwne, że nie można tych plików usunąć.
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
kominekl napisał(a):Czekam na raport Malwarebytes`a.
Czy na tym koncie masz uprawnienia administratora?
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
UA: Mozilla/5.0 (Windows NT 5.1; rv:8.0) Gecko/20100101 Firefox/8.0
Zarejestrowani użytkownicy: Bing [Bot]